Policy management for Linux desktops

Define, distribute, and enforce desktop configuration policies across your fleet — in real time. Open source, secure by default, built for enterprise Linux.

Get Started

Bor — Policy Management
Bor Policy Management dashboard

    How it works

    A central server, lightweight agents, real-time streaming

    Centralized management

    Author and manage policies from a web console built with PatternFly. Organize nodes into groups and control access with RBAC.

    Real-time delivery

    Policies stream to agents over gRPC the moment they change. Delta sync minimizes bandwidth; snapshot fallback guarantees consistency.

    Secure by default

    mTLS with an auto-generated internal CA. One-time token enrollment. No shared secrets, no polling, no plaintext.

    Built for enterprise Linux

    Lightweight, native, and open source

    Zero-touch enrollment On domain-joined machines, agents enroll automatically using their Kerberos ticket — no tokens, no manual steps. For machines outside a domain, a short-lived one-time token generated from the web UI is used instead. Either way, mTLS certificates are exchanged automatically after the initial authentication and stored securely on the agent.

    Real-time policy delivery Policies reach every enrolled node the moment they are published. Persistent gRPC streams and delta sync keep bandwidth minimal and guarantee consistency — even across thousands of nodes or through network interruptions.

    Compliance without complexity Every policy change, authentication event, and enforcement action is recorded in a tamper-evident audit log. Built-in RBAC, LDAP/AD integration, and support for Kerberos and WebAuthn align access controls with your existing directory services — ready for compliance reviews out of the box.

    Simple to deploy and operate A single server binary backed by PostgreSQL, and a single lightweight agent. No message queues, no sidecars, no external dependencies. Install from a native package, manage with systemd — from zero to your first enrolled node in minutes.

    Supported policies

    What Bor can configure on your Linux desktops today

    Browsers & mail

    • Firefox

      Browser policies: updates, privacy, security, restrictions

    • Thunderbird

      Mail client policies: updates, privacy, security

    • Chrome Chrome and Chromium

      Browser policies for Google Chrome and Chromium

    • Microsoft Edge

      Browser policies for Microsoft Edge on Linux

    Desktop environment

    • KDE Plasma Kconfig

      Kiosk restrictions, System Settings lockdown, look and feel

    • Dconf

      Mandatory GSettings keys for GNOME and other dconf desktops

    System & security

    • Polkit

      Who may run privileged actions

    • Firewall firewalld

      Zone services, ports, rich rules and target

    • Session Access

      When users and groups may use the desktop

    • Package

      Repositories and packages to install or remove

    • Flatpak apps flatpak

      Remotes, apps and update settings for Flatpak

    Product marks are trademarks of their respective owners. Icons: Simple Icons (CC0) and Font Awesome Free (CC BY 4.0).