<!-- Add the related story/sub-task/bug number, like Resolves #123, or remove if NA --> **Related issue:** Resolves #44826 # Checklist for submitter If some of the following don't apply, delete the relevant line. - [x] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. - [x] Input data is properly validated, `SELECT *` is avoided, SQL injection is prevented (using placeholders for values in statements), JS inline code is prevented especially for url redirects, and untrusted data interpolated into shell scripts/commands is validated against shell metacharacters. ## Testing - [x] Added/updated automated tests - [x] Where appropriate, [automated tests simulate multiple hosts and test for host isolation](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/patterns-backend.md#unit-testing) (updates to one hosts's records do not affect another) - [x] QA'd all new/changed functionality manually For unreleased bug fixes in a release candidate, one of: - [x] Confirmed that the fix is not expected to adversely impact load test results ## fleetd/orbit/Fleet Desktop - [x] Verified compatibility with the latest released version of Fleet (see [Must rule](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/workflows/fleetd-development-and-release-strategy.md)) - [x] Verified that fleetd runs on macOS, Linux and Windows <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Windows MSI builds now correctly exclude placeholder secret values during installation, preventing unnecessary dummy configuration files from being created. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
93 lines
5.0 KiB
Go
93 lines
5.0 KiB
Go
package constant
|
|
|
|
import "time"
|
|
|
|
const (
|
|
// DefaultDirMode is the default file mode to apply to created directories.
|
|
DefaultDirMode = 0o755
|
|
// DefaultFileMode is the default file mode to apply to created files.
|
|
DefaultFileMode = 0o600
|
|
// DefaultWorldReadableFileMode is the default file mode to apply to files
|
|
// that can be read by other processes.
|
|
DefaultWorldReadableFileMode = 0o644
|
|
// DefaultSystemdUnitMode is the required file mode to systemd unit files.
|
|
DefaultSystemdUnitMode = DefaultWorldReadableFileMode
|
|
// DesktopAppExecName is the name of Fleet's Desktop executable.
|
|
//
|
|
// We use fleet-desktop as name to properly identify the process when listing
|
|
// running processes/tasks.
|
|
DesktopAppExecName = "fleet-desktop"
|
|
// DesktopTokenFileName is the filename on disk (in the orbit base dir) where we store the Fleet Desktop auth token
|
|
DesktopTokenFileName = "identifier"
|
|
// OrbitNodeKeyFileName is the filename on disk where we write the orbit node key to
|
|
OrbitNodeKeyFileName = "secret-orbit-node-key.txt"
|
|
// HardwareUUIDFileName is the filename on disk where we store the hardware UUID for migration detection
|
|
HardwareUUIDFileName = "hardware-uuid.txt"
|
|
// OrbitEnrollMaxRetries is the max number of retries when doing an enroll request.
|
|
// We set it to 6 to allow the retry backoff to take effect.
|
|
OrbitEnrollMaxRetries = 6
|
|
// OrbitEnrollBackoffMultiplier is the multiplier to use for backing off between enroll retries.
|
|
OrbitEnrollBackoffMultiplier = 2
|
|
// OrbitEnrollRetrySleep is the duration to sleep between enroll retries.
|
|
OrbitEnrollRetrySleep = 10 * time.Second
|
|
// OsqueryPidfile is the file containing the PID of the running osqueryd process
|
|
OsqueryPidfile = "osquery.pid"
|
|
// OsqueryEnrollSecretFileName is the filename on disk where we write
|
|
// the orbit enroll secret.
|
|
OsqueryEnrollSecretFileName = "secret.txt"
|
|
// SystemServiceName is the name of Orbit system service
|
|
// The service name is used by the OS service management framework
|
|
SystemServiceName = "Fleet osquery"
|
|
// FleetTLSClientCertificateFileName is the name of the TLS client certificate file
|
|
// used when connecting to the Fleet server.
|
|
FleetTLSClientCertificateFileName = "fleet_client.crt"
|
|
// FleetTLSClientKeyFileName is the name of the TLS client private key file
|
|
// used when connecting to the Fleet server.
|
|
FleetTLSClientKeyFileName = "fleet_client.key"
|
|
// UpdateTLSClientCertificateFileName is the name of the TLS client certificate file
|
|
// used when connecting to the update server.
|
|
UpdateTLSClientCertificateFileName = "update_client.crt"
|
|
// UpdateTLSClientKeyFileName is the name of the TLS client private key file
|
|
// used when connecting to the update server.
|
|
UpdateTLSClientKeyFileName = "update_client.key"
|
|
// SilenceEnrollLogErrorEnvVer is an environment variable name for disabling enroll log errors
|
|
SilenceEnrollLogErrorEnvVar = "FLEETD_SILENCE_ENROLL_ERROR"
|
|
// ServerOverridesFileName is the name of the file in the root directory
|
|
// that specifies the override configuration fetched from the server.
|
|
ServerOverridesFileName = "server-overrides.json"
|
|
// MigrationFileName is the name of the file used by fleetd to determine if the host is
|
|
// partially through an MDM migration.
|
|
MigrationFileName = "mdm_migration.txt"
|
|
// MDMMigrationTypeManual indicates that the MDM migration is for a manually enrolled host.
|
|
MDMMigrationTypeManual = "manual"
|
|
// MDMMigrationTypeADE indicates that the MDM migration is for an ADE enrolled host.
|
|
MDMMigrationTypeADE = "ade"
|
|
// MDMMigrationTypePreSonoma indicates that the MDM migration is for a host on a macOS version < 14.
|
|
MDMMigrationTypePreSonoma = "pre-sonoma"
|
|
// MDMMigrationOfflineWatcherInterval is the interval at which the offline watcher checks for
|
|
// the presence of the migration file.
|
|
MDMMigrationOfflineWatcherInterval = 3 * time.Minute
|
|
SonomaMajorVersion = 14
|
|
|
|
// OrbitTUFTargetName is the target name of the orbit component of fleetd in TUF.
|
|
OrbitTUFTargetName = "orbit"
|
|
// OsqueryTUFTargetName is the target name of the osquery component of fleetd in TUF.
|
|
OsqueryTUFTargetName = "osqueryd"
|
|
// DesktopTUFTargetName is the target name of the Fleet Desktop component of fleetd in TUF.
|
|
DesktopTUFTargetName = "desktop"
|
|
// FleetURLFileName is the file where Fleet URL is stored after being read from Apple config profile.
|
|
FleetURLFileName = "fleet_url.txt"
|
|
|
|
// SetupExperienceComplete is a file created when Linux (and soon Windows) completes setup experience
|
|
SetupExperienceFilename = "setup_experience.json"
|
|
|
|
FleetHTTPSignatureCertificateFileName = "host_identity.crt"
|
|
// FleetHTTPSignatureTPMKeyFileName is the filename for the TPM key used for HTTP signature authentication
|
|
FleetHTTPSignatureTPMKeyFileName = "host_identity_tpm.pem"
|
|
// FleetHTTPSignatureTPMKeyBackupFileName is the filename for the backup of the TPM key during renewal
|
|
FleetHTTPSignatureTPMKeyBackupFileName = "host_identity_tpm.old.pem"
|
|
|
|
// UnusedFlagKeyword is used by the MSI builder and installer to populate parameters, which cannot be empty.
|
|
UnusedFlagKeyword = "dummy"
|
|
)
|