Presentation is loading. Please wait.

Presentation is loading. Please wait.

MFCF’s Mac Management Methods

Similar presentations


Presentation on theme: "MFCF’s Mac Management Methods"— Presentation transcript:

1 MFCF’s Mac Management Methods
Dani Roloson James McConachie Jim Johnston Math Faculty Computing Facility

2 AGENDA Overview Previously Now Next Q&A

3 OVERVIEW MFCF offers 3 environments using a common file server for user home directories Mac, UNIX, Windows use Active Directory for authentication on our managed Macs Active Directory tends to consider Mac and UNIX the same regarding home directories

4 OVERVIEW wanted Mac subdirectory of UNIX home 10.6
Bombich augmentation with Open Directory (Magic Triangle) use samba mount 10.8+ /etc/auto_users use Kerberized NFS mount

5 Previously DeployStudio for imaging and end-of-term reimaging
JAMF Composer for packaging Apple Remote Desktop for supplementary management and patch installation Composer does before and after system snapshots - by default, hides machine specific files - ByHost, Caches

6 NOW - Hardware Mac Pro maxed out memory and processor for indexing packages and NetBooting Sonnet Thunderbolt 2 to 10Gb network Dell PowerEdge R420 JAMF software deployment & management server rack mounted, redundant power multihome, redundant 10Gb network - indexing packages allows for clean uninstalls

7 NOW - Software JAMF Casper Suite (for most functions) AutoCasperNBI
AutoCasperNBI macmule.com/autocaspernbi/ AutoDMG github.com/MagerValp/AutoDMG AutoDMG - takes an OS X installer and builds a system image, suitable for deployment

8 NOW - Packaging packaging is still done with Composer with additional JSS indexing to allow for clean uninstallation awareness of Composer’s limitations especially when packaging multiple versions of Java (Maple needs Java 6, MATLAB needs Java 7) missing automatic detection of content overlap file additions and changes are noticed but not removals delta changes are not recorded receipts database not updated consistently

9 NOW - Deploying Image enter machine into DNS (Infoblox)
connect machine to network option boot and select NetBoot Image authenticate and configure can predefine for machine groups after 20 minutes, reboot and test consolidated image (monolithic 30GB) Apple OS Updates restricted DeployStudio 50; JAMF 40 but unreliable; consolidated Monolithic 30 consistent; Sonnet 20 (NetBoot) monolithic has OS and core packages since reimage takes approximately as long as individual updating, we tend reimage

10 NOW - Issues lack of concurrency for Casper administration
use Casper Admin on single machine JSS web interface has additional/missing features and defects versus Casper Admin does offer workflow cloning doesn’t offer “No OS” for a partition JAMF binding of computer to domain works, but doesn't work with optional attributes undesired result since clone ends up with unwanted OS

11 NOW - Issues monolithic image - temporary solution lack of
revision control script search debugging/logging/exit code handling to avoid unreliable package installation related to conflicts between Java 6 and 7 required by various apps prefer thin/modular (OS separate from packages) to allow uninstalls

12 NEXT Yosemite network home directories Self Service (OS and packages)
testing Mac NetBoot from Linux BDSP server unlikely to use optional SCCM plug-in app benchmarking, assurance testing, & reports such as HW & SW inventory Application Management AutoPkgr (GUI for AutoPkg) Patch management from JAMF (beta) deal with sandboxing under instead of - switched from MIT to Heimdall Kerberos around 10.7 Boot Discovery Service Protocol (Mac NetBoot servers suffer from cumulative performance degradation; hoping Linux has better session management) - System Center Configuration Manager - Microsoft’s client management for mostly Windows clients may be two options when application update handling becomes our priority AutoPkg has integration also with Munki

13 NEXT - Application Management
Benefits to integrating tools such as AutoPkgr tedious package creation is automated (recipes for most apps) smart group criteria are automatically updated IT team can focus their attention elsewhere installer policy is automatically updated smart group - dynamic list of machines based on inventory properties - for example status of an application: installed, missing, or out-of-date; also hardware requirements can be tested: RAM, disk, OS

14 SUMMARY proceeding with Casper Suite recommend with caveats
change management would have to be implemented before federation concurrency would have to be controlled

15 Q&A Federation like North Carolina NEXUS vs MFCFADS conc Thank you

16 MFCF’s Mac Management Methods
Dani Roloson James McConachie Jim Johnston Math Faculty Computing Facility


Download ppt "MFCF’s Mac Management Methods"

Similar presentations


Ads by Google