Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
80 commits
Select commit Hold shift + click to select a range
e7b88f9
Dogfood: teams => "fleets" and queries => "reports"
mikermcneil Feb 5, 2026
457c9b8
Merge branch 'main' into after-testing-backwards-compat-dogfood-gets-…
mikermcneil Feb 5, 2026
19d1e04
Update company-owned-mobile-devices.yml
mikermcneil Feb 6, 2026
8981204
fleet_settings => settings
mikermcneil Feb 6, 2026
5a45cc2
Update default.yml
mikermcneil Feb 11, 2026
7700b7a
Create README.md
mikermcneil Feb 11, 2026
ce11309
Merge branch 'main' into after-testing-backwards-compat-dogfood-gets-…
mikermcneil Feb 11, 2026
b8f9f40
Merge branch 'main' into after-testing-backwards-compat-dogfood-gets-…
mikermcneil Feb 13, 2026
4bae51f
Update vision and add some TODOs for _AFTER_ we ship the ontological …
mikermcneil Feb 13, 2026
e161d37
add tvos
mikermcneil Feb 13, 2026
fef044d
Update README.md
mikermcneil Feb 13, 2026
f546ce3
add placeholder generator that simulates `fleetctl new`
mikermcneil Feb 13, 2026
44d6aa0
fix bugs
mikermcneil Feb 13, 2026
98eb1fa
remove accidentally checked-in generator output
mikermcneil Feb 13, 2026
4fe3646
Merge branch 'after-testing-backwards-compat-dogfood-gets-updated' of…
mikermcneil Feb 13, 2026
551ac5a
make it spit out the complete tree
mikermcneil Feb 13, 2026
20c8b7b
yolo
mikermcneil Feb 13, 2026
b8fee00
Merge branch 'main' into after-testing-backwards-compat-dogfood-gets-…
mikermcneil Feb 13, 2026
1d12785
Update gitignore template to include Icon
allenhouchins Feb 13, 2026
9a40620
Update index.js
mikermcneil Feb 18, 2026
edce329
Merge branch 'after-testing-backwards-compat-dogfood-gets-updated' of…
mikermcneil Feb 18, 2026
da6b03f
Merge branch 'main' into after-testing-backwards-compat-dogfood-gets-…
mikermcneil Feb 18, 2026
fb588be
Bring in actual github action files and update them to use "fleets" r…
mikermcneil Feb 19, 2026
ae2d033
bring over bits of .yml from dogfood
mikermcneil Feb 19, 2026
789a24f
Stub everything out, bringing in bits from dogfood
mikermcneil Feb 19, 2026
a19e9f3
use existing working doc URLs for now, rather than aspirational doc URLs
mikermcneil Feb 19, 2026
4cbc772
more finangling
mikermcneil Feb 20, 2026
0f20b1a
Update boilerplate based on convo w/ Allen yesterday
mikermcneil Feb 20, 2026
e5fddb4
turn on gitops mode automatically when generating from fleetctl new
mikermcneil Feb 20, 2026
326cd91
trivial
mikermcneil Feb 20, 2026
6fd4d4e
fix copypasta
mikermcneil Feb 20, 2026
b999300
Merge branch 'main' into after-testing-backwards-compat-dogfood-gets-…
mikermcneil Feb 20, 2026
7840b38
fix indentation
mikermcneil Feb 20, 2026
234af73
rename fleet manifest + minor text fixe
mikermcneil Feb 20, 2026
2d1e510
Remove unnecessary secrets
mikermcneil Feb 20, 2026
396fcec
fix generator and add testing instructions
mikermcneil Feb 20, 2026
5b17ec5
add TODO about lingering decision
mikermcneil Feb 20, 2026
0dd13f1
Update README.md
mikermcneil Feb 20, 2026
e9b03f4
Update README.md
mikermcneil Feb 20, 2026
6cc47bc
Update README.md
mikermcneil Feb 20, 2026
7510580
Update README.md
mikermcneil Feb 21, 2026
2debc0f
Update README.md
mikermcneil Feb 21, 2026
19b6f0f
Update README.md
mikermcneil Feb 21, 2026
3f6bc06
Update README.md
mikermcneil Feb 21, 2026
49b64eb
Merge branch 'main' into after-testing-backwards-compat-dogfood-gets-…
mikermcneil Feb 22, 2026
bde54e5
outline and prioritize sprint
mikermcneil Feb 22, 2026
6251eea
Fill in missing priorities
mikermcneil Feb 22, 2026
bb637ef
a few more I missed
mikermcneil Feb 22, 2026
38162be
... a bit more
mikermcneil Feb 22, 2026
03e221a
a bit further ahead
mikermcneil Feb 22, 2026
6dec6d1
a few other pieces I missed
mikermcneil Feb 22, 2026
4f2c6b3
Update README.md
mikermcneil Feb 23, 2026
a8bfcff
Update README.md
mikermcneil Feb 23, 2026
7e925fb
Update README.md
mikermcneil Feb 25, 2026
c93fc4f
Update README.md
mikermcneil Feb 26, 2026
55ac08e
Update README.md
mikermcneil Feb 26, 2026
2eef3ee
Merge branch 'main' into after-testing-backwards-compat-dogfood-gets-…
mikermcneil Feb 27, 2026
e0743f3
Update CODEOWNERS
mikermcneil Feb 27, 2026
675f2a4
enable `paths` glob
mikermcneil Feb 27, 2026
2b139b6
Merge branch 'after-testing-backwards-compat-dogfood-gets-updated' of…
mikermcneil Feb 27, 2026
9db865c
Update custom.js
mikermcneil Feb 27, 2026
7115edd
Merge branch 'main' into after-testing-backwards-compat-dogfood-gets-…
mikermcneil Mar 2, 2026
a034f4c
revert it-and-security folder to latest from main
mikermcneil Mar 2, 2026
703c125
about halfway done w/ default.yml
mikermcneil Mar 2, 2026
d143300
First complete pass at the "platonic"/minimally viable default.yml
mikermcneil Mar 2, 2026
4d9cfb4
further trimming
mikermcneil Mar 2, 2026
0f21b31
trivial
mikermcneil Mar 2, 2026
f331d91
trivial
mikermcneil Mar 2, 2026
5b1c36c
more exposition, cleaned out a comment
mikermcneil Mar 2, 2026
c33dedf
trivial
mikermcneil Mar 2, 2026
09bc59a
Merge branch 'main' into after-testing-backwards-compat-dogfood-gets-…
mikermcneil Mar 2, 2026
f36aebe
more fixes and cleanup
mikermcneil Mar 2, 2026
44717c4
lay out the path forward and remove more outdated comments
mikermcneil Mar 2, 2026
b36f3ac
More cleanup
mikermcneil Mar 2, 2026
301eff2
trivial
mikermcneil Mar 2, 2026
753e504
More improvements and decisions
mikermcneil Mar 2, 2026
772706d
first pass through complete boilerplate for workstations and BYOD fleets
mikermcneil Mar 3, 2026
e7a3517
do away with employee-issued mobile fleet
mikermcneil Mar 3, 2026
50aff03
Merge branch 'main' into after-testing-backwards-compat-dogfood-gets-…
mikermcneil Mar 3, 2026
7ee0bcc
decisions from meeting w/ harry and allen
mikermcneil Mar 3, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 0 additions & 6 deletions CODEOWNERS
Original file line number Diff line number Diff line change
Expand Up @@ -138,12 +138,6 @@ go.mod @fleetdm/go
##############################################################################################
#/.github/ISSUE_TEMPLATE @mikermcneil @sampfluger88 @lukeheath # Covered in custom.js See https://github.com/fleetdm/fleet/pull/18668


##############################################################################################
# 🌐 Fleet website
##############################################################################################
/website/.sailsrc @eashaw # Note: eashaw will not approve any PR that changes this file. This codeowner exists to make sure no changes are committed to the repo.

##############################################################################################
# 🌐 GitHub workflows
##############################################################################################
Expand Down
3 changes: 2 additions & 1 deletion website/.sailsrc
Original file line number Diff line number Diff line change
@@ -1,7 +1,8 @@
{
"generators": {
"modules": {
"landing-page": "./generators/landing-page"
"landing-page": "./generators/landing-page",
"gitops": "./generators/gitops"
}
},
"_generatedWith": {
Expand Down
3 changes: 2 additions & 1 deletion website/config/custom.js
Original file line number Diff line number Diff line change
Expand Up @@ -148,7 +148,8 @@ module.exports.custom = {
'website/config': 'eashaw',
'website/config/routes.js': 'eashaw',//« Website redirects and URLs
'website/scripts': 'eashaw',
'website/package.json': 'eashaw',
'website/package.json': 'eashaw',// « This is where new website dependencies get added
'website/.sailsrc': 'eashaw', // «This gets changed automatically when docs are compiled, so it's easy to accidentally check in changes that shouldn't be checked in.

// 🫧 Vulnerability dashboard
'ee/vulnerability-dashboard': 'eashaw',// (catch-all)
Expand Down
7 changes: 7 additions & 0 deletions website/generators/gitops/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
To test:

`cd website/`

Then:

`rm -rf /tmp/it-and-security/ && sails generate gitops && mv it-and-security /tmp/it-and-security && subl /tmp/it-and-security/`
93 changes: 93 additions & 0 deletions website/generators/gitops/index.js
Original file line number Diff line number Diff line change
@@ -0,0 +1,93 @@
module.exports = {

targets: {

'./it-and-security/README.md': { copy: './README.md.template' },
'./it-and-security/.github': { folder: {} },
'./it-and-security/.github/fleet-gitops': { folder: {} },
'./it-and-security/.github/fleet-gitops/action.yml': { copy: './github/fleet-gitops/action.yml.template' },
'./it-and-security/.github/fleet-gitops/gitops.sh': { copy: './github/fleet-gitops/gitops.sh.template' },
'./it-and-security/.github/workflows': { folder: {} },
'./it-and-security/.github/workflows/fleet-gitops-workflow.yml': { copy: './github/workflows/fleet-gitops-workflow.yml.template' },
'./it-and-security/.gitlab-ci.yml': { copy: './gitlab-ci.yml.template' },
'./it-and-security/.gitignore': { copy: './gitignore.template' },
'./it-and-security/default.yml': { copy: './default.yml.template' },
'./it-and-security/fleets/': { folder: {} },
'./it-and-security/fleets/workstations.yml': { copy: './fleets/workstations.yml.template' },
'./it-and-security/fleets/personal-mobile-devices.yml': { copy: './fleets/personal-mobile-devices.yml.template' },
'./it-and-security/labels/': { folder: {} },
'./it-and-security/labels/apple-silicon-macos-hosts.yml': { copy: './labels/apple-silicon-macos-hosts.yml.template' },
'./it-and-security/labels/x86-based-windows-hosts.yml': { copy: './labels/x86-based-windows-hosts.yml.template' },
'./it-and-security/labels/arm-based-windows-hosts.yml': { copy: './labels/arm-based-windows-hosts.yml.template' },
'./it-and-security/labels/debian-based-linux-hosts.yml': { copy: './labels/debian-based-linux-hosts.yml.template' },
'./it-and-security/platforms/': { folder: {} },
'./it-and-security/platforms/linux': { folder: {} },
'./it-and-security/platforms/linux/policies/.gitkeep': { copy: './gitkeep.template' },
'./it-and-security/platforms/linux/reports/.gitkeep': { copy: './gitkeep.template' },
'./it-and-security/platforms/linux/scripts/.gitkeep': { copy: './gitkeep.template' },
'./it-and-security/platforms/linux/software/.gitkeep': { copy: './gitkeep.template' },
'./it-and-security/platforms/windows': { folder: {} },
'./it-and-security/platforms/windows/configuration-profiles/.gitkeep': { copy: './gitkeep.template' },
'./it-and-security/platforms/windows/policies/.gitkeep': { copy: './gitkeep.template' },
'./it-and-security/platforms/windows/reports/.gitkeep': { copy: './gitkeep.template' },
'./it-and-security/platforms/windows/scripts/.gitkeep': { copy: './gitkeep.template' },
'./it-and-security/platforms/windows/software/.gitkeep': { copy: './gitkeep.template' },
'./it-and-security/platforms/macos': { folder: {} },
'./it-and-security/platforms/macos/configuration-profiles/.gitkeep': { copy: './gitkeep.template' },
'./it-and-security/platforms/macos/declaration-profiles/.gitkeep': { copy: './gitkeep.template' },
'./it-and-security/platforms/macos/enrollment-profiles/.gitkeep': { copy: './gitkeep.template' },
'./it-and-security/platforms/macos/enrollment-profiles/automatic-enrollment.dep.json': { copy: './platforms/macos/enrollment-profiles/automatic-enrollment.dep.json.template' },
'./it-and-security/platforms/macos/commands/.gitkeep': { copy: './gitkeep.template' },
'./it-and-security/platforms/macos/policies/.gitkeep': { copy: './gitkeep.template' },
'./it-and-security/platforms/macos/policies/all-software-updates-installed.yml': { copy: './platforms/macos/policies/all-software-updates-installed.yml' },
'./it-and-security/platforms/macos/reports/.gitkeep': { copy: './gitkeep.template' },
'./it-and-security/platforms/macos/scripts/.gitkeep': { copy: './gitkeep.template' },
'./it-and-security/platforms/macos/software/.gitkeep': { copy: './gitkeep.template' },
'./it-and-security/platforms/ios': { folder: {} },
'./it-and-security/platforms/ios/configuration-profiles/.gitkeep': { copy: './gitkeep.template' },
'./it-and-security/platforms/ios/declaration-profiles/.gitkeep': { copy: './gitkeep.template' },
'./it-and-security/platforms/ipados': { folder: {} },
'./it-and-security/platforms/ipados/configuration-profiles/.gitkeep': { copy: './gitkeep.template' },
'./it-and-security/platforms/ipados/declaration-profiles/.gitkeep': { copy: './gitkeep.template' },
// './it-and-security/platforms/tvos': { folder: {} },
// './it-and-security/platforms/tvos/configuration-profiles/.gitkeep': { copy: './gitkeep.template' },
'./it-and-security/platforms/android': { folder: {} },
'./it-and-security/platforms/android/configuration-profiles/.gitkeep': { copy: './gitkeep.template' },
'./it-and-security/platforms/android/managed-app-configurations/.gitkeep': { copy: './gitkeep.template' },
'./it-and-security/platforms/all/': { folder: {} },
'./it-and-security/platforms/all/icons/.gitkeep': { copy: './gitkeep.template' },
'./it-and-security/platforms/all/reports/.gitkeep': { copy: './gitkeep.template' },
'./it-and-security/platforms/all/policies/.gitkeep': { copy: './gitkeep.template' },

// - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
// • e.g. create a folder:
// ```
// './hey_look_a_folder': { folder: {} }
// ```
//
// • e.g. create a dynamically-named file relative to `scope.rootPath`
// (defined by the `filename` scope variable).
//
// The `template` helper reads the specified template, making the
// entire scope available to it (uses underscore/JST/ejs syntax).
// Then the file is copied into the specified destination (on the left).
// ```
// './:filename': { template: 'example.template.js' },
// ```
//
// • See https://sailsjs.com/docs/concepts/extending-sails/generators for more documentation.
// (Or visit https://sailsjs.com/support and talk to a maintainer of a core or community generator.)
// - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

},


/**
* The absolute path to the `templates` for this generator
* (for use with the `template` and `copy` builtins)
*
* @type {String}
*/
templatesDirectory: require('path').resolve(__dirname, './templates')

};
1 change: 1 addition & 0 deletions website/generators/gitops/templates/README.md.template
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
TODO
138 changes: 138 additions & 0 deletions website/generators/gitops/templates/default.yml.template
Original file line number Diff line number Diff line change
@@ -0,0 +1,138 @@
# # # # # # # # # # # # # # # # # # # # # # # # # # # # # #
#
# default.yml
#
# Use this global manifest (`default.yml`) to configure
# top-level settings for your organization as a whole, and
# controls/reports/etc that apply to all of your fleets.
#
# To see all supported options, check out:
# • https://fleetdm.com/docs/configuration/yaml-files
#
# # # # # # # # # # # # # # # # # # # # # # # # # # # # # #

org_settings:
org_info:
###########################################################
# The name of your organization is displayed to end users
# during the setup experience for new hardware, and to admins
# in the Fleet UI.
#
# Read more:
# • https://fleetdm.com/docs/configuration/yaml-files#org-info
###########################################################
org_name: "My organization"
# ^TODO: Replace with the name of your organization

server_settings:
###########################################################
# The server URL where Fleet is running.
#
# • No trailing slash at the end
# • `http://` or `https://` at the beginning.
#
# (You can copy this from the URL bar in your browser.)
#
# Warning: Careful not to change this URL after enrolling
# Apple devices with MDM pointed at Fleet. If this URL changes
# and Apple hosts already have MDM turned on, then end users
# will have to take action to restore MDM functionality (due
# to the way Apple's device management protocol works.)
###########################################################
server_url: "https://fleet.example.com"
# ^TODO: Replace with the URL where Fleet is running.

###########################################################
# Uncomment to use single sign-on (SSO) for admins accessing Fleet.
#
# Read more:
# • https://fleetdm.com/docs/configuration/yaml-files#sso-settings
# • https://fleetdm.com/docs/deploy/single-sign-on-sso
###########################################################
# sso_settings:
# idp_name: "Okta" # e.g. "Entra", "Okta", "Google Workspace", etc. (This appears to admins on the login screen as a "Sign in with ________" button.)
# metadata_url: "https://okta.com/replace-this-url" # This must exactly match the "IdP metadata URL" provided by your identity provider (IdP) when setting up this integration.
# entity_id: "fleet-admins" # This must exactly match the "Entity ID" field you chose when setting up this integration in your identity provider (IdP).

mdm:
###########################################################
# Uncomment to use single-sign on (SSO) to authenticate
# new computers enrolling in Fleet during end user setup.
#
# Read more:
# • https://fleetdm.com/docs/configuration/yaml-files#end-user-authentication
# • https://fleetdm.com/guides/setup-experience#end-user-authentication
###########################################################
# end_user_authentication:
# idp_name: "Okta" e.g. "Entra", "Okta", "Google Workspace", etc. (Displayed to end users.)
# metadata_url: "https://okta.com/replace-this-url" # This must exactly match the "IdP metadata URL" provided by your identity provider (IdP) when setting up this integration.
# entity_id: "fleet-end-users" # This must exactly match the "Entity ID" field you chose when setting up this integration in your identity provider (IdP).

###########################################################
# Uncomment when you are ready to start using zero-touch enrollment
# for Apple devices via Apple Business Manager (ABM).
#
# Read more:
# • https://fleetdm.com/docs/configuration/yaml-files#apple-business-manager
# • https://fleetdm.com/guides/apple-mdm-setup#apple-business-manager-abm
###########################################################
# apple_business_manager:
# - macos_fleet: "💻 Workstations" # Where new macOS devices from ABM will appear

###########################################################
# Uncomment to start using Apple's volume purchase program (VPP)
# for making software available from the App Store and managing
# software licenses.
#
# Read more:
# • https://fleetdm.com/docs/configuration/yaml-files#volume-purchasing-program
# • https://fleetdm.com/guides/apple-mdm-setup#volume-purchasing-program-vpp
###########################################################
# volume_purchasing_program:
# - fleets:
# - "💻 Workstations"
# - "📱🔐 Personal mobile devices"

controls:
###########################################################
# Uncomment when you are ready to migrate Macs to Fleet
# from a different MDM server, especially devices running
# macOS ≤v26.
#
# For more information about what this does, see:
# • https://fleetdm.com/docs/configuration/yaml-files#macos-migration
# • https://fleetdm.com/guides/mdm-migration#end-user-workflow
#
# Note: This is a global setting that cannot be applied per-fleet.
###########################################################
# macos_migration:
# enable: true
# mode: voluntary # Start with "voluntary", then change this to "forced" closer to the deadline.
# webhook_url: "https://your-custom-webhook-or-one-provided-off-the-shelf-by-fleet-for-the-mdm-you-are-coming-from.example.com/webhooks/receive-from-fleet"
# # ^ When end users click "Migrate to Fleet", this webhook is triggered.
# # By convention it looks up the device and unmanages it in the old MDM,
# # then enrolls the device in Fleet. Unsure? Get help @ fleetdm.com/support.


###########################################################
# Labels are static or dynamic groupings of computers for
# scoping, reporting, and more. Use labels for everything
# from "x86 macs" to "finance department" to "needs new battery".
#
# For more, see:
# • https://fleetdm.com/docs/configuration/yaml-files#labels
# • https://fleetdm.com/guides/managing-labels-in-fleet
#
# (Optional) You can choose to manage labels in the Fleet GUI
# instead of in your git repo by **commenting out** `labels`
# below and removing the `labels/` folder.
#
# > Note: If you exclude `labels` from your git repo, then any
# > AI-assisted tools you may be using like Claude/Copilot/Kilocode
# > won't be able to see them as easily for use in scoping,
# > and could make it harder to do prompts like, for example:
# > "Make sure everyone in finance has the latest version of Excel"
###########################################################
labels:
- paths: ./labels/*.yml

Original file line number Diff line number Diff line change
@@ -0,0 +1,109 @@
# # # # # # # # # # # # # # # # # # # # # # # # # # # # # #
#
# personal-mobile-devices.yml
#
# Use this fleet manifest to configure controls, software,
# and settings that apply only to computing devices (hosts)
# in this particular fleet.
#
# > Note: By convention, the "📱🔐 Personal mobile devices"
# > fleet is where employee-owned iPhone and Android phones
# > are enrolled, for example as part of a BYOD ("bring your
# > own device") program. This allows for clear separation
# > and encourages employee freedom and privacy.
#
# To see all supported options, check out:
# • https://fleetdm.com/docs/configuration/yaml-files
#
# # # # # # # # # # # # # # # # # # # # # # # # # # # # # #
name: "📱🔐 Personal mobile devices"
controls:
apple_setup:
###########################################################
# Uncomment to use single-sign on (SSO) to authenticate
# end users enrolling their personal device.
#
# Read more:
# • https://fleetdm.com/docs/configuration/yaml-files#end-user-authentication
# • https://fleetdm.com/guides/setup-experience#end-user-authentication
###########################################################
# enable_end_user_authentication: true

###########################################################
# Presets, restrictions, and configs
#
# > Since the mobile devices in this fleet are personal
# > devices owned by employees, it can be appropriate to
# > cherry-pick only a very limited set of restrictions
# > and presets to maximize privacy and employee freedom.
#
# For more, see:
# • https://fleetdm.com/docs/configuration/yaml-files#apple-settings-and-windows-settings
# • https://fleetdm.com/docs/configuration/yaml-files#android-settings
###########################################################
apple_settings:
profiles:
# … e.g.
# - path: ../lib/ios/declaration-profiles/Passcode settings.json
# - path: ../lib/ios/configuration-profiles/self-service.mobileconfig
android_settings:
profiles:
certificates:

###########################################################
# Managed OS updates
#
# To enable and enforce managed OS updates on iOS/iPadOS,
# uncomment `ios_updates` and `ipados_updates`.
#
# See also:
# • https://fleetdm.com/docs/configuration/yaml-files#ios-updates
# • https://fleetdm.com/docs/configuration/yaml-files#ipados-updates
# • https://fleetdm.com/guides/enforce-os-updates#apple-macos-ios-and-ipados-end-user-experience
###########################################################
# ios_updates:
# deadline: "2030-04-01"
# minimum_version: "18.5"
# ipados_updates:
# deadline: "2030-04-01"
# minimum_version: "18.5"

###########################################################
# Apps to make available from the Apple App Store or Google Play
###########################################################
software:
app_store_apps:
###########################################################
# iOS apps
###########################################################
# …
# - app_store_id: "618783545" # Slack
# display_name: "Slack"
# self_service: true
# setup_experience: true
# platform: ios
# categories:
# - "Communication"

###########################################################
# iPadOS apps
###########################################################
# …
# - app_store_id: "618783545" # Slack
# display_name: "Slack"
# self_service: true
# setup_experience: true
# platform: ipados
# categories:
# - "Productivity"
# - "Communication"

###########################################################
# Android apps
###########################################################
# …
# - app_store_id: "com.Slack" # Slack
# platform: android
# display_name: "Slack"
# self_service: true
# setup_experience: true
Loading
Loading