Commit Graph
85 Commits
Author SHA1 Message Date
Noah Talerman 467c5c4c44 DDM passcode cleanup (#22574)
- Remove configuration profile (.mobileconfig) now that Fleet is using
the DDM profile
- Remove duplicate DDM profile: passcode-settings-ddm.json
2024-10-02 17:07:46 -04:00
Rachael Shaw 00d31e8450 Update linux-device-health.policies.yml (#22516)
See https://github.com/fleetdm/fleet/pull/22498
2024-10-01 15:39:00 -05:00
Brock Walters cfd4159487 Update macos-passcode-settings.json (#22533)
Cuz JD is dum.
2024-10-01 05:50:30 -07:00
Brock Walters 3f249fd11b Nonpunctual passcode ddm (#22531)
# Checklist for submitter

Adds passcode DDM declaration to workstations.
2024-10-01 05:25:59 -07:00
Lucas Manuel Rodriguez 8428f193fa Move settings to no-team.yml (#22343)
Moving settings for hosts in "No team" from `default.yml` to
`teams/no-team.yml`.
2024-09-24 14:25:51 -03:00
Dave Herder 1fdd127f6c Add macOS policies for patching in workstations-canary.yml (#22323) 2024-09-23 14:17:39 -07:00
Noah Talerman eeb0579763 Dogfood: remove "Explore data (fleetdm.com)" team (#22246) 2024-09-20 12:16:41 -05:00
Sharon Katz b11edd9398 Add CIS policy for tests (#22112) 2024-09-17 17:49:23 -04:00
Luke Heath e0abd89371 Update macOS latest version policy (#22025) 2024-09-11 16:26:33 -05:00
Luke Heath 2e9b0c8460 Add VPP apps to teams with Apple devices (#21996) 2024-09-11 15:34:45 -05:00
Luke Heath ca4d45f400 Remove devices from demo policy (#21932) 2024-09-10 10:04:37 -05:00
Roberto Dip 078c0ac3b7 document and use MDM SSO settings via gitops (#21869)
for #21313
2024-09-09 17:03:20 -03:00
JD 2db4417bff GitOps remove SWU config profile from teams (#21860) 2024-09-06 12:03:59 -05:00
Shea Craig 239c69b747 Fix type error (#21667) 2024-09-05 11:18:15 -05:00
Roberto Dip ade1d06fd6 add windows configuration profiles to workstations canary (#21336)
Adding a few Windows configuration profiles so we can dogfood them. Most
of the profiles are adaptations from the macOS profiles.

I'm not an expert, adding them to the canary team for now to avoid
breaking anyone's machine.
2024-08-15 14:02:05 -03:00
Lucas Manuel Rodriguez 5554d05305 Use edge channels in "Compliance exclusions" team (#21335)
The more hosts dogfood the `edge` channels the better.
2024-08-15 10:12:04 -03:00
JD c25b22be88 Enforce Sonoma 14.6 and iOS/iPadOS 17.6 (#21314)
Enforce updates https://github.com/fleetdm/confidential/issues/7469
2024-08-14 12:11:48 -07:00
Victor Lyuboslavsky b2cfc4082e Added required "software" for GitOps YAML (#21271)
Fixes GitOps on main.
2024-08-13 16:03:29 +02:00
311a24c546 Zoom software self service to use Apple Silicon (#20767)
Updates GitOps to offer Apple Silicon version of Zoom in self-service.
https://github.com/fleetdm/confidential/issues/6916

---------

Co-authored-by: Noah Talerman <47070608+noahtalerman@users.noreply.github.com>
Co-authored-by: Noah Talerman <noahtal@umich.edu>
2024-07-26 07:57:46 -07:00
JDandVictor Lyuboslavsky a8bf2d95c1 Add zoom to self-service for Workstations (#20701)
Adds Zoom as a self-service option.

While the UI will not allow for similar installers, attempting arm64 vs.
Intel using a pre-install query.

https://github.com/fleetdm/confidential/issues/6916

---------

Co-authored-by: Victor Lyuboslavsky <victor.lyuboslavsky@gmail.com>
2024-07-25 11:50:04 -07:00
Zach Wasserman 0d56d8af56 Rename complaince-exclusions.yml to compliance-exclusions.yml (#20565) 2024-07-19 10:58:43 -07:00
Dave Herder e348fe75c7 adding crowdstrike detection on canary (#20619)
detecting the health of crowdstrike
2024-07-19 10:23:48 -07:00
Luke HeathandJD 1e50254c74 Update homebrew install and update script (#20533)
Co-authored-by: JD <spokanemac@users.noreply.github.com>
2024-07-18 12:48:53 -07:00
Noah Talerman 02f4bfb794 Dogfood: best practice teams (#20359) 2024-07-15 16:22:15 -07:00
Luke Heath 0f0933ebf3 Add homebrew install and update script (#20318) 2024-07-15 10:09:50 -07:00
Drew Baker 543354540a Update workstations-canary.yml (#20267) 2024-07-09 11:16:42 -04:00
Luke Heath d73446d1fe Set workstations to use DDM for macOS updates (#20178)
- On workstations, we dogfood the current recommended best practice:
https://fleetdm.com/docs/using-fleet/mdm-os-updates
- On workstations (canary), we dogfood using the calendar feature to run
managed OS updates.
2024-07-08 18:22:59 -04:00
Noah Talerman 9e695dae39 Dogfood: 📱 iPhones (#20038)
- Emojis
2024-06-28 12:11:05 -03:00
Lucas Manuel Rodriguez addb665c8b Dogfood iPhones team GitOps (#19897)
Changes to dogfood GitOps for #18866.
2024-06-20 17:13:24 -03:00
Drew Baker c961df618e Adding fallback wallpaper to system maintenance script (#19858) 2024-06-19 12:04:22 -07:00
Dave HerderandLuke Heath 30e4b252aa adding a subset of cis benchmarks policies to canary workstations team (#19572)
Co-authored-by: Luke Heath <luke@fleetdm.com>
2024-06-12 08:19:51 -07:00
Martin Angers 943a4566f4 Fix the windows-remove-fleetd.ps1 script so that the agent can be reinstalled (#19643) 2024-06-12 09:34:57 -04:00
Drew Baker a035752a9b Adding macos-system-maintenance-script to workstations canary 🐣 team (#19675)
Adding script that changes macOS background to
https://fleetdm.com/images/demo/fleet-system-maintenance.png and then
changes back to the original desktop.

Added reference to the script in the workstations canary team.
2024-06-11 18:47:04 -04:00
Drew BakerandLuke Heath c716c5d21a Add system maintenance policy to workstations canary (#19664)
Adding system maintenance policy to Workstations canary 🐣 team for demo
purposes.

---------

Co-authored-by: Luke Heath <luke@fleetdm.com>
2024-06-11 18:04:13 -04:00
Luke Heath fd1500747c Update macos MDM migration demo policy (#19632) 2024-06-10 14:49:42 -07:00
Luke Heath dd89ab6998 Update macos MDM migration demo script (#19621) 2024-06-10 10:48:35 -07:00
Noah Talerman 9a4b6a4abe Dogfood policies: deduplicate (#19613)
- Add inline policies that are unique to "Workstations" or "Workstations
(canary)" to remove duplicate policies in
`macos-device-health-canary.yml`
2024-06-10 09:00:06 -07:00
Luke Heath 3a4a2904d2 Update canary profiles and policies (#19598) 2024-06-07 13:10:24 -07:00
Drew BakerandJD 1746f020c7 move min mac os required policy (#19431)
Adding previously removed mac os min required version back to global
macos device health policies

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

<!-- Note that API documentation changes are now addressed by the
product design team. -->

- [ ] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://fleetdm.com/docs/contributing/committing-changes#changes-files)
for more information.
- [ ] Input data is properly validated, `SELECT *` is avoided, SQL
injection is prevented (using placeholders for values in statements)
- [ ] Added support on fleet's osquery simulator `cmd/osquery-perf` for
new osquery data ingestion features.
- [ ] Added/updated tests
- [ ] If database migrations are included, checked table schema to
confirm autoupdate
- For database migrations:
- [ ] Checked schema for all modified table for columns that will
auto-update timestamps during migration.
- [ ] Confirmed that updating the timestamps is acceptable, and will not
cause unwanted side effects.
- [ ] Ensured the correct collation is explicitly set for character
columns (`COLLATE utf8mb4_unicode_ci`).
- [ ] Manual QA for all new/changed functionality
  - For Orbit and Fleet Desktop changes:
- [ ] Manual QA must be performed in the three main OSs, macOS, Windows
and Linux.
- [ ] Auto-update manual QA, from released version of component to new
version (see [tools/tuf/test](../tools/tuf/test/README.md)).

---------

Co-authored-by: JD <spokanemac@users.noreply.github.com>
2024-05-31 14:45:18 -07:00
JDandNoah Talerman 94be5c0a9c Adds VM team to gitops (#19316)
Adds Virtual machines team to gitops. fleetdm/confidential#6762

---------

Co-authored-by: Noah Talerman <47070608+noahtalerman@users.noreply.github.com>
2024-05-29 11:19:24 -07:00
JD 18e42e7c32 Add script to enable MS Defender (#19234)
Add PowerShell script to enable Windows Defender per
https://github.com/fleetdm/confidential/issues/5476
2024-05-23 13:29:37 -07:00
Marko Lisica d2e23d1af3 Doogfooding - testing malformed declaration (#19170)
- Intentionally apply passcode declaration profile (DDM) with invalid value for one of
payloads
2024-05-22 18:01:56 -04:00
Rachael Shaw 1b5daad8b5 GitOps updates (#19147)
+ Update policy description for workstations maintenance windows (still
used the old one with grammatical errors).
+ Update org name to just "Fleet"
2024-05-20 14:59:59 -05:00
Noah TalermanandLuke Heath d5f666bfa3 Update "macOS - Check if latest version" policy (#19138)
- Simplify policy
- Move policy out of team files. Why? They use the same policy
- Sometimes values that look like integers are treated as strings in
osquery.
This might be happening here w/ the major, minor, patch
in the policy. Another example here:
https://github.com/fleetdm/fleet/issues/15962#issuecomment-1881783764

---------

Co-authored-by: Luke Heath <luke@fleetdm.com>
2024-05-20 11:48:28 -05:00
Lucas Manuel Rodriguez 431d6919fe Enable users and software on servers canary team (#19118)
Change needed to help verify
https://github.com/fleetdm/fleet/issues/18424 in dogfood.
/cc @xpkoala
2024-05-17 14:25:21 -04:00
Rachael Shaw 0ce6a9fbee Update "macOS - Check if latest version" policy description/resolution (#19120)
This will make our own calendar events look like the one in the calendar
wireframes/marketing images
2024-05-17 13:37:19 -04:00
JD 910c0bc4c3 Rename Explore data (fleetdm.com) team (#19074)
Renames team `Explore data (fleetdm.com)` to match team name in dogfood
for successful gitops run.
2024-05-16 12:10:42 -07:00
JDandNoah Talerman 4a6cd9c79f Update GitOps config to macOS Sonoma 14.5 (#19034)
Updates minimum macOS configuration to 14.5 for Sonoma.
https://github.com/fleetdm/confidential/issues/6576

TODO: 
- [x] Update MDM Payload in Tines workflow.

---------

Co-authored-by: Noah Talerman <47070608+noahtalerman@users.noreply.github.com>
2024-05-15 14:50:37 -07:00
Noah Talerman 9258f53ca3 Move commands into /lib (#18794)
- Move the send fleetd command to `/lib`
- Update name of send fleetd macOS MDM command to include the platform:
macos
2024-05-07 17:57:02 -04:00
JD 0b66bc4a9b Add Windows AV policy (#18551)
Adds policy and query to verify Windows Defender is installed and
working on Windows. https://github.com/fleetdm/fleet/issues/18494
2024-04-29 07:53:04 -07:00