Compare commits

...
Author SHA1 Message Date
Fedor Kororkov 057646cf89 Fix Tart release code signing (#1284) 2026-07-17 14:47:15 -04:00
Nikolai TillmannandClaude Fable 5 512c1c3630 Fix busy loop in tart exec -i after piped stdin reaches EOF (#1281)
Unregister the stdin readabilityHandler when availableData returns empty:
a closed pipe fd stays permanently readable, so Foundation re-invokes the
handler in a tight loop (fstat + zero-byte read) at 100% of one core for
the rest of the command's lifetime.

Fixes #1280

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 08:56:27 -04:00
Fedor Kororkov 9e6e59b379 [codex] Publish Tart to openai/homebrew-tools (#1277)
* Publish Tart to openai/homebrew-tools

* Write Tart formula under Formula directory

* Use macOS 26 runners

* docs: install Tart tools from OpenAI tap

* Add required GitHub Actions test check

* Fix hosted tests and notarization credentials
2026-07-16 21:32:18 -04:00
Greg Hurrell 32d084e9ed fix(homebrew): wrap macOS version dependency in on_macos block (#1264)
GoReleaser's Homebrew template always emits a bare `depends_on :macos`
for macOS-only formulae. Combining that with the `depends_on :macos =>
:ventura` line injected via custom_block triggers a Homebrew deprecation
warning on `brew upgrade`:

  Warning: Calling `depends_on :macos` with `depends_on macos:` is deprecated! Use `depends_on :macos` with `depends_on macos:` inside an `on_macos` block instead.
  Please report this issue to the cirruslabs/homebrew-cli tap (not Homebrew/* repositories), or even better, submit a PR to fix it:
    /opt/homebrew/Library/Taps/cirruslabs/homebrew-cli/tart.rb:22

Declaring the version constraint inside an `on_macos` block is the form
Homebrew recommends and silences the warning without changing behavior
(still macOS-only, Ventura or newer).
2026-06-15 18:25:38 -04:00
Tor Arne Vestbø 0a01a4430c Fix build warnings (#1262)
* Use let for the immutable disk image storage attachment

* Don't bind the unused error when catching connection-pool failures

* Report errors thrown inside tart run's fire-and-forget tasks

We were discarding any error thrown inside these unstructured tasks,
which silently hid failures to run the control socket or to start and
stop the VM, and which the compiler now warns about.

Wrap them in an ErrorReportingTask, which spawns the task and reports
any thrown error to stderr, rather than repeating a do/catch at every
call site. An unstructured task spawned from a synchronous context (a
signal handler or SwiftUI action) has no parent to propagate the error
to, so reporting it is the best we can do.

* Avoid blocking SwiftNIO calls in async guest agent connections

The gRPC channel setup in "tart exec" and the MAC address resolver
created a dedicated event loop group and tore both it and the channel
down with the blocking syncShutdownGracefully() and wait(), which are
unavailable from async contexts (the former is an error in the Swift 6
language mode).

Factor the connection out into a withGuestAgentChannel() helper that
uses the process-wide singleton event loop group, so there is no group
to shut down, and closes the channel with the async close().get().
2026-06-09 15:29:19 -07:00
Tor Arne Vestbø d1bfda63fc Add --provisioning-opts flag to provision macOS guests on first boot (#1263)
Exposes Apple's macOS 27 guest provisioning API
(VZMacGuestProvisioningOptions) so a macOS guest can be set up
automatically on the first boot after restore.

The flag takes a comma-separated list of key=value pairs mapping 1:1 to
the API properties (fullName, username, password, logsInAutomatically,
enablesRemoteLogin). It is validated to require a macOS 27+ host and a
macOS VM.

The entire user-facing surface is gated behind
'#if arch(arm64) && compiler(>=6.4)' so the flag doesn't appear in help
on toolchains that lack the macOS 27 SDK, while the runtime
'#available(macOS 27, *)' check gates actual use against the host OS.
2026-06-09 15:18:57 -07:00
Tor Arne Vestbø 2e63759c1b Don't run the AppKit run loop nested in Swift's async main (#1260)
When built against the macOS 27 (Xcode 27, Swift 6.4) SDK, "tart run"
brings up the VM window but the guest never boots.

Swift's asynchronous main() entry point implicitly starts an executor
that owns the main thread, and as of Swift 6.4 that executor is no
longer backed by the Dispatch main queue. Running an AppKit/SwiftUI
run loop nested inside it via MainApp.main() leaves the main run loop
unable to drain Swift tasks or DispatchQueue.main, so the task that
starts the VM is never scheduled, even though the window itself
(driven directly by AppKit during launch) still appears.

We now keep Root.main() synchronous, so that a command driving a run
loop can own the main thread at the top level, exactly like a plain
SwiftUI app. With AppKit owning the loop again, MainActor tasks and
the Dispatch main queue drain as before. Such commands opt in through
a new MainThreadCommand protocol; everything else keeps running
asynchronously via a detached task and dispatchMain().

Verified that the guest boots again, and that Ctrl+C still stops the
VM gracefully.
2026-06-09 09:53:06 -07:00
Fedor Kororkov 6ada2b955d Update README.md 2026-06-05 17:07:07 -07:00
Fedor Kororkov 1ea60ef420 Update docs after OpenAI move (#1240) 2026-06-05 17:05:23 -07:00
Fedor Kororkov 5ad172e7f0 Relicense under FSL-1.1-ALv2 (#1238)
* Relicense under FSL-1.1-ALv2

* Use project lifetime in copyright notice
2026-06-05 15:37:02 -07:00
Nikolay Edigaryev 5287b597a1 docs: clarify that nested virtualization is only for Linux VMs for now (#1233) 2026-05-12 21:45:18 +00:00
Fedor Korotkov 8aa377b71e Skip integration test gate for release (#1229) 2026-04-11 22:33:36 -04:00
Fedor Korotkov 1e52e17c21 Move brew completions to post_install (#1227)
* Move brew completions to post_install

* Reduce Layerizer test disk fixture size to 1GB

* Skip registry integration tests on Docker startup failure
2026-04-11 22:26:52 -04:00
Nikolay Edigaryev d39f7c6036 Docker-related fixes (#1221)
* tests: fix RegistryRunner's "-p" specification passed to "docker"

* tests: "docker" binary is now installed from Homebrew
2026-04-09 21:00:36 -07:00
Fedor Korotkov abfbb10618 [docs] Add announcement about joining OpenAI (#1223) 2026-04-07 03:55:20 -07:00
Nikolay Edigaryev 094f850046 Add Liquid Glass icon and sign the whole app bundle (#1216) 2026-03-20 23:19:21 +01:00
Fedor Korotkov f1305dc083 Update FAQ for local network prompt (#1211)
* Update FAQ for local network prompt

* Apply suggestions from code review
2026-03-06 17:57:06 +00:00
Nikolay Edigaryev 605234b5dd Mention macOS Tahoe everywhere instead of macOS Sequoia (#1208)
* Mention macOS Tahoe everywhere instead of macOS Sequoia

* Fix spurious rename
2026-03-02 08:50:29 -05:00
sneedandfeed be272d8abd Replace Sequoia with Tahoe in Quick Start's first few instructions & add Tahoe to images available (#1206)
* update quick-start.md for tahoe

* oops

* I forgot this part.
2026-02-27 08:27:59 -05:00
faa40b6832 Remove disk v1 support (#1204)
* Remove disk v1 support

* fix: address PR review feedback

- add explicit error for legacy disk.v1 media type during pull
- include actionable re-push guidance in runtime error

🤖 Generated with [Codex](https://chatgpt.com/codex)

Co-Authored-By: Codex <codex@openai.com>

* Re-use legacyDiskV1MediaType in error message

---------

Co-authored-by: Codex <codex@openai.com>
Co-authored-by: Nikolay Edigaryev <edigaryev@gmail.com>
2026-02-25 14:34:25 +00:00
Nikolay Edigaryev d45ef38cf7 StdinCredentials: increase maxCharacters to 8,192 (#1203) 2026-02-23 18:55:52 +01:00
Nikolay Edigaryev e26b376d51 tart list: remove "SizeOnDisk" and add "Accessed" field (#1202)
* tart list: introduce "Accessed" field to show last accessed date of a VM

* tart list: remove "SizeOnDisk" field as it's unused
2026-02-23 18:55:36 +01:00
Nikolay Edigaryev 8f8a24ad19 Use ghcr.io/squidfunk/mkdocs-material:latest container for docs (#1201)
* Use ghcr.io/squidfunk/mkdocs-material:latest container for docs

* CI: use ghcr.io/squidfunk/mkdocs-material:latest too
2026-02-17 14:59:25 -05:00
Fedor Korotkov 29e0606ea3 Update yearly pricing docs (#1197)
* Update yearly pricing docs

* fix: clarify pricing update in 2023 licensing post
2026-02-13 15:46:01 +00:00
Nikolay Edigaryev 594c6d74cd docs: migrate "Managing VMs" section to "Quick Start" (#1196) 2026-02-13 05:18:14 -05:00
Nikolay Edigaryev fc159c9992 docs: document TART_REGISTRY_HOSTNAME (#1195) 2026-02-12 21:56:24 +00:00
Nikolay Edigaryev 863e3c2925 Bind and connect to Unix domain sockets using relative paths (#1192) 2026-02-05 15:51:14 +01:00
Nikolay Edigaryev 372affb0dc Switch back to github.com/open-telemetry/opentelemetry-swift upstream (#1189) 2026-02-02 19:40:24 +01:00
87 changed files with 1229 additions and 1285 deletions
+24
View File
@@ -0,0 +1,24 @@
#!/bin/sh
set -eu
ARCH="$1"
SCRATCH_PATH=".build/$ARCH"
OUTPUT_PATH=".build/prebuilt/$ARCH"
swift build \
--build-system swiftbuild \
--scratch-path "$SCRATCH_PATH" \
--arch "$ARCH" \
--configuration release \
--product tart
BIN_PATH=$(swift build \
--build-system swiftbuild \
--scratch-path "$SCRATCH_PATH" \
--arch "$ARCH" \
--configuration release \
--show-bin-path)
mkdir -p "$OUTPUT_PATH"
cp "$BIN_PATH/tart" "$OUTPUT_PATH/tart"
+1 -1
View File
@@ -2,7 +2,7 @@
set -e
export VERSION="${CIRRUS_TAG:-0}"
export VERSION="${VERSION:-0}"
mkdir -p .ci/pkg/
cp .build/arm64-apple-macosx/release/tart .ci/pkg/tart
+8 -4
View File
@@ -1,7 +1,11 @@
#!/bin/sh
TMPFILE=$(mktemp)
envsubst < Sources/tart/CI/CI.swift > $TMPFILE
mv $TMPFILE Sources/tart/CI/CI.swift
set -e
/usr/libexec/PlistBuddy -c "Add :CFBundleShortVersionString string ${CIRRUS_TAG}" Resources/Info.plist
: "${VERSION:?VERSION must be set}"
TMPFILE=$(mktemp)
perl -pe 's/\$\{VERSION\}/$ENV{VERSION}/g' Sources/tart/CI/CI.swift > "$TMPFILE"
mv "$TMPFILE" Sources/tart/CI/CI.swift
/usr/libexec/PlistBuddy -c "Add :CFBundleShortVersionString string ${VERSION}" Resources/Info.plist
+24
View File
@@ -0,0 +1,24 @@
#!/bin/sh
set -eu
if [ "${TART_RELEASE_SNAPSHOT:-false}" = "true" ]; then
codesign \
--force \
--deep \
--sign - \
--entitlements Resources/tart-dev.entitlements \
dist/tart_darwin_all/tart.app
else
codesign \
--force \
--verbose \
--sign "Developer ID Application: Cirrus Labs, Inc. (9M2P8L4D89)" \
--timestamp \
--options runtime \
--keychain "$RUNNER_TEMP/build.keychain" \
--entitlements Resources/tart-prod.entitlements \
dist/tart_darwin_all/tart.app
codesign --verify --strict --verbose=2 dist/tart_darwin_all/tart.app
fi
+3 -89
View File
@@ -40,7 +40,7 @@ task:
name: Lint
alias: lint
macos_instance:
image: ghcr.io/cirruslabs/macos-runner:sequoia
image: ghcr.io/cirruslabs/macos-runner:tahoe
lint_script:
- swift package plugin --allow-writing-to-package-directory swiftformat --cache ignore --lint --report swiftformat.json .
always:
@@ -57,103 +57,17 @@ task:
name: Build ($BUILD_ARCH)
alias: build
macos_instance:
image: ghcr.io/cirruslabs/macos-runner:sequoia
image: ghcr.io/cirruslabs/macos-runner:tahoe
build_script: swift build --arch $BUILD_ARCH --product tart
sign_script: codesign --sign - --entitlements Resources/tart-dev.entitlements --force .build/$BUILD_ARCH-apple-macosx/debug/tart
binary_artifacts:
path: .build/$BUILD_ARCH-apple-macosx/debug/tart
task:
only_if: $CIRRUS_TAG == '' && ($CIRRUS_USER_PERMISSION == 'write' || $CIRRUS_USER_PERMISSION == 'admin')
name: Release (Dry Run)
depends_on:
- lint
- build
macos_instance:
image: ghcr.io/cirruslabs/macos-runner:sequoia
env:
MACOS_CERTIFICATE: ENCRYPTED[552b9d275d1c2bdbc1bff778b104a8f9a53cbd0d59344d4b7f6d0ca3c811a5cefb97bef9ba0ef31c219cb07bdacdd2c2]
AC_PASSWORD: ENCRYPTED[4a761023e7e06fe2eb350c8b6e8e7ca961af193cb9ba47605f25f1d353abc3142606f412e405be48fd897a78787ea8c2]
GITHUB_TOKEN: ENCRYPTED[!98ace8259c6024da912c14d5a3c5c6aac186890a8d4819fad78f3e0c41a4e0cd3a2537dd6e91493952fb056fa434be7c!]
GORELEASER_KEY: ENCRYPTED[!9b80b6ef684ceaf40edd4c7af93014ee156c8aba7e6e5795f41c482729887b5c31f36b651491d790f1f668670888d9fd!]
setup_script:
- cd $HOME
- echo $MACOS_CERTIFICATE | base64 --decode > certificate.p12
- security create-keychain -p password101 build.keychain
- security default-keychain -s build.keychain
- security unlock-keychain -p password101 build.keychain
- security import certificate.p12 -k build.keychain -P password101 -T /usr/bin/codesign -T /usr/bin/pkgbuild
- security set-key-partition-list -S apple-tool:,apple:,codesign: -s -k password101 build.keychain
- xcrun notarytool store-credentials "notarytool" --apple-id "hello@cirruslabs.org" --team-id "9M2P8L4D89" --password $AC_PASSWORD
install_script:
- brew install go
- brew install mitchellh/gon/gon
- brew install --cask goreleaser/tap/goreleaser-pro
info_script:
- security find-identity -v
- xcodebuild -version
- swift -version
goreleaser_script: goreleaser release --skip=publish --snapshot --clean
always:
dist_artifacts:
path: "dist/*"
task:
name: Release
only_if: $CIRRUS_TAG != ''
depends_on:
- lint
- test
- build
macos_instance:
image: ghcr.io/cirruslabs/macos-runner:sequoia
env:
MACOS_CERTIFICATE: ENCRYPTED[552b9d275d1c2bdbc1bff778b104a8f9a53cbd0d59344d4b7f6d0ca3c811a5cefb97bef9ba0ef31c219cb07bdacdd2c2]
AC_PASSWORD: ENCRYPTED[4a761023e7e06fe2eb350c8b6e8e7ca961af193cb9ba47605f25f1d353abc3142606f412e405be48fd897a78787ea8c2]
GITHUB_TOKEN: ENCRYPTED[!98ace8259c6024da912c14d5a3c5c6aac186890a8d4819fad78f3e0c41a4e0cd3a2537dd6e91493952fb056fa434be7c!]
GORELEASER_KEY: ENCRYPTED[!9b80b6ef684ceaf40edd4c7af93014ee156c8aba7e6e5795f41c482729887b5c31f36b651491d790f1f668670888d9fd!]
SENTRY_ORG: cirrus-labs
SENTRY_PROJECT: persistent-workers
SENTRY_AUTH_TOKEN: ENCRYPTED[!9eaf2875d51b113e2f68598441ff8e6b2e53242e48fcb93633bd75a373fbe2e7caa900d837cc92f0b142b65579731644!]
setup_script:
- cd $HOME
- echo $MACOS_CERTIFICATE | base64 --decode > certificate.p12
- security create-keychain -p password101 build.keychain
- security default-keychain -s build.keychain
- security unlock-keychain -p password101 build.keychain
- security import certificate.p12 -k build.keychain -P password101 -T /usr/bin/codesign -T /usr/bin/pkgbuild
- security set-key-partition-list -S apple-tool:,apple:,codesign: -s -k password101 build.keychain
- xcrun notarytool store-credentials "notarytool" --apple-id "hello@cirruslabs.org" --team-id "9M2P8L4D89" --password $AC_PASSWORD
install_script:
- brew install go getsentry/tools/sentry-cli
- brew install mitchellh/gon/gon
- brew install --cask goreleaser/tap/goreleaser-pro
info_script:
- security find-identity -v
- xcodebuild -version
- swift -version
release_script: goreleaser
upload_sentry_debug_files_script:
- cd .build/arm64-apple-macosx/release/
# Generate and upload symbols
- dsymutil tart
- sentry-cli debug-files upload tart.dSYM/
- SENTRY_PROJECT=tart sentry-cli debug-files upload tart.dSYM/
# Bundle and upload sources
- sentry-cli debug-files bundle-sources tart.dSYM
- sentry-cli debug-files upload tart.src.zip
- SENTRY_PROJECT=tart sentry-cli debug-files upload tart.src.zip
create_sentry_release_script:
- export SENTRY_RELEASE="tart@$CIRRUS_TAG"
- sentry-cli releases new $SENTRY_RELEASE
- sentry-cli releases set-commits $SENTRY_RELEASE --auto
- sentry-cli releases finalize $SENTRY_RELEASE
task:
name: Deploy Documentation
only_if: $CIRRUS_BRANCH == 'main'
container:
image: ghcr.io/cirruslabs/mkdocs-material-insiders:latest
image: ghcr.io/squidfunk/mkdocs-material:latest
registry_config: ENCRYPTED[!cf1a0f25325aa75bad3ce6ebc890bc53eb0044c02efa70d8cefb83ba9766275a994b4831706c52630a0692b2fa9cfb9e!]
env:
DEPLOY_TOKEN: ENCRYPTED[!45ed45666558902ed1c2400add734ec063103bec31841847e8c8764802fca229bfa6d85c690e16ad159e047574b48793!]
+2 -2
View File
@@ -9,7 +9,7 @@ permissions:
jobs:
build_cached:
name: Build tart (cached)
runs-on: ghcr.io/cirruslabs/macos-runner:tahoe
runs-on: macos-26
timeout-minutes: 30
steps:
- uses: actions/checkout@v5
@@ -29,7 +29,7 @@ jobs:
build_no_cache:
name: Build tart (no cache)
runs-on: ghcr.io/cirruslabs/macos-runner:tahoe
runs-on: macos-26
timeout-minutes: 30
steps:
- uses: actions/checkout@v5
+37
View File
@@ -0,0 +1,37 @@
name: CI
on:
merge_group:
pull_request:
push:
branches:
- main
workflow_dispatch:
permissions:
contents: read
jobs:
test:
name: Test
runs-on: macos-26
timeout-minutes: 60
steps:
- uses: actions/checkout@v6
- uses: actions/setup-go@v6
with:
go-version-file: integration-tests/go.mod
cache-dependency-path: integration-tests/go.sum
- name: Build
run: swift build --build-system swiftbuild
- name: Run unit tests
run: |
export PATH="$PATH:/usr/sbin"
swift test --build-system swiftbuild
# The Python suite boots Tart VMs, but hosted ARM macOS runners do not support nested virtualization.
- name: Run OpenTelemetry integration tests
run: |
bin_path="$(swift build --build-system swiftbuild --show-bin-path)"
codesign --sign - --entitlements Resources/tart-dev.entitlements --force "$bin_path/tart"
cd integration-tests
PATH="$bin_path:$PATH" go test -v ./...
+105
View File
@@ -0,0 +1,105 @@
name: Release
on:
push:
tags:
- "*"
workflow_dispatch:
permissions:
contents: read
jobs:
release:
if: github.event_name == 'push' && github.repository == 'openai/tart'
name: Release
runs-on: macos-26
environment: publish
timeout-minutes: 90
permissions:
contents: read
env:
VERSION: ${{ github.ref_name }}
steps:
- name: Checkout
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
with:
fetch-depth: 0
persist-credentials: false
- name: Import signing certificate
env:
KEYCHAIN_PASSWORD: temporary-password
MACOS_CERTIFICATE: ${{ secrets.MACOS_CERTIFICATE }}
P12_PASSWORD: password101
run: |
echo "$MACOS_CERTIFICATE" | base64 --decode > "$RUNNER_TEMP/certificate.p12"
security create-keychain -p "$KEYCHAIN_PASSWORD" "$RUNNER_TEMP/build.keychain"
security set-keychain-settings -lut 21600 "$RUNNER_TEMP/build.keychain"
security default-keychain -s "$RUNNER_TEMP/build.keychain"
security unlock-keychain -p "$KEYCHAIN_PASSWORD" "$RUNNER_TEMP/build.keychain"
security import "$RUNNER_TEMP/certificate.p12" \
-k "$RUNNER_TEMP/build.keychain" \
-P "$P12_PASSWORD" \
-T /usr/bin/codesign \
-T /usr/bin/pkgbuild
security set-key-partition-list \
-S apple-tool:,apple:,codesign: \
-s \
-k "$KEYCHAIN_PASSWORD" \
"$RUNNER_TEMP/build.keychain"
security list-keychain -d user -s "$RUNNER_TEMP/build.keychain"
- name: Create release app token for this repo
id: app-token
uses: actions/create-github-app-token@1b10c78c7865c340bc4f6099eb2f838309f1e8c3 # v3.1.1
with:
app-id: ${{ secrets.RELEASE_APP_ID }}
private-key: ${{ secrets.RELEASE_APP_PRIVATE_KEY }}
permission-contents: write
- name: Create release app token for homebrew-tools
id: tap-token
uses: actions/create-github-app-token@1b10c78c7865c340bc4f6099eb2f838309f1e8c3 # v3.1.1
with:
app-id: ${{ secrets.RELEASE_APP_ID }}
private-key: ${{ secrets.RELEASE_APP_PRIVATE_KEY }}
owner: openai
repositories: homebrew-tools
permission-contents: write
permission-pull-requests: write
- name: Release
uses: goreleaser/goreleaser-action@f06c13b6b1a9625abc9e6e439d9c05a8f2190e94 # v7
with:
distribution: goreleaser-pro
version: "~> v2"
args: release --clean
env:
GORELEASER_KEY: ${{ secrets.GORELEASER_KEY }}
GITHUB_TOKEN: ${{ steps.app-token.outputs.token }}
HOMEBREW_TAP_GITHUB_TOKEN: ${{ steps.tap-token.outputs.token }}
snapshot:
if: github.event_name == 'workflow_dispatch'
name: Release (Dry Run)
runs-on: macos-26
timeout-minutes: 90
permissions:
contents: read
env:
TART_RELEASE_SNAPSHOT: "true"
VERSION: snapshot
steps:
- name: Checkout
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
with:
fetch-depth: 0
persist-credentials: false
- name: Build snapshot
uses: goreleaser/goreleaser-action@f06c13b6b1a9625abc9e6e439d9c05a8f2190e94 # v7
with:
distribution: goreleaser-pro
version: "~> v2"
args: release --skip=publish --snapshot --clean
- name: Upload snapshot artifacts
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
with:
name: tart-snapshot
path: dist/*
+36 -20
View File
@@ -5,8 +5,8 @@ project_name: tart
before:
hooks:
- .ci/set-version.sh
- swift build --arch arm64 --configuration release --product tart
- swift build --arch x86_64 --configuration release --product tart
- sh .ci/build-release.sh arm64
- sh .ci/build-release.sh x86_64
builds:
- id: tart
@@ -19,26 +19,33 @@ builds:
- amd64
binary: tart.app/Contents/MacOS/tart
prebuilt:
path: '.build/{{- if eq .Arch "arm64" }}arm64{{- else }}x86_64{{ end }}-apple-macosx/release/tart'
path: '.build/prebuilt/{{- if eq .Arch "arm64" }}arm64{{- else }}x86_64{{ end }}/tart'
universal_binaries:
- name_template: tart.app/Contents/MacOS/tart
replace: true
hooks:
post: gon gon.hcl
post:
- mkdir -p dist/tart_darwin_all/tart.app/Contents/Resources
- cp Resources/embedded.provisionprofile dist/tart_darwin_all/tart.app/Contents/
- cp Resources/Info.plist dist/tart_darwin_all/tart.app/Contents/
- cp "Resources/actool/UPW Tart.icns" "Resources/actool/Assets.car" dist/tart_darwin_all/tart.app/Contents/Resources/
- cmd: .ci/sign-release.sh
output: true
archives:
- name_template: "{{ .ProjectName }}"
files:
- src: Resources/embedded.provisionprofile
dst: tart.app/Contents
strip_parent: true
- src: Resources/Info.plist
dst: tart.app/Contents
strip_parent: true
- src: Resources/AppIcon.png
dst: tart.app/Contents/Resources
strip_parent: true
- src: dist/tart_darwin_all/tart.app/Contents/Info.plist
dst: tart.app/Contents/Info.plist
- src: dist/tart_darwin_all/tart.app/Contents/embedded.provisionprofile
dst: tart.app/Contents/embedded.provisionprofile
- src: dist/tart_darwin_all/tart.app/Contents/Resources/UPW Tart.icns
dst: tart.app/Contents/Resources/UPW Tart.icns
- src: dist/tart_darwin_all/tart.app/Contents/Resources/Assets.car
dst: tart.app/Contents/Resources/Assets.car
- src: dist/tart_darwin_all/tart.app/Contents/_CodeSignature/CodeResources
dst: tart.app/Contents/_CodeSignature/CodeResources
- LICENSE
release:
@@ -46,9 +53,14 @@ release:
brews:
- name: tart
directory: Formula
repository:
owner: cirruslabs
name: homebrew-cli
owner: openai
name: homebrew-tools
token: "{{ .Env.HOMEBREW_TAP_GITHUB_TOKEN }}"
branch: "tart-{{ .Version }}"
pull_request:
enabled: true
caveats: |
Tart has been installed. You might want to reduce the default DHCP lease time
from 86,400 to 600 seconds to avoid DHCP shortage when running lots of VMs daily:
@@ -56,15 +68,19 @@ brews:
sudo defaults write /Library/Preferences/SystemConfiguration/com.apple.InternetSharing.default.plist bootpd -dict DHCPLeaseTimeSecs -int 600
See https://tart.run/faq/#changing-the-default-dhcp-lease-time for more details.
homepage: https://github.com/cirruslabs/tart
license: "Fair Source"
homepage: https://github.com/openai/tart
license: FSL-1.1-ALv2
description: Run macOS and Linux VMs on Apple Hardware
skip_upload: auto
dependencies:
- "cirruslabs/cli/softnet"
- "openai/tools/softnet"
install: |
libexec.install Dir["*"]
bin.write_exec_script "#{libexec}/tart.app/Contents/MacOS/tart"
generate_completions_from_executable(libexec/"tart.app/Contents/MacOS/tart", "--generate-completion-script")
custom_block: |
depends_on :macos => :ventura
on_macos do
depends_on :macos => :ventura
end
def post_install
generate_completions_from_executable(libexec/"tart.app/Contents/MacOS/tart", "--generate-completion-script")
end
+1 -1
View File
@@ -20,7 +20,7 @@ Table of Contents
```
## How to Create an Issue/Enhancement
1. Go to the [Issue page](https://github.com/cirruslabs/tart/issues) of the repository
1. Go to the [Issue page](https://github.com/openai/tart/issues) of the repository
2. Click on the "New Issue" button
3. Provide a descriptive title and detailed description of the issue or enhancement you're suggesting
4. Submit the issue
+95 -35
View File
@@ -1,45 +1,105 @@
Fair Source License, version 0.9
# Functional Source License, Version 1.1, ALv2 Future License
Copyright (C) 2023 Cirrus Labs, Inc.
## Abbreviation
Licensor: Cirrus Labs, Inc.
FSL-1.1-ALv2
Software: Tart
## Notice
Use Limitation: 100 users. User is defined as a single core of a central processing unit (CPU) used by the product.
The Use Limitation does not apply to CPUs installed in devices used by a single individual.
Copyright 2022-2026 OpenAI
License Grant. Licensor hereby grants to each recipient of the
Software ("you") a non-exclusive, non-transferable, royalty-free and
fully-paid-up license, under all of the Licensor's copyright and
patent rights, to use, copy, distribute, prepare derivative works of,
publicly perform and display the Software, subject to the Use
Limitation and the conditions set forth below.
## Terms and Conditions
Use Limitation. The license granted above allows use by up to the
number of users per entity set forth above (the "Use Limitation"). For
determining the number of users, "you" includes all affiliates,
meaning legal entities controlling, controlled by, or under common
control with you. If you exceed the Use Limitation, your use is
subject to payment of Licensor's then-current list price for licenses.
### Licensor ("We")
Conditions. Redistribution in source code or other forms must include
a copy of this license document to be provided in a reasonable
manner. Any redistribution of the Software is only allowed subject to
this license.
The party offering the Software under these Terms and Conditions.
Trademarks. This license does not grant you any right in the
trademarks, service marks, brand names or logos of Licensor.
### The Software
DISCLAIMER. THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OR
CONDITION, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO WARRANTIES
OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
NONINFRINGEMENT. LICENSORS HEREBY DISCLAIM ALL LIABILITY, WHETHER IN
AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN
CONNECTION WITH THE SOFTWARE.
The "Software" is each version of the software that we make available under
these Terms and Conditions, as indicated by our inclusion of these Terms and
Conditions with the Software.
Termination. If you violate the terms of this license, your rights
will terminate automatically and will not be reinstated without the
prior written consent of Licensor. Any such termination will not
affect the right of others who may have received copies of the
Software from you.
### License Grant
Subject to your compliance with this License Grant and the Patents,
Redistribution and Trademark clauses below, we hereby grant you the right to
use, copy, modify, create derivative works, publicly perform, publicly display
and redistribute the Software for any Permitted Purpose identified below.
### Permitted Purpose
A Permitted Purpose is any purpose other than a Competing Use. A Competing Use
means making the Software available to others in a commercial product or
service that:
1. substitutes for the Software;
2. substitutes for any other product or service we offer using the Software
that exists as of the date we make the Software available; or
3. offers the same or substantially similar functionality as the Software.
Permitted Purposes specifically include using the Software:
1. for your internal use and access;
2. for non-commercial education;
3. for non-commercial research; and
4. in connection with professional services that you provide to a licensee
using the Software in accordance with these Terms and Conditions.
### Patents
To the extent your use for a Permitted Purpose would necessarily infringe our
patents, the license grant above includes a license under our patents. If you
make a claim against any party that the Software infringes or contributes to
the infringement of any patent, then your patent license to the Software ends
immediately.
### Redistribution
The Terms and Conditions apply to all copies, modifications and derivatives of
the Software.
If you redistribute any copies, modifications or derivatives of the Software,
you must include a copy of or a link to these Terms and Conditions and not
remove any copyright notices provided in or with the Software.
### Disclaimer
THE SOFTWARE IS PROVIDED "AS IS" AND WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING WITHOUT LIMITATION WARRANTIES OF FITNESS FOR A PARTICULAR
PURPOSE, MERCHANTABILITY, TITLE OR NON-INFRINGEMENT.
IN NO EVENT WILL WE HAVE ANY LIABILITY TO YOU ARISING OUT OF OR RELATED TO THE
SOFTWARE, INCLUDING INDIRECT, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES,
EVEN IF WE HAVE BEEN INFORMED OF THEIR POSSIBILITY IN ADVANCE.
### Trademarks
Except for displaying the License Details and identifying us as the origin of
the Software, you have no right under these Terms and Conditions to use our
trademarks, trade names, service marks or product names.
## Grant of Future License
We hereby irrevocably grant you an additional license to use the Software under
the Apache License, Version 2.0 that is effective on the second anniversary of
the date we make the Software available. On or after that date, you may use the
Software under the Apache License, Version 2.0, in which case the following
will apply:
Licensed under the Apache License, Version 2.0 (the "License"); you may not use
this file except in compliance with the License.
You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software distributed
under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR
CONDITIONS OF ANY KIND, either express or implied. See the License for the
specific language governing permissions and limitations under the License.
+2 -2
View File
@@ -7,7 +7,7 @@ Perhaps, the easiest, but not the most comprehensive way to tell what's going on
In the example below, you will run `tart pull` via `time(1)` to gather generalized CPU, I/O and memory usage metrics:
```shell
/usr/bin/time -l tart pull ghcr.io/cirruslabs/macos-sequoia-base:latest
/usr/bin/time -l tart pull ghcr.io/cirruslabs/macos-tahoe-base:latest
```
**Note:** you need to specify a full path to `time(1)` binary, otherwise the shell's built-in `time` command will be invoked, which doesn't have the `-l` command-line argument.
@@ -48,7 +48,7 @@ To use it, make sure that [Xcode](https://developer.apple.com/xcode/resources/)
Once done, you can create a CPU profile of `tart pull`:
```shell
xctrace record --template "CPU Profiler" --target-stdout - --launch -- /opt/homebrew/bin/tart pull ghcr.io/cirruslabs/macos-sequoia-base:latest
xctrace record --template "CPU Profiler" --target-stdout - --launch -- /opt/homebrew/bin/tart pull ghcr.io/cirruslabs/macos-tahoe-base:latest
```
Now that `xctrace(1)` is running, you'll see the `tart pull`-related output first, and once finished, the following line will appear:
+4 -4
View File
@@ -1,5 +1,5 @@
{
"originHash" : "0da1cc30fa3c41e8c2e2edcdd55706549908275a54f681203e0eeade279deab9",
"originHash" : "061dfe6cdf4e6dbf32b51c5e7023c4ae69726dcafb42a35b34e5489b0338c17f",
"pins" : [
{
"identity" : "antlr4",
@@ -49,10 +49,10 @@
{
"identity" : "opentelemetry-swift",
"kind" : "remoteSourceControl",
"location" : "https://github.com/cirruslabs/opentelemetry-swift",
"location" : "https://github.com/open-telemetry/opentelemetry-swift",
"state" : {
"branch" : "use-feedback-handler",
"revision" : "2040f383e2a8b0a568a7617d147f8f1e23abb298"
"branch" : "main",
"revision" : "ed37be9525081509ab62410d38b705c2b3f0d5a4"
}
},
{
+1 -1
View File
@@ -25,7 +25,7 @@ let package = Package(
.package(url: "https://github.com/jozefizso/swift-xattr", from: "3.0.0"),
.package(url: "https://github.com/grpc/grpc-swift.git", .upToNextMajor(from: "1.27.0")),
.package(url: "https://buf.build/gen/swift/git/1.27.1-20260114140118-bd09c26a260f.1/cirruslabs_tart-guest-agent_grpc_swift.git", branch: "main"),
.package(url: "https://github.com/cirruslabs/opentelemetry-swift", branch: "use-feedback-handler"),
.package(url: "https://github.com/open-telemetry/opentelemetry-swift", branch: "main"),
.package(url: "https://github.com/open-telemetry/opentelemetry-swift-core", from: "2.3.0"),
],
+14 -29
View File
@@ -1,4 +1,4 @@
<img src="https://github.com/cirruslabs/tart/raw/main/Resources/TartSocial.png"/>
<img src="https://github.com/openai/tart/raw/main/Resources/TartSocial.png"/>
*Tart* is a virtualization toolset to build, run and manage macOS and Linux virtual machines (VMs) on Apple Silicon.
Built by CI engineers for your automation needs. Here are some highlights of Tart:
@@ -8,67 +8,52 @@ Built by CI engineers for your automation needs. Here are some highlights of Tar
* Use Tart Packer Plugin to automate VM creation.
* Easily integrates with any CI system.
Tart powers [Cirrus Runners](https://cirrus-runners.app/)
service — a drop-in replacement for the standard GitHub-hosted runners, offering 2-3 times better performance for a fraction of the price.
<p align="center">
<a href="https://cirrus-runners.app/?utm_source=github&utm_medium=referral" target=_blank>
<img src="https://github.com/cirruslabs/tart/raw/main/Resources/CirrusRunnersForGHA.png" height="65"/>
</a>
</p>
Many companies are using Tart in their internal setups. Here are just a few of them:
<p align="center">
<a href="https://atlassian.com/" target=_blank>
<img src="https://github.com/cirruslabs/tart/raw/main/Resources/Users/Atlassian.png" height="65"/>
<img src="https://github.com/openai/tart/raw/main/Resources/Users/Atlassian.png" height="65"/>
</a>
<a href="https://www.figma.com/" target=_blank>
<img src="https://github.com/cirruslabs/tart/raw/main/Resources/Users/Figma.png" height="65"/>
<img src="https://github.com/openai/tart/raw/main/Resources/Users/Figma.png" height="65"/>
</a>
<a href="https://mullvad.net/" target=_blank>
<img src="https://github.com/cirruslabs/tart/raw/main/Resources/Users/Mullvad.png" height="65"/>
<img src="https://github.com/openai/tart/raw/main/Resources/Users/Mullvad.png" height="65"/>
</a>
<a href="https://krisp.ai/" target=_blank>
<img src="https://github.com/cirruslabs/tart/raw/main/Resources/Users/Krisp.png" height="65"/>
<img src="https://github.com/openai/tart/raw/main/Resources/Users/Krisp.png" height="65"/>
</a>
<a href="https://testingbot.com/" target=_blank>
<img src="https://github.com/cirruslabs/tart/raw/main/Resources/Users/TestingBot.png" height="65"/>
<img src="https://github.com/openai/tart/raw/main/Resources/Users/TestingBot.png" height="65"/>
</a>
<a href="https://symflower.com/" target=_blank>
<img src="https://github.com/cirruslabs/tart/raw/main/Resources/Users/Symflower.png" height="65"/>
<img src="https://github.com/openai/tart/raw/main/Resources/Users/Symflower.png" height="65"/>
</a>
<a href="https://transloadit.com/" target=_blank>
<img src="https://github.com/cirruslabs/tart/raw/main/Resources/Users/Transloadit.png" height="65"/>
<img src="https://github.com/openai/tart/raw/main/Resources/Users/Transloadit.png" height="65"/>
</a>
<a href="https://cirrus-ci.org/" target=_blank>
<img src="https://github.com/cirruslabs/tart/raw/main/Resources/Users/CirrusCI.png" height="65"/>
<img src="https://github.com/openai/tart/raw/main/Resources/Users/CirrusCI.png" height="65"/>
</a>
<a href="https://www.pitsdatarecovery.net/" target=_blank>
<img src="https://github.com/cirruslabs/tart/raw/main/Resources/Users/PITSGlobalDataRecoveryServices.png" height="65"/>
<img src="https://github.com/openai/tart/raw/main/Resources/Users/PITSGlobalDataRecoveryServices.png" height="65"/>
</a>
<a href="https://expo.dev/" target=_blank>
<img src="https://github.com/cirruslabs/tart/raw/main/Resources/Users/Expo.png" height="65"/>
<img src="https://github.com/openai/tart/raw/main/Resources/Users/Expo.png" height="65"/>
</a>
</p>
**Note:** If your company or project is using Tart please consider [sharing with the community](https://github.com/cirruslabs/tart/discussions/857).
<p align="center">
<a href="https://aws.amazon.com/marketplace/pp/prodview-qczco34wlkdws?utm_source=github&utm_medium=referral" target=_blank>
<img src="https://github.com/cirruslabs/tart/raw/main/Resources/AWSMarkeplaceLogo.png" height="90"/>
</a>
</p>
**Note:** If your company or project is using Tart please consider [sharing with the community](https://github.com/openai/tart/discussions/857).
## Usage
Try running a Tart VM on your Apple Silicon device running macOS 13.0 (Ventura) or later (will download a 25 GB image):
```bash
brew install cirruslabs/cli/tart
brew install openai/tools/tart
tart clone ghcr.io/cirruslabs/macos-tahoe-base:latest tahoe-base
tart run tahoe-base
```
Please check the [official documentation](https://tart.run) for more information and/or feel free to use [discussions](https://github.com/cirruslabs/tart/discussions)
Please check the [official documentation](https://tart.run) for more information and/or feel free to use [discussions](https://github.com/openai/tart/discussions)
for remaining questions.
Binary file not shown.

Before

Width:  |  Height:  |  Size: 44 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 120 KiB

+9 -7
View File
@@ -7,15 +7,17 @@
<key>CFBundleDisplayName</key>
<string>Tart</string>
<key>CFBundleIdentifier</key>
<string>org.cirruslabs.tart</string>
<string>com.github.cirruslabs.tart</string>
<key>CFBundleExecutable</key>
<string>tart</string>
<key>LSApplicationCategoryType</key>
<string>public.app-category.developer-tools</string>
<key>CFBundleIconFiles</key>
<array>
<string>AppIcon.png</string>
</array>
<key>CFBundlePackageType</key>
<string>APPL</string>
<key>LSApplicationCategoryType</key>
<string>public.app-category.developer-tools</string>
<key>CFBundleIconFile</key>
<string>UPW Tart</string>
<key>CFBundleIconName</key>
<string>UPW Tart</string>
<key>NSAppTransportSecurity</key>
<dict>
<key>NSAllowsArbitraryLoads</key>
Binary file not shown.

After

Width:  |  Height:  |  Size: 34 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 67 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 106 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 42 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 34 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 67 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 102 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 42 KiB

+140
View File
@@ -0,0 +1,140 @@
{
"fill" : "automatic",
"groups" : [
{
"blend-mode" : "normal",
"blur-material" : 0.5,
"layers" : [
{
"hidden" : false,
"image-name-specializations" : [
{
"value" : "4.4-–-layer.png"
},
{
"idiom" : "square",
"value" : "UPW Tart L4.png"
}
],
"name" : "UPW Tart L4"
}
],
"opacity" : 1,
"shadow" : {
"kind" : "neutral",
"opacity" : 1
},
"specular" : true,
"translucency" : {
"enabled" : true,
"value" : 0.25
}
},
{
"layers" : [
{
"image-name-specializations" : [
{
"value" : "3.3-–-layer.png"
},
{
"idiom" : "square",
"value" : "UPW Tart L3.png"
}
],
"name" : "UPW Tart L3",
"position-specializations" : [
{
"idiom" : "square",
"value" : {
"scale" : 1,
"translation-in-points" : [
0,
0
]
}
}
]
}
],
"shadow" : {
"kind" : "none",
"opacity" : 1
},
"specular" : false,
"translucency" : {
"enabled" : true,
"value" : 0.25
}
},
{
"blur-material" : null,
"layers" : [
{
"image-name-specializations" : [
{
"value" : "2.2-–-layer.png"
},
{
"idiom" : "square",
"value" : "UPW Tart L2.png"
}
],
"name" : "UPW Tart L2"
}
],
"position-specializations" : [
{
"idiom" : "square",
"value" : {
"scale" : 1,
"translation-in-points" : [
0,
0
]
}
}
],
"shadow" : {
"kind" : "none",
"opacity" : 1
},
"specular" : true,
"translucency" : {
"enabled" : true,
"value" : 0.25
}
},
{
"layers" : [
{
"image-name-specializations" : [
{
"value" : "1.1-–-layer.png"
},
{
"idiom" : "square",
"value" : "UPW Tart L1.png"
}
],
"name" : "UPW Tart L1"
}
],
"shadow" : {
"kind" : "layer-color",
"opacity" : 0.5
},
"specular" : true,
"translucency" : {
"enabled" : true,
"value" : 0.25
}
}
],
"supported-platforms" : {
"circles" : [
"watchOS"
],
"squares" : "shared"
}
}
Binary file not shown.
+10
View File
@@ -0,0 +1,10 @@
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
<key>CFBundleIconFile</key>
<string>UPW Tart</string>
<key>CFBundleIconName</key>
<string>UPW Tart</string>
</dict>
</plist>
Binary file not shown.
+1 -1
View File
@@ -1,5 +1,5 @@
struct CI {
private static let rawVersion = "${CIRRUS_TAG}"
private static let rawVersion = "${VERSION}"
static var version: String {
rawVersion.expanded() ? rawVersion : "SNAPSHOT"
+15 -15
View File
@@ -1,6 +1,5 @@
import ArgumentParser
import Foundation
import NIOPosix
import GRPC
import Cirruslabs_TartGuestAgent_Grpc_Swift
@@ -41,19 +40,12 @@ struct Exec: AsyncParsableCommand {
throw RuntimeError.VMNotRunning(name)
}
// Create a gRPC channel connected to the VM's control socket
let group = MultiThreadedEventLoopGroup(numberOfThreads: 1)
defer {
try! group.syncShutdownGracefully()
}
let channel = try GRPCChannelPool.with(
target: .unixDomainSocket(vmDir.controlSocketURL.path()),
transportSecurity: .plaintext,
eventLoopGroup: group,
)
defer {
try! channel.close().wait()
// Change the current working directory to a VM's base directory
// to work around Unix domain socket 104 byte limitation [1]
//
// [1]: https://blog.8-p.info/en/2020/06/11/unix-domain-socket-length/
if let baseURL = vmDir.controlSocketURL.baseURL {
FileManager.default.changeCurrentDirectoryPath(baseURL.path())
}
// Switch controlling terminal into raw mode when remote pseudo-terminal is requested
@@ -71,7 +63,10 @@ struct Exec: AsyncParsableCommand {
// Execute a command in a running VM
do {
try await execute(channel)
let controlSocketPath = vmDir.controlSocketURL.relativePath
try await withGuestAgentChannel(unixDomainSocketPath: controlSocketPath) { channel in
try await execute(channel)
}
} catch let error as GRPCConnectionPoolError {
throw RuntimeError.Generic("Failed to connect to the VM using its control socket: \(error.localizedDescription), is the Tart Guest Agent running?")
}
@@ -134,6 +129,11 @@ struct Exec: AsyncParsableCommand {
let data = handle.availableData
if data.isEmpty {
// EOF: unregister the handler, otherwise the fd stays permanently
// "readable" and Foundation re-invokes us in a tight loop, burning
// 100% of a core for the rest of the command's lifetime
handle.readabilityHandler = nil
continuation.finish()
} else {
continuation.yield(data)
+9 -1
View File
@@ -68,7 +68,15 @@ struct IP: AsyncParsableCommand {
throw RuntimeError.Generic("Cannot perform IP resolution via Tart Guest Agent when control socket URL is not set")
}
if let ip = try await AgentResolver.ResolveIP(controlSocketURL) {
// Change the current working directory to a VM's base directory
// to work around Unix domain socket 104 byte limitation [1]
//
// [1]: https://blog.8-p.info/en/2020/06/11/unix-domain-socket-length/
if let baseURL = controlSocketURL.baseURL {
FileManager.default.changeCurrentDirectoryPath(baseURL.path())
}
if let ip = try await AgentResolver.ResolveIP(controlSocketURL.relativePath) {
return ip
}
}
+31 -3
View File
@@ -7,7 +7,7 @@ fileprivate struct VMInfo: Encodable {
let Name: String
let Disk: Int
let Size: Int
let SizeOnDisk: Int
let Accessed: String
let Running: Bool
let State: String
}
@@ -39,13 +39,29 @@ struct List: AsyncParsableCommand {
if source == nil || source == "local" {
infos += sortedInfos(try VMStorageLocal().list().map { (name, vmDir) in
try VMInfo(Source: "local", Name: name, Disk: vmDir.sizeGB(), Size: vmDir.allocatedSizeGB(), SizeOnDisk: vmDir.allocatedSizeGB() - vmDir.deduplicatedSizeGB(), Running: vmDir.running(), State: vmDir.state().rawValue)
try VMInfo(
Source: "local",
Name: name,
Disk: vmDir.sizeGB(),
Size: vmDir.allocatedSizeGB(),
Accessed: formatAccessDate(try vmDir.accessDate()),
Running: vmDir.running(),
State: vmDir.state().rawValue
)
})
}
if source == nil || source == "oci" {
infos += sortedInfos(try VMStorageOCI().list().map { (name, vmDir, _) in
try VMInfo(Source: "OCI", Name: name, Disk: vmDir.sizeGB(), Size: vmDir.allocatedSizeGB(), SizeOnDisk: vmDir.allocatedSizeGB() - vmDir.deduplicatedSizeGB(), Running: vmDir.running(), State: vmDir.state().rawValue)
try VMInfo(
Source: "OCI",
Name: name,
Disk: vmDir.sizeGB(),
Size: vmDir.allocatedSizeGB(),
Accessed: formatAccessDate(try vmDir.accessDate()),
Running: vmDir.running(),
State: vmDir.state().rawValue
)
})
}
@@ -61,4 +77,16 @@ struct List: AsyncParsableCommand {
private func sortedInfos(_ infos: [VMInfo]) -> [VMInfo] {
infos.sorted(by: { left, right in left.Name < right.Name })
}
private func formatAccessDate(_ accessDate: Date) -> String {
switch format {
case .text:
let formatter = RelativeDateTimeFormatter()
formatter.unitsStyle = .full
return formatter.localizedString(for: accessDate, relativeTo: Date())
case .json:
let formatter = ISO8601DateFormatter()
return formatter.string(from: accessDate)
}
}
}
-4
View File
@@ -31,9 +31,6 @@ struct Push: AsyncParsableCommand {
discussion: "Can be specified multiple times to attach multiple labels."))
var labels: [String] = []
@Option(help: .hidden)
var diskFormat: String = "v2"
@Flag(help: ArgumentHelp("cache pushed images locally",
discussion: "Increases disk usage, but saves time if you're going to pull the pushed images later."))
var populateCache: Bool = false
@@ -85,7 +82,6 @@ struct Push: AsyncParsableCommand {
registry: registry,
references: references,
chunkSizeMb: chunkSize,
diskFormat: diskFormat,
concurrency: concurrency,
labels: parseLabels()
)
+132 -8
View File
@@ -137,7 +137,7 @@ struct Run: AsyncParsableCommand {
To work with block devices, the easiest way is to modify their permissions to be accessible to the current user:
sudo chown $USER /dev/diskX
tart run sequoia --disk=/dev/diskX
tart run macos --disk=/dev/diskX
Warning: after running the chown command above, all software running under the current user will be able to access /dev/diskX. If that violates your threat model, we recommend avoiding mounting block devices altogether.
""", valueName: "path[:options]"), completion: .file())
@@ -285,6 +285,28 @@ struct Run: AsyncParsableCommand {
@Flag(help: ArgumentHelp("Disable the keyboard"))
var noKeyboard: Bool = false
#if arch(arm64) && compiler(>=6.4)
@Option(help: ArgumentHelp("Provision a macOS guest on first boot using the guest provisioning API", discussion: """
Takes a comma-separated list of key=value pairs that configure the initial setup of a macOS guest
Requires the host to be running macOS 27 (or newer) and only takes effect on the first boot after
creation of a macOS 27 (or newer) guest VM.
Supported keys (matching VZMacGuestProvisioningOptions):
* fullName=<NAME> — the person's full name to configure
* username=<USERNAME> — the username for logging into the guest
* password=<PASSWORD> — the password to configure for the guest
* logsInAutomatically=true|false — whether to automatically log the person in at startup
* enablesRemoteLogin=true|false — whether to enable Remote Login (SSH) in the guest
""", valueName: "key=value,..."))
var provisioningOpts: String?
#endif
mutating func validate() throws {
if vnc && vncExperimental {
throw ValidationError("--vnc and --vnc-experimental are mutually exclusive")
@@ -352,6 +374,19 @@ struct Run: AsyncParsableCommand {
}
}
#if arch(arm64) && compiler(>=6.4)
if provisioningOpts != nil {
if #unavailable(macOS 27) {
throw ValidationError("--provisioning-opts requires the host to be running macOS 27 (or newer)")
}
let config = try VMConfig.init(fromURL: vmDir.configURL)
if config.os != .darwin {
throw ValidationError("--provisioning-opts can only be used with macOS VMs")
}
}
#endif
for disk in disk {
if disk.hasSuffix("-amd64.iso") {
throw ValidationError("Seems you have a disk targeting x86 architecture (hence amd64 in the name). Please use an 'arm64' version of the disk.")
@@ -360,7 +395,7 @@ struct Run: AsyncParsableCommand {
}
@MainActor
func run() async throws {
func runOnMainThread() throws {
let localStorage = try VMStorageLocal()
let vmDir = try localStorage.open(name)
@@ -408,6 +443,11 @@ struct Run: AsyncParsableCommand {
// Parse root disk options
let diskOptions = DiskOptions(rootDiskOpts)
// Parse guest provisioning options
#if arch(arm64) && compiler(>=6.4)
let provisioning = try provisioningOpts.map { try GuestProvisioningOptions($0) }
#endif
vm = try VM(
vmDir: vmDir,
network: userSpecifiedNetwork(vmDir: vmDir) ?? NetworkShared(),
@@ -473,7 +513,11 @@ struct Run: AsyncParsableCommand {
#endif
do {
try await vm!.start(recovery: recovery, resume: resume)
#if arch(arm64) && compiler(>=6.4)
try await vm!.start(recovery: recovery, resume: resume, provisioning: provisioning)
#else
try await vm!.start(recovery: recovery, resume: resume)
#endif
} catch let error as VZError {
if error.code == .virtualMachineLimitExceeded {
var hint = ""
@@ -514,7 +558,7 @@ struct Run: AsyncParsableCommand {
}
if #available(macOS 14, *) {
Task {
ErrorReportingTask("Failed to run control socket") {
try await ControlSocket(vmDir.controlSocketURL).run()
}
}
@@ -586,7 +630,7 @@ struct Run: AsyncParsableCommand {
signal(SIGUSR2, SIG_IGN)
let sigusr2Src = DispatchSource.makeSignalSource(signal: SIGUSR2)
sigusr2Src.setEventHandler {
Task {
ErrorReportingTask("Failed to request guest OS to stop") {
print("Requesting guest OS to stop...")
try vm!.virtualMachine.requestStop()
}
@@ -758,6 +802,11 @@ struct Run: AsyncParsableCommand {
}
}
// "tart run" drives an AppKit/SwiftUI run loop and therefore must own the main
// thread at the top level, so it opts out of Root's asynchronous command path.
// See Root.main() for the rationale.
extension Run: MainThreadCommand {}
struct MainApp: App {
static var suspendable: Bool = false
static var capturesSystemKeys: Bool = false
@@ -798,13 +847,13 @@ struct MainApp: App {
CommandGroup(replacing: .appInfo) { AboutTart(config: vm!.config) }
CommandMenu("Control") {
Button("Start") {
Task { try await vm!.virtualMachine.start() }
ErrorReportingTask("Failed to start VM") { try await vm!.virtualMachine.start() }
}
Button("Stop") {
Task { try await vm!.virtualMachine.stop() }
ErrorReportingTask("Failed to stop VM") { try await vm!.virtualMachine.stop() }
}
Button("Request Stop") {
Task { try vm!.virtualMachine.requestStop() }
ErrorReportingTask("Failed to request VM stop") { try vm!.virtualMachine.requestStop() }
}
if #available(macOS 14, *) {
if (MainApp.suspendable) {
@@ -1026,6 +1075,81 @@ struct DiskOptions {
}
}
struct GuestProvisioningOptions {
var fullName: String?
var username: String?
var password: String?
var logsInAutomatically: Bool?
var enablesRemoteLogin: Bool?
init(_ parseFrom: String) throws {
for pair in parseFrom.split(separator: ",") {
let keyValue = pair.split(separator: "=", maxSplits: 1)
guard keyValue.count == 2 else {
throw RuntimeError.VMConfigurationError("invalid provisioning option \"\(pair)\", expected key=value")
}
let key = String(keyValue[0])
let value = String(keyValue[1])
switch key {
case "fullName":
self.fullName = value
case "username":
self.username = value
case "password":
self.password = value
case "logsInAutomatically":
self.logsInAutomatically = try Self.parseBool(key, value)
case "enablesRemoteLogin":
self.enablesRemoteLogin = try Self.parseBool(key, value)
default:
throw RuntimeError.VMConfigurationError("unsupported provisioning option \"\(key)\"")
}
}
}
private static func parseBool(_ key: String, _ value: String) throws -> Bool {
switch value {
case "true":
return true
case "false":
return false
default:
throw RuntimeError.VMConfigurationError("invalid value \"\(value)\" for provisioning option \"\(key)\", expected \"true\" or \"false\"")
}
}
}
#if arch(arm64) && compiler(>=6.4)
@available(macOS 27, *)
extension GuestProvisioningOptions {
func toVZMacGuestProvisioningOptions() throws -> VZMacGuestProvisioningOptions {
let options = VZMacGuestProvisioningOptions()
if let fullName = fullName {
options.fullName = fullName
}
if let username = username {
options.username = username
}
if let password = password {
options.password = password
}
if let logsInAutomatically = logsInAutomatically {
options.logsInAutomatically = logsInAutomatically
}
if let enablesRemoteLogin = enablesRemoteLogin {
options.enablesRemoteLogin = enablesRemoteLogin
}
try options.validate()
return options
}
}
#endif
struct DirectoryShare {
let name: String?
let path: URL
+9 -1
View File
@@ -21,8 +21,16 @@ class ControlSocket {
// if any, otherwise we may get the "address already in use" error
try? FileManager.default.removeItem(atPath: controlSocketURL.path())
// Change the current working directory to a VM's base directory
// to work around Unix domain socket 104 byte limitation [1]
//
// [1]: https://blog.8-p.info/en/2020/06/11/unix-domain-socket-length/
if let baseURL = controlSocketURL.baseURL {
FileManager.default.changeCurrentDirectoryPath(baseURL.path())
}
let serverChannel = try await ServerBootstrap(group: eventLoopGroup)
.bind(unixDomainSocketPath: controlSocketURL.path()) { childChannel in
.bind(unixDomainSocketPath: controlSocketURL.relativePath) { childChannel in
childChannel.eventLoop.makeCompletedFuture {
return try NIOAsyncChannel<ByteBuffer, ByteBuffer>(
wrappingChannelSynchronously: childChannel
@@ -15,7 +15,7 @@ class StdinCredentials {
return (user, password)
}
private static func readStdinCredential(name: String, prompt: String, maxCharacters: Int = 1024, isSensitive: Bool) throws -> String {
private static func readStdinCredential(name: String, prompt: String, maxCharacters: Int = 8192, isSensitive: Bool) throws -> String {
var buf = [CChar](repeating: 0, count: maxCharacters + 1 /* sentinel */ + 1 /* NUL */)
guard let rawCredential = readpassphrase(prompt, &buf, buf.count, isSensitive ? RPP_ECHO_OFF : RPP_ECHO_ON) else {
throw StdinCredentialsError.CredentialRequired(which: name)
+28
View File
@@ -0,0 +1,28 @@
import GRPC
import NIOPosix
/// Connects to a guest agent's gRPC endpoint over a VM's control socket, runs
/// `body` with the resulting channel, and closes the channel afterwards on both
/// the success and error paths.
///
/// The connection uses the process-wide singleton event loop group, which must
/// not be shut down, so there is no group lifecycle to manage here.
func withGuestAgentChannel<T>(
unixDomainSocketPath socketPath: String,
_ body: (GRPCChannel) async throws -> T
) async throws -> T {
let channel = try GRPCChannelPool.with(
target: .unixDomainSocket(socketPath),
transportSecurity: .plaintext,
eventLoopGroup: .singletonMultiThreadedEventLoopGroup,
)
do {
let result = try await body(channel)
try await channel.close().get()
return result
} catch {
try? await channel.close().get()
throw error
}
}
@@ -1,42 +1,28 @@
import Foundation
import Network
import NIOPosix
import GRPC
import Cirruslabs_TartGuestAgent_Apple_Swift
import Cirruslabs_TartGuestAgent_Grpc_Swift
class AgentResolver {
static func ResolveIP(_ controlSocketURL: URL) async throws -> IPv4Address? {
static func ResolveIP(_ controlSocketPath: String) async throws -> IPv4Address? {
do {
return try await resolveIP(controlSocketURL)
} catch let error as GRPCConnectionPoolError {
return try await resolveIP(controlSocketPath)
} catch is GRPCConnectionPoolError {
return nil
}
}
private static func resolveIP(_ controlSocketURL: URL) async throws -> IPv4Address? {
// Create a gRPC channel connected to the VM's control socket
let group = MultiThreadedEventLoopGroup(numberOfThreads: 1)
defer {
try! group.syncShutdownGracefully()
private static func resolveIP(_ controlSocketPath: String) async throws -> IPv4Address? {
try await withGuestAgentChannel(unixDomainSocketPath: controlSocketPath) { channel in
// Invoke ResolveIP() gRPC method
let callOptions = CallOptions(timeLimit: .timeout(.seconds(1)))
let agentAsyncClient = AgentAsyncClient(channel: channel)
let resolveIPCall = agentAsyncClient.makeResolveIpCall(ResolveIPRequest(), callOptions: callOptions)
let response = try await resolveIPCall.response
return IPv4Address(response.ip)
}
let channel = try GRPCChannelPool.with(
target: .unixDomainSocket(controlSocketURL.path()),
transportSecurity: .plaintext,
eventLoopGroup: group,
)
defer {
try! channel.close().wait()
}
// Invoke ResolveIP() gRPC method
let callOptions = CallOptions(timeLimit: .timeout(.seconds(1)))
let agentAsyncClient = AgentAsyncClient(channel: channel)
let resolveIPCall = agentAsyncClient.makeResolveIpCall(ResolveIPRequest(), callOptions: callOptions)
let response = try await resolveIPCall.response
return IPv4Address(response.ip)
}
}
-75
View File
@@ -1,75 +0,0 @@
import Foundation
import Compression
class DiskV1: Disk {
private static let bufferSizeBytes = 4 * 1024 * 1024
private static let layerLimitBytes = 500 * 1000 * 1000
static func push(diskURL: URL, registry: Registry, chunkSizeMb: Int, concurrency: UInt, progress: Progress) async throws -> [OCIManifestLayer] {
var pushedLayers: [OCIManifestLayer] = []
// Open the disk file
let mappedDisk = try Data(contentsOf: diskURL, options: [.alwaysMapped])
var mappedDiskReadOffset = 0
// Compress the disk file as a single stream
let compressingFilter = try InputFilter(.compress, using: .lz4, bufferCapacity: Self.bufferSizeBytes) { (length: Int) -> Data? in
// Determine the size of the next chunk
let bytesRead = min(length, mappedDisk.count - mappedDiskReadOffset)
// Read the next uncompressed chunk
let data = mappedDisk.subdata(in: mappedDiskReadOffset ..< mappedDiskReadOffset + bytesRead)
// Advance the offset
mappedDiskReadOffset += bytesRead
// Provide the uncompressed chunk to the compressing filter
return data
}
// Cut the compressed stream into layers, each equal exactly ``Self.layerLimitBytes`` bytes,
// except for the last one, which may be smaller
while let compressedData = try compressingFilter.readData(ofLength: Self.layerLimitBytes) {
let layerDigest = try await registry.pushBlob(fromData: compressedData, chunkSizeMb: chunkSizeMb)
pushedLayers.append(OCIManifestLayer(
mediaType: diskV1MediaType,
size: compressedData.count,
digest: layerDigest
))
// Update progress using an absolute value
progress.completedUnitCount = Int64(mappedDiskReadOffset)
}
return pushedLayers
}
static func pull(registry: Registry, diskLayers: [OCIManifestLayer], diskURL: URL, concurrency: UInt, progress: Progress, localLayerCache: LocalLayerCache? = nil, deduplicate: Bool = false) async throws {
if !FileManager.default.createFile(atPath: diskURL.path, contents: nil) {
throw OCIError.FailedToCreateVmFile
}
// Open the disk file
let disk = try FileHandle(forWritingTo: diskURL)
defer { try! disk.close() }
// Decompress the layers onto the disk in a single stream
let filter = try OutputFilter(.decompress, using: .lz4, bufferCapacity: Self.bufferSizeBytes) { data in
if let data = data {
try disk.write(contentsOf: data)
}
}
for diskLayer in diskLayers {
try await registry.pullBlob(diskLayer.digest) { data in
try filter.write(data)
// Update the progress
progress.completedUnitCount += Int64(data.count)
}
}
try filter.finalize()
}
}
-1
View File
@@ -6,7 +6,6 @@ let ociConfigMediaType = "application/vnd.oci.image.config.v1+json"
// Layer media types
let configMediaType = "application/vnd.cirruslabs.tart.config.v1"
let diskV1MediaType = "application/vnd.cirruslabs.tart.disk.v1"
let diskV2MediaType = "application/vnd.cirruslabs.tart.disk.v2"
let nvramMediaType = "application/vnd.cirruslabs.tart.nvram.v1"
+137 -59
View File
@@ -32,86 +32,157 @@ struct Root: AsyncParsableCommand {
FQN.self,
])
public static func main() async throws {
// Note: main() is intentionally synchronous. Swift's asynchronous main() entry
// point implicitly starts an executor that owns the main thread — and since
// Swift 6.4 that executor is no longer backed by the Dispatch main queue — so
// running an AppKit/SwiftUI run loop nested inside it leaves the main run loop
// unable to drain Tasks or DispatchQueue.main, and a VM started via "tart run"
// never boots. Keeping main() synchronous lets a command that needs the main
// run loop own it at the top level, exactly like a plain SwiftUI app.
public static func main() {
// Add commands that are only available on specific macOS versions
if #available(macOS 14, *) {
configuration.subcommands.append(Suspend.self)
}
// Ensure the default SIGINT handled is disabled,
// otherwise there's a race between two handlers
signal(SIGINT, SIG_IGN);
// Handle cancellation by Ctrl+C ourselves
let task = withUnsafeCurrentTask { $0 }!
let sigintSrc = DispatchSource.makeSignalSource(signal: SIGINT)
sigintSrc.setEventHandler {
task.cancel()
}
sigintSrc.activate()
// Ensure the default SIGINT handler is disabled, otherwise there's a race
// between two handlers. We handle cancellation by Ctrl+C ourselves below.
signal(SIGINT, SIG_IGN)
// Set line-buffered output for stdout
setlinebuf(stdout)
defer { OTel.shared.flush() }
// Parse the command up-front, synchronously, so we can decide who gets to own
// the main thread before any concurrency is involved.
//
// ParsableCommand isn't Sendable, but we only ever hand it to the single task
// spawned below and never touch it again afterwards, so transferring it into
// that task is safe.
nonisolated(unsafe) let command: ParsableCommand
do {
command = try parseAsRoot()
} catch {
exit(withError: error)
}
if let mainThreadCommand = command as? MainThreadCommand {
// This command drives a run loop on the main thread, so run it right here,
// letting it own the main thread at the top level.
MainActor.assumeIsolated {
runOnMainThread(mainThreadCommand)
}
} else {
// Every other command is asynchronous and doesn't touch the main thread, so
// drive it from a detached task and let the Dispatch main queue keep the
// process alive until the command exits.
let task = Task.detached {
await runInBackground(command)
}
// Handle cancellation by Ctrl+C ourselves
let sigintSrc = DispatchSource.makeSignalSource(signal: SIGINT)
sigintSrc.setEventHandler {
task.cancel()
}
sigintSrc.activate()
dispatchMain()
}
}
@MainActor
private static func runOnMainThread(_ command: MainThreadCommand) {
let span = startCommandSpan(for: command)
runGarbageCollection(for: command)
do {
// Parse command
var command = try parseAsRoot()
// Enters the run loop and only returns once the command exits via
// Foundation.exit(), so the lines below are a best-effort fallback.
try command.runOnMainThread()
} catch {
handleError(error, span: span)
}
// Create a root span for the command we're about to run
let span = OTel.shared.tracer.spanBuilder(spanName: type(of: command)._commandName).startSpan()
defer { span.end() }
OpenTelemetry.instance.contextProvider.setActiveSpan(span)
span.end()
OTel.shared.flush()
Foundation.exit(0)
}
// Enrich root command span with command's arguments
let commandLineArguments = ProcessInfo.processInfo.arguments.map { argument in
AttributeValue.string(argument)
}
span.setAttribute(key: "Command-line arguments", value: .array(AttributeArray(values: commandLineArguments)))
private static func runInBackground(_ command: ParsableCommand) async {
let span = startCommandSpan(for: command)
runGarbageCollection(for: command)
// Enrich root command span with Cirrus CI-specific tags
if let tags = ProcessInfo.processInfo.environment["CIRRUS_SENTRY_TAGS"] {
for (key, value) in tags.split(separator: ",").compactMap(splitEnvironmentVariable) {
span.setAttribute(key: key, value: .string(value))
}
}
// Run garbage-collection before each command (shouldn't take too long)
if type(of: command) != type(of: Pull()) && type(of: command) != type(of: Clone()){
do {
try Config().gc()
} catch {
fputs("Failed to perform garbage collection: \(error)\n", stderr)
}
}
// Run command
do {
if var asyncCommand = command as? AsyncParsableCommand {
try await asyncCommand.run()
} else {
var command = command
try command.run()
}
} catch {
// Not an error, just a custom exit code from "tart exec"
if let execCustomExitCodeError = error as? ExecCustomExitCodeError {
OTel.shared.flush()
Foundation.exit(execCustomExitCodeError.exitCode)
}
// Capture the error into OpenTelemetry
OpenTelemetry.instance.contextProvider.activeSpan?.recordException(error)
// Handle a non-ArgumentParser's exception that requires a specific exit code to be set
if let errorWithExitCode = error as? HasExitCode {
fputs("\(error)\n", stderr)
OTel.shared.flush()
Foundation.exit(errorWithExitCode.exitCode)
}
// Handle any other exception, including ArgumentParser's ones
exit(withError: error)
handleError(error, span: span)
}
span.end()
OTel.shared.flush()
Foundation.exit(0)
}
// Create a root span for the command we're about to run.
private static func startCommandSpan(for command: ParsableCommand) -> Span {
let span = OTel.shared.tracer.spanBuilder(spanName: type(of: command)._commandName).startSpan()
OpenTelemetry.instance.contextProvider.setActiveSpan(span)
// Enrich root command span with command's arguments
let commandLineArguments = ProcessInfo.processInfo.arguments.map { argument in
AttributeValue.string(argument)
}
span.setAttribute(key: "Command-line arguments", value: .array(AttributeArray(values: commandLineArguments)))
// Enrich root command span with Cirrus CI-specific tags
if let tags = ProcessInfo.processInfo.environment["CIRRUS_SENTRY_TAGS"] {
for (key, value) in tags.split(separator: ",").compactMap(splitEnvironmentVariable) {
span.setAttribute(key: key, value: .string(value))
}
}
return span
}
// Run garbage-collection before each command (shouldn't take too long).
private static func runGarbageCollection(for command: ParsableCommand) {
if type(of: command) != type(of: Pull()) && type(of: command) != type(of: Clone()) {
do {
try Config().gc()
} catch {
fputs("Failed to perform garbage collection: \(error)\n", stderr)
}
}
}
private static func handleError(_ error: Error, span: Span) -> Never {
// Not an error, just a custom exit code from "tart exec"
if let execCustomExitCodeError = error as? ExecCustomExitCodeError {
span.end()
OTel.shared.flush()
Foundation.exit(execCustomExitCodeError.exitCode)
}
// Capture the error into OpenTelemetry
OpenTelemetry.instance.contextProvider.activeSpan?.recordException(error)
span.end()
// Handle a non-ArgumentParser's exception that requires a specific exit code to be set
if let errorWithExitCode = error as? HasExitCode {
fputs("\(error)\n", stderr)
OTel.shared.flush()
Foundation.exit(errorWithExitCode.exitCode)
}
// Handle any other exception, including ArgumentParser's ones
OTel.shared.flush()
exit(withError: error)
}
private static func splitEnvironmentVariable(_ tag: String.SubSequence) -> (String, String)? {
@@ -123,3 +194,10 @@ struct Root: AsyncParsableCommand {
return (String(splits[0]), String(splits[1]))
}
}
// A command that drives an AppKit/SwiftUI run loop and therefore has to own the
// main thread at the top level, rather than running inside Swift's asynchronous
// main() executor. See Root.main() for the rationale.
protocol MainThreadCommand: ParsableCommand {
@MainActor func runOnMainThread() throws
}
+18
View File
@@ -1,5 +1,23 @@
import Foundation
// A fire-and-forget task that reports any thrown error to stderr. An unstructured
// Task spawned from a synchronous context (a signal handler, a SwiftUI action) has
// no parent to propagate its error to, so we report it here instead of dropping it.
struct ErrorReportingTask {
let task: Task<Void, Never>
@discardableResult
init(_ context: String, operation: @escaping @Sendable () async throws -> Void) {
task = Task {
do {
try await operation()
} catch {
fputs("\(context): \(error)\n", stderr)
}
}
}
}
extension Collection {
subscript (safe index: Index) -> Element? {
indices.contains(index) ? self[index] : nil
+9 -4
View File
@@ -244,13 +244,13 @@ class VM: NSObject, VZVirtualMachineDelegate, ObservableObject {
return try VM(vmDir: vmDir)
}
func start(recovery: Bool, resume shouldResume: Bool) async throws {
func start(recovery: Bool, resume shouldResume: Bool, provisioning: GuestProvisioningOptions? = nil) async throws {
try network.run(sema)
if shouldResume {
try await resume()
} else {
try await start(recovery)
try await start(recovery, provisioning: provisioning)
}
}
@@ -286,10 +286,15 @@ class VM: NSObject, VZVirtualMachineDelegate, ObservableObject {
}
@MainActor
private func start(_ recovery: Bool) async throws {
private func start(_ recovery: Bool, provisioning: GuestProvisioningOptions? = nil) async throws {
#if arch(arm64)
let startOptions = VZMacOSVirtualMachineStartOptions()
startOptions.startUpFromMacOSRecovery = recovery
#if compiler(>=6.4)
if let provisioning = provisioning, #available(macOS 27, *) {
try startOptions.setGuestProvisioning(provisioning.toVZMacGuestProvisioningOptions())
}
#endif
try await virtualMachine.start(options: startOptions)
#else
try await virtualMachine.start()
@@ -399,7 +404,7 @@ class VM: NSObject, VZVirtualMachineDelegate, ObservableObject {
}
// Storage
var attachment = try VZDiskImageStorageDeviceAttachment(
let attachment = try VZDiskImageStorageDeviceAttachment(
url: diskURL,
readOnly: false,
// When not specified, use "cached" caching mode for Linux VMs to prevent file-system corruption[1]
+13 -22
View File
@@ -2,6 +2,8 @@ import Compression
import Foundation
import OpenTelemetryApi
let legacyDiskV1MediaType = "application/vnd.cirruslabs.tart.disk.v1"
enum OCIError: Error {
case ShouldBeExactlyOneLayer
case ShouldBeAtLeastOneLayer
@@ -29,16 +31,12 @@ extension VMDirectory {
try configFile.close()
// Pull VM's disk layers and decompress them into a disk file
let diskImplType: Disk.Type
let layers: [OCIManifestLayer]
if manifest.layers.contains(where: { $0.mediaType == legacyDiskV1MediaType }) {
throw RuntimeError.Generic("Pulling OCI images with legacy disk media type \(legacyDiskV1MediaType) is no longer supported, please re-push the image using a current Tart version")
}
if manifest.layers.contains(where: { $0.mediaType == diskV1MediaType }) {
diskImplType = DiskV1.self
layers = manifest.layers.filter { $0.mediaType == diskV1MediaType }
} else if manifest.layers.contains(where: { $0.mediaType == diskV2MediaType }) {
diskImplType = DiskV2.self
layers = manifest.layers.filter { $0.mediaType == diskV2MediaType }
} else {
let layers = manifest.layers.filter { $0.mediaType == diskV2MediaType }
if layers.isEmpty {
throw OCIError.ShouldBeAtLeastOneLayer
}
@@ -55,10 +53,10 @@ extension VMDirectory {
ProgressObserver(progress).log(defaultLogger)
do {
try await diskImplType.pull(registry: registry, diskLayers: layers, diskURL: diskURL,
concurrency: concurrency, progress: progress,
localLayerCache: localLayerCache,
deduplicate: deduplicate)
try await DiskV2.pull(registry: registry, diskLayers: layers, diskURL: diskURL,
concurrency: concurrency, progress: progress,
localLayerCache: localLayerCache,
deduplicate: deduplicate)
} catch let error where error is FilterError {
throw RuntimeError.PullFailed("failed to decompress disk: \(error.localizedDescription)")
}
@@ -90,7 +88,7 @@ extension VMDirectory {
try manifest.toJSON().write(to: manifestURL)
}
func pushToRegistry(registry: Registry, references: [String], chunkSizeMb: Int, diskFormat: String, concurrency: UInt, labels: [String: String] = [:]) async throws -> RemoteName {
func pushToRegistry(registry: Registry, references: [String], chunkSizeMb: Int, concurrency: UInt, labels: [String: String] = [:]) async throws -> RemoteName {
var layers = Array<OCIManifestLayer>()
// Read VM's config and push it as blob
@@ -111,14 +109,7 @@ extension VMDirectory {
let progress = Progress(totalUnitCount: diskSize)
ProgressObserver(progress).log(defaultLogger)
switch diskFormat {
case "v1":
layers.append(contentsOf: try await DiskV1.push(diskURL: diskURL, registry: registry, chunkSizeMb: chunkSizeMb, concurrency: concurrency, progress: progress))
case "v2":
layers.append(contentsOf: try await DiskV2.push(diskURL: diskURL, registry: registry, chunkSizeMb: chunkSizeMb, concurrency: concurrency, progress: progress))
default:
throw RuntimeError.OCIUnsupportedDiskFormat(diskFormat)
}
layers.append(contentsOf: try await DiskV2.push(diskURL: diskURL, registry: registry, chunkSizeMb: chunkSizeMb, concurrency: concurrency, progress: progress))
// Read VM's NVRAM and push it as blob
defaultLogger.appendNewLine("pushing NVRAM...")
+1 -1
View File
@@ -27,7 +27,7 @@ struct VMDirectory: Prunable {
baseURL.appendingPathComponent("manifest.json")
}
var controlSocketURL: URL {
baseURL.appendingPathComponent("control.sock")
URL(fileURLWithPath: "control.sock", relativeTo: baseURL)
}
var explicitlyPulledMark: URL {
-3
View File
@@ -74,7 +74,6 @@ enum RuntimeError : Error {
case ImportFailed(_ message: String)
case SoftnetFailed(_ message: String)
case OCIStorageError(_ message: String)
case OCIUnsupportedDiskFormat(_ format: String)
case SuspendFailed(_ message: String)
case PullFailed(_ message: String)
case VirtualMachineLimitExceeded(_ hint: String)
@@ -139,8 +138,6 @@ extension RuntimeError : CustomStringConvertible {
return "Softnet failed: \(message)"
case .OCIStorageError(let message):
return "OCI storage error: \(message)"
case .OCIUnsupportedDiskFormat(let format):
return "OCI disk format \(format) is not supported by this version of Tart"
case .SuspendFailed(let message):
return "Failed to suspend the VM: \(message)"
case .PullFailed(let message):
+2 -23
View File
@@ -14,7 +14,7 @@ final class LayerizerTests: XCTestCase {
do {
registryRunner = try await RegistryRunner()
} catch {
try XCTSkipIf(ProcessInfo.processInfo.environment["CI"] == nil)
throw XCTSkip("Registry is unavailable: \(error)")
}
}
@@ -24,30 +24,9 @@ final class LayerizerTests: XCTestCase {
registryRunner = nil
}
func testDiskV1() async throws {
// Original disk file to be pushed to the registry
let originalDiskFileURL = try fileWithRandomData(sizeBytes: 5 * 1024 * 1024 * 1024)
addTeardownBlock {
try FileManager.default.removeItem(at: originalDiskFileURL)
}
// Disk file to be pulled from the registry
// and compared against the original disk file
let pulledDiskFileURL = FileManager.default.temporaryDirectory.appendingPathComponent(UUID().uuidString)
print("pushing disk...")
let diskLayers = try await DiskV1.push(diskURL: originalDiskFileURL, registry: registry, chunkSizeMb: 0, concurrency: 4, progress: Progress())
print("pulling disk...")
try await DiskV1.pull(registry: registry, diskLayers: diskLayers, diskURL: pulledDiskFileURL, concurrency: 16, progress: Progress())
print("comparing disks...")
try XCTAssertEqual(Digest.hash(originalDiskFileURL), Digest.hash(pulledDiskFileURL))
}
func testDiskV2() async throws {
// Original disk file to be pushed to the registry
let originalDiskFileURL = try fileWithRandomData(sizeBytes: 5 * 1024 * 1024 * 1024)
let originalDiskFileURL = try fileWithRandomData(sizeBytes: 1 * 1024 * 1024 * 1024)
addTeardownBlock {
try FileManager.default.removeItem(at: originalDiskFileURL)
}
+1 -1
View File
@@ -10,7 +10,7 @@ final class RegistryTests: XCTestCase {
do {
registryRunner = try await RegistryRunner()
} catch {
try XCTSkipIf(ProcessInfo.processInfo.environment["CI"] == nil)
throw XCTSkip("Registry is unavailable: \(error)")
}
}
+2 -2
View File
@@ -13,7 +13,7 @@ class RegistryRunner {
let stdoutPipe = Pipe()
let proc = Process()
proc.executableURL = URL(fileURLWithPath: "/usr/local/bin/docker")
proc.executableURL = URL(fileURLWithPath: "/opt/homebrew/bin/docker")
proc.arguments = arguments
proc.standardOutput = stdoutPipe
try proc.run()
@@ -31,7 +31,7 @@ class RegistryRunner {
init() async throws {
// Start container
let container = try Self.dockerCmd("run", "-d", "--rm", "-p", "127.0.0.1:0:5000", "registry:2")
let container = try Self.dockerCmd("run", "-d", "--rm", "-p", "127.0.0.1::5000", "registry:2")
.trimmingCharacters(in: CharacterSet.newlines)
containerID = container
Executable
+30
View File
@@ -0,0 +1,30 @@
#!/usr/bin/env bash
# Set shell options to enable fail-fast behavior
#
# * -e: fail the script when an error occurs or command fails
# * -u: fail the script when attempting to reference unset parameters
# * -o pipefail: by default an exit status of a pipeline is that of its
# last command, this fails the pipe early if an error in
# any of its commands occurs
#
set -euo pipefail
OUTPUT_PATH="Resources/actool"
PLIST_PATH="$OUTPUT_PATH/Info.plist"
rm -rf "${OUTPUT_PATH}"
mkdir -p "${OUTPUT_PATH}"
actool "Resources/UPW Tart.icon" \
--compile "${OUTPUT_PATH}" \
--output-format human-readable-text \
--notices \
--warnings \
--errors \
--app-icon "UPW Tart" \
--output-partial-info-plist $PLIST_PATH \
--include-all-app-icons \
--target-device mac \
--minimum-deployment-target 13.0 \
--platform macosx
+1 -1
View File
@@ -13,7 +13,7 @@ brew install go
Finally, run the following command from this (`benchmark/`) directory:
```shell
go run cmd/main.go fio --image ghcr.io/cirruslabs/macos-sequoia-base:latest --prepare 'sudo purge && sync'
go run cmd/main.go fio --image ghcr.io/cirruslabs/macos-tahoe-base:latest --prepare 'sudo purge && sync'
```
You can also enable the debugging output to diagnose issues:
+1 -1
View File
@@ -23,7 +23,7 @@ func NewCommand() *cobra.Command {
}
cmd.Flags().BoolVar(&debug, "debug", false, "enable debug logging")
cmd.Flags().StringVar(&image, "image", "ghcr.io/cirruslabs/macos-sequoia-xcode:latest", "image to use for testing")
cmd.Flags().StringVar(&image, "image", "ghcr.io/cirruslabs/macos-tahoe-xcode:latest", "image to use for testing")
cmd.Flags().StringVar(&prepare, "prepare", "", "command to run before running each benchmark")
return cmd
Binary file not shown.
Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.8 MiB

@@ -11,6 +11,12 @@ categories:
# Changing Tart License
!!! note "Current license"
This post describes a historical license change announced on February 11, 2023.
As of June 5, 2026, Tart is maintained by OpenAI and licensed under
[FSL-1.1-ALv2](https://github.com/openai/tart/blob/main/LICENSE).
The usage limits, paid tiers, pricing, support commitments, and contact details described below no longer apply.
**TLDR:** We are transitioning Tart's licensing from AGPL-3.0 to [Fair Source 100](https://fair.io/). This change will
permit unlimited installations on personal computers, but organizations that exceed a certain number of server
installations utilizing 100 CPU cores will be required to obtain a paid license.
@@ -20,7 +26,7 @@ installations utilizing 100 CPU cores will be required to obtain a paid license.
Exactly a year ago on February 11th 2022 we started working on Tart – a tiny CLI to run macOS virtual machines on Apple Silicon.
Three months later we successfully started using Tart in our own production system and decided to share Tart with everyone.
<img src="https://github.com/cirruslabs/tart/raw/main/Resources/TartSocial.png"/>
<img src="https://github.com/openai/tart/raw/main/Resources/TartSocial.png"/>
The goal was to establish a community of users and contributors to transform Tart from a small CLI to a robust tool
for various scenarios. **Unfortunately, we were not successful in attracting a significant number of contributors.**
@@ -60,10 +66,10 @@ device without a physical display connected. For example, a Mac Mini with a HDMI
but a Mac Mini on a desk with a connected physical display is considered a personal computer. **Usage on personal computers
and before reaching the 100 CPU cores limit is royalty-free and does not have the viral properties of AGPL.**
When an organization surpasses the 100 CPU cores limit, they will be required to obtain a [Gold Tier License](../../licensing.md#license-tiers),
which costs \$1000 per month. Upon reaching a limit of 500 CPU cores, a [Platinum Tier License](../../licensing.md#license-tiers)
(\$3000 per month) will be required, and for organizations that exceed 3000 CPU cores, a custom [Diamond Tier License](../../licensing.md#license-tiers)
(\$1 per core per month) will be necessary. **All paid license tiers will include priority feature development and SLAs on support with urgent issues.**
When an organization surpasses the 100 CPU cores limit, they will be required to obtain a Gold Tier License,
which costs \$12,000 per year. Upon reaching a limit of 500 CPU cores, a Platinum Tier License
(\$36,000 per year) will be required, and for organizations that exceed 3000 CPU cores, a custom Diamond Tier License
(\$12 per core per year) will be necessary. **All paid license tiers will include priority feature development and SLAs on support with urgent issues.**
## Have we considered alternatives?
@@ -74,6 +80,5 @@ this approach is not addressing concerns related to the viral nature of AGPL for
we concluded that transitioning to a source-available model with a mandatory paid licensing is fair, as the licensing fees
are relatively insignificant for companies that reach a significant level of usage.
If you have any questions or concerns, please feel free to reach out to [licensing@cirruslabs.org](mailto:licensing@cirruslabs.org).
If the new licensing model is not suitable for your organization, you are welcome to continue using the AGPL version of Tart,
but please ensure it is not used in a non-AGPL environment.
+3 -3
View File
@@ -78,7 +78,7 @@ in “worker” mode on macOS hosts. Orchard controller is using extremely fast
## Conclusion
Please give [Orchard](https://github.com/cirruslabs/orchard) a try! To run it locally in development mode on any Apple Silicon device
Please give [Orchard](https://github.com/openai/orchard) a try! To run it locally in development mode on any Apple Silicon device
please run the following command:
```bash
@@ -86,9 +86,9 @@ brew install cirruslabs/cli/orchard
orchard dev
```
This will launch a development cluster with a single worker on your machine. Refer to [Orchard documentation](https://github.com/cirruslabs/orchard#creating-virtual-machines)
This will launch a development cluster with a single worker on your machine. Refer to [Orchard documentation](https://github.com/openai/orchard#creating-virtual-machines)
on how to create your first virtual machine and access it.
In a [separate blog post](2023-04-28-orchard-ssh-over-grpc.md)
we’ll cover how Orchard implements seamless SSH access over a gRPC connection. Stay tuned and please don’t hesitate to
[reach out](https://github.com/cirruslabs/orchard/discussions/landing)!
[open an issue](https://github.com/openai/orchard/issues)!
@@ -11,7 +11,7 @@ categories:
# SSH over gRPC or how Orchard simplifies accessing VMs in private networks
We started developing [Orchard](https://github.com/cirruslabs/orchard), an orchestrator for [Tart](https://tart.run/), with the requirement that it should allow users to access virtual machines running on worker nodes in private networks that users might not have access to.
We started developing [Orchard](https://github.com/openai/orchard), an orchestrator for [Tart](https://tart.run/), with the requirement that it should allow users to access virtual machines running on worker nodes in private networks that users might not have access to.
At the same time, we wanted to enable users to access VMs on these remote workers just as easily as they’d access network services on their local Tart VMs.
@@ -102,14 +102,14 @@ Overall, the technology described in this article somewhat resembles what [we pr
We really hope this feature will be useful for many, just as the Cirrus Terminal, and that it will remove the pain of scaling Tart beyond a single machine.
You can give [Orchard](https://github.com/cirruslabs/orchard) a try by running it locally in development mode on any Apple Silicon device:
You can give [Orchard](https://github.com/openai/orchard) a try by running it locally in development mode on any Apple Silicon device:
```bash
brew install cirruslabs/cli/orchard
orchard dev
```
This will launch a development cluster with a single worker on your machine. Refer to [Orchard documentation](https://github.com/cirruslabs/orchard#creating-virtual-machines)
This will launch a development cluster with a single worker on your machine. Refer to [Orchard documentation](https://github.com/openai/orchard#creating-virtual-machines)
on how to create your first virtual machine and access it.
Stay tuned and don’t hesitate to send us your feedback either [on GitHub](https://github.com/cirruslabs/orchard) or [Twitter](https://twitter.com/cirrus_labs)!
Stay tuned and don’t hesitate to send us your feedback either [on GitHub](https://github.com/openai/orchard) or [Twitter](https://twitter.com/cirrus_labs)!
+9 -13
View File
@@ -19,25 +19,21 @@ Today we'd like to share some news and updates around the Tart ecosystem since t
In the last 7 months Tart community almost tripled and growth is continuing to accelerate. Tart just crossed 25,000 installations,
dozens of companies that we know of are using Tart in their daily workflows. If your company is not in the list please consider
[joining](https://github.com/cirruslabs/tart/blob/main/Resources/Users/HowToAddYourself.md)!
[joining](https://github.com/openai/tart/blob/main/Resources/Users/HowToAddYourself.md)!
<div class="grid cards" markdown>
- ![](https://github.com/cirruslabs/tart/raw/main/Resources/Users/Krisp.png){ height="65" }
- ![](https://github.com/cirruslabs/tart/raw/main/Resources/Users/Mullvad.png){ height="65" }
- ![](https://github.com/cirruslabs/tart/raw/main/Resources/Users/ahrefs.png){ height="65" }
- ![](https://github.com/cirruslabs/tart/raw/main/Resources/Users/Suran.png){ height="65" }
- ![](https://github.com/cirruslabs/tart/raw/main/Resources/Users/Symflower.png){ height="65" }
- ![](https://github.com/cirruslabs/tart/raw/main/Resources/Users/Transloadit.png){ height="65" }
- ![](https://github.com/cirruslabs/tart/raw/main/Resources/Users/PITSGlobalDataRecoveryServices.png){ height="65" }
- ![](https://github.com/cirruslabs/tart/raw/main/Resources/Users/Uphold.png){ height="65" }
- ![](https://github.com/openai/tart/raw/main/Resources/Users/Krisp.png){ height="65" }
- ![](https://github.com/openai/tart/raw/main/Resources/Users/Mullvad.png){ height="65" }
- ![](https://github.com/openai/tart/raw/main/Resources/Users/ahrefs.png){ height="65" }
- ![](https://github.com/openai/tart/raw/main/Resources/Users/Suran.png){ height="65" }
- ![](https://github.com/openai/tart/raw/main/Resources/Users/Symflower.png){ height="65" }
- ![](https://github.com/openai/tart/raw/main/Resources/Users/Transloadit.png){ height="65" }
- ![](https://github.com/openai/tart/raw/main/Resources/Users/PITSGlobalDataRecoveryServices.png){ height="65" }
- ![](https://github.com/openai/tart/raw/main/Resources/Users/Uphold.png){ height="65" }
</div>
We are also very pleased by how the community responded to [the license change](2023-02-11-changing-tart-license.md).
We now have a number of companies running Tart at scale under the new license. Revenue from the licensing allowed us to
allocate time to continue improving Tart which brings us to the section below.
## Recent updates and what's changing in Tart 2.0.0
In the last 7 months we've had 12 feature releases that brought a lot of features requested by the community. Here are just
-71
View File
@@ -1,71 +0,0 @@
---
draft: false
date: 2023-10-06
search:
exclude: true
authors:
- fkorotkov
categories:
- announcement
---
# Tart is now available on AWS Marketplace
Announcing [official AMIs for EC2 Mac Instances](https://aws.amazon.com/marketplace/pp/prodview-qczco34wlkdws)
with preconfigured Tart installation that is optimized to work within AWS infrastructure.
EC2 Mac Instances is a gem of engineering powered by AWS Nitro devices. Just imagine there is a physical Mac Mini with
a plugged in Nitro device that can push the physical power button!
![EC2 M2 Pro](../images/ec2-mac2-m2pro.png)
This clever synergy between Apple Hardware and Nitro System allows seamless integration with VPC networking and booting macOS from an EBS volume.
In this blog post we’ll see how a virtualization solution like Tart can compliment and elevate experience with EC2 Mac Instances.
<!-- more -->
Let’s start from the basics, what EC2 Mac Instances allow to do compared to physical Mac Minis seating in offices of
many companies around the world?
First and foremost, EC2 Mac Instances sit inside AWS data centers and can leverage all the goodies of VPC networking
within your company's existing infrastructure. No need to connect your Macs in the office through a VPN and deal
with networking and security.
Additionally, EC2 Mac Instances are booting from EBS volumes which means it is possible to always have reproducible instances
and apply all the best practices of Infrastructure-as-Code. Managing a fleet of physical Macs is a pain and it's very hard
to make them configured in a reproducible and stable way. With booting from identical EBS volumes your team is always sure
about the identical initial state of the fleet.
## Compromises of EC2 Mac Instances
The flexibility of EBS volumes for macOS comes with some compromises that virtualization solutions like Tart can help with.
The initial boot from an EBS volume takes some time and not instant. macOS itself is pretty heavy and a Nitro device needs
to download tens of gigabytes that macOS requires in order to boot. This means that **resetting a EC2 Mac Instance to a clean state
is not instant and usually takes a couple of minutes** when you can’t utilize the precious resources for your workloads.
It is much easier to tailor such EBS volumes with tools like Packer but there is still a **friction to test newly created EBS volumes**
since one needs to start and run a EC2 Mac Instance and it’s not possible to test things locally. Similarly it is even harder
to test beta versions of macOS that require manual interaction with a running instance.
## Solution
Tart can help with all the compromises! Tart virtual machines (VMs) have nearly native performance thanks to utilizing
native `Virtualization.Framework` that was developed along the first Apple Silicon chip. **Tart VMs can be copied/disposed
instantly and booting a fresh Tart VM takes only several seconds**. It is also possible to run two different Tart VMs in parallel
that can have completely different versions of macOS and packages. For example, it is possible to have the latest stable macOS
with the release version of Xcode along with the next version of macOS with the latest beta of Xcode.
Creation of Tart VMs can be automated with [a Packer plugin](https://github.com/cirruslabs/packer-plugin-tart) the same way as
creation of EC2 AMIs with one caveat that **Tart Packer Plugin works locally so you can test the same virtual machine locally
as you would run it in the cloud**.
Lightweight nature of Tart VMs with a focus on an easy-to-integrate Tart CLI compliments any macOS automation and helps to reduce
the feedback cycle and improves reproducibility of macOS environments even further.
## Conclusion
We are excited to bring [official AMIs that include Tart installation optimized to work within AWS](https://aws.amazon.com/marketplace/pp/prodview-qczco34wlkdws).
In the coming weeks when macOS Sonoma will become available on AWS we’ll release another update specifically targeting EC2 Mac Instances.
This update will simplify access to local SSDs of Mac Instances that are slightly faster than EBS volumes. Stay tuned and don’t hesitate
to ask any [questions](https://tart.run/licensing/).
@@ -11,7 +11,7 @@ categories:
# Jumping through the hoops: SSH jump host functionality in Orchard
Almost a year ago, when we started building [Orchard](https://github.com/cirruslabs/orchard), an orchestration system for Tart, we quickly realized that most worker machines will be in a private network, and that VMs will be only reachable from the worker machines themselves. Thus, one of our goals became to simplify accessing the compute resources in a cluster through a centralized controller host.
Almost a year ago, when we started building [Orchard](https://github.com/openai/orchard), an orchestration system for Tart, we quickly realized that most worker machines will be in a private network, and that VMs will be only reachable from the worker machines themselves. Thus, one of our goals became to simplify accessing the compute resources in a cluster through a centralized controller host.
This effort resulted in commands like `orchard port-forward` and `orchard ssh`, which were later improved to support connecting not just to the VMs, but to the worker machines themselves.
@@ -55,8 +55,6 @@ Once running, you can connect to any VM in the cluster using the `ssh -J <servic
## Future plans
First of all, we’d like to thank our paid clients, without which this feature wouldn’t be possible. [Become one now](../../licensing.md) and get the benefit of higher Tart VMs and Orchard workers allowances and making sure that the roadmap for Tart and Orchard is aligned with your company's needs.
In the near future we plan to implement a mechanism similar to `authorized_keys` file that will allow attaching public SSH keys to the Orchard controller’s service accounts, and thus avoid the need to type the passwords.
Stay tuned and don’t hesitate to send us your feedback on [GitHub](https://github.com/cirruslabs/orchard) and [Twitter](https://x.com/cirrus_labs)!
Stay tuned and don’t hesitate to send us your feedback on [GitHub](https://github.com/openai/orchard) and [Twitter](https://x.com/cirrus_labs)!
@@ -11,9 +11,9 @@ categories:
# Bridging the gaps with the Tart Guest Agent
We're introducing a new improvement for the Tart usability experience: a [Tart Guest Agent](https://github.com/cirruslabs/tart-guest-agent).
We're introducing a new improvement for the Tart usability experience: a [Tart Guest Agent](https://github.com/openai/tart-guest-agent).
This agent provides automatic disk resizing, seamless clipboard sharing for macOS guests (a [long-awaited](https://github.com/cirruslabs/tart/issues/14) feature), and the ability to run commands, without SSH and networking, using the new `tart exec` command.
This agent provides automatic disk resizing, seamless clipboard sharing for macOS guests (a [long-awaited](https://github.com/openai/tart/issues/14) feature), and the ability to run commands, without SSH and networking, using the new `tart exec` command.
As of recently, we include this agent in all non-vanilla Cirrus Labs images, so you likely won't need to do anything to benefit from these usability improvements.
@@ -47,7 +47,7 @@ Using gRPC simplifies `tart exec` implementation because of code generation and
Thanks to [gRPC Swift](https://github.com/grpc/grpc-swift), which is built on top of [SwiftNIO](https://github.com/apple/swift-nio), we get [`async/await`](https://docs.swift.org/swift-book/documentation/the-swift-programming-language/concurrency/) support for free, further simplifying the `tart exec` logic.
As for the Tart Guest Agent, the final result is a Golang binary that [can be customized](https://github.com/cirruslabs/tart-guest-agent?tab=readme-ov-file#guest-agent-for-tart-vms) depending on the execution context:
As for the Tart Guest Agent, the final result is a Golang binary that [can be customized](https://github.com/openai/tart-guest-agent?tab=readme-ov-file#guest-agent-for-tart-vms) depending on the execution context:
* launchd global daemon — runs as a privileged user (`root`), has no clipboard access
* `--resize-disk` — resizes the disk when there's a free space at the end of a disk (assuming that one previously ran `tart set --disk-size`)
@@ -59,14 +59,10 @@ We’ve also introduced `--run-daemon` (which implies `--resize-disk`) and `--ru
## Future plans
First, we'd like to thank our paid clients, without whom this feature wouldn't have been possible.
[Become one now](../../licensing.md) and enjoy higher allowances for Tart VMs and Orchard workers—while helping ensure that our roadmap aligns with your company's needs.
In the near future we plan to implement:
* Linux support — to provide seamless experience for Linux guests too
* a new `tart ip` resolver — to provide a more robust IP retrieval facility for Linux guests, which often struggle to populate the host's ARP table with their network activity
* `tart cp` command — to copy files from/to guest VMs
Stay tuned, and feel free to send us feedback on [GitHub](https://github.com/cirruslabs/tart) and [Twitter](https://x.com/cirrus_labs)!
Stay tuned, and feel free to send us feedback on [GitHub](https://github.com/openai/tart) and [Twitter](https://x.com/cirrus_labs)!
@@ -1,44 +0,0 @@
---
draft: false
date: 2025-10-27
search:
exclude: true
authors:
- fkorotkov
categories:
- announcement
---
# Press Release: Cirrus Labs Successfully Enforces Its Fair Source License
**New York City, NY – October 27th, 2025 – Cirrus Labs, Inc.**, a leading provider of platforms for digital transformation, today announced that it has reached a settlement agreement regarding a violation of its Fair Source License.
<!-- more -->
Cirrus Labs makes its Tart Virtualization Toolset, a leading virtualization toolset to build, run and manage macOS and Linux virtual machines (VMs) on Apple Silicon,
freely available on GitHub under the Fair Source License, a source-available license. Tart is used by tens of thousands of engineers at no charge within its generous free‑use limits.
Many large enterprises that need to exceed those limits support continued development through paid licenses. Cirrus Labs also uses Tart to power [Cirrus Runners](https://cirrus-runners.app/)
— a drop‑in replacement for macOS and Linux runners for GitHub Actions — offered at a fixed monthly price for unlimited usage.
Cirrus Labs discovered that, **despite a prior licensing request that was declined due to a conflict of interest**, another company used Tart in a manner that exceeded the license’s free‑use limits,
in order to create a competing product.
After several months of negotiations, the matter was settled and a settlement payment to Cirrus Labs was agreed upon.
!!! quote "Comment by Fedor Korotkov, CEO of Cirrus Labs"
As a company we embrace healthy competition that ultimately benefits the end user. Most of our users have no trouble complying with our license,
and even when they need something more than our free use limits, we can almost always grant them a license that fits their needs. **This was an exceptional case.**
We are pleased to have reached this settlement, which validates our source-available licensing strategy and reinforces our commitment to protecting our company and serving our community.
Cirrus Labs was represented in this matter by [Jordan Raphael](https://byronraphael.com/attorneys/jordan-raphael/) of Byron Raphael LLP, a boutique intellectual property law firm,
and [Heather Meeker](https://www.techlawpartners.com/heather), a well-known specialist in open source and source available licensing.
The specific financial terms of the settlement and the identity of the counterparty remain confidential.
**About Cirrus Labs:** Cirrus Labs, Inc. is a bootstrapped developer-infrastructure company founded in 2017. Our offerings among others include Tart and Cirrus Runners,
and our software is used by teams at category-leading companies including Atlassian, Figma, Zendesk, Sentry and many more.
Learn more at [https://tart.run/](https://tart.run/) and [https://cirrus-runners.app/](https://cirrus-runners.app/).
**Contact:** [hello@cirruslabs.org](mailto:hello@cirruslabs.org)
+20 -5
View File
@@ -59,7 +59,7 @@ Remote images are pulled into `~/.tart/cache/OCIs/`.
## Nested virtualization support?
Tart is limited by functionality of Apple's `Virtualization.Framework`. At the moment `Virtualization.Framework`
supports nested virtualization only on M3 or M4 chips running macOS 15 (Sequoia). By default, it is disabled, but can be enabled by passing the `--nested` flag to `tart run`.
supports nested virtualization only on M3 or M4 chips running macOS 15 (Sequoia) or later and [only for Linux VMs](https://github.com/openai/tart/issues/1231#issuecomment-4410915463). By default, it is disabled, but can be enabled by passing the `--nested` flag to `tart run`.
## Connecting to a service running on host
@@ -74,9 +74,24 @@ netstat -nr | awk '/default/{print $2; exit}'
```
Note: that accessing host is only possible with the default NAT network. If you are running your virtual machines with
[Softnet](https://github.com/cirruslabs/softnet) (via `tart run --net-softnet <VM NAME>)`, then the network isolation
[Softnet](https://github.com/openai/softnet) (via `tart run --net-softnet <VM NAME>)`, then the network isolation
is stricter and it's not possible to access the host.
## Avoiding the "Local Network" permission pop-up
Starting from macOS 15 (Sequoia), a GUI "Local Network" permission pop-up might appear when Tart is used by another tool that needs to connect to a VM over a private IPv4 network, for example [Packer](https://developer.hashicorp.com/packer/integrations/cirruslabs/tart/latest/components/builder/tart).
This is not caused by Tart itself, but by the host-side process that needs network access into the guest.
If you need a non-interactive workaround, you can configure the [local network privacy preferences](https://developer.apple.com/documentation/technotes/tn3179-understanding-local-network-privacy#macOS-considerations) on the host so that all [RFC 1918](https://datatracker.ietf.org/doc/html/rfc1918#section-3) address ranges that Tart VMs commonly use are excluded from the prompt:
```shell
sudo defaults write com.apple.network.local-network AllowedEthernetLocalNetworkAddresses -array "10.0.0.0/8" "172.16.0.0/12" "192.168.0.0/16"
sudo defaults write com.apple.network.local-network AllowedWiFiLocalNetworkAddresses -array "10.0.0.0/8" "172.16.0.0/12" "192.168.0.0/16"
```
After applying these settings, reboot the host.
## Changing the default NAT subnet
To change the default network to `192.168.77.1`:
@@ -97,7 +112,7 @@ sudo defaults write /Library/Preferences/SystemConfiguration/com.apple.vmnet.pli
By default, the built-in macOS DHCP server allocates IP-addresses to the VMs for the duration of 86,400 seconds (one day), which may easily cause DHCP exhaustion if you run more than ~253 VMs per day, or in other words, more than one VM every ~6 minutes.
This issue is worked around automatically [when using Softnet](http://github.com/cirruslabs/softnet), however, if you don't use or can't use it, the following command will reduce the lease time from the default 86,400 seconds (one day) to 600 seconds (10 minutes):
This issue is worked around automatically [when using Softnet](https://github.com/openai/softnet), however, if you don't use or can't use it, the following command will reduce the lease time from the default 86,400 seconds (one day) to 600 seconds (10 minutes):
```shell
sudo defaults write /Library/Preferences/SystemConfiguration/com.apple.InternetSharing.default.plist bootpd -dict DHCPLeaseTimeSecs -int 600
@@ -184,12 +199,12 @@ security unlock-keychain login.keychain
This command also supports the `-p` command-line argument that allows you to supply a password and unlock non-interactively, which is great for scripts.
Alternatively, you can pass the credentials via the environment variables, see [Registry Authorization](integrations/vm-management.md#registry-authorization) for more details on how to do that.
Alternatively, you can pass the credentials via the environment variables, see [Registry Authorization](quick-start.md#registry-authorization) for more details on how to do that.
## How is Tart different from Anka?
Under the hood Tart is using the same technology as Anka 3.0 so there should be no real difference in performance
or features supported. If there is some feature missing please don't hesitate to [create a feature request](https://github.com/cirruslabs/tart/issues).
or features supported. If there is some feature missing please don't hesitate to [create a feature request](https://github.com/openai/tart/issues).
Instead of Anka Registry, Tart can work with any OCI-compatible container registry. This provides a much more consistent
and scalable experience for distributing virtual machines.
+2 -2
View File
@@ -18,9 +18,9 @@ steps:
- command: uname -a
plugins:
- cirruslabs/tart#main:
image: ghcr.io/cirruslabs/macos-sequoia-base:latest
image: ghcr.io/cirruslabs/macos-tahoe-base:latest
```
This will run `uname -r` in a macOS Tart VM cloned from `ghcr.io/cirruslabs/macos-sequoia-base:latest`.
This will run `uname -r` in a macOS Tart VM cloned from `ghcr.io/cirruslabs/macos-tahoe-base:latest`.
See plugin's [Configuration section](https://github.com/cirruslabs/tart-buildkite-plugin#configuration) for the full list of available options.
+5 -5
View File
@@ -5,8 +5,8 @@ description: Tool for running isolated tasks reproducibly in any environment wit
# Cirrus CLI
Tart itself is only responsible for managing virtual machines, but we've built Tart support into a tool called Cirrus CLI
also developed by Cirrus Labs. [Cirrus CLI](https://github.com/cirruslabs/cirrus-cli) is a command line tool with
Tart itself is only responsible for managing virtual machines, but Cirrus Labs built Tart support into a tool called
[Cirrus CLI](https://github.com/cirruslabs/cirrus-cli), a command line tool with
one configuration format to execute common CI steps (run a script, cache a folder, etc.) locally or in any CI system.
We built Cirrus CLI to solve "But it works on my machine!" problem.
@@ -18,7 +18,7 @@ task:
name: hello
macos_instance:
# can be a remote or a local virtual machine
image: ghcr.io/cirruslabs/macos-sequoia-base:latest
image: ghcr.io/cirruslabs/macos-tahoe-base:latest
hello_script:
- echo "Hello from within a Tart VM!"
- echo "Here is my CPU info:"
@@ -38,7 +38,7 @@ cirrus run
[Cirrus CI](https://cirrus-ci.org/) already leverages Tart to power its macOS cloud infrastructure. The `.cirrus.yml`
config from above will just work in Cirrus CI and your tasks will be executed inside Tart VMs in our cloud.
**Note:** Cirrus CI only allows [images managed and regularly updated by us](https://github.com/orgs/cirruslabs/packages?tab=packages&q=macos).
**Note:** Cirrus CI only allows [images managed and regularly updated by Cirrus Labs](https://github.com/orgs/cirruslabs/packages?tab=packages&q=macos).
## Retrieving artifacts from within Tart VMs
@@ -50,7 +50,7 @@ exposes it via [`artifacts` instruction](https://cirrus-ci.org/guide/writing-tas
task:
name: Build
macos_instance:
image: ghcr.io/cirruslabs/macos-sequoia-xcode:latest
image: ghcr.io/cirruslabs/macos-tahoe-xcode:latest
build_script: swift build --product tart
binary_artifacts:
path: .build/debug/tart
+1 -1
View File
@@ -42,7 +42,7 @@ Now you can use Tart Images in your `.gitlab-ci.yml`:
```yaml
# You can use any remote Tart Image.
# Tart Executor will pull it from the registry and use it for creating ephemeral VMs.
image: ghcr.io/cirruslabs/macos-sequoia-base:latest
image: ghcr.io/cirruslabs/macos-tahoe-base:latest
test:
tags:
+41
View File
@@ -0,0 +1,41 @@
---
title: Automating VM image building with Packer
description: Use Packer to build custom VM images, configure VMs and work with remote OCI registries.
---
Please refer to [Tart Packer Plugin repository](https://github.com/cirruslabs/packer-plugin-tart) for setup instructions.
Here is an example of a template to build a local image based of a remote image:
```hcl
packer {
required_plugins {
tart = {
version = ">= 0.5.3"
source = "github.com/cirruslabs/tart"
}
}
}
source "tart-cli" "tart" {
vm_base_name = "ghcr.io/cirruslabs/macos-tahoe-base:latest"
vm_name = "my-custom-tahoe"
cpu_count = 4
memory_gb = 8
disk_size_gb = 70
ssh_password = "admin"
ssh_timeout = "120s"
ssh_username = "admin"
}
build {
sources = ["source.tart-cli.tart"]
provisioner "shell" {
inline = ["echo 'Disabling spotlight indexing...'", "sudo mdutil -a -i off"]
}
# more provisioners
}
```
Here is a [repository with Packer templates](https://github.com/cirruslabs/macos-image-templates) used to build [all the images managed by Cirrus Labs](https://github.com/orgs/cirruslabs/packages?tab=packages&q=macos).
-143
View File
@@ -1,143 +0,0 @@
---
title: Managing Virtual Machine
description: Use Packer to build custom VM images, configure VMs and work with remote OCI registries.
---
# Managing Virtual Machine
## Creating from scratch
Tart supports macOS and Linux virtual machines. All commands like `run` and `pull` work the same way regardless of the underlying OS a particular VM image has.
The only difference is how such VM images are created. Please check sections below for [macOS](#creating-a-macos-vm-image-from-scratch) and [Linux](#creating-a-linux-vm-image-from-scratch) instructions.
### Creating a macOS VM image from scratch
Tart can create VMs from `*.ipsw` files. You can download a specific `*.ipsw` file [here](https://ipsw.me/) or you can
use `latest` instead of a path to `*.ipsw` to download the latest available version:
```bash
tart create --from-ipsw=latest sequoia-vanilla
tart run sequoia-vanilla
```
After the initial booting of the VM, you'll need to manually go through the macOS installation process. As a convention we recommend creating an `admin` user with an `admin` password. After the regular installation please do some additional modifications in the VM:
1. Enable Auto-Login. Users & Groups -> Login Options -> Automatic login -> admin.
2. Allow SSH. Sharing -> Remote Login
3. Disable Lock Screen. Preferences -> Lock Screen -> disable "Require Password" after 5.
4. Disable Screen Saver.
5. Run `sudo visudo` in Terminal, find `%admin ALL=(ALL) ALL` add `admin ALL=(ALL) NOPASSWD: ALL` to allow sudo without a password.
### Creating a Linux VM image from scratch
Linux VMs are supported on hosts running macOS 13.0 (Ventura) or newer.
```bash
# Create a bare VM
tart create --linux ubuntu
# Install Ubuntu
tart run --disk focal-desktop-arm64.iso ubuntu
# Run VM
tart run ubuntu
```
After the initial setup please make sure your VM can be SSH-ed into by running the following commands inside your VM:
```bash
sudo apt update
sudo apt install -y openssh-server
sudo ufw allow ssh
```
## Configuring a VM
By default, a Tart VM uses 2 CPUs and 4 GB of memory with a `1024x768` display. This can be changed after VM creation with `tart set` command.
Please refer to `tart set --help` for additional details.
## Building with Packer
Please refer to [Tart Packer Plugin repository](https://github.com/cirruslabs/packer-plugin-tart) for setup instructions.
Here is an example of a template to build a local image based of a remote image:
```hcl
packer {
required_plugins {
tart = {
version = ">= 0.5.3"
source = "github.com/cirruslabs/tart"
}
}
}
source "tart-cli" "tart" {
vm_base_name = "ghcr.io/cirruslabs/macos-sequoia-base:latest"
vm_name = "my-custom-sequoia"
cpu_count = 4
memory_gb = 8
disk_size_gb = 70
ssh_password = "admin"
ssh_timeout = "120s"
ssh_username = "admin"
}
build {
sources = ["source.tart-cli.tart"]
provisioner "shell" {
inline = ["echo 'Disabling spotlight indexing...'", "sudo mdutil -a -i off"]
}
# more provisioners
}
```
Here is a [repository with Packer templates](https://github.com/cirruslabs/macos-image-templates) used to build [all the images managed by us](https://github.com/orgs/cirruslabs/packages?tab=packages&q=macos).
## Working with a Remote OCI Container Registry
Tart supports interacting with Open Container Initiative (OCI) registries, but only runs images created and pushed by Tart. This means images created for container engines, like Docker, can't be pulled. Instead, create a custom image as documented above.
For example, let's say you want to push/pull images to an OCI registry hosted at `https://acme.io/`.
### Registry Authorization
First, you need to login to `acme.io` with the `tart login` command:
```bash
tart login acme.io
```
If you login to your registry with OAuth, you may need to create an access token to use as the password.
Credentials are securely stored in Keychain.
In addition, Tart supports [Docker credential helpers](https://docs.docker.com/engine/reference/commandline/login/#credential-helpers)
if defined in `~/.docker/config.json`.
Finally, `TART_REGISTRY_USERNAME` and `TART_REGISTRY_PASSWORD` environment variables allow to override authorization
for all registries which might useful for integrating with your CI's secret management.
### Pushing a Local Image
Once credentials are saved for `acme.io`, run the following command to push a local images remotely with two tags:
```bash
tart push my-local-vm-name acme.io/remoteorg/name:latest acme.io/remoteorg/name:v1.0.0
```
### Pulling a Remote Image
You can either pull an image:
```bash
tart pull acme.io/remoteorg/name:latest
```
or create a VM from a remote image:
```bash
tart clone acme.io/remoteorg/name:latest my-local-vm-name
```
If the specified image is not already present, this invocation calls the `tart pull` implicitly before cloning.
-113
View File
@@ -1,113 +0,0 @@
---
search:
exclude: true
---
<!-- markdownlint-disable -->
# Privacy Policy
In addition to this Privacy Policy, Cirrus Labs also has a [Terms of Service](terms.md).
### The Gist
Cirrus Labs Inc will collect certain non-personally identify information about you as you use our sites. We may use
this data to better understand our users. We can also publish this data, but the data will be about a large group of users,
not individuals.
We will also ask you to provide personal information, but you'll always be able to opt out. If you give us personal
information, we won't do anything evil with it.
We can also use cookies, but you can choose not to store these.
That's the basic idea, but you must read through the entire Privacy Policy below and agree with all the details
before you use any of our sites.
### Reuse
This document is based upon the [Automattic Privacy Policy](https://automattic.com/privacy/) and is licensed under
[Creative Commons Attribution Share-Alike License 2.5](https://creativecommons.org/licenses/by-sa/2.5/). Basically,
this means you can use it verbatim or edited, but you must release new versions under the same license and
you have to credit Automattic somewhere (like this!). Automattic is not connected with and does not sponsor or endorse
Cirrus Labs Inc or its use of the work.
Cirrus Labs Inc ("Cirrus Labs") makes available services include our web sites (https://tart.run/), our blog, our API,
and any other software, sites, and services offered by Cirrus Labs Inc in connection to any of those (taken together, the "Service").
It is Cirrus Labs Inc's policy to respect your privacy regarding any information we may collect while operating our websites.
### Questions
If you have question about this Privacy Policy, please contact us at hello@cirruslabs.org
### Visitors
Like most website operators, Cirrus Labs Inc collects non-personally-identifying information of the sort that web browsers and
servers typically make available, such as the browser type, language preference, referring site, and the date and time of each visitor request.
Cirrus Labs Inc's purpose in collecting non-personally identifying information is to better understand how Cirrus Labs Inc's
visitors use its website. From time to time, Cirrus Labs Inc may release non-personally-identifying information in the aggregate,
e.g., by publishing a report on trends in the usage of its website.
Cirrus Labs Inc also collects potentially personally-identifying information like Internet Protocol (IP) addresses.
Cirrus Labs Inc does not use such information to identify its visitors, however, and does not disclose such information,
other than under the same circumstances that it uses and discloses personally-identifying information, as described below.
We may also collect and use IP addresses to block users who violated our Terms of Service.
### Gathering of Personally-Identifying Information
Certain visitors to Cirrus Labs Inc's websites choose to interact with Cirrus Labs Inc in ways that require
Cirrus Labs Inc to gather personally-identifying information. The amount and type of information that Cirrus Labs Inc gathers
depends on the nature of the interaction. Cirrus Labs Inc collects such information only insofar as is necessary or
appropriate to fulfill the purpose of the visitor's interaction with Cirrus Labs Inc. Cirrus Labs Inc does not disclose
personally-identifying information other than as described below. And visitors can always refuse to supply personally-identifying information,
with the caveat that it may prevent them from engaging in certain Service-related activities.
Additionally, some interactions, such as posting a comment, may ask for optional personal information. For instance,
when posting a comment, may provide a website that will be displayed along with a user's name when the comment is displayed.
Supplying such personal information is completely optional and is only displayed for the benefit and the convenience of the user.
### Aggregated Statistics
Cirrus Labs Inc may collect statistics about the behavior of visitors to the Service. For instance, Cirrus Labs Inc
may monitor the most popular parts of the https://tart.run/. Cirrus Labs Inc may display this information publicly or
provide it to others. However, Cirrus Labs Inc does not disclose personally-identifying information other than as described below.
### Protection of Certain Personally-Identifying Information
Cirrus Labs Inc discloses potentially personally-identifying and personally-identifying information only to those of its employees,
contractors and affiliated organizations that (i) need to know that information in order to process it on Cirrus Labs Inc's behalf
or to provide services available at Cirrus Labs Inc's websites, and (ii) that have agreed not to disclose it to others.
Some of those employees, contractors and affiliated organizations may be located outside of your home country; by using the Service,
you consent to the transfer of such information to them. Cirrus Labs Inc will not rent or sell potentially personally-identifying and
personally-identifying information to anyone. Other than to its employees, contractors and affiliated organizations, as described above,
Cirrus Labs Inc discloses potentially personally-identifying and personally-identifying information only when required to do so by law,
or when Cirrus Labs Inc believes in good faith that disclosure is reasonably necessary to protect the property or rights of Cirrus Labs Inc,
third parties or the public at large. If you are a registered user of the Service and have supplied your email address, Cirrus Labs Inc may
occasionally send you an email to tell you about new features, solicit your feedback, or just keep you up to date with what's going on with
Cirrus Labs Inc and our products. We primarily use our website and blog to communicate this type of information, so we expect to keep
this type of email to a minimum. If you send us a request (for example via a support email or via one of our feedback mechanisms),
we reserve the right to publish it in order to help us clarify or respond to your request or to help us support other users.
Cirrus Labs Inc takes all measures reasonably necessary to protect against the unauthorized access, use, alteration or
destruction of potentially personally-identifying and personally-identifying information.
### Browser Cookies
A cookie is a string of information that a website stores on a visitor's computer, and that the visitor's browser provides
to the Service each time the visitor returns. Cirrus Labs Inc uses cookies to help Cirrus Labs Inc identify and track visitors,
their usage of Cirrus Labs Inc Service, and their Service access preferences. Cirrus Labs Inc visitors who do not wish to have
cookies placed on their computers should set their browsers to refuse cookies before using Cirrus Labs Inc's websites, with
the drawback that certain features of Cirrus Labs Inc's websites may not function properly without the aid of cookies.
### Data Storage
Cirrus Labs Inc uses third party vendors and hosting partners to provide the necessary hardware, software, networking,
storage, and related technology required to run the Service. You understand that although you retain full rights to your data,
it may be stored on third party storage and transmitted through third party networks.
### Privacy Policy Changes
Although most changes are likely to be minor, Cirrus Labs Inc may change its Privacy Policy from time to time,
and in Cirrus Labs Inc's sole discretion. Cirrus Labs Inc encourages visitors to frequently check this page for any changes
to its Privacy Policy. Your continued use of this site after any change in this Privacy Policy will constitute your
acceptance of such change.
This page was last updated on 02/20/2023.
-249
View File
@@ -1,249 +0,0 @@
---
search:
exclude: true
---
<!-- markdownlint-disable -->
# Terms of Service
This page covers Terms of Service only for Cirrus Runners and Tart Documentation website in addition to the [Privacy Policy](privacy.md).
### The Gist
Cirrus Labs Inc ("Cirrus Labs") operates the [Cirrus Runners service](https://cirrus-runners.app/) which we hope you use.
If you use it, please use it responsibly. If you don't, we'll have to terminate your subscription.
For paid plans, you'll be charged on a monthly basis. You can cancel anytime, but there are no refunds.
The Terms of Service and our prices can change at any time unless specified in your agreement. We'll warn you 30 days in advance of any price changes.
We'll try to warn you about major changes to the Terms of Service, but we make no guarantees.
That's the basic idea, but you must read through the entire Terms of Service below and agree with all the details before
you use any of our websites or services (whether or not you have signed up).
### Reuse
This document is an adaptation of the Code Climate Terms of Service, which is an adaptation of the Heroku Terms of Service,
which is turn an adaptation of the Google App Engine Terms of Service. The original work has been modified
with permission under the [Creative Commons Attribution 3.0 License](https://creativecommons.org/licenses/by/3.0/).
Neither Code Climate, Inc, nor Heroku, Inc. nor Google, Inc. is connected with and they do not sponsor or endorse
Cirrus Labs or its use of the work.
You're welcome to adapt and use this document for your own needs. If you make an improvement, we'd appreciate it if
you would let us know, so we can consider improving our own document.
### Your Agreement with Cirrus Labs Inc
Your use of the Cirrus Runners Service is governed by this agreement (the "Terms"). The "Service" means the services Cirrus Labs
makes available include our websites (https://tart.run/, https://cirrus-runners.app/), our blog, and any other software, sites,
and services offered by Cirrus Labs in connection to any of those.
"Customer Source Code" means any source code you directly or indirectly submit to Cirrus Runners for the purpose of using the Service.
"Content" means all content generated by Cirrus Runners on your behalf (including metric data) and does not include Customer Source Code.
In order to use the Service, You (the "Customer", "You", or "Your") must first agree to the Terms. You understand and agree
that Cirrus Labs will treat Your use of the Service as acceptance of the Terms from that point onwards.
Cirrus Labs may make changes to the Terms from time to time. You may reject the changes by terminating Your subscription.
You understand and agree that if You use the Service after the date on which the Terms have changed, Cirrus Labs will treat
Your use as acceptance of the updated Terms.
If you have any question about the Terms, please [contact us](../licensing.md#general-support).
### Use of the Service
* You must provide accurate and complete registration information any time You register to use the Service.
* You are responsible for the security of Your passwords and for any use of Your user.
* Your use of the Service must comply with all applicable laws, regulations and ordinances.
* You agree to not engage in any activity that interferes with or disrupts the Service.
* Cirrus Labs reserves the right to enforce quotas and usage limits (to any resources, including the API) at its sole discretion,
with or without notice, which may result in Cirrus Labs disabling or throttling your usage of the Service for any amount of time.
### Service Policies and Privacy
The Service shall be subject to the privacy policy for the Service available at [Privacy Policy](privacy.md), hereby
expressly into the Terms of Service by reference. You agree to the use of Your data in accordance with Cirrus Labs' privacy policies.
### Fees for Use of the Service
* The Service may be provided to You without charge up with certain limits or for a certain "trial" period of time.
* All payments for use of the Service will go through Stripe unless specified in the agreement.
* Cirrus Labs may change its fees and payment policies for the Service by notifying You at least thirty (30) days before the beginning of the billing cycle in which such change will take effect.
### Cancellation and Termination
* You must cancel your subscription via Stripe or my emailing sales@cirruslabs.org.
* You agree that Cirrus Labs, in its sole discretion and for any or no reason, may terminate or suspend Your subscription. You agree that any termination of Your access to the Service may be without prior notice, and You agree that Cirrus Labs will not be liable to You or any third party for such termination.
### Customer Source Code
* Cirrus Labs claims no ownership or control over any Customer Source Code. You retain copyright and any other rights You
already hold in the Customer Source Code and You are responsible for protecting those rights, as appropriate.
* You agree to assume full responsibility for configuring the Service to allow appropriate access to any Customer Source Code provided to the Service.
* You retain sole responsibility for any collaborators or third-party services that you allow to view Customer Source Code and entrust them at your own risk.
* Cirrus Labs is not responsible if you fail to configure, or misconfigure, your project and inadvertently allow unauthorized parties to view any Customer Source Code.
### Ideas and Feedback
You may choose to or we may invite You to submit comments or ideas about the Service, including but not limited to ideas
about improving the Service or our products ("Ideas"). By submitting any Idea, You agree that Your disclosure is unsolicited
and without restriction and will not place Cirrus Labs under any fiduciary or other obligation, and that we are free to
use the Idea without any additional compensation to You, and/or to disclose the Idea on a non-confidential basis or otherwise to anyone.
### Modification of the Service
* You acknowledge and agree that the Service may change from time to time without prior notice to You.
* Changes include, without limitation, changes to fee and payment policies, security patches, added or removed functionality, and other enhancements or restrictions.
* Cirrus Labs shall not be liable to you or to any third party for any modification, price change, suspension or discontinuance of the Service.
### External Resources
The Service may include hyperlinks to other websites or content or resources or email content. You acknowledge and
agree that Cirrus Labs is not responsible for the availability of any such external sites or resources, and does not
endorse any advertising, products or other materials on or available from such web sites or resources.
### License from Cirrus Runners and Restrictions
Subject to and conditioned upon your compliance with these Terms of Service, we grant to you a personal, worldwide,
royalty-free, non-assignable and non-exclusive license to use the software provided to You by Cirrus Labs as part of
the Service as provided to You by Cirrus Labs. This license is for the sole purpose of enabling You to use and enjoy
the benefit of the Service as provided by Cirrus Labs, in the manner permitted by the Terms.
You may not (and You may not permit anyone else to): (a) copy, modify, create a derivative work of, reverse engineer,
decompile or otherwise attempt to extract the source code of the Service or any part thereof, unless this is expressly
permitted or required by law, or unless You have been specifically told that You may do so by Cirrus Labs, in writing
(e.g., through an open source software license); or (b) attempt to disable or circumvent any security mechanisms used by the Service.
Open source software licenses for components of the Service released under an open source license constitute separate written agreements.
To the limited extent that the open source software licenses expressly supersede these Terms of Service, the open source licenses
govern Your agreement with Cirrus Labs for the use of the components of the Service released under an open source license.
You may not use the Service in any manner that could damage, disable, overburden or impair our servers or networks, or
interfere with any other users' use or enjoyment of the Service.
You may not attempt to gain unauthorized access to any of the Service, member accounts, or computer systems or networks,
through hacking, password mining or any other means.
Without limiting anything else contained herein, you agree that you shall not (and you agree not to allow any third party to):
* remove any notices of copyright, trademark or other proprietary rights contained in/on or accessible through the Service
or in any content or other material obtained via the Service;
* use any robot, spider, website search/retrieval application, or other automated device, process or means to access,
retrieve or index any portion of the Service;
* reformat or frame any portion of the web pages that are part of the Service;
* use the Service for commercial purposes not permitted under these Terms;
* create users by automated means or under false or fraudulent pretenses;
* attempt to defeat any security or verification measure relating to the Service;
* provide or use tracking or monitoring functionality in connection with the Service, including, without limitation,
to identify other users’ actions or activities;
* impersonate or attempt to impersonate Cirrus Labs or any employee, contractor or associate of Cirrus Labs, or any other
person or entity; or collect or store personal data about other users in connection with the prohibited activities described in this paragraph.
### Our Copyright Dispute Policy
Cirrus Labs respects the intellectual property of others and requires that our users do the same. It is our policy to
terminate the membership of repeat infringers. If you believe that material or content residing on or accessible through
the Service infringes a copyright, please send a notice of copyright infringement containing the following information
to the Designated Copyright Agent listed below:
* identification of the copyrighted work claimed to have been infringed, or, if multiple copyrighted works are covered
by a single notification, a representative list of such works;
* information reasonably sufficient to permit us to contact you, such as an address, telephone number, and an email address;
* a statement by you that you have a good faith belief that the disputed use is not authorized by the copyright owner, its agent, or the law;
* a statement by you, made under penalty of perjury, that the above information in your notification is accurate and that
you are the copyright owner or are authorized to act on the copyright owner's behalf; and
* your physical or electronic signature.
Our Designated Copyright Agent for notification of claimed infringement can be reached by email at: hello@cirruslabs.org.
The Service may contain advertisements and/or links to other websites (“Third Party Sites”). Cirrus Labs does not endorse,
sanction or verify the accuracy or ownership of the information contained in/on any Third Party Site or any products or
services advertised on Third Party Sites. If you decide to leave the Site and navigate to Third Party Sites, or install
any software or download content from any such Third Party Sites, you do so at your own risk. Once you access a Third Party Site
through a link on our Site, you may no longer be protected by these Terms of Service and you may be subject to the terms
and conditions of such Third Party Site. You should review the applicable policies, including privacy and data gathering practices,
of any Third Party Site to which you navigate from the Site, or relating to any software you use or install from a Third Party Site.
Concerns regarding a Third Party Site should be directed to the Third Party Site itself. Cirrus Labs bears no responsibility for
any action associated with any Third Party Site.
### Disclaimer of Warranties
IF YOU ACCESS THE SERVICE, YOU DO SO AT YOUR OWN RISK. WE PROVIDE THE SERVICE “AS IS”, “WITH ALL FAULTS” AND “AS AVAILABLE.”
WE MAKE NO EXPRESS OR IMPLIED WARRANTIES OR GUARANTEES ABOUT THE SERVICE. TO THE MAXIMUM EXTENT PERMITTED BY LAW, WE HEREBY
DISCLAIM ALL SUCH WARRANTIES, INCLUDING ALL STATUTORY WARRANTIES, WITH RESPECT TO THE SERVICE, INCLUDING WITHOUT LIMITATION
ANY WARRANTIES THAT THE SERVICE IS MERCHANTABLE, OF SATISFACTORY QUALITY, ACCURATE, FIT FOR A PARTICULAR PURPOSE OR NEED,
OR NON-INFRINGING. WE DO NOT GUARANTEE THAT THE RESULTS THAT MAY BE OBTAINED FROM THE USE OF THE SERVICE WILL BE EFFECTIVE,
RELIABLE OR ACCURATE OR WILL MEET YOUR REQUIREMENTS. WE DO NOT GUARANTEE THAT YOU WILL BE ABLE TO ACCESS OR USE THE SERVICE
(EITHER DIRECTLY OR THROUGH THIRD-PARTY NETWORKS) AT TIMES OR LOCATIONS OF YOUR CHOOSING. WE ARE NOT RESPONSIBLE FOR THE ACCURACY,
RELIABILITY, TIMELINESS OR COMPLETENESS OF INFORMATION PROVIDED BY ANY OTHER USERS OF THE SERVICE OR ANY OTHER DATA OR
INFORMATION PROVIDED OR RECEIVED THROUGH THE SERVICE. EXCEPT AS EXPRESSLY SET FORTH HEREIN, CIRRUS LABS MAKES NO WARRANTIES
ABOUT THE INFORMATION SYSTEMS, SOFTWARE AND FUNCTIONS MADE ACCESSIBLE BY OR THROUGH THE SERVICE OR ANY SECURITY ASSOCIATED
WITH THE TRANSMISSION OF SENSITIVE INFORMATION. CIRRUS LABS DOES NOT WARRANT THAT THE SERVICE WILL OPERATE ERROR-FREE,
THAT ERRORS IN THE SERVICE WILL BE FIXED, THAT LOSS OF DATA WILL NOT OCCUR, OR THAT THE SERVICE OR SOFTWARE ARE FREE OF
COMPUTER VIRUSES, CONTAMINANTS OR OTHER HARMFUL ITEMS. UNDER NO CIRCUMSTANCES WILL CIRRUS LABS, ANY OF OUR AFFILIATES,
DISTRIBUTORS, PARTNERS, LICENSORS, AND/OR ANY OF OUR OR THEIR DIRECTORS, OFFICERS, EMPLOYEES, CONSULTANTS, AGENTS, OR
OTHER REPRESENTATIVES BE LIABLE FOR ANY LOSS OR DAMAGE CAUSED BY YOUR RELIANCE ON INFORMATION OBTAINED THROUGH THE SERVICE.
### Limitations on Liability
YOUR SOLE AND EXCLUSIVE REMEDY FOR ANY DISPUTE WITH US IS THE CANCELLATION OF YOUR REGISTRATION. IN NO EVENT SHALL OUR
TOTAL CUMULATIVE LIABILITY TO YOU FOR ANY AND ALL CLAIMS RELATING TO OR ARISING OUT OF YOUR USE OF THE SERVICE,
REGARDLESS OF THE FORM OF ACTION, EXCEED THE GREATER OF: (A) THE TOTAL AMOUNT OF FEES, IF ANY, THAT YOU PAID TO UTILIZE
THE SERVICE OR (B) ONE HUNDRED DOLLARS ($100). IN NO EVENT SHALL WE BE LIABLE TO YOU (OR TO ANY THIRD PARTY CLAIMING
UNDER OR THROUGH YOU) FOR ANY DIRECT, INDIRECT, SPECIAL, INCIDENTAL, CONSEQUENTIAL, PUNITIVE OR EXEMPLARY DAMAGES OR
ANY BODILY INJURY, EMOTIONAL DISTRESS, DEATH OR ANY OTHER DAMAGES ARISING FROM YOUR USE OF OR INABILITY TO USE THE SERVICE,
WHETHER ON-LINE OR OFF-LINE, OR OTHERWISE IN CONNECTION WITH THE SERVICE. THESE EXCLUSIONS APPLY TO ANY CLAIMS FOR LOST PROFITS,
LOST DATA, LOSS OF GOODWILL OR BUSINESS REPUTATION, COST OF PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES, WORK STOPPAGE,
COMPUTER FAILURE OR MALFUNCTION, ANY OTHER COMMERCIAL DAMAGES OR LOSSES, OR ANY PERSONAL INJURY OR PROPERTY DAMAGES,
EVEN IF WE KNEW OR SHOULD HAVE KNOWN OF THE POSSIBILITY OF SUCH DAMAGES. BECAUSE SOME STATES OR JURISDICTIONS DO NOT ALLOW
THE EXCLUSION OR THE LIMITATION OF LIABILITY FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES, IN SUCH STATES OR JURISDICTIONS,
OUR LIABILITY SHALL BE LIMITED TO THE EXTENT PERMITTED BY LAW. IF YOU ARE A CALIFORNIA RESIDENT, YOU WAIVE YOUR RIGHTS
WITH RESPECT TO CALIFORNIA CIVIL CODE SECTION 1542, WHICH SAYS "A GENERAL RELEASE DOES NOT EXTEND TO CLAIMS WHICH THE
CREDITOR DOES NOT KNOW OR SUSPECT TO EXIST IN HIS FAVOR AT THE TIME OF EXECUTING THE RELEASE, WHICH, IF KNOWN BY HIM
MUST HAVE MATERIALLY AFFECTED HIS SETTLEMENT WITH THE DEBTOR.”
### Indemnification
You agree to hold harmless and indemnify Cirrus Labs, and its subsidiaries, affiliates, officers, agents, employees,
advertisers, licensors, suppliers or partners (collectively "Cirrus Labs and Partners") from and against any
third party claim arising from or in any way related to (a) Your breach of the Terms, (b) Your use of the Service,
(c) Your violation of applicable laws, rules or regulations in connection with the Service, or (d) Your Customer Source Code,
including any liability or expense arising from all claims, losses, damages (actual and consequential), suits, judgments,
litigation costs and attorneys' fees, of every kind and nature. In such a case, Cirrus Labs will provide You with
written notice of such claim, suit or action.
### Choice of Law and Dispute Resolution
The Terms of Service shall be deemed to have been entered into and shall be construed and enforced in accordance with
the laws of the State of New York as applied to contracts made and performed entirely within New York, without giving
effect to any conflicts of law statutes. Any controversy, dispute or claim arising out of or related to the
Terms of Service or the Service shall be settled by final and binding arbitration to be conducted by an arbitration
tribunal in the State of New York and the County of New York, pursuant to the rules of the American Arbitration Association.
Any and all disputes that you may have with Cirrus Labs shall be resolved individually, without resort to any form of class action.
### General Legal Terms
The Terms constitute the whole legal agreement between You and Cirrus Labs and govern Your use of the Service and
completely replace any prior agreements between You and Cirrus Labs in relation to the Service.
If any part of the Terms of Service is held invalid or unenforceable, that portion shall be construed in a manner
consistent with applicable law to reflect, as nearly as possible, the original intentions of the parties, and
the remaining portions shall remain in full force and effect.
The failure of Cirrus Labs to exercise or enforce any right or provision of the Terms of Service shall not constitute
a waiver of such right or provision. The failure of either party to exercise in any respect any right provided for herein
shall not be deemed a waiver of any further rights hereunder.
You agree that if Cirrus Labs does not exercise or enforce any legal right or remedy which is contained in the Terms
(or which Cirrus Labs has the benefit of under any applicable law), this will not be taken to be a formal waiver of
Cirrus Labs' rights and that those rights or remedies will still be available to Cirrus Labs.
Cirrus Labs shall not be liable for failing or delaying performance of its obligations resulting from any condition
beyond its reasonable control, including but not limited to, governmental action, acts of terrorism, earthquake, fire,
flood or other acts of God, labor conditions, power failures, and Internet disturbances.
We may assign this contract at any time to any parent, subsidiary, or any affiliated company, or as part of the sale to,
merger with, or other transfer of our company to another entity.
This page was last updated on 02/03/2019.
-102
View File
@@ -1,102 +0,0 @@
---
hide:
- navigation
title: Licensing and Support
description: Free Tier with 100 CPU core limit. Very affordable Tiers for larger enterprises.
---
Both [Tart Virtualization](https://github.com/cirruslabs/tart) and [Orchard Orchestration](https://github.com/cirruslabs/orchard)
are licensed under [Fair Source License](https://fair.io/). Usage on personal computers including personal workstations is royalty-free,
but organizations that exceed a certain number of server installations (100 CPU cores for Tart and/or 4 hosts for Orchard)
will be required to obtain a paid license.
??? note "Host CPU Core usage"
The virtual CPU cores of Tart VMs are not tied to specific physical cores of the host CPU. Instead, for optimal performance
Tart VMs will automatically try to balance compute between all available cores of the host CPU. As a result,
all performance and energy-efficient cores of the host CPU are always counted towards the license usage.
## License Tiers
By default, when no [license is purchased](#get-the-license), it is assumed that an organization is using a Free Tier license.
You can find the Free Tier license text in [Tart](https://github.com/cirruslabs/tart/blob/main/LICENSE) and [Orchard](https://github.com/cirruslabs/orchard/blob/main/LICENSE) repositories.
Free Tier license has a 100 CPU core limit for Tart and 4 Orchard Workers limit for Orchard.
??? info "Usage Scenarios Examples"
Here are a few examples that fit into the free tier:
- Using Tart on 12 Mac Minis with 8 CPUs each running up to 24 VMs in parallel.
- Creating an Orchard cluster of 4 Mac Studio workers with 24 CPUs each.
Here are a few examples that do not fit into the free tier:
- Using Tart on 13 Mac Minis with 8 CPUs each.
- Creating an Orchard cluster of 5 Mac Minis workers with 8 CPUs each.
### Gold Tier
If an organization wishes to exceed the limits of the Free Tier license, a purchase of the [Gold Tier License](#get-the-license) is required, which costs \$1000 per month.
Gold Tier license has a 500 CPU core limit for Tart and 20 Orchard Workers limit for Orchard.
### Platinum Tier
If an organization wishes to exceed the limits of the Gold Tier license, a purchase of the [Platinum Tier License](#get-the-license) is required, which costs \$3000 per month.
Platinum Tier license has a 3,000 CPU core limit for Tart and 200 Orchard Workers limit for Orchard.
### Diamond Tier
For organizations that wish to exceed the limits of the Platinum Tier license, a purchase of a [custom Diamond Tier License](#get-the-license) is required, which costs \$1 per CPU core per month and gives the ability to run unlimited Orchard Workers.
## Get the license
If your organization is interested in purchasing one of the license tiers, please email [licensing@cirruslabs.org](mailto:licensing@cirruslabs.org).
You can see a template of a license subscription agreement [here](assets/TartLicenseSubscription.pdf).
!!! info "Running on AWS?"
There are [official AMIs for EC2 Mac Instances](https://aws.amazon.com/marketplace/pp/prodview-qczco34wlkdws)
with preconfigured Tart installation that is optimized to work within AWS infrastructure.
Additionally, there is a [ECR Pulic Gallery mirror](https://gallery.ecr.aws/cirruslabs/macos) of all the
[Tart VM images managed by us](https://github.com/cirruslabs/macos-image-templates).
## General Support
The best way to ask general questions about particular use cases is to email our support team at [support@cirruslabs.org](mailto:support@cirruslabs.org).
Our support team is trying our best to respond ASAP, but there is no guarantee on a response time unless your organization
has a paid license subscription which includes [Priority Support](#priority-support).
If you have a feature request or noticed lack of some documentation please feel free to [create a GitHub issue](https://github.com/cirruslabs/tart/issues/new).
Our support team will answer it by replying to the issue or by updating the documentation.
## Priority Support
In addition to the general support we provide a *Priority Support* with guaranteed response times included in all the paid license tiers.
| Severity | Support Impact | First Response Time SLA | Hours | How to Submit |
|----------|-----------------------------------------------------------------------------------------------|-------------------------|-------|--------------------------------------------------------------------------------------------------|
| 1 | Emergency (service is unavailable or completely unusable). | 30 minutes | 24x7 | Please use urgent email address. |
| 2 | Highly Degraded (Important features unavailable or extremely slow; No acceptable workaround). | 4 hours | 24x5 | Please use priority email address. |
| 3 | Medium Impact. | 8 hours | 24x5 | Please use priority email address. |
| 4 | Low Impact. | 24 hours | 24x5 | Please use regular support email address. Make sure to send the email from your corporate email. |
`24x5` means period of time from 9AM on Monday till 5PM on Friday in EST timezone.
<!-- markdownlint-disable MD037 -->
??? note "Support Impact Definitions"
* **Severity 1** - Your installation of Orchard is unavailable or completely unusable. An urgent issue can be filed and
our On-Call Support Engineer will respond within 30 minutes. Example: Orchard Controller is showing 502 errors for all users.
* **Severity 2** - Orchard installation is Highly Degraded. Significant Business Impact. Important features are unavailable
or extremely slowed, with no acceptable workaround.
* **Severity 3** - Something is preventing normal service operation. Some Business Impact. Important features of Tart or Orchard
are unavailable or somewhat slowed, but a workaround is available.
* **Severity 4** - Questions or Clarifications around features or documentation. Minimal or no Business Impact.
Information, an enhancement, or documentation clarification is requested, but there is no impact on the operation of Tart and/or Orchard.
!!! info "How to submit a priority or an urgent issue"
Once your organization [obtains a license](#license-tiers), members of your organization
will get access to separate support emails specified in your subscription contract.
+1 -1
View File
@@ -2,7 +2,7 @@
Compared to Worker, which can only be deployed on a macOS machine, Controller can be also deployed on Linux.
In fact, we've made a [container image](https://github.com/cirruslabs/orchard/pkgs/container/orchard) to ease deploying the Controller in container-native environments such as Kubernetes.
In fact, we've made a [container image](https://github.com/orgs/cirruslabs/packages/container/package/orchard) to ease deploying the Controller in container-native environments such as Kubernetes.
Another thing to keep in mind that Orchard API is secured by default: all requests must be authenticated with the credentials of a service account. When you first run Orchard Controller, a `bootstrap-admin` service account will be created automatically and credentials will be printed to the standard output.
+1 -1
View File
@@ -31,7 +31,7 @@ In this deployment method, we'll create a new job definition file for the launch
To begin, first install Orchard:
```shell
brew install cirruslabs/cli/orchard
brew install openai/tools/orchard
```
Ensure that the following command:
+3 -3
View File
@@ -1,4 +1,4 @@
Orchard has a REST API that follows [OpenAPI specification](https://swagger.io/specification/) and is described in [`api/openapi.yaml`](https://github.com/cirruslabs/orchard/blob/main/api/openapi.yaml).
Orchard has a REST API that follows [OpenAPI specification](https://swagger.io/specification/) and is described in [`api/openapi.yaml`](https://github.com/openai/orchard/blob/main/api/openapi.yaml).
You can run `orchard dev` locally and navigate to `http://127.0.0.1:6120/v1/` for interactive documentation.
@@ -85,7 +85,7 @@ def main():
# Create VM
response = requests.post("http://127.0.0.1:6120/v1/vms", auth=basic_auth, json={
"name": vm_name,
"image": "ghcr.io/cirruslabs/macos-sequoia-base:latest",
"image": "ghcr.io/cirruslabs/macos-tahoe-base:latest",
"cpu": 4,
"memory": 4096,
"startup_script": {
@@ -144,7 +144,7 @@ func main() {
Meta: v1.Meta{
Name: vmName,
},
Image: "ghcr.io/cirruslabs/macos-sequoia-base:latest",
Image: "ghcr.io/cirruslabs/macos-tahoe-base:latest",
CPU: 4,
Memory: 4096,
StartupScript: &v1.VMScript{
+1 -1
View File
@@ -10,7 +10,7 @@ Since the Orchard's initial release, we've managed to maintain the backwards com
In case a new functionality is introduced, you might be required to finish the upgrade of both the Controller and the Worker(s) to be able to use it fully.
In case there will be backwards-incompatible changes introduced in the future, we will try to do our best and highlight this in the [release notes](https://github.com/cirruslabs/orchard/releases) accordingly.
In case there will be backwards-incompatible changes introduced in the future, we will try to do our best and highlight this in the [release notes](https://github.com/openai/orchard/releases) accordingly.
## Observability
+14 -15
View File
@@ -1,6 +1,6 @@
Tart is great for running workloads on a single machine, but what if you have more than one computer at your disposal
and
a couple of VMs is not enough anymore for your needs? This is where [Orchard](https://github.com/cirruslabs/orchard)
a couple of VMs is not enough anymore for your needs? This is where [Orchard](https://github.com/openai/orchard)
comes in to play!
It allows you to orchestrate multiple Tart-capable hosts from either an Orchard CLI (which we demonstrate below)
@@ -9,7 +9,7 @@ or [through the API](integration-guide.md).
The easiest way to start is to run Orchard in local development mode:
```shell
brew install cirruslabs/cli/orchard
brew install openai/tools/orchard
orchard dev
```
@@ -26,7 +26,7 @@ more information.
Now, let's create a Virtual Machine:
```shell
orchard create vm --image ghcr.io/cirruslabs/macos-sequoia-base:latest sequoia-base
orchard create vm --image ghcr.io/cirruslabs/macos-tahoe-base:latest tahoe-base
```
You can check a list of VM resources to see if the Virtual Machine we've created above is already running:
@@ -48,7 +48,7 @@ instance. Orchard Controller instance is secured by default and all API calls ar
To SSH into a VM, use the `orchard ssh` command:
```shell
orchard ssh vm sequoia-base
orchard ssh vm tahoe-base
```
You can specify the `--username` and `--password` flags to specify the username/password pair to use for the SSH
@@ -58,14 +58,14 @@ You can also execute remote commands instead of spawning a login shell, similarl
a command argument:
```shell
orchard ssh vm sequoia-base "uname -a"
orchard ssh vm tahoe-base "uname -a"
```
You can execute scripts remotely this way, by telling the remote command-line interpreter to read from the standard
input and using the redirection operator as follows:
```shell
orchard ssh vm sequoia-base "bash -s" < script.sh
orchard ssh vm tahoe-base "bash -s" < script.sh
```
### VNC
@@ -73,7 +73,7 @@ orchard ssh vm sequoia-base "bash -s" < script.sh
Similarly to `ssh` command, you can use `vnc` command to open Screen Sharing into a remote VM:
```shell
orchard vnc vm sequoia-base
orchard vnc vm tahoe-base
```
You can specify the `--username` and `--password` flags to specify the username/password pair to use for the VNC
@@ -84,7 +84,7 @@ protocol. By default, `admin`/`admin` is used.
The following command will delete the VM we've created above and clean-up the resources associated with it:
```shell
orchard delete vm sequoia-base
orchard delete vm tahoe-base
```
## Environment variables
@@ -92,10 +92,9 @@ orchard delete vm sequoia-base
In addition to controlling the Orchard via the CLI arguments, there are environment variables that may be beneficial
both when automating Orchard and in daily use:
| Variable name | Description |
|---------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| `ORCHARD_HOME` | Override Orchard's home directory. Useful when running multiple Orchard instances on the same host and when testing. |
| `ORCHARD_LICENSE_TIER` | The default license limit only allows connecting 4 Orchard Workers to the Orchard Controller. If you've purchased a [Gold Tier License](../licensing.md), set this variable to `gold` to increase the limit to 20 Orchard Workers. And if you've purchased a [Platinum Tier License](../licensing.md), set this variable to `platinum` to increase the limit to 200 Orchard Workers. |
| `ORCHARD_URL` | Override controller URL on per-command basis. |
| `ORCHARD_SERVICE_ACCOUNT_NAME` | Override service account name (used for controller API auth) on per-command basis. |
| `ORCHARD_SERVICE_ACCOUNT_TOKEN` | Override service account token (used for controller API auth) on per-command basis. |
| Variable name | Description |
|---------------------------------|------------------------------------------------------------------------------------------------------------------|
| `ORCHARD_HOME` | Override Orchard's home directory. Useful when running multiple Orchard instances on the same host and testing. |
| `ORCHARD_URL` | Override controller URL on a per-command basis. |
| `ORCHARD_SERVICE_ACCOUNT_NAME` | Override service account name (used for controller API auth) on a per-command basis. |
| `ORCHARD_SERVICE_ACCOUNT_TOKEN` | Override service account token (used for controller API auth) on a per-command basis. |
+2 -2
View File
@@ -3,10 +3,10 @@
The easiest way to install Orchard CLI is through the [Homebrew](https://brew.sh/):
```shell
brew install cirruslabs/cli/orchard
brew install openai/tools/orchard
```
Binaries and packages for other architectures can be found in [GitHub Releases](https://github.com/cirruslabs/orchard/releases).
Binaries and packages for other architectures can be found in [GitHub Releases](https://github.com/openai/orchard/releases).
## Setting up a context
+115 -11
View File
@@ -8,32 +8,36 @@ description: Install Tart and run your first virtual machine on Apple Silicon in
Try running a Tart VM on your Apple Silicon device running macOS 13.0 (Ventura) or later (will download a 25 GB image):
```bash
brew install cirruslabs/cli/tart
tart clone ghcr.io/cirruslabs/macos-sequoia-base:latest sequoia-base
tart run sequoia-base
brew install openai/tools/tart
tart clone ghcr.io/cirruslabs/macos-tahoe-base:latest tahoe-base
tart run tahoe-base
```
??? info "Manual installation from a release archive"
It's also possible to manually install `tart` binary from the latest released archive:
```bash
curl -LO https://github.com/cirruslabs/tart/releases/latest/download/tart.tar.gz
curl -LO https://github.com/openai/tart/releases/latest/download/tart.tar.gz
tar -xzvf tart.tar.gz
./tart.app/Contents/MacOS/tart clone ghcr.io/cirruslabs/macos-sequoia-base:latest sequoia-base
./tart.app/Contents/MacOS/tart run sequoia-base
./tart.app/Contents/MacOS/tart clone ghcr.io/cirruslabs/macos-tahoe-base:latest tahoe-base
./tart.app/Contents/MacOS/tart run tahoe-base
```
Please note that `./tart.app/Contents/MacOS/tart` binary is required to be used in order to trick macOS
to pick `tart.app/Contents/embedded.provisionprofile` for elevated privileges that Tart needs.
<p align="center">
<img src="https://github.com/cirruslabs/tart/raw/main/Resources/TartScreenshot.png"/>
<img src="https://github.com/openai/tart/raw/main/Resources/TartScreenshot.png"/>
</p>
## VM images
The following macOS images are currently available:
* macOS 26 (Tahoe)
* `ghcr.io/cirruslabs/macos-tahoe-vanilla:latest`
* `ghcr.io/cirruslabs/macos-tahoe-base:latest`
* `ghcr.io/cirruslabs/macos-tahoe-xcode:latest`
* macOS 15 (Sequoia)
* `ghcr.io/cirruslabs/macos-sequoia-vanilla:latest`
* `ghcr.io/cirruslabs/macos-sequoia-base:latest`
@@ -70,7 +74,7 @@ tart set ubuntu --disk-size 50
tart run ubuntu
```
These Linux images can be ran natively on [Vetu](https://github.com/cirruslabs/vetu), our virtualization solution for Linux, assuming that Vetu itself is running on an `arm64` machine.
These Linux images can be run natively on [Vetu](https://github.com/openai/vetu), a virtualization solution for Linux, assuming that Vetu itself is running on an `arm64` machine.
Similarly to macOS, there's also a [full list of images](https://github.com/orgs/cirruslabs/packages?repo_name=linux-image-templates) in which you can discovery specific tags (e.g. `ghcr.io/cirruslabs/ubuntu:22.04`) and [Linux-specific Packer templates](https://github.com/cirruslabs/linux-image-templates) that were used to generate these images.
@@ -86,7 +90,7 @@ These credentials work both for logging in via GUI, console (Linux) and SSH.
If the guest VM is running and configured to accept incoming SSH connections you can conveniently connect to it like so:
```bash
ssh admin@$(tart ip sequoia-base)
ssh admin@$(tart ip tahoe-base)
```
!!! tip "Running scripts inside Tart virtual machines"
@@ -95,10 +99,61 @@ ssh admin@$(tart ip sequoia-base)
```bash
brew install cirruslabs/cli/sshpass
sshpass -p admin ssh -o "StrictHostKeyChecking no" -o "UserKnownHostsFile=/dev/null" admin@$(tart ip sequoia-base) "uname -a"
sshpass -p admin ssh -o "StrictHostKeyChecking no" -o "UserKnownHostsFile=/dev/null" admin@$(tart ip sequoia-base) < script.sh
sshpass -p admin ssh -o "StrictHostKeyChecking no" -o "UserKnownHostsFile=/dev/null" admin@$(tart ip tahoe-base) "uname -a"
sshpass -p admin ssh -o "StrictHostKeyChecking no" -o "UserKnownHostsFile=/dev/null" admin@$(tart ip tahoe-base) < script.sh
```
## Creating VM images
Tart supports macOS and Linux virtual machines. All commands like `run` and `pull` work the same way regardless of the underlying OS a particular VM image has.
The only difference is how such VM images are created. Please check sections below for [macOS](#creating-a-macos-vm-image-from-scratch) and [Linux](#creating-a-linux-vm-image-from-scratch) instructions.
### Creating a macOS VM image from scratch
Tart can create VMs from `*.ipsw` files. You can download a specific `*.ipsw` file [here](https://ipsw.me/) or you can
use `latest` instead of a path to `*.ipsw` to download the latest available version:
```bash
tart create --from-ipsw=latest tahoe-vanilla
tart run tahoe-vanilla
```
After the initial booting of the VM, you'll need to manually go through the macOS installation process. As a convention we recommend creating an `admin` user with an `admin` password. After the regular installation please do some additional modifications in the VM:
1. Enable Auto-Login. Users & Groups -> Login Options -> Automatic login -> admin.
2. Allow SSH. Sharing -> Remote Login
3. Disable Lock Screen. Preferences -> Lock Screen -> disable "Require Password" after 5.
4. Disable Screen Saver.
5. Run `sudo visudo` in Terminal, find `%admin ALL=(ALL) ALL` add `admin ALL=(ALL) NOPASSWD: ALL` to allow sudo without a password.
### Creating a Linux VM image from scratch
Linux VMs are supported on hosts running macOS 13.0 (Ventura) or newer.
```bash
# Create a bare VM
tart create --linux ubuntu
# Install Ubuntu
tart run --disk focal-desktop-arm64.iso ubuntu
# Run VM
tart run ubuntu
```
After the initial setup please make sure your VM can be SSH-ed into by running the following commands inside your VM:
```bash
sudo apt update
sudo apt install -y openssh-server
sudo ufw allow ssh
```
### Configuring a VM
By default, a Tart VM uses 2 CPUs and 4 GB of memory with a `1024x768` display. This can be changed after VM creation with `tart set` command.
Please refer to `tart set --help` for additional details.
## Mounting directories
To mount a directory, run the VM with the `--dir` argument:
@@ -161,3 +216,52 @@ The directory we've mounted above will be accessible from the `/mnt/shared/proje
```shell
com.apple.virtio-fs.automount /mnt/shared virtiofs rw,relatime 0 0
```
## Working with a Remote OCI Container Registry
Tart supports interacting with Open Container Initiative (OCI) registries, but only runs images created and pushed by Tart. This means images created for container engines, like Docker, can't be pulled. Instead, create a custom image as documented above.
For example, let's say you want to push/pull images to an OCI registry hosted at `https://acme.io/`.
### Registry Authorization
First, you need to login to `acme.io` with the `tart login` command:
```bash
tart login acme.io
```
If you login to your registry with OAuth, you may need to create an access token to use as the password.
Credentials are securely stored in Keychain.
In addition, Tart supports [Docker credential helpers](https://docs.docker.com/engine/reference/commandline/login/#credential-helpers)
if defined in `~/.docker/config.json`.
Finally, `TART_REGISTRY_USERNAME` and `TART_REGISTRY_PASSWORD` environment variables allow to override authorization
for all registries, which might be useful for integrating with your CI's secret management.
You can also set the `TART_REGISTRY_HOSTNAME` environment variable to apply these overrides only to a specific host.
### Pushing a Local Image
Once credentials are saved for `acme.io`, run the following command to push a local images remotely with two tags:
```bash
tart push my-local-vm-name acme.io/remoteorg/name:latest acme.io/remoteorg/name:v1.0.0
```
### Pulling a Remote Image
You can either pull an image:
```bash
tart pull acme.io/remoteorg/name:latest
```
or create a VM from a remote image:
```bash
tart clone acme.io/remoteorg/name:latest my-local-vm-name
```
If the specified image is not already present, this invocation calls the `tart pull` implicitly before cloning.
+2 -2
View File
@@ -185,7 +185,7 @@
/>
</div>
<figcaption class="md-typeset">
<h2>Run at scale with <a href="https://github.com/cirruslabs/orchard">Orchard</a></h2>
<h2>Run at scale with <a href="https://github.com/openai/orchard">Orchard</a></h2>
<p>
Tart toolset includes Orchard Orchestration &mdash; tool to run and manage Tart virtual
machines at scale on a cluster of Apple Silicon hosts. An Orchard Cluster exposes a simple REST API to
@@ -214,7 +214,7 @@
</h1>
</header>
<script>
fetch("https://api.github.com/repos/cirruslabs/tart/releases?per_page=100")
fetch("https://api.github.com/repos/openai/tart/releases?per_page=100")
.then((response) => response.json())
.then((releases) => {
let allDownloads = 0;
-12
View File
@@ -1,12 +0,0 @@
source = [ "dist/tart_darwin_all/tart.app/Contents/MacOS/tart" ]
bundle_id = "com.github.cirruslabs.tart"
apple_id {
username = "hello@cirruslabs.org"
password = "@env:AC_PASSWORD"
}
sign {
application_identity = "Developer ID Application: Cirrus Labs, Inc."
entitlements_file = "Resources/tart-prod.entitlements"
}
+1 -1
View File
@@ -46,7 +46,7 @@ def vm_with_random_disk(tart):
disk_path = os.path.join(tart.home(), "vms", vm_name, "disk.img")
with tempfile.NamedTemporaryFile(delete=False) as tf:
tf.write(os.urandom(amount_to_transfer.bytes))
tf.write(os.urandom(int(amount_to_transfer.bytes)))
tf.close()
os.rename(tf.name, disk_path)
+11 -9
View File
@@ -1,10 +1,10 @@
repo_url: https://github.com/cirruslabs/tart/
repo_url: https://github.com/openai/tart/
site_url: https://tart.run/
edit_uri: blob/main/docs/
site_name: Tart Virtualization
site_author: Cirrus Labs
copyright: © Cirrus Labs 2017-present
site_author: OpenAI
copyright: © OpenAI 2022-present
site_description: >
Tart is a virtualization toolset to build, run and manage macOS and Linux virtual machines (VMs) on Apple Silicon.
@@ -53,6 +53,9 @@ plugins:
debug: true
- search
- minify
- redirects:
redirect_maps:
'integrations/vm-management.md': quick-start.md
markdown_extensions:
- markdown.extensions.admonition
@@ -96,8 +99,7 @@ nav:
- "GitHub Actions": https://cirrus-runners.app/
- "GitLab Runner": integrations/gitlab-runner.md
- "Buildkite": integrations/buildkite.md
- "Managing VMs": integrations/vm-management.md
- "Support & Licensing": licensing.md
- "Packer": integrations/packer.md
- "Orchestration":
- "Quick Start": orchard/quick-start.md
- "Architecture and Security": orchard/architecture-and-security.md
@@ -108,8 +110,8 @@ nav:
- "Integrating with the API": orchard/integration-guide.md
- "FAQ": faq.md
- "Legal":
- 'Terms of Service': legal/terms.md
- 'Privacy': legal/privacy.md
- 'Terms of Use': https://openai.com/policies/terms-of-use/
- 'Privacy Policy': https://openai.com/policies/privacy-policy/
- Blog:
- blog/index.md
@@ -125,5 +127,5 @@ extra:
find what they're searching for. With your consent, you're helping us to
make our documentation better.
social:
- icon: fontawesome/brands/twitter
link: 'https://twitter.com/cirrus_labs'
- icon: fontawesome/brands/x-twitter
link: 'https://x.com/OpenAI'
+1 -1
View File
@@ -1,3 +1,3 @@
#!/usr/bin/env bash
docker run --pull=always --rm -it -p 8000:8000 -v ${PWD}:/docs ghcr.io/cirruslabs/mkdocs-material-insiders:latest build
docker run --pull=always --rm -it -p 8000:8000 -v ${PWD}:/docs ghcr.io/squidfunk/mkdocs-material:latest build
+4 -3
View File
@@ -1,18 +1,19 @@
#!/bin/sh
# helper script to build and run a signed tart binary
# usage: ./scripts/run-signed.sh run sequoia-base
# usage: ./scripts/run-signed.sh run macos
set -e
swift build --product tart
codesign --sign - --entitlements Resources/tart-dev.entitlements --force .build/debug/tart
rm -Rf .build/tart.app/
mkdir -p .build/tart.app/Contents/MacOS .build/tart.app/Contents/Resources
cp -c .build/debug/tart .build/tart.app/Contents/MacOS/tart
cp -c Resources/embedded.provisionprofile .build/tart.app/Contents/embedded.provisionprofile
cp -c Resources/Info.plist .build/tart.app/Contents/Info.plist
cp -c Resources/AppIcon.png .build/tart.app/Contents/Resources
cp -c "Resources/actool/UPW Tart.icns" "Resources/actool/Assets.car" .build/tart.app/Contents/Resources/
codesign --sign - --entitlements Resources/tart-dev.entitlements --force .build/tart.app
.build/tart.app/Contents/MacOS/tart "$@"
+1 -1
View File
@@ -1,3 +1,3 @@
#!/usr/bin/env bash
docker run --pull=always --rm -it -p 8000:8000 -v ${PWD}:/docs ghcr.io/cirruslabs/mkdocs-material-insiders:latest
docker run --pull=always --rm -it -p 8000:8000 -v ${PWD}:/docs ghcr.io/squidfunk/mkdocs-material:latest