Skip to content

Repository files navigation

Windows ISO Builder

GitHub Actions-only pipeline for building and optimizing Windows ISO images.

Combines UUP dump ISO assembly with Tiny11 optimization into a single workflow.


🔄 Pipeline

UUP dump API → Download UUP files → Prepare Windows media ┬→ Build ISO ─────────→ Upload raw ISO artifact
                                                          └→ Tiny11 → Build ISO ┤  ├→ optional ISO tests
                                               autounattend.xml is added once ┘  └→ optional Yandex import
  1. UUP dump — fetches Windows update packages and prepares the Windows media
  2. Tiny11 — removes bloatware, applies registry tweaks, bypasses system requirements
  3. ISO creation — creates one final ISO, after Tiny11 when optimization is enabled
  4. Unattended setup — embeds autounattend.xml in every final ISO

🚀 Quick Start (GitHub Actions)

  1. Fork this repository
  2. Go to Actions → Build Windows
  3. Select parameters and click Run workflow
  4. Download the ISO from Artifacts

⚙️ Workflow Inputs

Windows Configuration

Input Options Default
Version Windows 11 26H2, 26H2 Experimental, 26H1, 25H2, 25H2 Beta, Future Platforms Windows 11 26H2
Architecture x64, arm64 x64
Edition Pro, Home Pro
Language 38 languages (ar-sa → zh-tw) English (United States)
Revision Optional build matching the selected version, for example 26340.9233 for 26H2 Experimental —

Build Options

Input Description Default
ESD Use ESD compression false
NetFx3 Add .NET Framework 3.5 false
Tiny11 Apply Tiny11 optimization true
Yandex Disk Privately upload the finished ISO and SHA256 sidecar to Yandex Disk false
ISO test Quickly validate the x64 ISO and verify Windows PE boot in QEMU false
Full install test Validate the ISO, install x64 Windows in QEMU, and audit the first boot false

☁️ Optional Yandex Disk Upload

Enable Yandex Disk when starting the workflow to copy only that build's ISO and .sha256 file to private application storage. The ISO is published as an uncompressed GitHub artifact first, then Yandex Disk imports it directly from GitHub through a temporary signed URL. The Actions runner does not download or re-upload the large ISO.

The Yandex import runs as a separate job alongside any requested ISO tests. It verifies the remote file's exact size and SHA256 before uploading the small checksum sidecar. A Yandex failure is reported in that job's summary but does not discard the GitHub artifact or prevent the tests from running. The import job can be rerun without rebuilding the ISO.

One-time setup:

  1. Register a Yandex OAuth application for API access.
  2. Grant only cloud_api:disk.app_folder (access to the application's own Disk folder).
  3. Copy the application's Client ID, open https://oauth.yandex.ru/authorize?response_type=token&client_id=<Client_ID>, allow access, and copy the returned access_token. Keep it private.
  4. In the GitHub repository, open Settings → Secrets and variables → Actions, create the repository secret YANDEX_DISK_TOKEN, and paste the token as its value.

Uploaded files remain private and appear inside the application's folder under Apps / Приложения in Yandex Disk. Rebuilding an ISO with the same filename replaces that file; the workflow never creates a public link. GitHub also keeps a separate small verification artifact containing the .sha256 file and verification instructions.


🛠️ Tiny11 Optimization

When enabled, the prepared Windows media is processed directly through Tiny11 before the single final ISO is created. Tiny11:

Removes Bloatware (40+ apps)

  • Teams, OneDrive, Edge, Copilot, Recall
  • Xbox Game Bar & Gaming Services
  • Clipchamp, Paint 3D, 3D Viewer, Mixed Reality Portal
  • Weather, News, Maps, Bing Search, Cortana
  • Office Hub, Solitaire, Sticky Notes, To Do, and more

Registry Optimizations

  • TPM 2.0 / Secure Boot / CPU / RAM requirement bypass
  • All telemetry endpoints disabled
  • Sponsored apps and consumer features blocked
  • OneDrive backup prompts disabled
  • BitLocker encryption disabled
  • Chat icon / Widgets / Cortana startup removed

🧩 Unattended Setup (autounattend.xml)

Every final ISO produced by the Build Windows workflow contains autounattend.xml at its root whether Tiny11 is enabled or not. The builder prepares the copy for the selected x64/ARM64 architecture and Pro/Home edition, while the tracked file remains the x64 Pro template.

During Windows Setup it provides:

  • OOBE bypass (local account, no Microsoft account required)
  • Additional app/capability/feature cleanup on first boot
  • Core isolation (VBS/HVCI) disabled
  • Privacy-focused defaults

Tiny11 still adds its separate offline image cleanup and registry changes when enabled.


✅ ISO Testing in GitHub Actions

Enable ISO test when dispatching the Build Windows GitHub Actions workflow to run an optional test job after the ISO artifact is uploaded. The test:

  • verifies the ISO boot files and x64 WIM/ESD metadata;
  • runs wimverify against boot.wim and install.wim or install.esd;
  • validates a root autounattend.xml when present;
  • boots the ISO with UEFI in QEMU and waits up to 20 minutes for a Windows PE startup marker.

The boot test uses KVM when the runner exposes /dev/kvm and automatically falls back to TCG software emulation otherwise. Its answer file and startup marker are stored on a temporary raw FAT image; the guest signals startup over COM1, shuts down cleanly, and the runner reads the marker only after QEMU exits.

When Full install test is enabled, this separate Windows PE boot job is skipped. The full test performs the same structural and WIM/ESD checks first, then proceeds directly to installation, first boot, and audit. Selecting both checkboxes therefore does not download or test the ISO twice.

To test an existing image without rebuilding it, dispatch the Test Windows ISO from URL GitHub Actions workflow. Supply a direct HTTPS URL to the ISO and, optionally, its SHA256. A download page or a GitHub Actions artifact page is not a direct ISO URL. QEMU and WIM tools are installed only on the temporary Ubuntu runner.

Full installation test

Enable Full install test to perform a separate, opt-in integration test on an ephemeral Ubuntu runner. It first validates the ISO structure and WIM/ESD integrity without a redundant Windows PE boot, then requires KVM and starts the x64 VM with UEFI Secure Boot, Microsoft-enrolled OVMF keys, and a software TPM 2.0. The test creates a sparse 64 GiB virtual disk, installs image index 1 with a temporary CI answer-file overlay, boots the installed system, runs the production FirstLogon.ps1, and returns a JSON audit report. The ISO and repository autounattend.xml are not modified.

When Tiny11 is enabled, the guest audit checks the setup logs, selected registry policies, disabled services, removed Appx packages, capabilities, optional features, and Edge/OneDrive paths. The complete JSON result is validated exclusively over COM1; the host then dismisses transient shell UI, captures a clean-desktop screenshot, and ends QEMU immediately without waiting for Windows to shut down. The raw FAT media supplies the CI answer file and audit script and retains diagnostic logs, but it is not accepted as a result channel. Compact logs are uploaded, and the virtual disk is always deleted. The job frees unused SDKs only on the temporary GitHub runner and requires at least 25 GiB of free workspace before starting.

The URL workflow provides matching Full installation test and Tiny11 audit checkboxes. Structural validation always runs; when the full installation test is selected, the separate Windows PE boot is skipped even if its checkbox is also selected. Disable Tiny11 audit when testing an ISO that was not produced by this repository.


🤖 Agent Documentation

Agent-facing documentation is available in AGENTS.md and .agents/:


📁 Repository Structure

windows-iso-builder/
├── .agents/
│   ├── README.md                   # Agent docs entry point
│   ├── ci-runbook.md               # GitHub Actions operation and safety notes
│   ├── repository-map.md           # File ownership map
│   └── workflow.md                 # GitHub Actions pipeline notes
├── .github/workflows/
│   ├── build.yml                    # Build and optional ISO test workflow
│   └── test-iso-url.yml             # Test an existing ISO from an HTTPS URL
├── scripts/
│   ├── test-windows-iso.ps1         # CI-only ISO and Windows PE smoke test
│   ├── test-windows-install.ps1     # CI-only full installation orchestrator
│   ├── test-installed-windows.ps1   # In-guest installed-state audit
│   ├── tiny11maker-headless.ps1     # Internal Tiny11 workflow worker
│   └── upload-yandex-disk.ps1       # Optional GitHub-to-Yandex server-side import
├── AGENTS.md                        # Root pointer for IDE/CLI agents
├── uup-dump-get-windows-iso.ps1     # Internal UUP workflow worker
├── CustomAppsList.txt               # UUP dump app selection
├── autounattend.xml                 # OOBE bypass & post-install
├── .gitignore
├── README.md
└── LICENSE

🏗️ Execution Environment

Building and validation are performed exclusively by the workflows under .github/workflows/:

  • Build Windows uses a managed Windows runner for UUP preparation and Tiny11 processing.
  • Optional ISO validation and installation auditing use ephemeral Ubuntu runners.
  • Test Windows ISO from URL validates an existing image entirely on an ephemeral Ubuntu runner.

The PowerShell files in this repository are internal workflow workers. The supported entry points are the GitHub Actions workflow-dispatch forms.

For Running Built ISOs (with Tiny11)

System requirements are bypassed:

  • A processor matching the selected ISO architecture (x64 or ARM64)
  • 1GB+ RAM (2GB+ recommended)
  • 10GB+ storage
  • No TPM / Secure Boot required

🙏 Credits


⚠️ Disclaimer

This tool is provided "as is" without warranty. You must have a valid Windows license. Use at your own risk.

About

No description, website, or topics provided.

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages