HNHacker News
TopNewBestAskShowJobs

eniac111

226 karma · joined October 3, 2016

[ my public key: https://keybase.io/eniac; my proof: https://keybase.io/eniac/sigs/irbu8gnsgDBSHum3cBymgmxu_I4cQ_s7vcFz_M003wA ]
submissionscomments
eniac111··on Show HN: Bor – Open-source policy management for Linux desktops
I'm currently working on a Git support and an unified format for import/export of the policies :)
eniac111··on Show HN: Bor – Open-source policy management for Linux desktops
Interesting project, I've never heard of it. Looks very similar as functionality, but Bor is a centralized management system. As you said, it's more like "company deploys to many employees". The target is not only companies. It would be useful in Schools, universities, community centers, etc.
eniac111··on Show HN: Bor – Open-source policy management for Linux desktops
The general documentation is something that definitely needs a lot of improvement, but it's currently under active development.

Policies are delivered over a persistent gRPC stream, secured with mTLS, where each node gets it's own cert from Bor's built-in CA at enrollment - so there's no SSH key sprawl and no credentials on the server that could log into machines. Since agents connect outbound to the server, it works through NAT and firewalls without opening any inbound ports on desktops, and policy changes propagate in seconds over the already-open stream. SHH-push would have meant maintaining an inventory of searchable hosts and a server that can shell into the whole fleet - a much bigger attach surface for less capability.

eniac111··on Show HN: Bor – Open-source policy management for Linux desktops
The default enrollment is based on temporary (5 min lifetime)tokens, generated from the UI. Domain-joined machines use Kerberos, but this is optional. Using the temporary tokens, the admin have to execute the agent with a command-line option for enrollment.

About the files, most of the bor-managed files are not defaults, coming from the system packages. If a given file is overridden by a package, the Bor agent will immediately rollback the managed version.

Also, there is a priority value on each policy, if several policies have the same property.

eniac111··on Show HN: Bor – Open-source policy management for Linux desktops
Not directly. This might be somehow configured with PAM. It's a good use case, thanks for the idea!

It could easily block porn, enforcing DNS over HTTPS in the web browsers, using providers with adult content protection.

eniac111··on Show HN: Bor – Open-source policy management for Linux desktops
- Samba already supports policies for Linux, but it's not a "finished product", not actively maintained and it does not have Bor's tamper protection of the managed files. - IaC tools like Ansible/Puppet are good alternatives, but coding the whole configuration is not comfortable for some system administrations. Especially those with Windows Server AD background. Also, setting up strict policies avoids running of arbitrary code on the target systems, which is good for enterprise compliance certification. - It's not a domain controller because there are no user entities, only nodes. Bor works together with Windows AD/ Samba or FreeIPA. It supports LDAP and Kerberos authentication. Domain-joined machines could automatically enroll without setting the temporary token, issued from the UI.
eniac111··on Show HN: Bor – Open-source policy management for Linux desktops
Unfortunately, only LDAP is currently supported. There is no implementation of Enterprise SSO like Oauth/SAML. It's planned for the future, but not in priority for now.

I have never tested Cinnamon, but it should work in theory, because it stores most of it's settings in dconf.

Custom scripts: deliberately not, so far. Once a management agent runs arbitrary scripts as root, it stops being a policy system and becomes remote-code-execution-as-a-service — the security review, the audit story, and the "what exactly is enforced on this machine?" It may be implemented in the future, but with a ENV variable/config property from the application configuration. The same goes for configuration management systems like Ansible.

Thank you for the interest! I'm interested in developing a community around the software.

eniac111··on Show HN: Bor – Open-source policy management for Linux desktops
Delivery is push, not pull. Each agent holds a persistent gRPC stream to the server (mTLS). Policy changes are broadcast over that stream the moment they're released — agents apply them in real time. If the connection drops, the agent reconnects with backoff and sends its last-known revision; the server replays exactly what it missed (or a full snapshot). So there's no "check every N minutes" anywhere in the design. Most user changes never stick in the first place. Where the desktop stack has a native lockdown mechanism, Bor uses it: dconf keys are written together with a dconf locks file, so a locked setting simply can't be changed from GNOME's UI; KDE settings are written with the Kiosk [$i] immutability marker, which KDE itself enforces; and everything else (Firefox/Chrome/Edge policies.json, polkit rules, firewalld zones) lives in root-owned files under /etc that an unprivileged user can't touch. Those applications treat managed policy as non-overridable by design. Root-level drift is caught by inotify, not a timer. For every file it manages, the agent watches the parent directory via inotify (parent dir, so atomically-renamed replacements are caught too). If anything external modifies or deletes a managed file — a curious admin with sudo, a config-management tool, a package postinstall script — the watcher fires immediately and the agent rewrites the file from its cached policy state and re-reports compliance to the server. In practice the revert happens within milliseconds of the write, and the tamper event is visible server-side, so drift isn't just corrected — it's auditable. (The agent suppresses events from its own writes, so it doesn't fight itself.)
eniac111··on Ask HN: What are you working on? (June 2026)
I'm mostly working on Bor in my free time. Bor is a policy manager for the Linux desktop: https://getbor.dev/
eniac111··on Ask HN: What are you working on? (May 2026)
Bor - Linux Desktop policy management ( https://getbor.dev/ ).

In short, it unifies the configuration of different desktop components as policies ( dconf, Kconfig, polkit, Chrome, Firefox, etc.. . It's LGPL.

You can check my slides for the upcoming Tuxconf conference this Friday: https://getbor.dev/publications/tuxcon2026/

Cheers! Blago :)

eniac111··on Show HN: Bor – Policy management for Linux desktops
@dreamglider,

I've always missed something like this in the industry, when I was trying to integrate Linux desktops in different organizations. There are tools like Ansible and Foreman, but they are not "out of the box" structured like simple policies. For example, it would be more difficult to run an arbitrary code with Bor, compared to Ansible. It's important for the enterprise compliance and we we never had anything like GPOs in the Linux world.

The current target are the desktop machines. That's why the currently implemented features are the most essential ones - desktop environments (KDE, Gnome), browsers ( Firefox, Chrome), security - Polkit.

Unfortunately, it doesn't manage certificates at the current stage of development. There are no webhooks, but thee audit logs may be exported to a syslog server.

eniac111··on Show HN: Mushroam – Turn any URL into a promo video
Your internal API to POE is not working :/
eniac111··on Show HN: GovAuctions lets you browse government auctions at once
It would be good to mention which government in the title :)
eniac111··on Friendica – A Decentralized Social Network
Heh, I've found this post while installing Gotosocial :D
eniac111··on Ask HN: Share your personal website
https://petrovs.info
eniac111··on I converted a rotary phone into a meeting handset
https://petrovs.info/post/2023-01-12-shaiba/ This is my USB rotary dial. It's always fun with the young people when I bring it to IT conferences.
eniac111··on Writerdeck.org
Writing without AI agent assistance? How is that possible?
eniac111··on Show HN: Spegel, a Terminal Browser That Uses LLMs to Rewrite Webpages
Cool! It would be even better if it was able to create simple web pages for vintage browsers.
eniac111··on Show HN: Kleks – declarative documents with live preview (in Rust+WASM)
Awesome!
eniac111··on VMOS – Virtual Android on Android
From the GitHub README:

"If you use the VMOS Pro Android 5.1 ROM for internal use, commercial profit or uploading to the app market without authorization, we will collect evidence and report to the police (copyright infringement) or prosecute. Anyone who reports unauthorized or illegal use of VMOS Pro Android 5.1 ROM code to develop products will be rewarded upon verification. We will keep the identity of the whistleblower confidential!"

eniac111··on Writing "/etc/hosts" breaks the Substack editor
https://en.wikipedia.org/wiki/Bush_hid_the_facts
eniac111··on Open source and self hostable/private file converter
Really nice! I had this idea since years. A simple open source tool that may replace the random websites for file conversions in small and middle companies. The traffic from the search engine results may be redirected to an internsl tool with a proxy for example.
eniac111··on Google announces agreement to acquire Wiz
Unfortunately, Google have the tendency to kill their cloud products.
eniac111··on Waymo drives through sinkhole in San Francisco during storm [video]
In eastern Europe this is just normal :D
eniac111··on Building a Medieval Castle from Scratch
We have a similar project in Bulgaria, but it's a huge ponzy scheme
eniac111··on FOSDEM 2024: my experience, some notes and tech tips
Exactly. There are almost 30 rooms with live talks. Only universities might fit an event from this size.
eniac111··on FOSDEM 2024: my experience, some notes and tech tips
Hi from the Video team 8-)
eniac111··on Celebrity Flights
I'm waiting for the data about their farts.
eniac111··on Thoughts on Miniflux
I'm thinking about a new Qt desktop/mobile client with the "Download" functionality :)
eniac111··on Slack Down?
heh :) https://status.slack.com/
Page 1 of 2Next →