Part 7 · Platform, hosting and artificial intelligence
Blue Fox OS workstations
Describe your Blue Fox OS fleet on one record, set per-person exceptions, track and revoke machines, and hold disk passphrases in escrow.
Blue Fox OS is the workstation system that Symbifox installs and configures remotely. This chapter covers the Policy application, where a single record describes an organization's whole fleet: what gets installed, how the session is protected, what the desktop looks like, and who is allowed to set up a machine. It is written for the person who runs the fleet, and for the separate person who holds the disk passphrases. The goal: a new machine installs without anyone touching a setting, and a change made in Symbifox reaches the machines already in use.
Overview#
The Policy application has five menus. Four ideas are enough to read them.
- Organization record: the shared rules, one record per company. It holds installation, sign-in, security, the look of the session, applications and browser extensions.
- Per-person exception: an optional record that changes only what you fill in. Any field left blank falls back to the organization's rule.
- Machine: an installed workstation. It enrols itself during installation, in the name of whoever authorized the install, then re-reads its policy every day.
- Escrow: the disk passphrase, generated by the installer and stored encrypted in Symbifox. Only someone with the Custodian role can read it, and every read is written on the machine's record.
A machine always receives the merge of both levels: the organization record, with the person's exception on top. For lists (mounted folders, web apps, applications, extensions), the exception adds or removes items; it never replaces the whole list.
What sets this approach apart: a workstation is no longer something you configure, it is the reflection of a record. The automatic install file is served by Symbifox from that same record, and a change reaches machines in use at their next sync. Only the machine name, language and keyboard stay as they were set at installation.
Configuration#
Access and rights#
Two roles, kept apart on purpose.
| Role | What it opens |
|---|---|
| Fleet manager (the Settings right in the Administration section) | See the Policy application, maintain records, exceptions and catalogues, view machines and revoke one. They can see whether a passphrase is in escrow, never the passphrase itself. |
| Custodian (the right whose name ends in "Peut reveler les phrases de passe de disque", can reveal disk passphrases) | Read a passphrase held in escrow, and remove it from escrow. |
The Custodian right does not come with administration. Once the module is installed, nobody holds it, not even the administrator who installed it: it has to be granted explicitly, and that step shows up in Symbifox's log. This is deliberate, so that "who can administer Symbifox" never quietly becomes "who can open every disk in the fleet".
Settings#
There is nothing to set under Settings. Everything lives on the organization record, under Policy › Org Defaults.
Passphrase escrow needs one step on the server: an encryption key stored outside the database, set by whoever administers the server. The help text under the Escrow disk passphrase checkbox says where it goes. Without that key, the installer does not attempt escrow and asks for a typed passphrase, as before.
Base data#
Three things must exist before the first installation.
- The organization record, with at least the domain and the system image (Zero-Touch tab). With no image, automatic installation is turned off for that organization.
- The organization's identity provider, whose addresses go in the Authorization and Zero-Touch tabs. It is what asks the installing person for two-factor sign-in.
- Symbifox users for the people who will receive a workstation: internal, active users attached to the record's company. A machine always enrols in the name of an existing user. A portal account, an archived account or an account from another company can never set up a workstation, whatever the setting.
The application and extension catalogues are optional: without them, a machine gets the base already built into the system image.
Getting started#
This walk-through creates an organization record and takes you to a first enrolled machine.
- Go to Policy › Org Defaults, then select New.
- Pick the Company and enter the Domain: the address the installing person will type when the machine starts, without "https://" or "www".
- On the Install tab, check the Locale, Timezone and keyboard; on the Zero-Touch tab, fill in the OCI Image and the identity provider's addresses.
- On the Authorization tab, choose who may set up a workstation, then save. A new record starts on Members of selected groups with no group: nobody can set up a machine until you choose the Authorized groups.
- Start the new machine from the Blue Fox OS USB key, pick automatic installation in the boot menu and type the domain.
- On the installing person's phone, scan the code shown on the machine's screen and sign in. The installation carries on by itself.
- Come back to Policy › Machines: the machine is listed, with its name, its user and its first sync.
Common tasks#
Create an organization record#
An organization has exactly one record. Symbifox refuses a second one for the same company.
- Go to Policy › Org Defaults, then select New.
- Pick the Company.
- Enter the Domain. Left blank, it is taken from the company's website.
- Work through the tabs in order: Authorization, Install, Zero-Touch, Login, Policies, Session, Apps, Browser.
- Save.
The record is served to machines straight away. When the instance holds several companies, each record needs its own domain: an address that matches no record gets a refusal, never another organization's policy.
Choose who may set up a workstation#
- Open the organization record, Authorization tab.
- Under Who can provision, choose Members of selected groups, Explicit users or Any internal user of the company.
- Depending on the choice, fill in Authorized groups or Authorized users.
- If needed, set Identity claim: the piece of information from the identity provider (email, username or identifier) compared with the login of Symbifox users.
- Save.
A new record starts on Members of selected groups, with no group: it authorizes nobody until you choose one. Existing records keep their choice. Whatever the mode, portal accounts, archived accounts and accounts from another company are refused.
The person who signs in is matched to a user through the Identity claim alone, which must match their login exactly (ignoring case). No matching user, or more than one, and setup is refused. The Require install client in token box adds a check: the sign-in must have been made for the workstation installer, not for another application of the same identity provider. It needs a provider that issues JWT tokens; leave it unchecked if you are not sure.
This rule is checked again at every sync. Removing someone from the authorized group is enough to cut off their machines: they keep the last policy they received, but get no new one.
Set installation, language and keyboard#
- Open the Install tab.
- In the Regional block, check the Locale, Timezone and Hostname Pattern. "{username}" in the pattern is replaced with the person's username.
- Leave Root Mode on Locked.
- In the Keyboard block, set both the Keymap and the XKB layout, then the XKB variant if needed.
- Save.
Set sign-in and security#
- Open the Login tab and choose the Login Mode: Local accounts, or the organization's directory accounts.
- For the directory, fill in its address, its base and the service account that queries it. The Mot de passe de liaison (directory service password) is never displayed: type it only to replace it.
- Leave Compte de secours local (local recovery account) checked unless your organization has decided otherwise.
- Open the Policies tab. Set Allow offline login and its length in days, MFA required and Auto-lock (minutes).
- Check TPM2 auto-unlock if the disk should unlock by itself at start-up, with no passphrase to type. Leave TPM2 PCRs at its default.
- Check Escrow disk passphrase to put the passphrases of future machines in escrow.
- Save.
An offline limit of zero never expires, and an auto-lock of zero is off. Escrow only applies to machines installed after it is turned on.
Set the look of the session#
- Open the Session tab.
- Enter the Accent Color and the wallpaper address in Wallpaper Url.
- Choose the Clock format: 24 h or 12 h (AM/PM).
- Under Default mounts, add one line per Nextcloud folder to mount: a name, the remote path, the location on the machine.
- Under Default PWAs, add the web apps to install, and check Pinned to pin them.
- Save.
The clock adapts to the person on its own: when their time zone differs from the organization's, a second clock appears showing the organization's time. There is no setting for it.
Choose the installed applications#
The system image already includes Brave, Thunderbird, Nextcloud and Bitwarden. The record adds and removes on top of that base.
- Open the Apps tab.
- Under Default apps, add the extra applications to install.
- Under Apps to remove, add the base applications to take out.
- Save.
The picker first offers only the Recommandées BF applications (recommended by Blue Fox). Remove that filter to choose from the whole catalogue. An application in both lists is removed: removal wins.
Maintain the application catalogue#
The catalogue is empty once the module is installed. It fills in one pass from Flathub, the application library Blue Fox OS uses.
- Go to Policy › Flatpak Catalogue.
- If the list is empty, add a first line by hand with an application's ID, for example "com.brave.Browser".
- Tick a line, open the Action menu and select Synchroniser Flathub (sync with Flathub).
- Wait for the notification, which gives the number of applications added and updated.
- Turn on the Recommandee BF toggle for the applications to offer by default.
The sync never touches your recommendation choices. It does not run on its own: run it again whenever you want a fresh catalogue.
Enforce browser extensions#
Enforced extensions are installed in Brave automatically, and the person cannot remove them.
- Go to Policy › Browser Extensions to see the catalogue. It ships with Symbifox Signets, Symbifox Tokens and Bitwarden.
- To add a Chrome Web Store extension, add a line with its name and its Extension ID: the 32 letters at the end of its store page address. Keep Source on Chrome Web Store.
- Open the organization record, Browser tab.
- Add the extensions to enforce, then save.
No extension is enforced out of the box. Symbifox extensions are served by your own instance. The Pass the instance address checkbox pre-fills your Symbifox address in the extension; access is still granted by the person.
Make an exception for one person#
- Go to Policy › User Overrides, then select New.
- Pick the User and the Company.
- Fill in only what changes: colour, wallpaper, clock format, automatic disk unlock, language, time zone or keyboard.
- Add extra folders, web apps, applications or extensions if needed.
- Use Apps to remove and Browser extensions to skip to take away what the organization record enforces.
- Save.
The time zone follows a three-step rule: the exception first, then the user's own time zone preference in Symbifox, then the organization record. Only fill it in here to pin a machine to a time zone that is not its user's.
Show the person's photo at sign-in#
The workstation's sign-in screen shows the person's face. There is nothing to turn on.
- Open the person's employee record in the Employees application.
- Add a photo in PNG or JPEG format.
- Wait for the machine's next sync.
Without an employee record, the user's photo is used. The initials avatar Symbifox generates by default is not sent, because the workstation cannot display it.
Get the automatic install file#
The install file is served by your Symbifox, from the organization record. Nobody needs to download it: the machine requests it when the domain is typed at start-up.
- Open the organization record, Zero-Touch tab.
- Check the OCI Image, the Tenant Display Name and the addresses in the OIDC device-flow bootstrap block.
- To check it, open
https://your-domain/blue-fox-install.ksin a browser, using the record's domain. - A plain text file appears: automatic installation is ready for that domain.
The file's language, keyboard and time zone come from the Install tab. A blank OCI Image turns automatic installation off: the address then answers that nothing is configured for that domain. The file holds no secrets.
View enrolled machines#
- Go to Policy › Machines.
- Read Vue le (last seen): the date of the last successful sync.
- Use the Jamais synchronisee filter (never synced) to find enrolled machines that have never re-read their policy.
- Group by Usager (user) to see all of one person's machines.
A reinstall creates a new record: the old one stays, and Vue le tells you which one is still alive. Revoke the old one.
A machine record stays attached to the person and organization that enrolled it: nobody else can take it over in their own name. To hand a workstation to someone else, reinstall it and have that person authorize the setup: the machine gets a new record in their name. Then revoke the old record.
Revoke a machine#
Revoke a workstation that is lost, stolen, replaced or leaving the organization.
- Open the machine under Policy › Machines.
- Select Revoquer (revoke) and confirm.
- Check for the Revoquee ribbon on the record.
The machine is cut off at its next sync and can no longer re-enrol. Revoking erases nothing on the machine: it keeps its last known policy. Revoked machines are listed under the Revoquees filter.
Read a passphrase held in escrow#
Before you start: you need the Custodian right. The passphrase is for when the disk no longer unlocks by itself, for example after a motherboard replacement.
- Open the machine under Policy › Machines. The Phrase sequestree (passphrase in escrow) box must be checked.
- Select Reveler la phrase de passe (reveal the passphrase).
- Read the warning and confirm.
- Select the passphrase in the window to copy it, or read it out.
- Select Fermer (close) as soon as you have what you need.
The read is recorded before the passphrase is even shown: Revelations goes up by one, and Derniere revelation and Revelee par record the time and your name. The window has no copy button, by design.
The Phrase de passe du disque window only opens through that button, and only the person who opened it can see it. After five minutes it no longer shows the passphrase: select Reveler la phrase de passe again, which counts as a new read.
Remove a passphrase from escrow#
Remove it once the disk has been destroyed or wiped: keeping the key to a disk that no longer exists has nothing but downsides.
- Open the machine, as a Custodian.
- Select Retirer le sequestre (remove from escrow) and confirm.
Removal is permanent. The passphrase cannot be recovered afterwards. This is the only way to erase an escrowed passphrase: an existing deposit is never replaced, not even by the person the workstation belongs to.
Give someone the Custodian role#
- Turn on developer mode.
- Go to Settings › Users & Companies › Groups.
- Open the group whose name ends in "Peut reveler les phrases de passe de disque".
- On the Users tab, add the person, then save.
Give this role to few people, and not necessarily to the ones who manage the fleet.
The menus, one by one#
All menus sit under the Policy application, visible to fleet managers only.
- Policy › Org Defaults: the list of organization records, one per company. Columns: Company, Domain, Who can provision, Login Mode, MFA required and Allow offline login. This is the chapter's starting screen.
- Policy › User Overrides: per-person exceptions, with the user, the company and the accent colour. A person has at most one exception per company.
- Policy › Flatpak Catalogue: the application catalogue, recommended ones first. The list is edited in place. The Recommandées BF filter and the Recommandée grouping help you maintain the short list.
- Policy › Browser Extensions: the extension catalogue, edited in place, with the Recommandee BF toggle, the ID, the source, the instance address option and a note.
- Policy › Machines: enrolled workstations, most recently seen first. Columns: Hostname, User, Org, Vue le, Synchronisations (sync count) and Phrase sequestree. The Version de l'image (image version), Derniere IP, Enrole le (enrolled on) and Sequestre le (escrowed on) columns can be added as needed.
Reference#
Fields on the organization record#
| Tab | Field | Description | Required or default |
|---|---|---|---|
| (header) | Company | The company described. One record per company. | Required, the current company |
| (header) | Domain | The address typed when the machine starts. Picks the record when the instance holds several. | Taken from the company website |
| Authorization | Who can provision | Members of chosen groups, named users, or any internal user of the company. Portal, archived and other-company accounts are always refused. | Members of selected groups, for a new record |
| Authorization | Identity claim | The identity provider information matched exactly against the login. | « email » |
| Authorization | Require install client in token | Refuses a sign-in made for an application other than the installer. | Unchecked |
| Install | Locale, Timezone | Language and time zone of the machines. | "fr_CA.UTF-8", "America/Montreal" |
| Install | Hostname Pattern | Pattern for the machine name. | "bf-{username}" |
| Install | Keymap, XKB layout, XKB variant, XKB options | Console keyboard, then desktop keyboard. | "ca", "ca", blank, Alt+Shift switches layouts |
| Zero-Touch | OCI Image | The system image to install. Blank turns automatic installation off. | Blank |
| Zero-Touch | Tenant Display Name | The organization name shown during installation and at welcome. | The company name |
| Zero-Touch | Nextcloud URL | The organization's Nextcloud address, to connect files without a second sign-in. | Blank |
| Login | Login Mode | Local accounts or directory accounts. | Directory |
| Login | Compte de secours local | Keeps a recovery account on the machine. | Checked |
| Policies | Allow offline login, Offline validity (days) | Sign-in without a network, and for how long. | Checked, 7 days |
| Policies | MFA required | Two-factor sign-in required. | Checked |
| Policies | Auto-lock (minutes) | Lock after inactivity. | 15 |
| Policies | TPM2 auto-unlock | The disk unlocks by itself at start-up; the passphrase remains a fallback. | Unchecked |
| Policies | Escrow disk passphrase | Puts in escrow the passphrases of machines installed afterwards. | Unchecked |
| Session | Accent Color, Wallpaper Url, Clock format | The look of the desktop. | Symbifox blue, blank, 24 h |
| Apps | Default apps, Apps to remove | Additions and removals on top of the image's base. | Empty |
| Browser | Browser extensions | Extensions enforced in Brave. | Empty |
Fields on the Machine record#
| Field | Description | Required or default |
|---|---|---|
| Hostname | The machine name, set at installation. | Reported |
| User, Org | The person whose policy is served, and their organization record. | Reported, read-only |
| UUID machine | The identity the machine drew at installation. | Reported |
| Version de l'image | The version of the installed system. | Reported |
| Enrole le, Vue le, Synchronisations | Enrolment, last sync, number of syncs. | Reported |
| Phrase sequestree, Sequestre le | Whether a passphrase is in escrow, and since when. | Reported |
| Revelations, Derniere revelation, Revelee par | Number of reads, the latest one, and who made it. | Updated on every read |
Reports and exports#
No printed report. Lists export like every list in Symbifox. No passphrase ever leaves through an export: only the reveal button displays it.
Automations#
| What happens on its own | How often |
|---|---|
| Every enrolled machine re-reads its policy and applies what changed. | Once a day |
| A new machine enrols and deposits its passphrase, if escrow is on. | At installation |
| The person's authorization is checked again. | At every sync |
The application catalogue never refreshes on its own: the Flathub sync is run by hand.
Public pages and portal#
No portal page. The module serves a few technical addresses that only workstations use. The install file, /blue-fox-install.ks, is public and holds no secrets; the policy itself is only handed to a person signed in with the identity provider and authorized, or to an enrolled machine. A Symbifox session open in the browser does not give access to the policy.
Modules that extend this application#
Understanding#
Why the machine re-reads its policy on its own. At installation, the machine receives an identity of its own, separate from the person who installed it. Every day, it re-reads its policy with that identity. Symbifox keeps only a fingerprint of it: even a full copy of the database is not enough to impersonate the machine.
Why revoking does not lock the machine. Revocation cuts the link; it erases nothing. A revoked machine keeps its last known policy, so it is never left without a configuration. To take a machine back in hand, reinstall it.
Why the Custodian is a separate role. Running a fleet's policy is an administration task; holding a disk passphrase is not. The module keeps the two apart, and makes every read a counted, dated and signed act.
Why escrow cannot be added later. The passphrase is generated by the installer and deposited during installation, the only moment an authorized person is demonstrably present. A machine installed before escrow was turned on, or whose deposit failed, keeps a passphrase typed by hand that only that person knows. To cover it, reinstall it.
Why an escrowed passphrase is never replaced. A deposit is not replaced by a new one, even one coming from the workstation itself. A normal reinstall creates a new record and is not affected. To deposit another passphrase on the same record, the Guardian first removes the old one, a restricted and traced action.
Why escrow fails safe. If the server lacks the encryption key, the installer does not use the passphrase it generated: it asks for a typed one, as before. A disk locked by a passphrase nobody holds would be worse than either alternative.
What installation does if the network drops. It does not stop: it falls back to default settings. A machine installed that way may not be enrolled; it then does not appear under Machines and will not follow policy changes.
What no longer changes after installation. The machine name, language and keyboard stay as they were set at installation. Everything else follows the record.
Troubleshooting#
| Symptom | Likely cause | Fix |
|---|---|---|
| The Policy application does not appear. | The account lacks the Settings right in the Administration section. | Have that right added, or hand the task to an administrator. |
| The install file address says nothing is configured. | The OCI Image is blank, or the typed domain matches no record. | Fill in the image and the record's Domain. |
| The person signs in, but the machine gets default settings. | They are not authorized to set up machines under the Authorization tab: no group chosen, a portal, archived or other-company account, or an identity claim matching no login (or several). | Add them to the authorized group or list, and check that their login matches the Identity claim exactly. |
| A change to the record does not reach a machine. | The machine has not synced yet, is not enrolled, or has been revoked. | Check Vue le and the record's ribbon; a machine missing from the list needs a reinstall. |
| The Reveler la phrase de passe button is missing. | The account lacks the Custodian right, or no passphrase is in escrow for this machine. | Have the Custodian role granted; if Phrase sequestree is unchecked, the passphrase exists only with whoever typed it. |
| Reading fails, saying escrow is not configured. | The encryption key is missing on the server, or has changed since the machine was installed. | Have the server administrator check the key. |
| The terminal and the desktop use different keyboards. | Only one of the two keyboard settings is filled in. | Set Keymap and XKB layout together. |
| The Flathub sync is not in the Action menu. | No line is ticked: the menu only appears with a selection. | Add a line by hand if the catalogue is empty, tick it, then try again. |