#!/bin/bash
# ==============================================================================
# 1. DEFINE TARGET VOLUME
# ==============================================================================
TARGET_VOLUME="/Volumes/Macintosh HD"
if [ ! -d "${TARGET_VOLUME}" ]; then
echo "ERROR: Target volume '${TARGET_VOLUME}' not found!"
echo "Please open Disk Utility, select your volume, click 'Mount', and retry."
exit 1
fi
echo "======================================================================"
echo "STAGING UNIFIED LOCAL FIRST-BOOT CONFIGURATION PIPELINE"
echo "======================================================================"
# Create target deployment storage drive directories
mkdir -p "${TARGET_VOLUME}/private/var/tmp"
PAYLOAD_SCRIPT="${TARGET_VOLUME}/private/var/tmp/firstboot.sh"
# ==============================================================================
# 2. GENERATE FIRST-BOOT EXECUTION PAYLOAD (PART 1: ROOT SYSTEM SETUP)
# ==============================================================================
echo "Writing deployment payload to ${PAYLOAD_SCRIPT}..."
cat << 'EOF' > "${PAYLOAD_SCRIPT}"
#!/bin/bash
# Allow core system network interfaces 30 seconds to completely stabilize
sleep 30
# --- CONFIGURATION VARIABLES ---
USER_NAME="admin"
REAL_NAME="admin"
PASSWORD="12345"
# Segmented Infrastructure Servers & Authentication
LOCAL_SCRIPT_SERVER="https://10.214.1.241"
LOCAL_FILES_SERVER="https://10.214.1.241/files"
SECURE_CREDS="admin:Lumiere@2026"
# Target Office Wireless Network Credentials
WIFI_SSID="TymeDigital - Guest"
WIFI_PASSWORD="UnlockingHumanPotential!215"
APP_DIR="/Applications"
TMP_DIR="/tmp/app_staging"
# 1. SETUP ASSISTANT AUTOMATION (GLOBAL DEFINED OVERRIDE)
echo "Configuring Global Setup Assistant skip profiles..."
SETUP_PREFS="/Library/Preferences/com.apple.SetupAssistant.plist"
# Configure native system panel skips to bypass initial user creation screens
defaults write "${SETUP_PREFS}" DidSeeCloudSetup -bool true
defaults write "${SETUP_PREFS}" DidSeePrivacy -bool true
defaults write "${SETUP_PREFS}" DidSeeTrueTone -bool true
defaults write "${SETUP_PREFS}" DidSeeTouchID -bool true
defaults write "${SETUP_PREFS}" DidSeeScreenTime -bool true
defaults write "${SETUP_PREFS}" DidSeeSiri -bool true
defaults write "${SETUP_PREFS}" LastSeenSiriVersion -string "2.0"
defaults write "${SETUP_PREFS}" DidSeeSyncDiagnostics -bool true
defaults write "${SETUP_PREFS}" DidSeeAppAnalytics -bool true
defaults write "${SETUP_PREFS}" DidSeeLocationSettings -bool true
defaults write "${SETUP_PREFS}" DidSeeSoftwareUpdate -bool true
defaults write "${SETUP_PREFS}" DidSeeFileVault -bool true
defaults write "${SETUP_PREFS}" DidSeeActivationLock -bool true
defaults write "${SETUP_PREFS}" DidSeeTermsOfAddress -bool true
defaults write "${SETUP_PREFS}" DidSeeAccessibility -bool true
defaults write "${SETUP_PREFS}" DidSeeAppleID -bool true
defaults write "${SETUP_PREFS}" DidSeeMigrationAssistant -bool true
defaults write "${SETUP_PREFS}" LastSeenBuddyBuildVersion -string "999A999"
# Bypasses for adult profile, store management, and single operator context configuration
defaults write "${SETUP_PREFS}" DidSeeCommercialUse -bool true
defaults write "${SETUP_PREFS}" DidSeeAppStore -bool true
defaults write "${SETUP_PREFS}" DidSeeSoleUser -bool true
chmod 644 "${SETUP_PREFS}"
chown root:wheel "${SETUP_PREFS}"
# --- SYSTEM WIDE LOCATION SERVICES AUTO-ENABLE (ROOT LEVEL) ---
echo "Forcing System-Wide Location Services authorization..."
mkdir -p /var/db/locationd
defaults write /var/db/locationd/clients.plist LocationServicesEnabled -int 1
# Generate and authorize localized system host context mappings
UUID_STR=$(uuidgen)
defaults write /var/db/locationd/Library/Preferences/ByHost/com.apple.locationd LocationServicesEnabled -int 1
defaults write /var/db/locationd/Library/Preferences/ByHost/com.apple.locationd.${UUID_STR} LocationServicesEnabled -int 1
# Enforce strict system daemon ownership guidelines on database objects
chown -R _locationd:_locationd /var/db/locationd
chmod 700 /var/db/locationd
# 2. LOCAL ACCOUNT PROVISIONING
echo "Provisioning administrative account..."
if ! id "${USER_NAME}" &>/dev/null; then
sysadminctl -addUser "${USER_NAME}" -fullName "${REAL_NAME}" -password "${PASSWORD}"
dscl . -append /Groups/admin GroupMembership "${USER_NAME}"
fi
# 3. AUTOMATED WI-FI NETWORK PROVISIONING (PERSISTENT PROFILE)
echo "Detecting hardware wireless interfaces..."
WIFI_DEVICE=$(networksetup -listallhardwareports | awk '/Hardware Port: Wi-Fi/{getline; print $2}')
if [ -n "${WIFI_DEVICE}" ]; then
echo "Powering on wireless hardware interface (${WIFI_DEVICE})..."
networksetup -setairportpower "${WIFI_DEVICE}" on
echo "Adding SSID to System Preferred Networks for persistent auto-connect..."
# Index 0 forces this network to have the highest connection priority
networksetup -addpreferredwirelessnetworkatindex "${WIFI_DEVICE}" "${WIFI_SSID}" 0 WPA2 "${WIFI_PASSWORD}"
echo "Connecting natively to wireless network SSID: ${WIFI_SSID}..."
networksetup -setairportnetwork "${WIFI_DEVICE}" "${WIFI_SSID}" "${WIFI_PASSWORD}"
else
echo "Warning: No hardware Wi-Fi interface detected on this machine architecture."
fi
# Allocation for DHCP lease negotiation and authentication handshake stabilization
sleep 10
# 4. APPLICATION INSTALLATION ENGINE
mkdir -p "${TMP_DIR}"
# --- SYSTEM PROVISIONING: ROSETTA 2 ENGINE ---
if [[ "$(uname -m)" == "arm64" ]]; then
echo "Apple Silicon detected. Automating silent background Rosetta 2 installation..."
softwareupdate --install-rosetta --agree-to-license
else
echo "Intel Architecture detected. Skipping Rosetta 2 compilation step."
fi
# --- Public Web Applications (Native .pkg Deployments) ---
echo "Downloading public web utilities..."
# Google Chrome
echo "Downloading and installing Native Apple Silicon Google Chrome..."
curl -fL -o "${TMP_DIR}/googlechrome.pkg" "https://dl.google.com/chrome/mac/universal/stable/googlechrome.pkg"
if [ -f "${TMP_DIR}/googlechrome.pkg" ] && [ -s "${TMP_DIR}/googlechrome.pkg" ]; then
installer -pkg "${TMP_DIR}/googlechrome.pkg" -target /
else
echo "Error downloading native package, attempting fallback distribution pipeline..."
curl -fL -o "${TMP_DIR}/googlechrome-fallback.pkg" "https://dl.google.com/chrome/mac/stable/accept_tos%3Dhttps%253A%252F%252Fwww.google.com%252Fintl%252Fen_ph%252Fchrome%252Fterms%252F%26_and_accept_tos%3Dhttps%253A%252F%252Fpolicies.google.com%252Fterms/googlechrome.pkg"
installer -pkg "${TMP_DIR}/googlechrome-fallback.pkg" -target /
fi
# Slack
echo "Downloading and installing Slack (Apple Silicon)..."
curl -fL -o "${TMP_DIR}/Slack-arm64.pkg" "https://slack.com/api/desktop.latestRelease?redirect=1&variant=pkg&arch=arm64"
if [ -f "${TMP_DIR}/Slack-arm64.pkg" ] && [ -s "${TMP_DIR}/Slack-arm64.pkg" ]; then
installer -pkg "${TMP_DIR}/Slack-arm64.pkg" -target /
else
curl -fL -o "${TMP_DIR}/Slack-arm64-fallback.pkg" "https://downloads.slack-edge.com/releases/macos/pkg/arm64/slack-mac.pkg"
installer -pkg "${TMP_DIR}/Slack-arm64-fallback.pkg" -target /
fi
# Zoom
echo "Downloading and installing Native Apple Silicon Zoom Client..."
curl -fL -o "${TMP_DIR}/ZoomSilicon.pkg" "https://zoom.us/client/latest/zoomusInstallerFull.pkg?archType=arm64"
installer -pkg "${TMP_DIR}/ZoomSilicon.pkg" -target /
# MS Intune Company Portal
echo "Downloading and installing MS Intune Company Portal via Microsoft Enterprise CDN..."
curl -fL -o "${TMP_DIR}/CompanyPortal-Installer.pkg" "https://go.microsoft.com/fwlink/?linkid=853070"
if [ -f "${TMP_DIR}/CompanyPortal-Installer.pkg" ] && [ -s "${TMP_DIR}/CompanyPortal-Installer.pkg" ]; then
installer -pkg "${TMP_DIR}/CompanyPortal-Installer.pkg" -target /
else
echo "Warning: Direct Microsoft link resolved an anomaly. Dropping back to infrastructure mirror node..."
curl -k -u "${SECURE_CREDS}" -L -o "${TMP_DIR}/CompanyPortal-Fallback.pkg" "${LOCAL_FILES_SERVER}/CompanyPortal-Installer.pkg"
installer -pkg "${TMP_DIR}/CompanyPortal-Fallback.pkg" -target /
fi
# OpenVPN Connect
echo "Downloading and installing OpenVPN Connect..."
curl -fL -o "${TMP_DIR}/openvpn.dmg" "https://openvpn.net/downloads/openvpn-connect-v3-macos.dmg"
if [ -f "${TMP_DIR}/openvpn.dmg" ]; then
hdiutil attach "${TMP_DIR}/openvpn.dmg" -mountpoint "${TMP_DIR}/openvpn_mnt" -nobrowse
OPENVPN_PKG=$(find "${TMP_DIR}/openvpn_mnt" -name "*.pkg" -maxdepth 2 | head -n 1)
if [ -n "${OPENVPN_PKG}" ]; then
installer -pkg "${OPENVPN_PKG}" -target /
else
echo "Warning: OpenVPN PKG payload not found on disk image mount."
fi
hdiutil detach "${TMP_DIR}/openvpn_mnt"
else
echo "Warning: Failed to download OpenVPN Connect image payload."
fi
# Bitwarden
echo "Downloading and installing Bitwarden..."
curl -fL -o "${TMP_DIR}/bitwarden.dmg" "https://vault.bitwarden.com/download/?app=desktop&platform=macos"
hdiutil attach "${TMP_DIR}/bitwarden.dmg" -mountpoint "${TMP_DIR}/bit_mnt" -nobrowse
cp -R "${TMP_DIR}/bit_mnt/Bitwarden.app" "${APP_DIR}/"
hdiutil detach "${TMP_DIR}/bit_mnt"
# --- Local Asset Server Applications ---
echo "Downloading corporate assets securely from local files server..."
# Microsoft Teams
curl -k -u "${SECURE_CREDS}" -L -o "${TMP_DIR}/MicrosoftTeams.pkg" "${LOCAL_FILES_SERVER}/MicrosoftTeams.pkg"
installer -pkg "${TMP_DIR}/MicrosoftTeams.pkg" -target /
# Microsoft 365 Suite
curl -k -u "${SECURE_CREDS}" -L -o "${TMP_DIR}/M365.pkg" "${LOCAL_FILES_SERVER}/M365.pkg"
installer -pkg "${TMP_DIR}/M365.pkg" -target /
# UEMS Mac Agent
echo "Downloading UEMS Mac Agent archive..."
curl -k -u "${SECURE_CREDS}" -L -o "${TMP_DIR}/UEMSMacAgent.tar.gz" "${LOCAL_FILES_SERVER}/UEMSMacAgent.tar.gz"
mkdir -p "${TMP_DIR}/uems_extracted"
echo "Extracting UEMS Mac Agent tarball payload..."
tar -zxf "${TMP_DIR}/UEMSMacAgent.tar.gz" -C "${TMP_DIR}/uems_extracted"
if [ -f "${TMP_DIR}/uems_extracted/UEMSMacAgent/UEMS_MacAgent.pkg" ]; then
echo "Installing UEMS Mac Agent..."
installer -pkg "${TMP_DIR}/uems_extracted/UEMSMacAgent/UEMS_MacAgent.pkg" -target /
else
echo "Warning: Target nested package context '${TMP_DIR}/uems_extracted/UEMSMacAgent/UEMS_MacAgent.pkg' not found."
fi
# Tenable Nessus Agent
echo "Downloading and deploying Nessus Agent..."
curl -k -u "${SECURE_CREDS}" -L -o "${TMP_DIR}/NessusAgent-11.2.0.dmg" "${LOCAL_FILES_SERVER}/NessusAgent-11.2.0.dmg"
if [ -f "${TMP_DIR}/NessusAgent-11.2.0.dmg" ]; then
hdiutil attach "${TMP_DIR}/NessusAgent-11.2.0.dmg" -mountpoint "${TMP_DIR}/nessus_mnt" -nobrowse
if [ -f "${TMP_DIR}/nessus_mnt/Install Nessus Agent.pkg" ]; then
installer -pkg "${TMP_DIR}/nessus_mnt/Install Nessus Agent.pkg" -target /
else
echo "Warning: 'Install Nessus Agent.pkg' not found on the mounted volume context."
fi
hdiutil detach "${TMP_DIR}/nessus_mnt"
else
echo "Warning: Failed to fetch Nessus Agent DMG from the asset storage node."
fi
# Cisco AMP Connector
curl -k -u "${SECURE_CREDS}" -L -o "${TMP_DIR}/amp_GoTymeVN_last.dmg" "${LOCAL_FILES_SERVER}/amp_GoTymeVN_last.dmg"
hdiutil attach "${TMP_DIR}/amp_GoTymeVN_last.dmg" -mountpoint "${TMP_DIR}/amp_mnt" -nobrowse
if [ -f "${TMP_DIR}/amp_mnt/cisco-sccm-bootstrap.pkg" ]; then
installer -pkg "${TMP_DIR}/amp_mnt/cisco-sccm-bootstrap.pkg" -target /
fi
hdiutil detach "${TMP_DIR}/amp_mnt"
NOW=$(date -jn) && curl -X POST -H 'Content-type: application/json' --data '{"text":"'"${NOW}"'-Step 4: Done step install software offline !"}' https://hooks.slack.com/services/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
# ==============================================================================
# CLEANUP AND HANDOFF DELEGATION
# ==============================================================================
chown -R root:wheel "${APP_DIR}/"*.app
chmod -R 755 "${APP_DIR}/"*.app
rm -rf "${TMP_DIR}"
# Destroy the system-wide bootstrap LaunchDaemon entry
rm -f /Library/LaunchDaemons/com.pipeline.firstboot.plist
# 5-Second delay verification before system execution self-destruction routine
for i in {5..1}
do
echo "Root installation phase complete. Rebooting computer in ${i} seconds..."
sleep 1
done
# INVERTED FILE ELIMINATION CHAIN: Deletes this script payload immediately before processing restart
rm -f -- "$0" && reboot
EOF
chmod +x "${PAYLOAD_SCRIPT}"
# ==============================================================================
# 3. GENERATE LOGIN INTERACTIVE PAYLOAD (PART 2: USER LAND LAUNCHAGENT)
# ==============================================================================
AGENT_SCRIPT="${TARGET_VOLUME}/private/var/tmp/userlogin.sh"
echo "Writing first login payload script to ${AGENT_SCRIPT}..."
cat << 'EOF' > "${AGENT_SCRIPT}"
#!/bin/bash
# Cooldown delay loop to ensure the user space graphical session finishes assembling
sleep 5
CURRENT_USER=$(scutil <<< "show State:/Users/ConsoleUser" | awk '/Name :/ {print $3}')
# Fallback block validation checking for non-graphical context drops
if [ -z "${CURRENT_USER}" ] || [ "${CURRENT_USER}" = "loginwindow" ] || [ "${CURRENT_USER}" = "root" ]; then
exit 0
fi
# Execute only if the target admin logs in
if [ "${CURRENT_USER}" = "admin" ]; then
echo "Executing per-user localization profile preferences engine for user: ${CURRENT_USER}"
GLOBAL_PREFS="/Users/admin/Library/Preferences/.GlobalPreferences.plist"
SETUP_PREFS="/Users/admin/Library/Preferences/com.apple.SetupAssistant.plist"
# Configure localization structure properties maps (Vietnam / EN-US Context)
defaults write "${GLOBAL_PREFS}" AppleLanguages -array "en-US"
defaults write "${GLOBAL_PREFS}" AppleLocale -string "en_VN"
defaults write "${GLOBAL_PREFS}" Country -string "VN"
defaults write "${GLOBAL_PREFS}" AppleInterfaceStyleSwitchesAutomatically -bool true
defaults write "${GLOBAL_PREFS}" AppleInterfaceStyle -string "Light"
# --- USER LAND ENVIRONMENT LOCATION SERVICES OVERRIDES ---
echo "Writing Location Service variables into local target profile space..."
defaults write "/Users/admin/Library/Preferences/com.apple.locationd.plist" LocationServicesEnabled -int 1
USER_UUID=$(uuidgen)
defaults write "/Users/admin/Library/Preferences/ByHost/com.apple.locationd" LocationServicesEnabled -int 1
defaults write "/Users/admin/Library/Preferences/ByHost/com.apple.locationd.${USER_UUID}" LocationServicesEnabled -int 1
# Clean setup verification markers for the current user folder path
defaults write "${SETUP_PREFS}" DidSeeAvatarSetup -bool true
defaults write "${SETUP_PREFS}" DidSeeCloudSetup -bool true
defaults write "${SETUP_PREFS}" DidSeePrivacy -bool true
defaults write "${SETUP_PREFS}" DidSeeLocationSettings -bool true
# Sync permissions maps on configuration trees
chown -R admin:staff "/Users/admin/Library/Preferences"
echo "----------------------------------------------------------------------"
echo "ATTENTION REQUIRED: Triggering System Security Panels for Manual Toggle..."
echo "----------------------------------------------------------------------"
# Modern system settings architecture anchors (macOS Ventura, Sonoma, Sequoia)
# Full Disk Access
open "x-apple.systemsettings:com.apple.settings.PrivacySecurity.Extension?Privacy_AllFiles"
sleep 3
# System Extensions
open "x-apple.systemsettings:com.apple.settings.PrivacySecurity.Extension?Privacy_SystemExtensions"
# Self-cleanup launch configurations so this user engine executes precisely once
rm -f "/Library/LaunchAgents/com.pipeline.userlogin.plist"
rm -f -- "$0"
fi
EOF
chmod 755 "${AGENT_SCRIPT}"
chown root:wheel "${AGENT_SCRIPT}"
# ==============================================================================
# 4. GENERATE SYSTEM SCHEDULER LaunchDaemon PLIST (PART 1 DEPLOYMENT)
# ==============================================================================
echo "Creating automated system boot LaunchDaemon scheduler..."
LAUNCH_DAEMON="${TARGET_VOLUME}/Library/LaunchDaemons/com.pipeline.firstboot.plist"
cat << 'EOF' > "${LAUNCH_DAEMON}"
Label
com.pipeline.firstboot
ProgramArguments
/bin/bash
/private/var/tmp/firstboot.sh
RunAtLoad
EOF
chmod 644 "${LAUNCH_DAEMON}"
chown root:wheel "${LAUNCH_DAEMON}"
# ==============================================================================
# 5. GENERATE USER SPACE LaunchAgent PLIST (PART 2 DEPLOYMENT)
# ==============================================================================
echo "Creating automated user-login LaunchAgent scheduler..."
LAUNCH_AGENT="${TARGET_VOLUME}/Library/LaunchAgents/com.pipeline.userlogin.plist"
cat << 'EOF' > "${LAUNCH_AGENT}"
Label
com.pipeline.userlogin
ProgramArguments
/bin/bash
/private/var/tmp/userlogin.sh
RunAtLoad
EOF
chmod 644 "${LAUNCH_AGENT}"
chown root:wheel "${LAUNCH_AGENT}"
# ==============================================================================
# 6. STAGING COUNTDOWN AND ENGINE EXECUTION
# ==============================================================================
echo "======================================================================"
echo "SUCCESS: Staging phase complete. Active profiles linked successfully!"
echo "======================================================================"
SERIAL=$(ioreg -l | grep "IOPlatformSerialNumber" | sed -E 's/.*= "(.*)"/\1/') && curl -X POST -H 'Content-type: application/json' --data '{"text":"'"*${SERIAL}*"' | Begin: Downloaded and Running Script !"}' https://hooks.slack.com/services/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
for i in {5..1}
do
echo "Rebooting machine automatically into deployment state in ${i} seconds..."
sleep 1
done
echo "Initiating production engine execution reboot now..."
reboot