Split Windows client bootstrap profiles
This commit is contained in:
@@ -33,7 +33,10 @@ function Write-PackageManifest {
|
||||
param(
|
||||
[Parameter(Mandatory)][string]$PackageRoot,
|
||||
[Parameter(Mandatory)][string]$PackageVersion,
|
||||
[Parameter(Mandatory)][string]$PackageKind
|
||||
[Parameter(Mandatory)][string]$PackageKind,
|
||||
[ValidateSet('Windows10Legacy', 'Windows11Modern')]
|
||||
[string]$CompatibilityProfile,
|
||||
[string]$TargetOperatingSystem
|
||||
)
|
||||
|
||||
$resolvedPackageRoot = (Resolve-Path -LiteralPath $PackageRoot).Path.TrimEnd('\')
|
||||
@@ -48,13 +51,19 @@ function Write-PackageManifest {
|
||||
}
|
||||
})
|
||||
$manifest = [ordered]@{
|
||||
SchemaVersion = 1
|
||||
SchemaVersion = 2
|
||||
Product = 'SGU Credential Provider'
|
||||
PackageKind = $PackageKind
|
||||
Version = $PackageVersion
|
||||
CreatedAt = (Get-Date).ToUniversalTime().ToString('o')
|
||||
Files = $files
|
||||
}
|
||||
if ($CompatibilityProfile) {
|
||||
$manifest['CompatibilityProfile'] = $CompatibilityProfile
|
||||
}
|
||||
if ($TargetOperatingSystem) {
|
||||
$manifest['TargetOperatingSystem'] = $TargetOperatingSystem
|
||||
}
|
||||
[IO.File]::WriteAllText(
|
||||
(Join-Path $resolvedPackageRoot 'package-manifest.json'),
|
||||
($manifest | ConvertTo-Json -Depth 6),
|
||||
@@ -78,21 +87,28 @@ if (-not $runtimeInstaller) {
|
||||
}
|
||||
|
||||
New-Item -ItemType Directory -Path $resolvedOutputRoot -Force | Out-Null
|
||||
$clientRoot = Join-Path $resolvedOutputRoot "sgu-client-bootstrap-$Version"
|
||||
$windows11ClientRoot = Join-Path $resolvedOutputRoot "sgu-windows11-client-bootstrap-$Version"
|
||||
$windows10ClientRoot = Join-Path $resolvedOutputRoot "sgu-windows10-legacy-client-bootstrap-$Version"
|
||||
$clientRoot = $windows11ClientRoot
|
||||
$serverRoot = Join-Path $resolvedOutputRoot "sgu-server-bootstrap-$Version"
|
||||
$linuxClientRoot = Join-Path $resolvedOutputRoot "sgu-linux-client-bootstrap-$Version"
|
||||
$azureRoot = Join-Path $resolvedOutputRoot "sgu-azure-infrastructure-$Version"
|
||||
$clientZip = "$clientRoot.zip"
|
||||
$windows11ClientZip = "$windows11ClientRoot.zip"
|
||||
$windows10ClientZip = "$windows10ClientRoot.zip"
|
||||
$serverZip = "$serverRoot.zip"
|
||||
$linuxClientZip = "$linuxClientRoot.zip"
|
||||
$azureZip = "$azureRoot.zip"
|
||||
foreach ($target in @($clientRoot,$serverRoot,$linuxClientRoot,$azureRoot,$clientZip,$serverZip,$linuxClientZip,$azureZip)) {
|
||||
foreach ($target in @(
|
||||
$windows11ClientRoot,$windows10ClientRoot,$serverRoot,$linuxClientRoot,$azureRoot,
|
||||
$windows11ClientZip,$windows10ClientZip,$serverZip,$linuxClientZip,$azureZip)) {
|
||||
if (Test-Path -LiteralPath $target) {
|
||||
throw "Release target already exists: $target"
|
||||
}
|
||||
}
|
||||
|
||||
New-Item -ItemType Directory -Path $clientRoot,$serverRoot,$linuxClientRoot,$azureRoot -Force | Out-Null
|
||||
New-Item -ItemType Directory `
|
||||
-Path $windows11ClientRoot,$windows10ClientRoot,$serverRoot,$linuxClientRoot,$azureRoot `
|
||||
-Force | Out-Null
|
||||
$welcomeFontNames = @(
|
||||
'IndivisaTextSans-Regular.otf',
|
||||
'IndivisaTextSans-Bold.otf',
|
||||
@@ -105,10 +121,6 @@ Copy-RequiredFile -Source (Join-Path $PSScriptRoot 'Invoke-SguClientBootstrap.ps
|
||||
-Destination (Join-Path $clientRoot 'Invoke-SguClientBootstrap.ps1')
|
||||
Copy-RequiredFile -Source (Join-Path $PSScriptRoot 'Start-SguClientEnrollment.cmd') `
|
||||
-Destination (Join-Path $clientRoot 'Start-SguClientEnrollment.cmd')
|
||||
Copy-RequiredFile -Source (Join-Path $PSScriptRoot 'Start-SguAzureClientEnrollment.cmd') `
|
||||
-Destination (Join-Path $clientRoot 'Start-SguAzureClientEnrollment.cmd')
|
||||
Copy-RequiredFile -Source (Join-Path $PSScriptRoot 'Install-SguAzureP2sClient.ps1') `
|
||||
-Destination (Join-Path $clientRoot 'Install-SguAzureP2sClient.ps1')
|
||||
$clientScripts = @(
|
||||
'Enable-LabRemoteAccess.ps1',
|
||||
'Enable-SguClientMonitoring.ps1',
|
||||
@@ -141,8 +153,26 @@ foreach ($fontName in $welcomeFontNames) {
|
||||
}
|
||||
Copy-RequiredFile -Source $runtimeInstaller.FullName `
|
||||
-Destination (Join-Path $clientRoot "payload\prerequisites\$($runtimeInstaller.Name)")
|
||||
Write-PackageManifest -PackageRoot $clientRoot -PackageVersion $Version -PackageKind Client
|
||||
Compress-Archive -Path (Join-Path $clientRoot '*') -DestinationPath $clientZip `
|
||||
|
||||
# Both Windows packages share the provider and enrollment implementation. The
|
||||
# Windows 10 artifact freezes the direct-network compatibility surface, while
|
||||
# the Windows 11 artifact adds the modern Azure P2S/pre-logon entry point.
|
||||
Copy-Item -Path (Join-Path $windows11ClientRoot '*') `
|
||||
-Destination $windows10ClientRoot -Recurse -Force
|
||||
Copy-RequiredFile -Source (Join-Path $PSScriptRoot 'Start-SguAzureClientEnrollment.cmd') `
|
||||
-Destination (Join-Path $windows11ClientRoot 'Start-SguAzureClientEnrollment.cmd')
|
||||
Copy-RequiredFile -Source (Join-Path $PSScriptRoot 'Install-SguAzureP2sClient.ps1') `
|
||||
-Destination (Join-Path $windows11ClientRoot 'Install-SguAzureP2sClient.ps1')
|
||||
|
||||
Write-PackageManifest -PackageRoot $windows10ClientRoot -PackageVersion $Version `
|
||||
-PackageKind WindowsClient -CompatibilityProfile Windows10Legacy `
|
||||
-TargetOperatingSystem 'Windows 10 Pro, Enterprise, or Education (build below 22000)'
|
||||
Write-PackageManifest -PackageRoot $windows11ClientRoot -PackageVersion $Version `
|
||||
-PackageKind WindowsClient -CompatibilityProfile Windows11Modern `
|
||||
-TargetOperatingSystem 'Windows 11 Pro, Enterprise, or Education (build 22000 or later)'
|
||||
Compress-Archive -Path (Join-Path $windows10ClientRoot '*') -DestinationPath $windows10ClientZip `
|
||||
-CompressionLevel Optimal
|
||||
Compress-Archive -Path (Join-Path $windows11ClientRoot '*') -DestinationPath $windows11ClientZip `
|
||||
-CompressionLevel Optimal
|
||||
|
||||
# Linux clients use their native PAM/SSSD sign-in stack rather than the Windows
|
||||
@@ -242,7 +272,8 @@ Compress-Archive -Path (Join-Path $azureRoot '*') -DestinationPath $azureZip `
|
||||
-CompressionLevel Optimal
|
||||
|
||||
$checksums = @(
|
||||
("{0} {1}" -f (Get-FileHash -LiteralPath $clientZip -Algorithm SHA256).Hash, (Split-Path $clientZip -Leaf))
|
||||
("{0} {1}" -f (Get-FileHash -LiteralPath $windows10ClientZip -Algorithm SHA256).Hash, (Split-Path $windows10ClientZip -Leaf))
|
||||
("{0} {1}" -f (Get-FileHash -LiteralPath $windows11ClientZip -Algorithm SHA256).Hash, (Split-Path $windows11ClientZip -Leaf))
|
||||
("{0} {1}" -f (Get-FileHash -LiteralPath $serverZip -Algorithm SHA256).Hash, (Split-Path $serverZip -Leaf))
|
||||
("{0} {1}" -f (Get-FileHash -LiteralPath $linuxClientZip -Algorithm SHA256).Hash, (Split-Path $linuxClientZip -Leaf))
|
||||
("{0} {1}" -f (Get-FileHash -LiteralPath $azureZip -Algorithm SHA256).Hash, (Split-Path $azureZip -Leaf))
|
||||
@@ -252,8 +283,10 @@ $checksumsPath = Join-Path $resolvedOutputRoot "SHA256SUMS-$Version.txt"
|
||||
|
||||
[pscustomobject]@{
|
||||
Version = $Version
|
||||
ClientPackage = $clientZip
|
||||
ClientSha256 = (Get-FileHash -LiteralPath $clientZip -Algorithm SHA256).Hash
|
||||
Windows10LegacyClientPackage = $windows10ClientZip
|
||||
Windows10LegacyClientSha256 = (Get-FileHash -LiteralPath $windows10ClientZip -Algorithm SHA256).Hash
|
||||
Windows11ClientPackage = $windows11ClientZip
|
||||
Windows11ClientSha256 = (Get-FileHash -LiteralPath $windows11ClientZip -Algorithm SHA256).Hash
|
||||
LinuxClientPackage = $linuxClientZip
|
||||
LinuxClientSha256 = (Get-FileHash -LiteralPath $linuxClientZip -Algorithm SHA256).Hash
|
||||
ServerPackage = $serverZip
|
||||
|
||||
Reference in New Issue
Block a user