enrolla

Enrolled devices

CSV

Hosts enrolled for unison-ro and unison-admin certificate authentication. This is the list patcha reads to work out how it can reach a device, so a host missing here is a host patcha will treat as manual-entry only.

ClientHostnameAddressOS JumpPrincipalsLast verified

Nothing to show. Has the inventory been pushed yet?

Coverage

Enrolled hosts per client, and how many have not been confirmed working in the last 30 days. Enrolled and working are different facts: one host in this inventory had certificate auth silently broken for two months by an AllowUsers whitelist, and was only found when somebody tried to use it.

ClientEnrolledStale > 30d

Enrol a server

enrolla does not run enrolment, and deliberately cannot: enrolling a server needs an existing administrative credential on the target, which belongs to you and must not be held by a web service. What it can do is remove the guesswork about which script, which arguments, and what has to happen afterwards.

Inventory pushes

Every push is a full snapshot. Devices that stop appearing are marked absent rather than deleted, so a sweep that failed halfway cannot erase the fleet in one call.

WhenBySourceRows AddedUpdatedAbsentWarnings