AWS Mac实例Ansible部署Xcode时许可证接受失败问题
AWS Mac实例Packer+Ansible构建自定义AMI时Xcode许可证同意失败问题
问题背景
在AWS上通过Packer和Ansible部署多台Mac实例,构建包含Xcode 15.3的自定义AMI,源AMI为amzn-ec2-macos-14.3-20240208-211058。执行Ansible的Xcode安装任务时,"Accept license"步骤持续失败,报错提示未同意Xcode许可证协议,调整任务执行顺序后仍无法解决。
相关Ansible任务代码
- name: Remove existing Xcode.app file: path: "/Applications/Xcode.app" state: absent become: true tags: - xcode - name: Remove existing Xcode-beta.app file: path: "/Applications/Xcode-beta.app" state: absent become: true tags: - xcode - name: Check Xcode XIP exists stat: path: "{{ xcode_xip_path }}" register: "xcode_xip_check" changed_when: false tags: - xcode - name: Download Xcode XIP file from aws s3 bucket shell: /usr/local/bin/aws s3 cp s3://{{ aws_s3_bucket_name }}/{{ xcode_xip_name }} {{ xcode_xip_path }} --no-progress when: not xcode_xip_check.stat.exists tags: - xcode - name: Extract {{ xcode_xip_name }} command: xip -x {{ xcode_xip_path }} args: chdir: /Applications tags: - xcode - name: Accept license shell: "/Applications/Xcode.app/Contents/Developer/usr/bin/xcodebuild -license accept" become: true tags: - xcode - name: Switch dev tools to Xcode command: xcode-select --switch /Applications/Xcode.app/Contents/Developer become: true tags: - xcode - name: Validate xcode command: "/Applications/Xcode.app/Contents/Developer/usr/bin/xcodebuild -runFirstLaunch" become: true tags: - xcode - name: Activate developer mode command: /usr/sbin/DevToolsSecurity -enable become: true tags: - xcode - name: Install Additional Components MobileDevice command: installer -pkg MobileDevice.pkg -target / become: true args: chdir: /Applications/Xcode.app/Contents/Resources/Packages/ tags: - xcode - name: Install Additional Components MobileDeviceDevelopment command: installer -pkg MobileDeviceDevelopment.pkg -target / become: true args: chdir: /Applications/Xcode.app/Contents/Resources/Packages/ tags: - xcode - name: Install Additional Components XcodeSystemResources command: installer -pkg XcodeSystemResources.pkg -target / become: true args: chdir: /Applications/Xcode.app/Contents/Resources/Packages/ tags: - xcode - name: Remove installer {{ xcode_xip_path }} file: path: "{{ xcode_xip_path }}" state: absent tags: - xcode
错误日志
amazon-ebs.mac-packer-aws: TASK [Accept license] ************************************** amazon-ebs.mac-packer-aws: task path: /var/lib/ansible-playbook/tasks/xcode-install.yml:39 amazon-ebs.mac-packer-aws: fatal: [127.0.0.1]: FAILED! => { amazon-ebs.mac-packer-aws: "changed": false, amazon-ebs.mac-packer-aws: "module_stderr": "You have not agreed to the Xcode license agreements. Please run 'sudo xcodebuild -license' from within a Terminal window to review and agree to the Xcode and Apple SDKs license.\n", amazon-ebs.mac-packer-aws: "module_stdout": "", amazon-ebs.mac-packer-aws: "msg": "MODULE FAILURE\nSee stdout/stderr for the exact error", amazon-ebs.mac-packer-aws: "rc": 69 amazon-ebs.mac-packer-aws: }
解决方法
1. 调整任务执行顺序
当前流程是先同意许可证再切换开发者工具路径,但xcodebuild依赖xcode-select指向的路径来识别系统的许可证状态。将任务顺序调整为:
- 先执行
Switch dev tools to Xcode - 再执行
Accept license
修改后的任务片段:
- name: Switch dev tools to Xcode command: xcode-select --switch /Applications/Xcode.app/Contents/Developer become: true tags: - xcode - name: Accept license shell: "/Applications/Xcode.app/Contents/Developer/usr/bin/xcodebuild -license accept" become: true tags: - xcode
2. 直接修改许可证偏好文件
Mac系统通过/Library/Preferences/com.apple.dt.Xcode.plist存储Xcode许可证同意状态,可以直接通过命令设置,替代xcodebuild -license accept:
- name: Accept Xcode license via plist shell: | defaults write /Library/Preferences/com.apple.dt.Xcode IDELastGMLicenseAgreedTo -string "Xcode_15.3" defaults write /Library/Preferences/com.apple.dt.Xcode IDEXcodeVersionForAgreedGMLicense -string "15.3" plutil -convert xml1 /Library/Preferences/com.apple.dt.Xcode.plist become: true tags: - xcode
注意:Xcode_15.3是Xcode 15.3对应的许可证标识,不同版本需要替换为对应字符串。
3. 非交互式环境下完善命令执行条件
在Packer的非交互式环境中,执行xcodebuild时需要确保环境变量正确,修改许可证同意任务:
- name: Accept license in non-interactive env shell: | export DEVELOPER_DIR="/Applications/Xcode.app/Contents/Developer" sudo "$DEVELOPER_DIR/usr/bin/xcodebuild" -license accept become: true tags: - xcode
4. 先读取许可证再同意
部分场景下,先读取许可证内容再执行同意操作可解决非交互式环境的问题:
- name: Accept license with pre-read shell: | /Applications/Xcode.app/Contents/Developer/usr/bin/xcodebuild -license show | sudo /Applications/Xcode.app/Contents/Developer/usr/bin/xcodebuild -license accept become: true tags: - xcode
验证方法
修改Ansible任务后,重新通过Packer构建AMI,启动测试实例后执行以下命令验证:
xcodebuild -version xcode-select -p
若能正常输出Xcode版本和开发者路径,说明许可证同意成功。
内容的提问来源于stack exchange,提问作者Miguel Cardoso
相关产品推荐
相关产品推荐

