Skip to content

非公式本サイトは非公式の日本語ドキュメントであり、Cloudflare 公式サイトではありません。最新情報はdevelopers.cloudflare.comをご確認ください。

Kandji

最終更新 Markdown で表示Agent セットアップ

Kandji は、Cloudflare One Client(旧称 WARP)をカスタムアプリとしてデプロイします。Kandji がカスタムアプリをデプロイする仕組みの概要は、ナレッジベース記事 を参照してください。

macOS

最も簡単なデプロイでは、Kandji が用意したダウンロード可能な構成プロファイルを使います。このプロファイルは Cloudflare One Client のユーザー通知を有効にし、Privacy Preference Policy Control(PPPC)でフルディスクアクセスを設定します。

  1. カスタムプロファイル をダウンロードします。

  2. カスタムプロファイルを追加します。

    1. Library > Add New > Add Library Item > Custom Profile に移動します。
    2. Add & Configure を選択します。
  3. カスタムプロファイルを設定します。

    1. カスタム構成プロファイルの Name を入力します。
    2. カスタムプロファイルをテスト用の Blueprint に割り当てます。
    3. Device FamiliesMac に設定します。
    4. 先ほどダウンロードした cloudflare_warp.mobileconfig ファイルをアップロードします。
    5. カスタムプロファイルを保存します。
    Kandji で Cloudflare One Client 向けのカスタムプロファイルを設定する

    注: この画像のラベルは、以前の製品名を示している場合があります。

  4. カスタムアプリを追加します。

    1. Library > Add New > Add Library Item > Custom App に移動します。
    2. Add & Configure を選択します。
  5. カスタムアプリを設定します。

    1. カスタムアプリに名前を付けます。

    2. プロファイルと同じテスト用 Blueprint にカスタムアプリを割り当てます。

    3. インストールタイプとして Audit and Enforce を選択します。

    4. 下の Audit and Enforce Script をコピーし、Audit Script テキストフィールドに貼り付けます。

    5. 最小アプリバージョンを強制するには、監査スクリプトの ENFORCED_VERSION 変数を、監査スクリプトが強制するバージョン番号(例: 1.5.207.0)に更新します。

      ENFORCED_VERSION を空("")のままにすると、監査スクリプトはバージョンを確認せず、Applications フォルダまたは Applications 内のサブフォルダに Cloudflare WARP.app があるかだけを確認します。詳細はスクリプト内のコメントを参照してください。

    6. Install Details セクションで Installer Package を選択します。

    7. Installer Package で、Cloudflare_WARP_<VERSION>.pkg ファイルをアップロードします。インストーラーパッケージがまだない場合は、こちらからダウンロード します。

    8. Save を選択します。

Cloudflare One Client がインストールされたことを確認するには、Custom App ライブラリでアプリを選択し、Status タブを表示します。

Cloudflare One Client をデプロイしたあと、Cloudflare One Client の GUI に表示される 接続ステータス メッセージで、接続の進行状況を確認できます。

Audit and Enforce Script

次の監査スクリプトは、Cloudflare One Client がインストールされているかを確認し、任意で最小バージョン番号を強制します。

#!/bin/zsh

###################################################################################################
# Created by Matt Wilson | [email protected] | Kandji, Inc. | Solutions Engineering
###################################################################################################
# Created on 07/30/2021
###################################################################################################
# Software Information
###################################################################################################
# This script is designed to check if an application is present. If the app is present, the
# script will check to see if a minimum version is being enforced. If a minimum app version is not
# being enforced, the script will only check to see if the app is installed or not.
###################################################################################################
# License Information
###################################################################################################
# Copyright 2021 Kandji, Inc.
#
# Permission is hereby granted, free of charge, to any person obtaining a copy of this
# software and associated documentation files (the "Software"), to deal in the Software
# without restriction, including without limitation the rights to use, copy, modify, merge,
# publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons
# to whom the Software is furnished to do so, subject to the following conditions:
#
# The above copyright notice and this permission notice shall be included in all copies or
# substantial portions of the Software.
#
# THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED,
# INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR
# PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE
# FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR
# OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER
# DEALINGS IN THE SOFTWARE.
###################################################################################################

# Script version
_VERSION="1.0.0"

###################################################################################################
###################################### VARIABLES ##################################################
###################################################################################################
# If you would like to enforce a minimum version, be sure to update the ENFORCED_VERSION variable
# with the version number that the audit script should enforce. (Example version number
# 1.5.207.0). If ENFORCED_VERSION is left blank, the audit script will not check for a version and
# will only check for the presence of the Cloudflare WARP app at the defined APP_PATH.
ENFORCED_VERSION="1.5.207.0"

###################################################################################################

# Make sure that the application matches the name of the app that will be installed.
# This script will dynamically search for the application in the Applications folder. So
# there is no need to define an application path. The app must either install in the
# Applications folder or up to 3 sub-directories deep.
#   For example Applications/<app_folder_name>/<app_name.app>
APP_NAME="Cloudflare WARP.app"

# Change the PROFILE_PAYLOAD_ID_PREFIX variable to the profile prefix you want to wait on before
# running the installer. If the profile is not found, this audit and enforce script will exit 00
# and do nothing until the next kandji agent check-in.
PROFILE_PAYLOAD_ID_PREFIX="io.kandji.cloudflare.C59FD67"

###################################################################################################
###################################### FUNCTIONS ##################################################
###################################################################################################

return_installed_app_version() {
    # Return the currently installed application version
    #
    # $1 - Is the name of the application.
    local app_name="$1"
    local installed_version="" # Initialize local variable

    # Uses the find binary to look for the app inside of the Applications directory and
    # any subdirectories up to 3 levels deep.
    local find_app="$(/usr/bin/find /Applications -maxdepth 3 -name $app_name)"
    local ret="$?"

    # Check to see if the app is installed.
    if [[ "$ret" -eq 0 ]] && [[ -d "$find_app" ]] &&
        [[ "$app_name" == "$(/usr/bin/basename $find_app)" ]]; then
        # If the previous command returns true and the returned object is a directory
        # and the app name that we are looking for is exactly equal to the app name
        # found by the find command.

        # Gets the installed app version and replaces any "-" with "."
        installed_version=$(/usr/bin/defaults read \
            "$find_app/Contents/Info.plist" CFBundleShortVersionString |
            /usr/bin/sed "s/-/./g")

    else
        installed_version="None"
    fi

    echo "$installed_version"
}

###################################################################################################
###################################### MAIN LOGIC #################################################
###################################################################################################

# All of the main logic be here ... modify at your own risk.

# The profiles variable will be set to an array of profiles that match the prefix in
# the PROFILE_PAYLOAD_ID_PREFIX variable
profiles=$(/usr/bin/profiles show | grep "$PROFILE_PAYLOAD_ID_PREFIX" | sed 's/.*\ //')

# If the PROFILE_PAYLOAD_ID_PREFIX is not found, exit 0 to wait for the next agent run.
if [[ ${#profiles[@]} -eq 0 ]]; then
    echo "no profiles with ID $PROFILE_PAYLOAD_ID_PREFIX were found ..."
    echo "Waiting until the profile is installed before proceeding ..."
    echo "Will check again at the next Kandji agent check-in ..."
    exit 0

else
    echo "Profile prefix $PROFILE_PAYLOAD_ID_PREFIX present ..."

    # Uses the find binary to look for the app inside of the Applications directory and
    # any subdirectories up to 3 levels deep.
    find_app="$(/usr/bin/find /Applications -maxdepth 3 -name $APP_NAME)"
    ret="$?"

    # Check to see if the app is installed.
    if [[ "$ret" -eq 0 ]] && [[ -d "$find_app" ]] &&
        [[ "$APP_NAME" == "$(/usr/bin/basename $find_app)" ]]; then
        # If the previous command returns true and the returned object is a directory
        # and the app name that we are looking for is exactly equal to the app name
        # found by the find command.
        echo "$find_app was found ..."

        # Check to see if an ENFORCED_VERSION is set. If not, exit 0.
        if [[ "$ENFORCED_VERSION" == "" ]]; then
            echo "A minimum enforced version is not set ..."
            exit 0
        fi

        # Get the currently install version
        # Pass the APP_NAME variable from above to the return_installed_app_version function
        # Removing the periods from the version number so that we can make a comparison.
        installed_version="$(return_installed_app_version $APP_NAME | /usr/bin/sed 's/\.//g')"

        # Removing the periods from the version number so that we can make a comparison.
        enforced_version="$(echo $ENFORCED_VERSION | /usr/bin/sed 's/\.//g')"

        # Check to see if the installed_version is less than the enforced_version. If it is then
        # exit 1 to initiate the installation process.
        if [[ "$installed_version" -lt "$enforced_version" ]]; then
            echo "Installed app version $installed_version less than enforced version $ENFORCED_VERSION"
            echo "Starting the app install process ..."
            exit 1

        else
            echo "Enforced vers: $enforced_version"
            echo "Installed app version: $installed_version"
            echo "Minimum app version enforcement met ..."
            echo "No need to run the installer ..."
            exit 0
        fi

    else
        echo "$APP_NAME was not found in the Applications folder ..."
        echo "Need to install $APP_NAME ..."
        exit 1

    fi

fi

exit 0

TLS 復号

Kandji の macOS エージェントは証明書ピン留め(certificate pinning)を使っており、Gateway TLS decryption と互換性がありません。Gateway TLS decryption が オン の場合は、Kandji を SSL/TLS 検査から除外する Do Not Inspect ポリシー を作成する必要があります。詳細は Kandji のドキュメント を参照してください。

役に立ちましたか?