Commit Graph
965 Commits
Author SHA1 Message Date
Noah Talerman 2c5bbd8a09 End users w/ Stolen Device Protection will have to wait 1 hour before they can enroll their personal iPhone (#37007)
- @noahtalerman: Ran into this trying to enroll my personal iPhone to
Fleet. I was in SF (based in NYC)
2025-12-10 10:10:23 -05:00
Noah Talerman d87d07d8e8 Connect end users to Wi-Fi/VPN: Example Windows profile (#36993)
Based on learnings w/ `pingali`:
https://docs.google.com/document/d/11sFA_IbgwH4OHv8QBTiRRSx-9cP-CcbdPe5ZQkGeDKg/edit?tab=t.0
2025-12-10 10:08:59 -05:00
Mason Buettner dcc1e5454d Update installation instructions for fleetctl (#36351)
Removed sudo from npm install command and added guidance that it may be
required in specific scenarios.
2025-12-10 10:02:59 -05:00
Noah Talerman ee0fbd8a06 Windows and Linux setup experience (#36991)
Mention "bootstrap package" to help Mac admins, who are familiar with
the term, realize that they can install a bootstrap package when new
Windows workstations first boot
2025-12-10 14:43:37 +09:00
Steven Palmesano 360a98fd1a Fix broken link to dual-boot best practices (#36960) 2025-12-10 14:35:44 +09:00
Noah Talerman 4a4ac4380c What Android API endpoints to expose (#36983)
Context: We learned that `pingali` didn't have this API endpoint expose:
`/api/*/fleet/android_enterprise/enrollment_token/android_enterprise/enrollment_token`

We think this is preventing them from enrolling Android hosts.
2025-12-09 13:18:00 -08:00
Steven Palmesano 5b1f971df7 Correct capitalization of macOS (#36905) 2025-12-09 12:32:05 +09:00
Noah Talerman 6248d8e126 Fleet 4.77 release article: Okta conditional access is coming in 4.78 (#36668) 2025-12-08 17:14:45 -08:00
Mike Thomas 7fca0f8ae8 Update a-new-chapter-for-device-management.md (#36393)
- fixed faulty parallelism in the bullets, without changing the meaning.
("With Fleet, you can community driven" does not make sense.)
- changed the order of the bullets to balance the suggested change
better.
2025-12-09 10:01:28 +09:00
Rachael Shaw c7c8e722c9 Placeholder for Okta conditional access guide (#36722)
This creates a stub for the upcoming Okta conditional access feature
guide, and gets the redirects in place so QA can test the links.

<img width="1624" height="1060" alt="Screenshot 2025-12-04 at 5 27
17 PM"
src="https://github.com/user-attachments/assets/f277ac39-93da-4a28-a7a1-5a7998700e63"
/>
2025-12-05 09:55:03 -06:00
Steven Palmesano 820f6c85f0 Change note from footnote to blockquote (#36550)
Relates to https://github.com/fleetdm/fleet/issues/36195
2025-12-05 07:09:54 -06:00
6f632da279 Update uninstall documentation for fleetd (#36565)
Update the uninstall documentation for fleetd by providing detailed
steps for macOS, Windows, and Linux.

---------

Co-authored-by: Graham Williams <gray@live.co.uk>
Co-authored-by: Mike Thomas <78363703+mike-j-thomas@users.noreply.github.com>
2025-12-05 06:09:42 -05:00
gerardweese d8e25196ff Update fleetctl.md (#36640)
Correction of typo for example of  fleetctl user create --team argument
2025-12-05 17:42:42 +09:00
Steven Palmesano ac5cf2ef26 Hyphenate "brick-by-brick" for consistency (#36611)
The last instance is hyphenated, and I believe this is how we've been
using it internally.
2025-12-05 17:41:14 +09:00
Brock Walters 84de32d882 Fix typos and enhance clarity in Fleet documentation (#36471)
Corrected typos and improved clarity in the document.
2025-12-05 17:27:30 +09:00
Dale Ribeiro 37781911f6 Fix typo in Linux disk encryption documentation (#36719) 2025-12-05 17:24:32 +09:00
Magnus Jensen d681a52764 Remove extra info callout on Wi-Fi guide (#36675)
Removes an extra info callout

<img width="939" height="425" alt="image"
src="https://github.com/user-attachments/assets/c1057014-b5cd-4892-b517-2ec3b34f4f8a"
/>
2025-12-04 16:03:03 -06:00
Dale RibeiroandNoah Talerman 0d02ef6b1b Update Linux disk encryption documentation (#36705)
Clarify limitations of key escrowing for multiple user accounts.

---------

Co-authored-by: Noah Talerman <47070608+noahtalerman@users.noreply.github.com>
2025-12-04 16:02:39 -06:00
kitzy 58e254f1e4 Add Docker Compose deployment guide and configuration files (#36507)
- Add comprehensive Docker Compose deployment guide article
- Add docker-compose.yml with Fleet, MySQL, and Redis services
- Add env.example template with configuration options
- Include TLS setup options for both reverse proxy and direct TLS
- Add troubleshooting and production considerations

Resolves #33774
2025-12-04 12:11:59 -05:00
Marko Lisica 22b17f0d55 VPP apps supported only if available in US region (#36665)
Added a note about US region support for VPP apps.
2025-12-04 09:27:20 -05:00
Marko Lisica 34db806d56 Explain behavior of unmanaged profiles (#36416)
Related to:

- #34879
2025-12-03 18:25:02 -05:00
Noah Talerman afb8731e6c Release article: 4.77 (#36148) 2025-12-02 17:24:46 -06:00
+5 25191f3054 Preview of v4.77.0 doc changes (#35924)
This PR will remain in draft as a preview of upcoming documentation
changes for 4.77.0

---------

Co-authored-by: Marko Lisica <83164494+marko-lisica@users.noreply.github.com>
Co-authored-by: Noah Talerman <47070608+noahtalerman@users.noreply.github.com>
Co-authored-by: Victor Lyuboslavsky <2685025+getvictor@users.noreply.github.com>
Co-authored-by: Ian Littman <iansltx@gmail.com>
Co-authored-by: Noah Talerman <noahtal@umich.edu>
Co-authored-by: Lucas Manuel Rodriguez <lucas@fleetdm.com>
Co-authored-by: Magnus Jensen <magnus@fleetdm.com>
Co-authored-by: Jordan Montgomery <elijah.jordan.montgomery@gmail.com>
Co-authored-by: Janis Watts <184028114+jmwatts@users.noreply.github.com>
Co-authored-by: Allen Houchins <32207388+allenhouchins@users.noreply.github.com>
Co-authored-by: Gabriel Hernandez <ghernandez345@gmail.com>
Co-authored-by: Mike Thomas <78363703+mike-j-thomas@users.noreply.github.com>
Co-authored-by: Scott Gress <scottmgress@gmail.com>
Co-authored-by: Carlo <1778532+cdcme@users.noreply.github.com>
2025-12-02 17:24:15 -06:00
Magnus JensenandRachael Shaw e81c826368 Add missing Smallstep mention in Wi-Fi Article (#35345)
Adds missing Smallstep mention, updates title and SEO article title.

---------

Co-authored-by: Rachael Shaw <r@rachael.wtf>
2025-12-02 16:00:09 -06:00
Irena ReedyandMike Thomas a56cf9df49 Create the-mdm-mirgration-reality.md (#36353)
Co-authored-by: Mike Thomas <78363703+mike-j-thomas@users.noreply.github.com>
2025-12-02 10:06:12 -05:00
Lucas Manuel Rodriguez 924f0a6f52 Fix Entra conditional access integration docs (#36472) 2025-12-01 09:26:22 -05:00
Mason Buettner aa0581176f Clarify reporting of specific software configuration vulnerabilities (#36299)
Added note about reporting vulnerabilities that impact specific software
configurations.
2025-11-27 11:57:43 -05:00
Noah Talerman 847707fdac Revise quarterly roadmap blog post (#36154)
Some features are getting pushed to Q1 2026
2025-11-27 11:42:57 -05:00
Allen Houchins 46bdcaa6c0 Changing "macOS Setup Assistant" to "Setup Assistant" in frontend and guide (#36296)
We recently implemented this change:
https://github.com/fleetdm/fleet/pull/35782

I think it makes sense to capitalize Setup Assistant because it is a
proper noun. However, we should drop macOS from the name since the Setup
Assistant exists on iOS/iPadOS too and the skip panes functionality is
platform agnostic. Otherwise users may be confused on how they achieve
this on their iOS/iPadOS devices since this is so explicitly labeled as
macOS.
2025-11-27 08:16:00 -06:00
Mike Thomas 0d91b75c6e Create a-new-chapter-for-device-management.md (#36392)
Publish "A new chapter for device management" blog post.
2025-11-27 19:50:09 +09:00
Rachael Shaw a7177e466a Update permissions language about scripts (#36370)
For #28390
2025-11-26 16:52:30 -06:00
Brock Walters 4e099d233f Revise article to generalize company reference and improve text (#36322)
Updated the article to reflect the company as fintech giant. Made
various grammatical corrections and improved clarity throughout the
text.

@irenareedy @mike-j-thomas Please ensure that this gets approved
immediately so that Fleet can comply with the wishes of this company to
not be named in the case study article at this time. Thanks.
2025-11-26 20:02:10 +09:00
Ian Littman 52425ae20e Revert "Guide update: Self-service for iOS/iPadOS (#35767)" out of main (#36151)
This reverts commit 161cb89ae2, as it got
merged into `main` rather than the docs branch. PR against the correct
branch: #36150.
2025-11-24 11:29:55 -06:00
Michael Pinto 3762bdf451 Update role-based-access.md to include Linux in the list for "view di… (#36060)
…sk encryption"

<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

- [ ] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files)
for more information.

- [ ] Input data is properly validated, `SELECT *` is avoided, SQL
injection is prevented (using placeholders for values in statements)
- [ ] If paths of existing endpoints are modified without backwards
compatibility, checked the frontend/CLI for any necessary changes

## Testing

- [ ] Added/updated automated tests
- [ ] Where appropriate, [automated tests simulate multiple hosts and
test for host
isolation](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/patterns-backend.md#unit-testing)
(updates to one hosts's records do not affect another)

- [ ] QA'd all new/changed functionality manually

For unreleased bug fixes in a release candidate, one of:

- [ ] Confirmed that the fix is not expected to adversely impact load
test results
- [ ] Alerted the release DRI if additional load testing is needed

## Database migrations

- [ ] Checked schema for all modified table for columns that will
auto-update timestamps during migration.
- [ ] Confirmed that updating the timestamps is acceptable, and will not
cause unwanted side effects.
- [ ] Ensured the correct collation is explicitly set for character
columns (`COLLATE utf8mb4_unicode_ci`).

## New Fleet configuration settings

- [ ] Setting(s) is/are explicitly excluded from GitOps

If you didn't check the box above, follow this checklist for
GitOps-enabled settings:

- [ ] Verified that the setting is exported via `fleetctl
generate-gitops`
- [ ] Verified the setting is documented in a separate PR to [the GitOps
documentation](https://github.com/fleetdm/fleet/blob/main/docs/Configuration/yaml-files.md#L485)
- [ ] Verified that the setting is cleared on the server if it is not
supplied in a YAML file (or that it is documented as being optional)
- [ ] Verified that any relevant UI is disabled when GitOps mode is
enabled

## fleetd/orbit/Fleet Desktop

- [ ] Verified compatibility with the latest released version of Fleet
(see [Must
rule](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/workflows/fleetd-development-and-release-strategy.md))
- [ ] If the change applies to only one platform, confirmed that
`runtime.GOOS` is used as needed to isolate changes
- [ ] Verified that fleetd runs on macOS, Linux and Windows
- [ ] Verified auto-update works from the released version of component
to the new version (see [tools/tuf/test](../tools/tuf/test/README.md))
2025-11-21 06:49:20 -08:00
Dante Catalfamo d9e6bbf610 Update published date for fleet-goes-to-gophercon-2025.md (#33894) 2025-11-20 14:27:44 -05:00
Marko Lisica 9ceb47686e Document certificate minimum validtity period for automatic renewal (#35816) 2025-11-19 13:29:22 -08:00
Michael Pinto e7e0f29cac Fixing broken links in how-to-install-osquery-and-enroll-linux-device… (#35977)
…s-into-fleet.md

<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

- [ ] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files)
for more information.

- [ ] Input data is properly validated, `SELECT *` is avoided, SQL
injection is prevented (using placeholders for values in statements)
- [ ] If paths of existing endpoints are modified without backwards
compatibility, checked the frontend/CLI for any necessary changes

## Testing

- [ ] Added/updated automated tests
- [ ] Where appropriate, [automated tests simulate multiple hosts and
test for host
isolation](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/patterns-backend.md#unit-testing)
(updates to one hosts's records do not affect another)

- [ ] QA'd all new/changed functionality manually

For unreleased bug fixes in a release candidate, one of:

- [ ] Confirmed that the fix is not expected to adversely impact load
test results
- [ ] Alerted the release DRI if additional load testing is needed

## Database migrations

- [ ] Checked schema for all modified table for columns that will
auto-update timestamps during migration.
- [ ] Confirmed that updating the timestamps is acceptable, and will not
cause unwanted side effects.
- [ ] Ensured the correct collation is explicitly set for character
columns (`COLLATE utf8mb4_unicode_ci`).

## New Fleet configuration settings

- [ ] Setting(s) is/are explicitly excluded from GitOps

If you didn't check the box above, follow this checklist for
GitOps-enabled settings:

- [ ] Verified that the setting is exported via `fleetctl
generate-gitops`
- [ ] Verified the setting is documented in a separate PR to [the GitOps
documentation](https://github.com/fleetdm/fleet/blob/main/docs/Configuration/yaml-files.md#L485)
- [ ] Verified that the setting is cleared on the server if it is not
supplied in a YAML file (or that it is documented as being optional)
- [ ] Verified that any relevant UI is disabled when GitOps mode is
enabled

## fleetd/orbit/Fleet Desktop

- [ ] Verified compatibility with the latest released version of Fleet
(see [Must
rule](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/workflows/fleetd-development-and-release-strategy.md))
- [ ] If the change applies to only one platform, confirmed that
`runtime.GOOS` is used as needed to isolate changes
- [ ] Verified that fleetd runs on macOS, Linux and Windows
- [ ] Verified auto-update works from the released version of component
to the new version (see [tools/tuf/test](../tools/tuf/test/README.md))
2025-11-19 15:19:56 -06:00
161cb89ae2 Guide update: Self-service for iOS/iPadOS (#35767)
Fixes #35362

---------

Co-authored-by: Marko Lisica <83164494+marko-lisica@users.noreply.github.com>
Co-authored-by: Mike Thomas <78363703+mike-j-thomas@users.noreply.github.com>
2025-11-19 08:52:16 -05:00
Noah Talerman 6e635e7888 Delete Entra modal: Update instructions (#35874)
Deleting Microsoft Entra ID doesn't unblock end users. Instead, to
unblock, the IT admin has to disable the "Conditional Access" policy in
Entra.

Context: https://github.com/fleetdm/fleet/pull/35632/files#r2524534037
2025-11-18 06:45:24 -08:00
Jordan MontgomeryandNoah Talerman 98452d4827 [API/YAML] Docs for new setup experience script PUT endpoint (#35736)
API changes for #35309 

Also updates bug notes to call out fixed version.

Related PR #35651

---------

Co-authored-by: Noah Talerman <47070608+noahtalerman@users.noreply.github.com>
2025-11-14 17:47:34 -05:00
Irena ReedyandMike Thomas 83acd14d95 Article: when-icloud-backups-break-mdm-enrollment-md. (#35178)
For reference: https://github.com/fleetdm/confidential/issues/12351

---------

Co-authored-by: Mike Thomas <78363703+mike-j-thomas@users.noreply.github.com>
2025-11-14 12:16:34 -05:00
Noah Talerman e919ab53b0 Query reports: How to start collecting results again (#35716)
Context:
https://fleetdm.slack.com/archives/C019WG4GH0A/p1763056269172289?thread_ts=1762986256.339339&cid=C019WG4GH0A
2025-11-14 10:42:32 -05:00
Graham Williams 0b3f9bbe96 Update link for vulnerability processing documentation (#35262)
Updates broken link for vulnerability-processing.md
2025-11-13 08:38:08 +00:00
Noah TalermanandJordan Montgomery ad3f9f32c5 [Guide update] Which API endpoints to expose (#35061)
- iOS/iPadOS and Android hosts

---------

Co-authored-by: Jordan Montgomery <elijah.jordan.montgomery@gmail.com>
2025-11-12 15:39:47 -05:00
Mitch FranceseandBrock Walters 542e8ff259 Update links to example configuration profiles (#35420)
Fixing broken links in the article to point to absolute paths.

---------

Co-authored-by: Brock Walters <153771548+nonpunctual@users.noreply.github.com>
2025-11-12 15:08:18 -05:00
Noah Talerman 3904295c42 Fleet 4.76: Vulnerabilities (CVEs) are supported for Cursor, Windsurf, and VSCode-forks (#35634)
We learned that CVEs work:
https://github.com/fleetdm/fleet/issues/35523#issuecomment-3523047239
2025-11-12 13:56:42 -05:00
Noah Talerman 15703e9e6a Fleet 4.76: Santa tables came out in 4.75 (#35616) 2025-11-12 10:08:55 -06:00
Noah Talerman a85a66272d Enable scripts remotely w/o re-deploying fleetd (#33169)
- @noahtalerman: I think we can merge in this PR before we dogfood the
scripts ourselves. Dogfood request is here:
https://github.com/fleetdm/fleet/issues/33170

---

- @noahtalerman: `customer-montague` was frustrated that they had to
re-deploy fleetd to enable scripts. At organizations that have a
third-party tool that can run scripts (other than Fleet), this is
avoidable! We want to document how to enable scripts remotely w/o
re-deploying fleetd.

More context:
https://github.com/fleetdm/fleet/issues/29193#issuecomment-3137337041
2025-11-12 10:39:48 -05:00
Noah Talerman 22e6dcd5e2 Update roadmap preview (#35019)
This fall, Fleet is also working on first-time setup for iOS/iPadOS and
Android:
- https://github.com/fleetdm/fleet/issues/34042
- https://github.com/fleetdm/fleet/issues/30890
- https://github.com/fleetdm/fleet/issues/33761
2025-11-12 12:05:03 +01:00
Noah Talerman d02add03c0 [Guide update] Wi-Fi/VPN certificates (#35490)
- As of Fleet 4.76, automatic renewal is Apple only
- If validity is less than 30 days, auto renewal happens at half the
validity period
2025-11-11 17:57:28 -05:00