3 ms·
I’d like to pick the brains here on HN. I’m looking to do something like autoinstall for my office but is there an easier way have my employees do their own th
by someonehere 2y ago
I’d like to pick the brains here on HN.
I’m looking to do something like autoinstall for my office but is there an easier way have my employees do their own thumb drive (remote users) and get the config they need from me? I’m looking for an MDM Intune like enrollment that’s easier and configured it a certain way. I’m not in a position to use and manage Puppet.
- zamadatix 2y agoThe installer (subiquity) supports the "autoinstall" config files embedded in the install USB/ISO if you want. You can also just point the USB/ISO's autoinstall to an HTTPS address so an update doesn't require spinning new install media (does require the install start with some form of network access then). If you have wildly technical users only then they can even just have them type the autoinstall web address in the grub entry before the standard install media autoboots the entry (this falls apart the second someone isn't ultra techncial). In any of these cases the autoinstall file can still handle both the installer as well as post install custom scripts to do whatever you need but then it's done. For long term management/enrollment you'd need to look at something beyond just putting stuff on the installer USB/ISO. Ubuntu has Landscape for this but there are some alternatives. Just depends on what you need to manage long term and what you can realistically do (e.g. you note you aren't in a spot to manage something like Puppet).
- Joel_Mckay 2y agoOne advantage with standardized workstation OS images, is the bugs/updates/compatibility only requires a 1 support ticket solution. Deploy a gpg signed public script to periodically download and install updates from a public server. i.e. anyone that has to update knows the package is from you, and the machine role is pre-defined by you with a config file in "/etc/example/myhost.conf". If secrecy is required, than publish host specific encrypted public payloads named for their primary interface MAC. This is how to handle clowns pulling drives in colocation data-centers. Cheers =)