{"id":101,"date":"2019-01-28T06:00:30","date_gmt":"2019-01-28T06:00:30","guid":{"rendered":"https:\/\/www.alansiu.net\/munkiguide\/?p=101"},"modified":"2025-08-07T04:42:55","modified_gmt":"2025-08-07T04:42:55","slug":"connectingclienttorepo","status":"publish","type":"post","link":"https:\/\/www.alansiu.net\/munkiguide\/connectingclienttorepo\/","title":{"rendered":"Connecting a Munki client to the Munki repo"},"content":{"rendered":"<p>Now that you&#8217;ve set up a web server, put the Munki repo folders on it, installed Munki tools on it, imported an item into it, and set up a manifest for it, you can finally connect a Mac client to it.<\/p>\n<p>Good news! Since you installed all the Munki tools (not just the admin ones), your Mac web server that&#8217;s hosting the Munki repo can also be a Munki client of itself.<\/p>\n<p>Probably the easiest way to connect the Munki client to the Munki server is to give your Munki repo a fully qualified domain name (fqdn) of <em style=\"white-space:nowrap;\">munki.YOURSCHOOL.edu\/munki_repo<\/em><\/p>\n<p>There are <a href=\"https:\/\/github.com\/munki\/munki\/wiki\/Default-Repo-Detection#details\">certain repo URLs Munki will try automatically<\/a>. So it&#8217;s one less thing for you to define. If you don&#8217;t want to give your repo that kind of fqdn or prefer to reference it by IP address (make sure the IP address is static, then!), you&#8217;ll have to set a <a href=\"https:\/\/github.com\/munki\/munki\/wiki\/Preferences\">Munki preference<\/a> for SoftwareRepoURL:<\/p>\n<p><code>sudo defaults write \/Library\/Preferences\/ManagedInstalls SoftwareRepoURL \"http:\/\/192.168.1.200\/munki_repo\"<\/code><\/p>\n<p>or<\/p>\n<p><code>sudo defaults write \/Library\/Preferences\/ManagedInstalls SoftwareRepoURL \"http:\/\/somesubdomainthatsnotmunki.YOURSCHOOL.edu\/munki_repo\"<\/code><\/p>\n<p>Reminder: if your Munki repo can be referenced via <em style=\"white-space: nowrap;\">munki.YOURSCHOOL.edu\/munki_repo<\/em>, you do <strong>not<\/strong> need to set a SoftwareRepoURL.<\/p>\n<p>Also, for now we&#8217;re just using regular <em>http<\/em> instead of <em>https<\/em>, but after you get a little more comfortable with Munki, you definitely want to switch over to <em>https<\/em> either via <a href=\"https:\/\/donatstudios.com\/Local-Certificate-On-macOS-Apache\" target=\"_blank\" rel=\"noopener noreferrer\">self-signed certificate<\/a> or a proper certificate authority\u2013issued certificate (<a href=\"https:\/\/certbot.eff.org\/instructions?ws=apache&#038;os=osx\" target=\"_blank\" rel=\"noopener noreferrer\">Let&#8217;s Encrypt<\/a> ones are free).<\/p>\n<p>Now that it&#8217;s configured, let&#8217;s test it out.<\/p>\n<p><code>sudo managedsoftwareupdate -v<\/code><\/p>\n<p>You should see something like this:<\/p>\n<p><code>Managed Software Update Tool<br \/>\nCopyright 2010-2018 The Munki Project<br \/>\nhttps:\/\/github.com\/munki\/munki<\/p>\n<p>Starting...<br \/>\nChecking for available updates...<br \/>\n    No client id specified. Requesting NAMEOFCOMPUTER.lan...<br \/>\n    Getting manifest NAMEOFCOMPUTER.lan...<br \/>\n    Retrieving list of software for this machine...<br \/>\n    Bytes received: 233<br \/>\n    Request failed. Trying NAMEOFCOMPUTER...<br \/>\n    Getting manifest NAMEOFCOMPUTER...<br \/>\n    Retrieving list of software for this machine...<br \/>\n    Bytes received: 229<br \/>\n    Request failed. Trying SERIALNUMBEROFCOMPUTER...<br \/>\n    Getting manifest SERIALNUMBEROFCOMPUTER...<br \/>\n    Retrieving list of software for this machine...<br \/>\n    Bytes received: 231<br \/>\n    Request failed. Trying <strong>site_default<\/strong>...<br \/>\n    Getting manifest <strong>site_default<\/strong>...<br \/>\n    Using manifest: <strong>site_default<\/strong><br \/>\n    Preventing idle sleep<br \/>\n    **Checking for installs**<br \/>\n    Getting catalog testing...<br \/>\n    **Checking for removals**<br \/>\n    **Checking for managed updates**<br \/>\n    Getting client resources...<br \/>\n    Bytes received: 242<br \/>\n    Getting client resources...<br \/>\n    Bytes received: 242<br \/>\n    No change in InstallInfo.<br \/>\n    Allowing idle sleep<br \/>\nFinishing...<br \/>\nDone.<\/code><\/p>\n<p>Just as Munki will try to guess the Munki repo (unless you specify it with SoftwareRepoURL), <a href=\"https:\/\/github.com\/munki\/munki\/wiki\/Default-Manifest-Resolution\" target=\"_blank\" rel=\"noopener noreferrer\">Munki will also try to guess what manifest you&#8217;re using (unless you specify one with ClientIdentifier)<\/a>. For greater flexibility, I would highly recommend <em>against<\/em> using a ClientIdentifier, unless you have a very good reason to do so. Until you can figure out how you want to structure your manifests, it&#8217;s best to start with just the <strong>site_default<\/strong> manifest you created earlier. That is the last manifest guess Munki makes. So if you later want to target machines more specifically, you can create a serial number manifest or a hostname manifest, which Munki will guess (and use) before even getting to <em>site_default<\/em>.<\/p>\n<p>Want to see what this would really look like to an end user (who probably won&#8217;t be running <em>managedsoftwareupdate<\/em> manually)?<\/p>\n<p>Go ahead and launch up <strong>\/Applications\/Managed Software Center.app<\/strong>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Now that you&#8217;ve set up a web server, put the Munki repo folders on it, installed Munki tools on it, imported an item into it, and set up a manifest for it, you can finally connect a Mac client to it. Good news! Since you installed all the Munki tools (not just the admin ones), [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[1],"tags":[],"class_list":["post-101","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"jetpack_shortlink":"https:\/\/wp.me\/paDrAJ-1D","jetpack_sharing_enabled":true,"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/www.alansiu.net\/munkiguide\/wp-json\/wp\/v2\/posts\/101","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.alansiu.net\/munkiguide\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.alansiu.net\/munkiguide\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.alansiu.net\/munkiguide\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.alansiu.net\/munkiguide\/wp-json\/wp\/v2\/comments?post=101"}],"version-history":[{"count":21,"href":"https:\/\/www.alansiu.net\/munkiguide\/wp-json\/wp\/v2\/posts\/101\/revisions"}],"predecessor-version":[{"id":522,"href":"https:\/\/www.alansiu.net\/munkiguide\/wp-json\/wp\/v2\/posts\/101\/revisions\/522"}],"wp:attachment":[{"href":"https:\/\/www.alansiu.net\/munkiguide\/wp-json\/wp\/v2\/media?parent=101"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.alansiu.net\/munkiguide\/wp-json\/wp\/v2\/categories?post=101"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.alansiu.net\/munkiguide\/wp-json\/wp\/v2\/tags?post=101"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}