Windeploy (alpha): Windows software, policies and DNS through Group Policy - testers wanted

Hello everyone,

I would like to show a new community module and ask for testers: windeploy brings Windows software, security settings and (soon) internal DNS records to the computers of a Samba AD domain, from the cluster admin UI. No Windows machine with RSAT is needed and no domain admin account is stored.

It is an alpha. Please try it on a test domain, not in production.

What it does

Software deployment

  • Search the winget community repository and pick packages.
  • A deployment is one GPO with one scheduled task per package. The task runs winget as SYSTEM, daily or weekly, or once with “run now”.
  • Link it to the whole domain or to organizational units.

Policies

  • Security settings for the computers, rolled out as GPOs: lock idle sessions, logon notice, removable media, BitLocker recovery keys into the directory, time source, Defender, firewall, NTLMv2, auditing, PowerShell logging. 20 settings in six groups.
  • Every change needs a reason and is kept in a list of changes.

DNS (next pre-release)

  • Show the internal DNS zones and add, change and delete records.
  • Records that Active Directory needs are shown, not changed.

How it works

  • GPOs are written by a delegated service account over LDAP and SMB, from a separate Samba runtime image. The rights belong to a group, windeploy-admins.
  • The account can be set up from the UI with domain admin credentials that are used once and not stored. The Guide page has the same steps to do by hand.
  • The module is rootless and needs no route and no port.

A rule applies as long as it exists

This took most of the testing. With a Windows 11 25H2 client I measured what happens when a GPO no longer applies:

  • Scheduled tasks are removed by the client at its next policy refresh. Installed software stays.
  • With “remove this item when it is no longer applied” Windows creates the task again at every refresh, so a start missed while the computer was off would be lost. The module makes up for it after the next start.
  • Removing a GPO with an advanced audit policy file clears all auditing on the client, also what a fresh Windows audits. The module sets the audit settings with a task instead.
  • Removing a deployment deletes its GPO. Removing the module deletes its GPOs; moving it to another node keeps them.

Install

Enable testing versions for the tebbiworld repository (Settings, Software repository), then install “GPO based Software Deployment for Windows” from the Software Center. Or:

add-module ghcr.io/tebbiworld/windeploy:0.1.0-alpha.3 1

If you do not have the repository yet:

api-cli run add-repository --data '{"name":"tebbiworld","url":"https://raw.githubusercontent.com/tebbiworld/ns8-repo/main/ns8/updates/","status":true,"testing":true}'

What I would like to know

  • Does the setup of the service account work in your domain?
  • Which winget packages fail when installed as SYSTEM?
  • Windows 10 and Windows Pro clients: I could only test Windows 11 Enterprise.
  • Which policy settings are missing for you?

Not tested yet

Windows 10, Windows Pro, a Windows domain controller, more than one domain controller, removable media and BitLocker with real hardware.

Source, issues and README: GitHub - tebbiworld/ns8-windeploy: NethServer 8 module: GPO based software deployment for Windows (winget packages through Group Policy scheduled tasks in a Samba or Windows Active Directory) · GitHub

Thanks to @stephdl for the review of the first version

1 Like

Update: windeploy 0.2.0

A short follow-up, because the first post is out of date in three places.

No testing versions needed any more

0.2.0 is a regular release. It shows up in the Software Center of every cluster that has the tebbiworld repository, without enabling testing versions. The add-module line from the first post becomes:

add-module ghcr.io/tebbiworld/windeploy:0.2.0 1

An installed 0.1.0 pre-release is updated in place; deployments, policy profiles and settings stay. It is still an early version, so please try it on a test domain first.

DNS is in, with zones

The page “DNS” is part of the module now:

  • Show the internal zones of the domain and their records; add, change and delete A, AAAA, CNAME, MX, SRV and TXT records, and PTR records in reverse zones. For an address the reverse record is kept along.
  • Create and delete zones. A reverse zone is created from its network: 192.168.1.0/24 gives 1.168.192.in-addr.arpa.
  • Reading works with the service account as it is. For writing, a domain admin gives the group windeploy-admins rights on a zone, once, from the page. No membership in DnsAdmins.
  • The zone of the domain, _msdcs, the AD service records and the domain controllers are shown, never changed. Records a computer registers itself are left alone as well.

Compare with the public DNS

This one came from practice. I moved a name at the DNS provider and could not reach it from inside, because the internal zone still had an old record for it. An internal zone answers for its whole name, and nothing tells you that inside and outside have drifted apart.

The DNS page now has a button for that: it lists the internal records next to what the public DNS says and marks them as equal, different or only internal. A record that differs can take the public value or be deleted. The public side is asked over DNS over HTTPS, because many routers redirect plain DNS to the internal server; the names of the zone go to that resolver, and the page says so.

Plan for the future: If the cluster has @dan’s dnshelper, the comparison links to it, so the public side can be changed there and the internal side here.

Still open

  • Windows 10 and Windows Pro clients: I could only test Windows 11 Enterprise.
  • More than one domain controller, and a Windows domain controller.
  • IPv6 records.

Feedback on any of these is welcome, here or as an issue: GitHub - tebbiworld/ns8-windeploy: NethServer 8 module: GPO based software deployment for Windows (winget packages through Group Policy scheduled tasks in a Samba or Windows Active Directory) · GitHub

1 Like