Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

Bor

Open-source policy management for Linux desktops

Details

External ID
49142569
Source
HN
Company
—
Product
Bor
Website domain
getbor.dev
Launched
Aug. 2, 2026
Cohort
—
Upvotes
197
Upvotes percentile
0.9704301075268817
Tags
—
Fetched at
Sept. 10, 2026, 5:32 a.m.
Updated at
Sept. 10, 2026, 5:32 a.m.

Description

Hi HN! I've been working on Bor, an open-source system for centralized Linux desktop management.Bor consists of a lightweight Go agent and a central server. Policies are streamed to clients over mTLS/gRPC in real time—no polling—and currently support Firefox, Chrome, KDE, dconf, polkit and package management, with more coming.Version 0.8 introduces several new policy types - Thunderbird, Microsoft Edge for Business and FirewallD zones, along with a number of improvements and fixes.I'd love feedback on the architecture, policy model, and whether this is something you'd consider for managing Linux workstations.

Enrichment

Theme
systems tools and desktop utilities
Vertical
Security
Function
Compliance & governance
Audience
Developer
AI stance
Not AI
Project type
Hobby / open-source project
Normalized one-liner
policy management for linux desktops
Manually corrected
False

Could you build this?

No Enterprise-grade centralized Linux desktop policy management involves OS-level security daemons, polkit rules, dconf overrides, firewalld manipulation, mTLS streaming gRPC, and tamper protection against privilege escalation.

What it would actually take: Architecture requires a hardened Go agent running as root with systemd integration, inotify/eBPF-based tamper watchers, and a Go central server communicating over persistent bi-directional gRPC with mTLS. Enforcing desktop state requires deep subsystem integrations into PAM, Polkit, D-Bus, firewalld XML, Flatpak overrides, and browser policy engines across distributions. Demands Linux systems engineering and security architecture experience.

Discussion

20 comments analyzed.

Competitors mentioned: Wazuh, Ansible, Pyinfra, Samba group policy objects, SSSD

Concerns raised: Documentation needs improvement, Policy conflict handling unclear (two rules touching same resource), Non-domain single-user laptops LDAP enrollment path unclear, Package postinstall rewrites conflict with managed files during sync

Feature requests: SCAP support for enforcing DISA STIGs, Git support and unified import/export format for policies, Better documentation diagrams (Mermaid format), Wazuh integration for fleet governance, Content filtering/parental controls (DNS over HTTPS, adult content blocking)

Competitors

Other products that read as similar to this one — 56 launches clear the similarity bar, closest 8 shown.

Attention rank: #2 of 57 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 229 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a compliance & governance tool for Media & entertainment yet.