GNU Guix package definition for the SentinelOne Linux agent
  • Scheme 80.1%
  • Shell 19.9%
Find a file
2026-08-14 06:34:40 -04:00
sentinelone-guix/packages Add SentinelOne Guix package 2026-08-14 06:34:40 -04:00
tests Add SentinelOne Guix package 2026-08-14 06:34:40 -04:00
.gitignore Add SentinelOne Guix package 2026-08-14 06:34:40 -04:00
.guix-channel Add SentinelOne Guix package 2026-08-14 06:34:40 -04:00
LICENSE Add SentinelOne Guix package 2026-08-14 06:34:40 -04:00
README.md Add SentinelOne Guix package 2026-08-14 06:34:40 -04:00

sentinelone-guix

An unofficial GNU Guix package definition for the proprietary SentinelOne Linux agent.

The package currently describes SentinelOne 24.3.3.1 for x86_64-linux. It extracts the vendor's Debian package into the Guix store, exposes sentinelctl, sentinelone-agent, and sentinelone-watchdog in bin/, and applies the libelf.so.0 compatibility fix used by the Nix package on which this work is based.

Use

SentinelOne installers are normally obtained from a SentinelOne management console and are governed by SentinelOne's terms. Download the matching 24.3.3.1 x86_64 Debian installer through an authorized account, then build with it as the package source:

guix build -L . \
  --with-source=sentinelone=/path/to/SentinelAgent_linux_x86_64_v24_3_3_1.deb \
  sentinelone

The source override is recommended. The package definition retains the exact artifact name, URL, and SHA-256 digest from the original Nix package for provenance, but that third-party mirror is not authoritative and may be unavailable.

To add this repository as a channel, add an entry like this to ~/.config/guix/channels.scm:

(cons (channel
       (name 'sentinelone-guix)
       (url "https://github.com/YOUR-ACCOUNT/sentinelone-guix"))
      %default-channels)

Run guix pull, then use the same --with-source build command without -L ..

This repository supplies the package only. Running the agent also requires privileged system integration, persistent writable state under /opt/sentinelone, and a management token. Do not put a management token in the Guix store or commit one to this repository.

Validation

Evaluate and lint the package definition without downloading the installer:

guix build -L . --dry-run sentinelone
guix lint -L . --no-network sentinelone

tests/smoke.sh creates an entirely synthetic Debian-package fixture and uses it to exercise the extraction and installation phases. It contains no SentinelOne software:

bash tests/smoke.sh

A successful fixture build proves the Guix packaging mechanics, not that the proprietary agent runs correctly. Full validation requires the matching licensed installer and a supported, disposable test machine enrolled in a SentinelOne site.

Acknowledgements

This Guix package is adapted from Morgan Helton's original devusb/sentinelone-nix package. That work in turn credits the GitLab Infrastructure team's Production Engineering SentinelOne/Nix packaging. Morgan's original MIT copyright notice is preserved in LICENSE.

SentinelOne is a trademark of SentinelOne, Inc. This project is not affiliated with or endorsed by SentinelOne. The MIT license covers this repository's packaging code and documentation only; it does not cover the proprietary SentinelOne agent.

License

MIT. See LICENSE.