Okay, so the last video has given me some thoughts on provisioning machines in a Linux based business. How to go from a blank machine to a ready to go workstation.
Options I see:
1. Start with distro installer, then manually do initial setup using a freeipa admin credential you type on the machine
2. Run distro installer unattended with answers file, then enroll manually afterwards as above
3. Write a small inventory web service with permissions in freeipa to create hosts. Distro installer queries this for its answers file, and gets setup with a bit of business logic in the web service, and one time enrollment keys. This can also do key escrow for things like luks backup keys automatically. Some script runs either in the end of the installer or on first boot to do the actual enrollment based on these one time keys.
4. Rely on Ansible to do the first time setup, which means you either need to use Ansible-pull and solve how to get credentials to the machine, or Ansible-push and need to figure out initial network setup so ansible can connect.
5. Use red hat foreman to do it all (downside is the system requirements are 16G of ram and like 500g disk space and it’s a chonky app with poor documentation)
Microsoft AD traditionally is most similar to 1, but the AD / GPO post-join configuration step uses the machines credentials to bootstrap everything else automatically. Microsoft’s other option is a central database that Microsoft maintains of who owns which hardware identity, and automatically joining based on the tpm verified serial data.
Apples method is maintaining a central database of who owns which hardware identified by the Apple Secure Enclave.
Red Hat’s product is Foreman, which doesn’t seem like its really able to scale down + lacks documentation in a way that suggests to me nobody is reading the public docs and is probably only deploying it with a Red hat support contract.
Opinions?