Skip to content

Instantly share code, notes, and snippets.

@sourcec0de
Created September 15, 2026 01:46
Show Gist options
  • Select an option

  • Save sourcec0de/7e92ef92a6d89bedbaec771a3152b063 to your computer and use it in GitHub Desktop.

Select an option

Save sourcec0de/7e92ef92a6d89bedbaec771a3152b063 to your computer and use it in GitHub Desktop.
Determinate Nix from an MDM that runs scripts as root (Iru).
#!/bin/bash
# Installs or updates Determinate Nix from an MDM that runs scripts as root (Iru).
#
# Adapted from:
# https://docs.determinate.systems/guides/mdm/
# https://raw.githubusercontent.com/kandji-inc/support/refs/heads/main/Scripts/InstallHomebrew.zsh
#
# The upstream Determinate script expects to be run by a logged-in, non-root admin user
# (via sudo). Under Iru the script runs as root with no console-user identity, so the
# Determinate package cannot tell which user it is being installed for. The block below
# resolves the console user the same way the Kandji InstallHomebrew.zsh script does and
# runs the upstream body with the identity variables sudo would have set for that user.
# Everything after the block is the upstream script.
set -euo pipefail
if [[ "$(/usr/bin/id -u)" -eq 0 && -z "${SUDO_USER:-}" ]]; then
console_user=$(/usr/sbin/scutil <<<"show State:/Users/ConsoleUser" |
/usr/bin/awk '/Name :/ && ! /loginwindow/ && ! /root/ && ! /_mbsetupuser/ { print $3 }' |
/usr/bin/awk -F '@' '{print $1}')
if [[ -z "$console_user" ]] || ! /usr/bin/dscl . -read "/Users/$console_user" >/dev/null 2>&1; then
echo "No valid console user is logged in; cannot install Determinate in user scope." >&2
exit 1
fi
SUDO_USER="$console_user"
SUDO_UID="$(/usr/bin/id -u "$console_user")"
SUDO_GID="$(/usr/bin/id -g "$console_user")"
export SUDO_USER SUDO_UID SUDO_GID
fi
TEAM_ID="X3JQ4VPJZ6"
PKG_ID="systems.determinate.Determinate"
PKG_URL="https://install.determinate.systems/determinate-pkg/stable/Universal"
installed_version="$(/usr/sbin/pkgutil --pkg-info-plist "$PKG_ID" 2>/dev/null |
/usr/bin/plutil -extract pkg-version raw -o - - 2>/dev/null || true)"
installed_version="${installed_version#v}"
download_url="$(/usr/bin/curl -fsIL -o /dev/null -w '%{url_effective}' "$PKG_URL")"
latest_version="$(echo "$download_url" | /usr/bin/grep -oE 'v?[0-9]+\.[0-9]+\.[0-9]+' | /usr/bin/head -1 || true)"
latest_version="${latest_version#v}"
if [[ -z "$download_url" || -z "$latest_version" ]]; then
echo "Could not determine the latest Determinate release from $PKG_URL (resolved to '$download_url')" >&2
exit 1
fi
if [[ -n "$installed_version" && "$installed_version" == "$latest_version" ]]; then
echo "Determinate $installed_version is already installed and up to date."
exit 0
fi
tmp_dir="$(/usr/bin/mktemp -d)"
pkg_path="$tmp_dir/Determinate.pkg"
trap '/bin/rm -rf "$tmp_dir"' EXIT
echo "Downloading Determinate $latest_version from $download_url ..."
/usr/bin/curl -fsSL "$download_url" -o "$pkg_path"
if ! /usr/sbin/spctl -a -vv -t install "$pkg_path" 2>&1 | /usr/bin/grep -q "($TEAM_ID)"; then
echo "Determinate.pkg is not signed by Developer ID team $TEAM_ID; refusing to install." >&2
exit 1
fi
echo "Installing Determinate $latest_version for user ${SUDO_USER:-$(/usr/bin/id -un)} ..."
/usr/sbin/installer -pkg "$pkg_path" -target /
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment