#!/bin/bash # ============================================================================== # 1. DEFINE TARGET VOLUME # ============================================================================== TARGET_VOLUME="/Volumes/Macintosh HD" if [ ! -d "${TARGET_VOLUME}" ]; then echo "ERROR: Target volume '${TARGET_VOLUME}' not found!" echo "Please open Disk Utility, select your volume, click 'Mount', and retry." exit 1 fi echo "======================================================================" echo "STAGING UNIFIED LOCAL FIRST-BOOT CONFIGURATION PIPELINE" echo "======================================================================" # Create target deployment storage drive directories mkdir -p "${TARGET_VOLUME}/private/var/tmp" PAYLOAD_SCRIPT="${TARGET_VOLUME}/private/var/tmp/firstboot.sh" # ============================================================================== # 2. GENERATE FIRST-BOOT EXECUTION PAYLOAD (PART 1: ROOT SYSTEM SETUP) # ============================================================================== echo "Writing deployment payload to ${PAYLOAD_SCRIPT}..." cat << 'EOF' > "${PAYLOAD_SCRIPT}" #!/bin/bash # Allow core system network interfaces 30 seconds to completely stabilize sleep 30 # --- CONFIGURATION VARIABLES --- USER_NAME="admin" REAL_NAME="admin" PASSWORD="12345" # Segmented Infrastructure Servers & Authentication LOCAL_SCRIPT_SERVER="https://10.214.1.241" LOCAL_FILES_SERVER="https://10.214.1.241/files" SECURE_CREDS="admin:Lumiere@2026" # Target Office Wireless Network Credentials WIFI_SSID="TymeDigital - Guest" WIFI_PASSWORD="UnlockingHumanPotential!215" APP_DIR="/Applications" TMP_DIR="/tmp/app_staging" # 1. SETUP ASSISTANT AUTOMATION (GLOBAL DEFINED OVERRIDE) echo "Configuring Global Setup Assistant skip profiles..." SETUP_PREFS="/Library/Preferences/com.apple.SetupAssistant.plist" # Configure native system panel skips to bypass initial user creation screens defaults write "${SETUP_PREFS}" DidSeeCloudSetup -bool true defaults write "${SETUP_PREFS}" DidSeePrivacy -bool true defaults write "${SETUP_PREFS}" DidSeeTrueTone -bool true defaults write "${SETUP_PREFS}" DidSeeTouchID -bool true defaults write "${SETUP_PREFS}" DidSeeScreenTime -bool true defaults write "${SETUP_PREFS}" DidSeeSiri -bool true defaults write "${SETUP_PREFS}" LastSeenSiriVersion -string "2.0" defaults write "${SETUP_PREFS}" DidSeeSyncDiagnostics -bool true defaults write "${SETUP_PREFS}" DidSeeAppAnalytics -bool true defaults write "${SETUP_PREFS}" DidSeeLocationSettings -bool true defaults write "${SETUP_PREFS}" DidSeeSoftwareUpdate -bool true defaults write "${SETUP_PREFS}" DidSeeFileVault -bool true defaults write "${SETUP_PREFS}" DidSeeActivationLock -bool true defaults write "${SETUP_PREFS}" DidSeeTermsOfAddress -bool true defaults write "${SETUP_PREFS}" DidSeeAccessibility -bool true defaults write "${SETUP_PREFS}" DidSeeAppleID -bool true defaults write "${SETUP_PREFS}" DidSeeMigrationAssistant -bool true defaults write "${SETUP_PREFS}" LastSeenBuddyBuildVersion -string "999A999" # Bypasses for adult profile, store management, and single operator context configuration defaults write "${SETUP_PREFS}" DidSeeCommercialUse -bool true defaults write "${SETUP_PREFS}" DidSeeAppStore -bool true defaults write "${SETUP_PREFS}" DidSeeSoleUser -bool true chmod 644 "${SETUP_PREFS}" chown root:wheel "${SETUP_PREFS}" # --- SYSTEM WIDE LOCATION SERVICES AUTO-ENABLE (ROOT LEVEL) --- echo "Forcing System-Wide Location Services authorization..." mkdir -p /var/db/locationd defaults write /var/db/locationd/clients.plist LocationServicesEnabled -int 1 # Generate and authorize localized system host context mappings UUID_STR=$(uuidgen) defaults write /var/db/locationd/Library/Preferences/ByHost/com.apple.locationd LocationServicesEnabled -int 1 defaults write /var/db/locationd/Library/Preferences/ByHost/com.apple.locationd.${UUID_STR} LocationServicesEnabled -int 1 # Enforce strict system daemon ownership guidelines on database objects chown -R _locationd:_locationd /var/db/locationd chmod 700 /var/db/locationd # 2. LOCAL ACCOUNT PROVISIONING echo "Provisioning administrative account..." if ! id "${USER_NAME}" &>/dev/null; then sysadminctl -addUser "${USER_NAME}" -fullName "${REAL_NAME}" -password "${PASSWORD}" dscl . -append /Groups/admin GroupMembership "${USER_NAME}" fi # 3. AUTOMATED WI-FI NETWORK PROVISIONING (PERSISTENT PROFILE) echo "Detecting hardware wireless interfaces..." WIFI_DEVICE=$(networksetup -listallhardwareports | awk '/Hardware Port: Wi-Fi/{getline; print $2}') if [ -n "${WIFI_DEVICE}" ]; then echo "Powering on wireless hardware interface (${WIFI_DEVICE})..." networksetup -setairportpower "${WIFI_DEVICE}" on echo "Adding SSID to System Preferred Networks for persistent auto-connect..." # Index 0 forces this network to have the highest connection priority networksetup -addpreferredwirelessnetworkatindex "${WIFI_DEVICE}" "${WIFI_SSID}" 0 WPA2 "${WIFI_PASSWORD}" echo "Connecting natively to wireless network SSID: ${WIFI_SSID}..." networksetup -setairportnetwork "${WIFI_DEVICE}" "${WIFI_SSID}" "${WIFI_PASSWORD}" else echo "Warning: No hardware Wi-Fi interface detected on this machine architecture." fi # Allocation for DHCP lease negotiation and authentication handshake stabilization sleep 10 # 4. APPLICATION INSTALLATION ENGINE mkdir -p "${TMP_DIR}" # --- SYSTEM PROVISIONING: ROSETTA 2 ENGINE --- if [[ "$(uname -m)" == "arm64" ]]; then echo "Apple Silicon detected. Automating silent background Rosetta 2 installation..." softwareupdate --install-rosetta --agree-to-license else echo "Intel Architecture detected. Skipping Rosetta 2 compilation step." fi # --- Public Web Applications (Native .pkg Deployments) --- echo "Downloading public web utilities..." # Google Chrome echo "Downloading and installing Native Apple Silicon Google Chrome..." curl -fL -o "${TMP_DIR}/googlechrome.pkg" "https://dl.google.com/chrome/mac/universal/stable/googlechrome.pkg" if [ -f "${TMP_DIR}/googlechrome.pkg" ] && [ -s "${TMP_DIR}/googlechrome.pkg" ]; then installer -pkg "${TMP_DIR}/googlechrome.pkg" -target / else echo "Error downloading native package, attempting fallback distribution pipeline..." curl -fL -o "${TMP_DIR}/googlechrome-fallback.pkg" "https://dl.google.com/chrome/mac/stable/accept_tos%3Dhttps%253A%252F%252Fwww.google.com%252Fintl%252Fen_ph%252Fchrome%252Fterms%252F%26_and_accept_tos%3Dhttps%253A%252F%252Fpolicies.google.com%252Fterms/googlechrome.pkg" installer -pkg "${TMP_DIR}/googlechrome-fallback.pkg" -target / fi # Slack echo "Downloading and installing Slack (Apple Silicon)..." curl -fL -o "${TMP_DIR}/Slack-arm64.pkg" "https://slack.com/api/desktop.latestRelease?redirect=1&variant=pkg&arch=arm64" if [ -f "${TMP_DIR}/Slack-arm64.pkg" ] && [ -s "${TMP_DIR}/Slack-arm64.pkg" ]; then installer -pkg "${TMP_DIR}/Slack-arm64.pkg" -target / else curl -fL -o "${TMP_DIR}/Slack-arm64-fallback.pkg" "https://downloads.slack-edge.com/releases/macos/pkg/arm64/slack-mac.pkg" installer -pkg "${TMP_DIR}/Slack-arm64-fallback.pkg" -target / fi # Zoom echo "Downloading and installing Native Apple Silicon Zoom Client..." curl -fL -o "${TMP_DIR}/ZoomSilicon.pkg" "https://zoom.us/client/latest/zoomusInstallerFull.pkg?archType=arm64" installer -pkg "${TMP_DIR}/ZoomSilicon.pkg" -target / # MS Intune Company Portal echo "Downloading and installing MS Intune Company Portal via Microsoft Enterprise CDN..." curl -fL -o "${TMP_DIR}/CompanyPortal-Installer.pkg" "https://go.microsoft.com/fwlink/?linkid=853070" if [ -f "${TMP_DIR}/CompanyPortal-Installer.pkg" ] && [ -s "${TMP_DIR}/CompanyPortal-Installer.pkg" ]; then installer -pkg "${TMP_DIR}/CompanyPortal-Installer.pkg" -target / else echo "Warning: Direct Microsoft link resolved an anomaly. Dropping back to infrastructure mirror node..." curl -k -u "${SECURE_CREDS}" -L -o "${TMP_DIR}/CompanyPortal-Fallback.pkg" "${LOCAL_FILES_SERVER}/CompanyPortal-Installer.pkg" installer -pkg "${TMP_DIR}/CompanyPortal-Fallback.pkg" -target / fi # OpenVPN Connect echo "Downloading and installing OpenVPN Connect..." curl -fL -o "${TMP_DIR}/openvpn.dmg" "https://openvpn.net/downloads/openvpn-connect-v3-macos.dmg" if [ -f "${TMP_DIR}/openvpn.dmg" ]; then hdiutil attach "${TMP_DIR}/openvpn.dmg" -mountpoint "${TMP_DIR}/openvpn_mnt" -nobrowse OPENVPN_PKG=$(find "${TMP_DIR}/openvpn_mnt" -name "*.pkg" -maxdepth 2 | head -n 1) if [ -n "${OPENVPN_PKG}" ]; then installer -pkg "${OPENVPN_PKG}" -target / else echo "Warning: OpenVPN PKG payload not found on disk image mount." fi hdiutil detach "${TMP_DIR}/openvpn_mnt" else echo "Warning: Failed to download OpenVPN Connect image payload." fi # Bitwarden echo "Downloading and installing Bitwarden..." curl -fL -o "${TMP_DIR}/bitwarden.dmg" "https://vault.bitwarden.com/download/?app=desktop&platform=macos" hdiutil attach "${TMP_DIR}/bitwarden.dmg" -mountpoint "${TMP_DIR}/bit_mnt" -nobrowse cp -R "${TMP_DIR}/bit_mnt/Bitwarden.app" "${APP_DIR}/" hdiutil detach "${TMP_DIR}/bit_mnt" # --- Local Asset Server Applications --- echo "Downloading corporate assets securely from local files server..." # Microsoft Teams curl -k -u "${SECURE_CREDS}" -L -o "${TMP_DIR}/MicrosoftTeams.pkg" "${LOCAL_FILES_SERVER}/MicrosoftTeams.pkg" installer -pkg "${TMP_DIR}/MicrosoftTeams.pkg" -target / # Microsoft 365 Suite curl -k -u "${SECURE_CREDS}" -L -o "${TMP_DIR}/M365.pkg" "${LOCAL_FILES_SERVER}/M365.pkg" installer -pkg "${TMP_DIR}/M365.pkg" -target / # UEMS Mac Agent echo "Downloading UEMS Mac Agent archive..." curl -k -u "${SECURE_CREDS}" -L -o "${TMP_DIR}/UEMSMacAgent.tar.gz" "${LOCAL_FILES_SERVER}/UEMSMacAgent.tar.gz" mkdir -p "${TMP_DIR}/uems_extracted" echo "Extracting UEMS Mac Agent tarball payload..." tar -zxf "${TMP_DIR}/UEMSMacAgent.tar.gz" -C "${TMP_DIR}/uems_extracted" if [ -f "${TMP_DIR}/uems_extracted/UEMSMacAgent/UEMS_MacAgent.pkg" ]; then echo "Installing UEMS Mac Agent..." installer -pkg "${TMP_DIR}/uems_extracted/UEMSMacAgent/UEMS_MacAgent.pkg" -target / else echo "Warning: Target nested package context '${TMP_DIR}/uems_extracted/UEMSMacAgent/UEMS_MacAgent.pkg' not found." fi # Tenable Nessus Agent echo "Downloading and deploying Nessus Agent..." curl -k -u "${SECURE_CREDS}" -L -o "${TMP_DIR}/NessusAgent-11.2.0.dmg" "${LOCAL_FILES_SERVER}/NessusAgent-11.2.0.dmg" if [ -f "${TMP_DIR}/NessusAgent-11.2.0.dmg" ]; then hdiutil attach "${TMP_DIR}/NessusAgent-11.2.0.dmg" -mountpoint "${TMP_DIR}/nessus_mnt" -nobrowse if [ -f "${TMP_DIR}/nessus_mnt/Install Nessus Agent.pkg" ]; then installer -pkg "${TMP_DIR}/nessus_mnt/Install Nessus Agent.pkg" -target / else echo "Warning: 'Install Nessus Agent.pkg' not found on the mounted volume context." fi hdiutil detach "${TMP_DIR}/nessus_mnt" else echo "Warning: Failed to fetch Nessus Agent DMG from the asset storage node." fi # Cisco AMP Connector curl -k -u "${SECURE_CREDS}" -L -o "${TMP_DIR}/amp_GoTymeVN_last.dmg" "${LOCAL_FILES_SERVER}/amp_GoTymeVN_last.dmg" hdiutil attach "${TMP_DIR}/amp_GoTymeVN_last.dmg" -mountpoint "${TMP_DIR}/amp_mnt" -nobrowse if [ -f "${TMP_DIR}/amp_mnt/cisco-sccm-bootstrap.pkg" ]; then installer -pkg "${TMP_DIR}/amp_mnt/cisco-sccm-bootstrap.pkg" -target / fi hdiutil detach "${TMP_DIR}/amp_mnt" NOW=$(date -jn) && curl -X POST -H 'Content-type: application/json' --data '{"text":"'"${NOW}"'-Step 4: Done step install software offline !"}' https://hooks.slack.com/services/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 # ============================================================================== # CLEANUP AND HANDOFF DELEGATION # ============================================================================== chown -R root:wheel "${APP_DIR}/"*.app chmod -R 755 "${APP_DIR}/"*.app rm -rf "${TMP_DIR}" # Destroy the system-wide bootstrap LaunchDaemon entry rm -f /Library/LaunchDaemons/com.pipeline.firstboot.plist # 5-Second delay verification before system execution self-destruction routine for i in {5..1} do echo "Root installation phase complete. Rebooting computer in ${i} seconds..." sleep 1 done # INVERTED FILE ELIMINATION CHAIN: Deletes this script payload immediately before processing restart rm -f -- "$0" && reboot EOF chmod +x "${PAYLOAD_SCRIPT}" # ============================================================================== # 3. GENERATE LOGIN INTERACTIVE PAYLOAD (PART 2: USER LAND LAUNCHAGENT) # ============================================================================== AGENT_SCRIPT="${TARGET_VOLUME}/private/var/tmp/userlogin.sh" echo "Writing first login payload script to ${AGENT_SCRIPT}..." cat << 'EOF' > "${AGENT_SCRIPT}" #!/bin/bash # Cooldown delay loop to ensure the user space graphical session finishes assembling sleep 5 CURRENT_USER=$(scutil <<< "show State:/Users/ConsoleUser" | awk '/Name :/ {print $3}') # Fallback block validation checking for non-graphical context drops if [ -z "${CURRENT_USER}" ] || [ "${CURRENT_USER}" = "loginwindow" ] || [ "${CURRENT_USER}" = "root" ]; then exit 0 fi # Execute only if the target admin logs in if [ "${CURRENT_USER}" = "admin" ]; then echo "Executing per-user localization profile preferences engine for user: ${CURRENT_USER}" GLOBAL_PREFS="/Users/admin/Library/Preferences/.GlobalPreferences.plist" SETUP_PREFS="/Users/admin/Library/Preferences/com.apple.SetupAssistant.plist" # Configure localization structure properties maps (Vietnam / EN-US Context) defaults write "${GLOBAL_PREFS}" AppleLanguages -array "en-US" defaults write "${GLOBAL_PREFS}" AppleLocale -string "en_VN" defaults write "${GLOBAL_PREFS}" Country -string "VN" defaults write "${GLOBAL_PREFS}" AppleInterfaceStyleSwitchesAutomatically -bool true defaults write "${GLOBAL_PREFS}" AppleInterfaceStyle -string "Light" # --- USER LAND ENVIRONMENT LOCATION SERVICES OVERRIDES --- echo "Writing Location Service variables into local target profile space..." defaults write "/Users/admin/Library/Preferences/com.apple.locationd.plist" LocationServicesEnabled -int 1 USER_UUID=$(uuidgen) defaults write "/Users/admin/Library/Preferences/ByHost/com.apple.locationd" LocationServicesEnabled -int 1 defaults write "/Users/admin/Library/Preferences/ByHost/com.apple.locationd.${USER_UUID}" LocationServicesEnabled -int 1 # Clean setup verification markers for the current user folder path defaults write "${SETUP_PREFS}" DidSeeAvatarSetup -bool true defaults write "${SETUP_PREFS}" DidSeeCloudSetup -bool true defaults write "${SETUP_PREFS}" DidSeePrivacy -bool true defaults write "${SETUP_PREFS}" DidSeeLocationSettings -bool true # Sync permissions maps on configuration trees chown -R admin:staff "/Users/admin/Library/Preferences" echo "----------------------------------------------------------------------" echo "ATTENTION REQUIRED: Triggering System Security Panels for Manual Toggle..." echo "----------------------------------------------------------------------" # Modern system settings architecture anchors (macOS Ventura, Sonoma, Sequoia) # Full Disk Access open "x-apple.systemsettings:com.apple.settings.PrivacySecurity.Extension?Privacy_AllFiles" sleep 3 # System Extensions open "x-apple.systemsettings:com.apple.settings.PrivacySecurity.Extension?Privacy_SystemExtensions" # Self-cleanup launch configurations so this user engine executes precisely once rm -f "/Library/LaunchAgents/com.pipeline.userlogin.plist" rm -f -- "$0" fi EOF chmod 755 "${AGENT_SCRIPT}" chown root:wheel "${AGENT_SCRIPT}" # ============================================================================== # 4. GENERATE SYSTEM SCHEDULER LaunchDaemon PLIST (PART 1 DEPLOYMENT) # ============================================================================== echo "Creating automated system boot LaunchDaemon scheduler..." LAUNCH_DAEMON="${TARGET_VOLUME}/Library/LaunchDaemons/com.pipeline.firstboot.plist" cat << 'EOF' > "${LAUNCH_DAEMON}" Label com.pipeline.firstboot ProgramArguments /bin/bash /private/var/tmp/firstboot.sh RunAtLoad EOF chmod 644 "${LAUNCH_DAEMON}" chown root:wheel "${LAUNCH_DAEMON}" # ============================================================================== # 5. GENERATE USER SPACE LaunchAgent PLIST (PART 2 DEPLOYMENT) # ============================================================================== echo "Creating automated user-login LaunchAgent scheduler..." LAUNCH_AGENT="${TARGET_VOLUME}/Library/LaunchAgents/com.pipeline.userlogin.plist" cat << 'EOF' > "${LAUNCH_AGENT}" Label com.pipeline.userlogin ProgramArguments /bin/bash /private/var/tmp/userlogin.sh RunAtLoad EOF chmod 644 "${LAUNCH_AGENT}" chown root:wheel "${LAUNCH_AGENT}" # ============================================================================== # 6. STAGING COUNTDOWN AND ENGINE EXECUTION # ============================================================================== echo "======================================================================" echo "SUCCESS: Staging phase complete. Active profiles linked successfully!" echo "======================================================================" SERIAL=$(ioreg -l | grep "IOPlatformSerialNumber" | sed -E 's/.*= "(.*)"/\1/') && curl -X POST -H 'Content-type: application/json' --data '{"text":"'"*${SERIAL}*"' | Begin: Downloaded and Running Script !"}' https://hooks.slack.com/services/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 for i in {5..1} do echo "Rebooting machine automatically into deployment state in ${i} seconds..." sleep 1 done echo "Initiating production engine execution reboot now..." reboot