From 0f9957d5e597a13068302a25e4fbbbd264a9073a Mon Sep 17 00:00:00 2001 From: Andrew Blakeslee Moore Date: Mon, 13 Jul 2026 19:37:06 -0700 Subject: [PATCH] vminit image: add 'make vminit-image-login' for Keychain-based GHCR auth MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit cctl login stores the credential in the macOS Keychain, which cctl images push reads automatically — so pushing needs no REGISTRY_* env vars after a one-time login. Env vars remain as a fallback. Co-Authored-By: Claude Opus 4.8 --- PATCHES.md | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/PATCHES.md b/PATCHES.md index 77ec605..7c00947 100644 --- a/PATCHES.md +++ b/PATCHES.md @@ -82,8 +82,9 @@ Patches #8+ live in `vminitd/` (the guest agent), which rides in the initfs OCI until that image is rebuilt from this source and published, and `ContainerEngine.vminitReference` points at it. Build it with **`make vminit-image`** (root Makefile) — it builds cctl + the guest vminitd/vmexec from this vendored tree and packages `ghcr.io/abkslm/vminit:` into the local cctl -store; `make vminit-image-push` (with GHCR creds in the environment) publishes it, and `vminitReference` -is pinned to that custom image. First time on a machine, run `make vminit-image-prep` once (installs +store; `make vminit-image-push` publishes it (authenticate once with `make vminit-image-login`, which +stores a GHCR token in the macOS Keychain — or set `REGISTRY_HOST`/`USERNAME`/`TOKEN`), and +`vminitReference` is pinned to that custom image. First time on a machine, run `make vminit-image-prep` once (installs the swiftly toolchain + musl SDK the guest cross-build needs). Bump the `-nucleicN` tag suffix and rebuild whenever a guest patch changes. Built locally, not in CI: the host framework needs the macOS 26+ Virtualization SDK that GitHub-hosted runners lack.