226 karma · joined October 3, 2016
Policies are delivered over a persistent gRPC stream, secured with mTLS, where each node gets it's own cert from Bor's built-in CA at enrollment - so there's no SSH key sprawl and no credentials on the server that could log into machines. Since agents connect outbound to the server, it works through NAT and firewalls without opening any inbound ports on desktops, and policy changes propagate in seconds over the already-open stream. SHH-push would have meant maintaining an inventory of searchable hosts and a server that can shell into the whole fleet - a much bigger attach surface for less capability.
About the files, most of the bor-managed files are not defaults, coming from the system packages. If a given file is overridden by a package, the Bor agent will immediately rollback the managed version.
Also, there is a priority value on each policy, if several policies have the same property.
It could easily block porn, enforcing DNS over HTTPS in the web browsers, using providers with adult content protection.
I have never tested Cinnamon, but it should work in theory, because it stores most of it's settings in dconf.
Custom scripts: deliberately not, so far. Once a management agent runs arbitrary scripts as root, it stops being a policy system and becomes remote-code-execution-as-a-service — the security review, the audit story, and the "what exactly is enforced on this machine?" It may be implemented in the future, but with a ENV variable/config property from the application configuration. The same goes for configuration management systems like Ansible.
Thank you for the interest! I'm interested in developing a community around the software.
In short, it unifies the configuration of different desktop components as policies ( dconf, Kconfig, polkit, Chrome, Firefox, etc.. . It's LGPL.
You can check my slides for the upcoming Tuxconf conference this Friday: https://getbor.dev/publications/tuxcon2026/
Cheers! Blago :)
I've always missed something like this in the industry, when I was trying to integrate Linux desktops in different organizations. There are tools like Ansible and Foreman, but they are not "out of the box" structured like simple policies. For example, it would be more difficult to run an arbitrary code with Bor, compared to Ansible. It's important for the enterprise compliance and we we never had anything like GPOs in the Linux world.
The current target are the desktop machines. That's why the currently implemented features are the most essential ones - desktop environments (KDE, Gnome), browsers ( Firefox, Chrome), security - Polkit.
Unfortunately, it doesn't manage certificates at the current stage of development. There are no webhooks, but thee audit logs may be exported to a syslog server.
"If you use the VMOS Pro Android 5.1 ROM for internal use, commercial profit or uploading to the app market without authorization, we will collect evidence and report to the police (copyright infringement) or prosecute. Anyone who reports unauthorized or illegal use of VMOS Pro Android 5.1 ROM code to develop products will be rewarded upon verification. We will keep the identity of the whistleblower confidential!"