# Enforce single distro on device without differing device type

**URL:** <https://hub.mender.io/t/enforce-single-distro-on-device-without-differing-device-type/4925>\
**Category:** General Discussions\
**Tags:** yocto\
**Created:** [May 4, 2022, 3:34pm UTC](https://hub.mender.io/t/enforce-single-distro-on-device-without-differing-device-type/4925 "2022-05-04T15:34:07Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![logbaseaofn](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/logbaseaofn/32/1323_2.png) [@logbaseaofn](https://hub.mender.io/u/logbaseaofn)\
**Post date:** [May 4, 2022, 3:34pm UTC](https://hub.mender.io/t/enforce-single-distro-on-device-without-differing-device-type/4925/1 "2022-05-04T15:34:07Z")

</div>

Hi,

I have a question about how to use some of the device type/artifact constructs. I have two devices with identical hardware and therefore share the same device type. I want to lock one machine to only get artifacts which satisfy certain conditions. For example, Device A has Distro X and should only ever get versions of Distro X, while Device B has Distro Y and should only ever get versions of Distro Y. Is there a way I can enforce this? Is it desirable to make them different device types even though they have the same hardware, or is there some sort of thing I can check before the “artifact install” state which I can check to block undesired behavior?

---

<div class="post-metadata">

**Author:** ![TheYoctoJester](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/theyoctojester/32/1444_2.png) [@TheYoctoJester](https://hub.mender.io/u/TheYoctoJester)\
**Post date:** [May 4, 2022, 3:41pm UTC](https://hub.mender.io/t/enforce-single-distro-on-device-without-differing-device-type/4925/2 "2022-05-04T15:41:04Z")

</div>

Hi @logbaseaofn,

This is possible by using device groups. If you want to match on a specific attribute this would require the dynamic grouping feature, which is only available on the Professional and Enterprise plans.

Let me know if I can help you with anything else!

Greetz,  
Josef

---

<div class="post-metadata">

**Author:** ![logbaseaofn](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/logbaseaofn/32/1323_2.png) [@logbaseaofn](https://hub.mender.io/u/logbaseaofn)\
**Post date:** [May 4, 2022, 3:54pm UTC](https://hub.mender.io/t/enforce-single-distro-on-device-without-differing-device-type/4925/3 "2022-05-04T15:54:52Z")

</div>

Hi, @TheYoctoJester

I am currently an enterprise customer. I am looking for a way to enforce on the device since we offer the ability to update over USB which just installs a given mender artifact.

---

<div class="post-metadata">

**Author:** ![lramirez](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/lramirez/32/1195_2.png) [@lramirez](https://hub.mender.io/u/lramirez)\
**Post date:** [May 4, 2022, 8:17pm UTC](https://hub.mender.io/t/enforce-single-distro-on-device-without-differing-device-type/4925/5 "2022-05-04T20:17:02Z")

</div>

Hi @logbaseaofn,

> [@logbaseaofn](#):
>
> Is it desirable to make them different device types even though they have the same hardware

I think this is the best approach. Despite using the same hardware, they count as different devices for your business model. If you need to target both devices (for example, any security patch), it will be as easy as making the artifact compatible with both devices.

For example, if you create an artifact containing only some text files, it will probably be compatible with any architecture. Still, if you require to make sure it reaches only one specific type of device, you should make it “compatible” only with this device at the artifact level. This is because the `device` concept in Mender is related not only to real hardware but also to your business needs.

A second option is to use State Scripts to check what distro you are running and abort the installation if needed; however, if you are OK with using two “types” of devices, then that option is more straightforward and involves less over-engineering.

---

<div class="post-metadata">

**Author:** ![logbaseaofn](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/logbaseaofn/32/1323_2.png) [@logbaseaofn](https://hub.mender.io/u/logbaseaofn)\
**Post date:** [May 5, 2022, 10:40pm UTC](https://hub.mender.io/t/enforce-single-distro-on-device-without-differing-device-type/4925/6 "2022-05-05T22:40:37Z")

</div>

Hi, @Iramirez

This sounds good. I will speak with my colleagues on how we can best implement this. I assume if we wanted to over-engineer it, before reboot the new rootfs is on the inactive partition so I can just mount it and do any checks like that? I agree that having different device types may be the way to go. Is there any supported way of changing device types of devices in the field? Or is that something we have to hack into an update?

---

<div class="post-metadata">

**Author:** ![oleorhagen](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/oleorhagen/32/297_2.png) [@oleorhagen](https://hub.mender.io/u/oleorhagen)\
**Post date:** [May 16, 2022, 6:17am UTC](https://hub.mender.io/t/enforce-single-distro-on-device-without-differing-device-type/4925/7 "2022-05-16T06:17:06Z")

</div>

@logbaseaofn perhaps [this](https://docs.mender.io/development/overview/artifact#provides-and-depends) is interesting to you as well? 🙂

---

<div class="post-metadata">

**Author:** ![logbaseaofn](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/logbaseaofn/32/1323_2.png) [@logbaseaofn](https://hub.mender.io/u/logbaseaofn)\
**Post date:** [July 14, 2022, 6:45pm UTC](https://hub.mender.io/t/enforce-single-distro-on-device-without-differing-device-type/4925/8 "2022-07-14T18:45:17Z")

</div>

This could certainly work if an artifact can provide multiple things - then I could provide some sort of identifier which can be depended upon for the distro-specific artifacts. I’ll look into it more as soon as I am able. Good find, thank you!
