Hi all
When we build macOS devices we use DepNotify and Installomater to install around 10 standard applications including, Chrome, Office, iTerm, Docker and a few other things. We also allow a larger selection of applications to be installed using Installomater via Self Service
In order to manage updates we have a policy that checks a smart group for each application to see if it is on the latest version and if the smart group indicates the machine is behind, it calls installomater again to update the application
This is having limited success and I'm not sure why.
Could anyone advise on whether there is a defacto standard way to update applications that would meet the following criteria:
1. It should work for as many common applications as possible
2. It should not require users to do anything:
3. It should be able to guarantee that applications are updated within a handful of days of a security update being released
4. There should be minimal involvement from IT in having to package, script or otherwise manage specific updates
Thanks in advance
Best Practice for Application Updates
Best answer by mickgrant
Hey - thanks for the reply.
So our end state is that we want to just have updates installed at all times, immedaitely and without any admin or user involvement. When I've looked at Jamf managing the patching, it seemed to be the case that you needed to manually upload packages for all sorts of software versions, which to me seemed crackers.
I'm currently looking at the Jamf App Catalog thing to see if that is any better. It seems to be on paper but I'm not sure if it is going to have an issue given that we have scores of machines that have already had apps deployed using Installomater. I have had one machine successfully get firefox installed. I'm currently testing to see what App Catalog will do when I ask it to install an app on a machine that already has the app on.
At the end of the day, I just want a way to keep apps up to date and consistent with our ISO 27001 security policies
Have a look at https://github.com/autopkg/autopkg
there is a GUI for it as well https://github.com/lindegroup/autopkgr
It plugs into Jamf patch management and is quite customisable
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.
