Skip to main content
Question

Autopkg users, show of hands.

  • November 29, 2016
  • 6 replies
  • 19 views

Forum|alt.badge.img+9
  • Valued Contributor

I am transitioning our mac environment onto another network and have to get all software re-approved. Being that there is no vendor/support for Autopkg I am receiving some resistance on it. Can I get a show of hands of everyone who uses it/has it approved for use? I’d like to present a list of agencies currently utilizing it as validation. Of particular use would be federal agencies. Feel free to contact me directly if you don't want to put that information here. paul.dickson at nbacc.dhs.gov.

6 replies

Forum|alt.badge.img+15
  • Valued Contributor
  • November 29, 2016

Federal agency checking in here.

That being said, I suspect that my ITSec issue would not approve, if they knew the details. I'm working towards setting up an internal .git repository to use as our AutoPKG repository and copying over the recipes we use.


Forum|alt.badge.img+1
  • New Contributor
  • November 29, 2016

We are also looking at using Autopkg, but there are some security concerns to take into account. For example, there isn't currently a way to tell if a recipe author is doing anything bad with their recipe, other than auditing the recipe manually and understanding what the recipe does. The recommended way to handle this is to set up up a workflow where each recipe you use has a corresponding override with trust settings. If the recipe changes, it will throw an error so you can audit the parent recipe again and update the trust settings. You can find more about that workflow here:

https://github.com/autopkg/autopkg/wiki/Autopkg-and-recipe-parent-trust-info

Note that these options are a feature of Autopkg 1.0, which is currently in prerelease (the current release is 0.6).


Forum|alt.badge.img+9
  • Author
  • Valued Contributor
  • November 29, 2016

@gsanna Thanks for the info. That may be enough to ease IS's minds.


Forum|alt.badge.img+14
  • Valued Contributor
  • November 29, 2016

Until patch management is ready, this is a no brainer. But yes, some validation is required since evil recipes are possible.


acodega
Forum|alt.badge.img+15
  • Valued Contributor
  • November 29, 2016

1.0 has been released today.


Forum|alt.badge.img+8
  • Valued Contributor
  • November 29, 2016

We looked at using AutoPKG, but decided that the concerns outweighed the benefits.