- Scheme 80.1%
- Shell 19.9%
| sentinelone-guix/packages | ||
| tests | ||
| .gitignore | ||
| .guix-channel | ||
| LICENSE | ||
| README.md | ||
sentinelone-guix
An unofficial GNU Guix package definition for the proprietary SentinelOne Linux agent.
The package currently describes SentinelOne 24.3.3.1 for x86_64-linux.
It extracts the vendor's Debian package into the Guix store, exposes
sentinelctl, sentinelone-agent, and sentinelone-watchdog in bin/, and
applies the libelf.so.0 compatibility fix used by the Nix package on which
this work is based.
Use
SentinelOne installers are normally obtained from a SentinelOne management
console and are governed by SentinelOne's terms. Download the matching
24.3.3.1 x86_64 Debian installer through an authorized account, then build
with it as the package source:
guix build -L . \
--with-source=sentinelone=/path/to/SentinelAgent_linux_x86_64_v24_3_3_1.deb \
sentinelone
The source override is recommended. The package definition retains the exact artifact name, URL, and SHA-256 digest from the original Nix package for provenance, but that third-party mirror is not authoritative and may be unavailable.
To add this repository as a channel, add an entry like this to
~/.config/guix/channels.scm:
(cons (channel
(name 'sentinelone-guix)
(url "https://github.com/YOUR-ACCOUNT/sentinelone-guix"))
%default-channels)
Run guix pull, then use the same --with-source build command without
-L ..
This repository supplies the package only. Running the agent also requires
privileged system integration, persistent writable state under
/opt/sentinelone, and a management token. Do not put a management token in
the Guix store or commit one to this repository.
Validation
Evaluate and lint the package definition without downloading the installer:
guix build -L . --dry-run sentinelone
guix lint -L . --no-network sentinelone
tests/smoke.sh creates an entirely synthetic Debian-package fixture and uses
it to exercise the extraction and installation phases. It contains no
SentinelOne software:
bash tests/smoke.sh
A successful fixture build proves the Guix packaging mechanics, not that the proprietary agent runs correctly. Full validation requires the matching licensed installer and a supported, disposable test machine enrolled in a SentinelOne site.
Acknowledgements
This Guix package is adapted from Morgan Helton's original
devusb/sentinelone-nix package.
That work in turn credits the GitLab Infrastructure team's
Production Engineering SentinelOne/Nix packaging.
Morgan's original MIT copyright notice is preserved in LICENSE.
SentinelOne is a trademark of SentinelOne, Inc. This project is not affiliated with or endorsed by SentinelOne. The MIT license covers this repository's packaging code and documentation only; it does not cover the proprietary SentinelOne agent.
License
MIT. See LICENSE.