Runes
Architecture patterns shared across my macOS admin concepts
Several of my tools solve the same problems in the same way: getting policy onto a Mac through MDM when macOS won't merge it, keeping secrets out of profiles, sharing data between tools without sharing code, and showing admins what will happen before it happens. These are the ideas behind them, written as patterns so you can reuse them in your own tools.
Each pattern follows the classic form: problem, context, solution, consequences, and known uses in my projects. A section for developers describes components and data flow, without code.
Thing
Profile Fragments, Merged on Device
Let each policy request be its own small configuration profile, and have the client merge whatever MDM delivers into one effective configuration.
Mimir, RatatoskrFáfnir
Org-Key Sealed Secrets
Put secrets into configuration profiles only as envelopes sealed to an organisation key that MDM delivers to the Mac's keychain, so plaintext never appears in the MDM console.
Mimir, Gimle, Jarl, Janus, LynceusBifröst
MDM-Provisioned Connections
Let MDM push the list of servers a tool connects to, shown read-only next to the user's own connections, with a switch that can hide user-added ones entirely.
Gimle, Jarl, LynceusRunic Forms
Custom Schema per Domain
Ship a JSON schema for every preference domain a tool reads, so admins configure it in a generated form in their MDM instead of hand-writing plists.
Gimle, Mimir, RatatoskrUrd's Well
Backup as Data Contract
Treat a tool's on-disk output as a documented, versioned contract with a reference reader, so other tools can use it as an offline data source without linking the producer's code.
Gimle, Janus, Jarl, LynceusVölva
Simulate Before You Act
Give every tool that changes Macs or reads production systems a way to show what it would do, with the same logic as the real run, before it does it.
Gimle, Mimir, Janus, Ratatoskr