25 ms·
What you can do is have a cron job that continuously polls one or more URLs looking for tarballs with Git repos accompanied by GnuPG or Signify signatures. The
by honestSysAdmin 2y ago
What you can do is have a cron job that continuously polls one or more URLs looking for tarballs with Git repos accompanied by GnuPG or Signify signatures. The primary idea is that the tarballs are only unpacked and executed if the signatures are valid and anything received by the machines is only executed after the hashes and signatures are successfully logged, this prevents (or at least documents) any abuse on the part of the IT team. Inside the tarballs are Salt, Ansible, and/or shell commands.
In addition to a cron job, we had an active pubsub listener on each machine to poke this process.
You can do this on macOS too, or at least, modern macOS "should" be able to do this.
We did this on a large fleet of user machines (laptops) running Windows 10/11, macOS, and Linux.