Catch configuration drift against an as-built baseline
Task
Capture an as-built record of lin-srv in a form a machine can compare -- packages, enabled services, listening ports, users and key configuration files -- make a few undocumented changes, and then find every one of them by comparing a second capture against the first. This is configuration drift detection with nothing but standard tools.
Steps
- Write
lab/drift/capture.shthat saves to a folder named on its command line: the sorted package list,systemctl list-unit-files --state=enabled,ss -tlnp, the list of user accounts from/etc/passwd, andsha256sumof/etc/ssh/sshd_config,/etc/fstaband/etc/hosts. - Run it into
lab/drift/as-built/. - Make four undocumented changes: install a package, enable a service, add a user, and edit
/etc/hosts. Record them inlab/drift/actual-changes.txtbut do not look at that file again yet. - Run the capture into
lab/drift/now/and savediff -r lab/drift/as-built lab/drift/nowtolab/drift/diff.txt. - List each change the diff reveals in
lab/drift/found.csvwith headerarea,change, then compare it with your record of actual changes.
Verify
These checks run in a POSIX shell: Terminal on macOS or Linux, and on Windows Git Bash (it comes with Git for Windows) or WSL. A stock Windows PowerShell or Command Prompt has no awk or grep, so there the first line fails.
ls lab/drift/as-built lab/drift/now | grep -c .
grep -Ec '^[<>]' lab/drift/diff.txt
awk -F, 'NR>1 {print $1}' lab/drift/found.csv | sort -u
awk -F, 'NR>1 {n++} END {print n" change(s) found"; exit (n<4)}' lab/drift/found.csv
The diff contains added or removed lines, and your found list covers packages, services, users and a configuration file checksum -- all four changes -- so the last command exits zero. A change the capture could not see means the capture is missing an area, and that is what to add before trusting it.
Notes
Configuration management tools such as Ansible, Puppet and DSC do this continuously and can put a drifted server back automatically. The capture here is the same idea at its smallest.
This is an independent study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.