macadmins / macadmins/python

Replace munki-pkg with swiftpkg for managed Python packaging

Open
#94 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Shell
Stars
257
Forks
29
PR merge metrics
No merged PRs in 30d

Description

## Objective
Migrate this repository's managed Python installer packaging to [codecarton/swiftpkg](https://github.com/codecarton/swiftpkg) and retire the munki-pkg build dependency.

## Current behavior
`build_python_framework_pkgs.zsh` downloads a pinned munki-pkg commit using `MP_SHA`, `MP_BINDIR`, and `MP_ZIP`. Its `build_pkg()` function generates `recommended/build-info.json`, stages `preinstall-cleanup`, invokes `munkipkg`, and moves the signed package into `outputs/`. Notarization and stapling run separately. Without an installer identity, the script skips package creation and still produces the framework ZIP.

## Implementation scope
- Select and pin a published swiftpkg CLI release compatible with Apple Silicon build hosts; verify the downloaded artifact against a pinned SHA-256 and document prerequisites.
- Replace the munki-pkg download, temporary paths, and invocation with swiftpkg; propagate failures clearly.
- Validate compatibility of every generated build-info setting, especially `ownership`, `suppress_bundle_relocation`, `preserve_xattr`, `distribution_style`, and `signing_info`. Implement equivalent behavior for any unsupported settings.
- Preserve the package identifier (`io.macadmins.python.recommended`), version derivation, output filename/location, payload layout, permissions, symlinks, extended attributes, and preinstall cleanup behavior.
- Preserve framework code signing and the existing installer signing/notarization/stapling sequence; avoid duplicate notarization.
- Ensure Python 3.11, 3.12, 3.13, and 3.14 workflows use the replacement and continue publishing expected artifacts; update workflows only where necessary.
- Update README build prerequisites and credits. Remove active munki-pkg dependencies and obsolete bootstrap references while retaining appropriate historical attribution.

## Acceptance criteria
- [ ] Local and CI packaging use the pinned swiftpkg CLI with verified artifact integrity; no active build path downloads or executes munki-pkg.
- [ ] All generated build-info options have verified equivalent behavior, with any migration differences documented.
- [ ] On Apple Silicon, inspect a baseline munki-pkg package and replacement package to confirm equivalent receipts, version, install paths, payload, ownership/modes, symlinks, extended attributes, installer scripts, and non-relocation behavior.
- [ ] Signed packages pass signature checks, notarization, and stapling validation using the existing signing credentials.
- [ ] Clean-install and upgrade smoke tests on a disposable Apple Silicon Mac confirm preinstall cleanup, framework installation at `/Library/ManagedFrameworks/Python/Python3.framework`, the `managed_python3` symlink, and execution/imports of the managed runtime and bundled dependencies.
- [ ] The no-installer-identity path continues producing the framework ZIP without requiring signing credentials.
- [ ] Each supported Python workflow builds and publishes the expected package artifact.
- [ ] `zsh -n build_python_framework_pkgs.zsh` passes; any modified workflow YAML parses successfully.
- [ ] README documents the replacement tool, pinned version/update procedure, and prerequisites.

## Boundaries
This change replaces the package builder. It does not remove support for deploying the resulting installer through Munki, change Python/runtime dependencies, add the Swiftpkgr desktop app, or change the managed framework's installation contract.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with build_python_framework_pkgs.zsh, especially build_pkg(), the munki-pkg bootstrap variables, and the existing build-info.json generation. Then inspect the Python 3.11–3.14 workflow files and README prerequisites. Compare baseline and replacement packages on Apple Silicon, and use the listed shell, signing, notarization, smoke-test, and artifact checks to verify completion.

Written by the indexing model from the issue text.

Assessment

Tech stack
shell
Domain
build-system, ci-cd, tooling
Issue type
Refactor
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.