Pan-Unix Control Agent

Note that development is in very early stages, targeting documentation first. There is no working code here yet.

puca, the Pan-Unix Control Agent, is an endpoint and configuration management system for Linux, BSD, and other Unix-like systems. It emphasises simplicity, minimal resource usage, and a small attack surface.

The agent runs on each system being managed, and connects to a central management point to retrieve instructions and send responses. Agent functionality is intentionally restricted, prioritising predictability and auditability over complex features.

From the central manager, an operator can see the following for all endpoints, or subsets of endpoints:

The operator can search for endpoints and add them to groups, according to arbitrary criteria, using a simple query language. These criteria can include server characteristics or even installed packages, allowing dynamic groups such as "all systems with under 4GB RAM that have GCC installed".

Operators can queue up actions for endpoints to run. Actions are retrieved by each endpoint's puca agent and executed by calls to the external tools uact, xyz, and scw. This allows the operator to:

Action delegation acts as a kind of multi-system sudo. For example, deployment of internal software to a production cluster could be handed off to a release management team, allowing them to co-ordinate releases without system administrator assistance or even any access to the target cluster.

Configuration management is available in a simple form, where endpoints and endpoint groups are configured using a declarative domain-specific language which is translated into appropriate actions.

Both the agent and the central manager produce metrics which can be collected by monitoring tools such as Zabbix, Prometheus, and so on, allowing alerts about endpoint status to be tailored to the local norms.

Endpoint registration policy is flexible — the manager, pucamgr, can impliticly trust all new puca agents, or require operators to approve new agents, or require registration with a pre-shared secret, or restrict by IP address. These can be combined, so for example operator approval can be required for agents from one subnet, while trusting agents using a pre-shared key from another subnet.

This software is distributed under the terms of the GNU General Public License version 3 or later.

Comments, bug reports, and patches can be sent using the Issue tracker, or through the Contact Form.