惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

AI
AI
S
Schneier on Security
T
Tenable Blog
A
Arctic Wolf
I
Intezer
博客园 - 司徒正美
A
About on SuperTechFans
The Hacker News
The Hacker News
H
Hacker News: Front Page
Security Archives - TechRepublic
Security Archives - TechRepublic
Attack and Defense Labs
Attack and Defense Labs
Webroot Blog
Webroot Blog
T
The Blog of Author Tim Ferriss
Know Your Adversary
Know Your Adversary
L
Lohrmann on Cybersecurity
D
Docker
T
The Exploit Database - CXSecurity.com
博客园_首页
Microsoft Azure Blog
Microsoft Azure Blog
N
Netflix TechBlog - Medium
H
Help Net Security
Hacker News: Ask HN
Hacker News: Ask HN
Recorded Future
Recorded Future
P
Proofpoint News Feed
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
Help Net Security
Help Net Security
L
LINUX DO - 最新话题
AWS News Blog
AWS News Blog
量子位
MyScale Blog
MyScale Blog
博客园 - 聂微东
S
Security @ Cisco Blogs
The Register - Security
The Register - Security
www.infosecurity-magazine.com
www.infosecurity-magazine.com
月光博客
月光博客
V2EX - 技术
V2EX - 技术
T
Troy Hunt's Blog
SecWiki News
SecWiki News
L
LangChain Blog
B
Blog
博客园 - 三生石上(FineUI控件)
Cyberwarzone
Cyberwarzone
H
Heimdal Security Blog
Scott Helme
Scott Helme
O
OpenAI News
B
Blog RSS Feed
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
M
MIT News - Artificial intelligence
Google DeepMind News
Google DeepMind News
雷峰网
雷峰网

Jamf Blog

Jamf Nation Live 2026 London and Berlin: AI Governance and DDM 5 Mac Security Gaps Hiding in Your Apple Fleet Classroom Management Tools and Student Learning Outcomes Mobile forensics, minutes not weeks Turn Security Signals into Action with Jamf and Amplifier Security Strengthen Jamf Zero Trust Network Access With Dedicated Internet Gateway Jamf AI Assistant Now Available: Smarter Apple Device Management and Security MacBook Neo: The New Enterprise Entry Point for Mac at Scale Boost Employee Productivity in the Enterprise with Jamf Platform Authentication and Declarative Device Management: The Future of Apple Management Automation for Small IT Teams: Save Time Managing Macs What a lower-cost MacBook Neo means for education Where Apple Meets the Enterprise: Jamf’s Interoperability Advantage for Secure, Automated Access Control Simplify access, secure your apps: why SSO matters for K-12 Inside Predator’s kernel engine RSA Conference 2026 recap: AI security, enterprise mobile security and the shift to connected security platforms ClickFix technique uses Script Editor instead of Terminal on macOS Why Mac configurations fall out of sync — and how to fix them G2 names Jamf in its 2026 Best Software Awards across three categories Empowering Mac users: How Jamf Self Service+ reduces tier one support overhead for enterprise IT teams Privacy by default, flexible when required: introducing limited privacy in Jamf Safe Internet From arrival to discharge: how iOS is reimagining the healthcare journey Federated Identity Management for K-12 Education Identity and access management in K-12 schools OpenClaw: the helpful AI that could quietly become your biggest insider threat Get Started with Scripting Series: macOS Terminal, Scripting and Jamf Pro API Managing Apple devices at Black Hat Europe with Jamf Scaling device deployments without scaling your IT team How Predator spyware defeats iOS recording indicators Making Mac work in a PC world The hidden costs of manual device provisioning Threat Actors Expand Abuse of Microsoft Visual Studio Code Mac management and security for lean IT teams Automated certificate management and device security integration The hidden risks in your mobile apps “Mac in 2026: Secure by Design Meets the Enterprise” webinar Jamf named a Unified Endpoint Management leader…again! Jamf recognized as a Leader in 2026 Gartner® Magic Quadrant™ for Endpoint Management Tools Predator’s kill switch: undocumented anti-analysis techniques in iOS spyware 2026: what to expect in tech Retail runs on iOS: Let’s take a tour through Jamf’s booth at NRF 2026 From ClickFix to code signed: the quiet shift of MacSync Stealer malware Jamf After Dark: How WorkBrew solves Homebrew security and compliance for Mac developers Managing emerging technologies: A playbook for modern IT leaders How schools can maximize learning using Apple devices and Jamf Practical intelligence: why it matters for enterprise teams Jamf Connect Q&A Jamf After Dark October recap: platform progress, identity shifts and security insights Powering managed virtualization and Windows app delivery in Mac-first enterprises FlexibleFerret malware continues to strike Back to security basics: phishing Introducing the Jamf 140 Course HIMSS 2026 recap Introducing Beacon by Jamf Threat Labs GhostClaw expands beyond npm: GitHub repositories and AI workflows deliver macOS infostealer Android and Jamf: manage and secure your mobile fleet Social engineering in K-12 for beginners Jamf Nation Live 2026: Hands-On Apple Expertise Across Six Cities Developer Mode-as-a-Defense: How iOS Security Features Deter Nation-State Spyware Stop chasing passwords: how school IT can reduce reset tickets Bring Your Own Key (BYOK): Take Control of Your Encryption in Jamf Cloud DarkSword iOS Exploit Kit: 3 Lessons for Mobile Security Threat Labs Jamf Training Celebrates 20 Years of Apple IT Education and Certification Balancing Safety and Learning: K-12 Content Filtering for IT Admins Why Mac security updates take too long and how to fix it Why the Jamf platform is the natural foundation for MSPs Jamf After Dark: mobile forensics Introducing the redesigned Mac threat prevention. Now available in beta.  Beyond access: rethinking the complete Apple deployment strategy for education Gain faster updates and real-time fleet visibility with DDM What the Canvas breach tells us about the state of education security Why K-12 students need web filtering that travels with their devices Jamf spotlighted in Okta Businesses at Work 2026 Report Jamf Nation Live 2026 recap MobiDash internals: ghost clicks and SSH tunnels in commercial adware Tech Partner Spotlight: Jamf + SmallStep MacBook Neo in K-12 Closing the gaps: How Jamf protects macOS and iOS with real-time threat prevention MSP engineering: The art of scoping in Jamf Pro at scale Mac in education is evolving. Jamf School makes it simple Why Apple devices deserve security built for them Seamless Learning Access: Simplicity that puts learning first Reducing IT firefighting: Fewer failed updates, less manual cleanup Apple WWDC26: Keynote recap How Jamf helps maximize your Microsoft investments MTE as a microscope WWDC26: Key takeaways for education institutions WWDC26: Key takeaways for Apple admins The JNUC 2026 session catalog is live — and the clock is ticking Jamf After Dark: Why we moved 1,900+ Apple devices back to Jamf AI governance for Mac: bringing AI under management AI Adoption Is High, Governance Is Lagging Klue Third-Party Cybersecurity Incident How Identity Automation, Claris, and Jamf Simplify Apple Workflows for Education What Is AI Governance? How Proactive Device Status Reporting Transforms Mac Fleet Visibility AI Governance on Mac: A Practical Guide for IT and Security Teams Restaurants Run on iOS: Jamf and IPORT at the NRA Show AI Governance on Mac: A Practical Guide for IT and Security Teams PamStealer: macOS Malware Posing as Clipboard Manager App
Managing Jamf configuration with Terraform and GitOps workflows
Ryan Legg · 2026-04-11 · via Jamf Blog

Some housekeeping rules

Before getting started with Terraform and testing workflows, there are a few things to be aware of:

  1. If you missed the first part of this blog series, you may want to familiarize yourself with all of the context this article is about.
  2. All the up-to-date information regarding Terraform – including future updates – is located on the Jamf developer site.
  3. As a best practice, it is recommended that testing be performed utilizing a test instance and not a production instance.

With that said, let’s get to work!

Installing Terraform

In keeping with simplicity, we recommend using Homebrew to install Terraform. After opening Terminal, proceed through the following steps:

  1. Type in the command: brew tap hashicorp/tap to access the HashiCorp official directory.
  2. Next, to install Terraform, execute the following command: brew install hashicorp/tap/terraform
  3. Last, to validate the installation was successful, enter the following command to view the version of Terraform installed: terraform -version

Note: For reference, detailed installation steps – alongside videos of the installation process – are documented on the HashiCorp developer’s site.

Starting a Terraform project

A Terraform Project file will contain many specific items that are required to get up and running and start building out your project. Most of the relevant files will end with the file extension .tf or something similar, like .tfvars.

Getting started may feel a bit daunting. While there are many components to getting started with Terraform, this guide aims to make this process easier.

  1. Create a folder to store the Terraform project: mkdir jamf-terraform
  2. Change the working directory to the newly created folder: cd ~/jamf-terraform
  3. Next, clone the template branch from the main Terraform module repo: git clone -b template https://github.com/Jamf-Concepts/terraform-jamf-platform

After this is done, you’ll have a fully functional, templated Terraform project ready to go for Jamf Pro and Jamf Security Cloud.

Adding a variable file

Something you would not want to end up in your GitHub repo are your login credentials or client secrets.

Thankfully, Terraform has a path for this.

Begin by launching your text editor of choice and copy-pasting the following text:

Name this file terraform.tfvars and save it to the top level of your newly cloned template repo.

ProTip: To keep things simple, we’ll be using basic authentication, but you can switch to using OAuth in the future.

Now, you can fill in the credential information, such as the jamfpro_username and jamfpro_password fields respectively in the newly created terraform.tfvars file. Additionally, you’ll need to create an API client within the endpoint security tenant to populate the Jamf Protect section.

Note: The General Settings Knob refers to the module included with the template, titled include_categories. This simple boolean variable lets admins declare whether to apply a specific module or let everything run each time.

Terraform state file

Since resources haven’t been committed to the instance yet, now is the perfect time to cover what the Terraform state file is.

Every time resources are added, changed or destroyed through Terraform, those updates are saved in a file called terraform.tfstate and then backed up to a file called terraform.tfstate.backup.

This is how Terraform remembers what has occurred within your instance – and it’s critical for forward functionality. Each time you run Terraform against an instance, this state file is consulted before anything is done. Each state file needs to be associated to its own instance, so it’s important to keep them separated to maintain functionality and reduce issues.

Running Terraform

The setup is in a good place with Terraform installed, a template repo and your credentials defined in a variables file.

We’re now ready to run our template module against our test Jamf Pro instance. To do so, open Terminal and run the following commands:

terraform init -upgrade

This initializes Terraform and upgrades any required providers to the latest versions for anyone who’s used this before on their machines. It also performs the initial installation for the required Terraform providers if you’re entirely new to the topic.

terraform fmt -recursive

This recursively formats any Terraform code in your local cloned branch to make sure it will all look correct and function properly.

terraform plan

This looks at your test Jamf Pro instance, the Terraform state file and module code for any changes (or new things) to apply (or remove) from your instance. It returns a full rundown of what will happen when you execute the module.

terraform apply

This first runs the plan (from the previous command) and reports back what will be added, changed or destroyed. It then asks you to confirm/deny this action by entering yes or no respectively.

terraform apply -parallelism=1

This forces all resources to be created to process one at a time. Since many SaaS apps have systems in place to detect potential attacks, sometimes this is the best way to approach running Terraform.

terraform destroy -parallelism=1

This destroys any created resources that are referenced in your state file in Terraform.

Each subsequent use of the plan, apply or destroy commands:

  • Consults your state file

  • Assesses what needs to be added, changed, or destroyed

  • And then executes the proper action

Running a specific module

When running the template module that’s included, it will create seven categories in your Jamf Pro test instance, named for each Apollo mission from 11-17 as a simple test. Once these are added, you can easily destroy them using the above commands. The goal here is to visually display Terraform’s structure, so you can start building modules that are relevant to your environment.

The anatomy of Terraform

The core of the functionality here is the hierarchy of .tf files. The root level main.tf, calls to the child module main.tf, which references the .tfvars and variables.tf files. Below is a full breakdown of the thread and order of communication:

When you run terraform apply:

  1. The state file is consulted.
  2. Main.tf (root) is assessed for child modules that are being requested.
  3. Variables.tf (root) is scanned for relevant variables for the child modules being applied.
  4. Terraform.tfvars is scanned for all relevant variables for running each child module.
  5. Main.tf (child) files are then called and executed, referencing their own local variables.tf files for relevant local child module variables.
  6. Each resource is then created, and references are saved to terraform.tfstate.
  7. Terraform reports back success or failure, along with relevant codes and response messaging, to aid with troubleshooting issues, if necessary.

Things to keep in mind

  • When you start building your own modules, you can copy the template module included and change it to suit your needs.

  • Each child module must have its own main.tf and variables.tf files.

  • Each child module needs to be represented in the root level main.tf.

  • Carefully read through the module in the template repo and look for every reference point so you fully understand how each piece works together to achieve the goal.

  • Boolean operations, referred to as knobs in your terraform.tfvars file, are used to call specific child modules. Incidentally, this section may be omitted so that all the modules are called when terraform apply executed.

  • Module calls may be set as dependent on a variable being populated, or simple inclusion or exclusion statements may be set to determine when modules run, based on your own criteria.

Terraform is a very powerful tool with many built-in functions that you can use. Some of these will be necessary as you build specific functions, while others may never be used but rest assured, they’re all very well documented by the developer.

References