Post

Replies

Boosts

Views

Activity

Comment on Automated FileVault unlock via external secret provider in headless server deployment
Actually, the network is available before the boot volume is unlocked (that's how I do it on my prototype). However, in our case, some nodes may only have a custom Thunderbolt device connected, providing network access only once the OS is fully booted. A mechanism equivalent to a USB key on the Thunderbolt port — acting as a pre-boot unlock token — would be sufficient for our use case.
Topic: Core OS SubTopic:
File Systems Q&A
Tags:
Jun ’26
Comment on Automated FileVault unlock via external secret provider in headless server deployment
Yes, sure, this is what we use today. Yet it needs a way to identify a server that is stuck at startup for that reason. If we had a way to make the Mac, for example, ask the closest available MDM server to unlock it (or any other; MDM may be a flaw in the security), it would be great. You have a public certificate for that service, and only it can unlock the remaining servers.
Topic: Core OS SubTopic:
File Systems Q&A
Tags:
Jun ’26
Comment on Automated FileVault unlock via external secret provider in headless server deployment
Ok, thank you.
Topic: Core OS SubTopic:
File Systems Q&A
Tags:
Replies
Boosts
Views
Activity
Jun ’26
Comment on Automated FileVault unlock via external secret provider in headless server deployment
Actually, the network is available before the boot volume is unlocked (that's how I do it on my prototype). However, in our case, some nodes may only have a custom Thunderbolt device connected, providing network access only once the OS is fully booted. A mechanism equivalent to a USB key on the Thunderbolt port — acting as a pre-boot unlock token — would be sufficient for our use case.
Topic: Core OS SubTopic:
File Systems Q&A
Tags:
Replies
Boosts
Views
Activity
Jun ’26
Comment on Automated FileVault unlock via external secret provider in headless server deployment
Yes, sure, this is what we use today. Yet it needs a way to identify a server that is stuck at startup for that reason. If we had a way to make the Mac, for example, ask the closest available MDM server to unlock it (or any other; MDM may be a flaw in the security), it would be great. You have a public certificate for that service, and only it can unlock the remaining servers.
Topic: Core OS SubTopic:
File Systems Q&A
Tags:
Replies
Boosts
Views
Activity
Jun ’26
Comment on Automated FileVault unlock via external secret provider in headless server deployment
It cannot be guaranteed. If you have your servers always on, but at some point there is a power outage, even with batteries, you may need to shut down some of your server. And then at Startup, …
Topic: Core OS SubTopic:
File Systems Q&A
Tags:
Replies
Boosts
Views
Activity
Jun ’26