SeaLion requires you to use sudo to install it as a service so that it will automatically restart whenever system reboots. All the commands executed by the SeaLion agent are run in the context of Sealion user which is a normal system user.
SeaLion requires you to use sudo to install it as a service so that it will automatically restart whenever system reboots. All the commands executed by the SeaLion agent are run in the context of Sealion user which is a normal system user.
How can I be sure that the install will be identical across all of my servers?
How can I pin a version that I've vetted for security holes?
How can I distribute this to servers that don't have arbitrary internet access?
How do I configure selinux/apparmor to work with your tool?
How can I uninstall this cleanly?
Curling into a elevated shell is a terrible way to do installs. Packages are cleaner, more secure, and more capable of being trusted. You're making the assumption that your s3 buckets will never be hacked, that your own webservers can never be hacked, and that experienced sysadmins are going to ignore your tool because of the amateur install method.
> How can I be sure that the install will be identical across all of my servers? Whenever you install SeaLion Agent, the most latest binary is installed. The agents in other servers are also updated, hence making them identical always.
> How can I pin a version that I've vetted for security holes? SeaLion agents are released after rigorous testing, to ensure we do not leave any security holes and features, currently SeaLion Agent is designed for auto update.
> How can I distribute this to servers that don't have arbitrary internet access? SeaLion agent requires Internet access to send data to its server. Hence internet access is mandatory.
> How do I configure selinux/apparmor to work with your tool? SeaLion agent works fine with SELinux in enforcing mode without any specific configuration.
> How can I uninstall this cleanly? sudo /usr/local/sealion-agent/uninstall.sh
Checksums are useless if your install script is compromised, as well as if the server hosting the checksums is compromised. Signing everything while using an installer that verifies signatures (like yum, rpm and apt) is more secure, and just relies on you not losing control of your private key, instead of entire servers.
> Whenever you install SeaLion Agent, the most latest binary is installed. The agents in other servers are also updated, hence making them identical always.
Assuming your upgrade location is not compromised. Does your auto-updater check checksums or signatures, or does it rely on your servers always serving up the correct files? What if you push an auto-update that breaks servers?
curl -s https://agent.sealion.com | bash /dev/stdin $1 $2 $3 $4 $5 $6
> SeaLion agents are released after rigorous testing, to ensure we do not leave any security holes and featuresNo offense, but when I'm responsible for what happens on multiple servers I would like to ensure that myself, by checking the tcp payloads, endpoints connected to, files opened, etc. I'm certainly not alone in this.
> SeaLion agent requires Internet access to send data to its server. Hence internet access is mandatory.
Sending data can be accomplished individual firewall rules to whitelisted IPs. s3 is too broad of a target to allow unlimited access to.
> SeaLion agent works fine with SELinux in enforcing mode without any specific configuration.
Great!
> sudo /usr/local/sealion-agent/uninstall.sh
Not the best, but it seems to be clean.