Skip to content

Instantly share code, notes, and snippets.

@arubdesu
Created October 8, 2014 18:10
Show Gist options
  • Save arubdesu/58d56c120d93f569b6d6 to your computer and use it in GitHub Desktop.
Save arubdesu/58d56c120d93f569b6d6 to your computer and use it in GitHub Desktop.
selling PE to security team
Even with the JAMF suite available, our remote management tools have not enabled efficiently taking inventory over the WAN or implementing an optimized patch management system. It also is used primarily on client workstations for just Macs, with the breadth of what Apple mostly covers when it comes to provided support, instead of fine-grained customization and server-grade functionality.
Puppet adds not only its core competency as a configuration management tool, which allows in-depth but hands-off auditing, but also, over the maturation of the Puppet Enterprise product, it's added a WAN-optimized orchestration tool. This mix of 'client checks in' and 'ad-hoc, on-demand, over-the-WAN execution’ makes it the leader in its space. We also would be able to leverage its certificate authority, which has been utilized in many environments to secure communication of the Managed Software Center tool which provides the most efficient 'self-service' model of patch management for Macs. The AIX/UNIX/Linux and SCCM teams have also expressed interest in leveraging instances of the product, as it is recommended by the platform vendors, and will add consistency and power to their workflows. Auditing sysadmin work will be much simpler as well, since the implementation is in plain text files which can be simulated in test environments, and teams can collaborate on best-practice solutions.
Allister
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment