Files
Allen Houchins 8d2a3abeaa Set byod_fleet for dogfood Apple Business Manager tokens (#49564)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->

Sets the new `byod_fleet` option on both Apple Business Manager tokens
in the dogfood GitOps config, so BYOD hosts appearing in Apple Business
Manager are automatically added to the right fleet instead of
"Unassigned":

- **Fleet Device Management Inc.** → `📱🔐 Personal mobile devices`
- **Mactivate LLC** → `🧪 Testing & QA`

Fleet names match the definitions in
`it-and-security/fleets/personal-mobile-devices.yml` and
`it-and-security/fleets/testing-and-qa.yml` verbatim (including emoji
prefixes). The file keeps the existing `apple_business_manager` parent
key (deprecated alias for `apple_business`) to match the surrounding
config; the alias machinery renames the parent before resolving nested
keys, so `byod_fleet` resolves correctly under it.

Note for reviewers: this only affects where *newly appearing* BYOD hosts
are placed — existing BYOD hosts in "Unassigned" are not retroactively
moved.

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

## Testing

- [x] QA'd all new/changed functionality manually — verified the YAML
parses (yaml.v3) and both ABM entries resolve to the intended fleet
names; config-only change to the dogfood GitOps setup, no product code
touched.
2026-07-20 09:41:33 -05:00

130 lines
5.0 KiB
YAML

agent_options:
path: ./lib/all/agent-options/agent-options.yml
org_settings:
conditional_access:
bypass_disabled: true
features:
enable_host_users: true
enable_software_inventory: true
fleet_desktop:
transparency_url: https://fleetdm.com/transparency
host_expiry_settings:
host_expiry_enabled: false
integrations:
google_calendar:
- api_key_json: $DOGFOOD_CALENDAR_API_KEY
domain: fleetdm.com
jira: []
zendesk: []
mdm:
end_user_authentication:
entity_id: fleet-end-users
idp_name: Okta
metadata_url: "$DOGFOOD_OKTA_METADATA_URL_END_USERS"
end_user_license_agreement: ../it-and-security/lib/macos/misc/eula.pdf
apple_business_manager:
- organization_name: Fleet Device Management Inc.
macos_fleet: "💻 Workstations"
ios_fleet: "📱🏢 Employee-issued mobile devices"
ipados_fleet: "📱🏢 Employee-issued mobile devices"
byod_fleet: "📱🔐 Personal mobile devices"
- organization_name: Mactivate LLC
macos_fleet: "🧪 Testing & QA"
ios_fleet: "🧪 Testing & QA"
ipados_fleet: "🧪 Testing & QA"
byod_fleet: "🧪 Testing & QA"
volume_purchasing_program:
- location: Fleet Device Management Inc.
fleets:
- "💻 Workstations"
- "📱🏢 Employee-issued mobile devices"
- "📱🔐 Personal mobile devices"
- "🧪 Testing & QA"
org_info:
contact_url: https://fleetdm.slack.com/archives/C09861YJUJ2
org_logo_url: ""
org_logo_url_light_background: ""
org_name: Fleet
secrets:
- secret: $DOGFOOD_GLOBAL_ENROLL_SECRET
server_settings:
deferred_save_host: false
enable_analytics: true
live_reporting_disabled: false
discard_reports_data: false
scripts_disabled: false
server_url: https://dogfood.fleetdm.com
sso_settings:
enable_jit_provisioning: true
enable_sso: true
enable_sso_idp_login: true
entity_id: fleet-admins
idp_image_url: ""
idp_name: Okta
metadata_url: "$DOGFOOD_OKTA_METADATA_URL_ADMINS"
webhook_settings:
failing_policies_webhook:
destination_url: $DOGFOOD_FAILING_POLICIES_WEBHOOK_URL
enable_failing_policies_webhook: true
host_batch_size: 0
policy_ids: []
host_status_webhook:
days_count: 5
destination_url: $DOGFOOD_HOST_STATUS_WEBHOOK_URL
enable_host_status_webhook: true
host_percentage: 20
interval: 360m0s
vulnerabilities_webhook:
destination_url: $DOGFOOD_VULNERABILITIES_WEBHOOK_URL
enable_vulnerabilities_webhook: true
host_batch_size: 0
activities_webhook:
destination_url: $DOGFOOD_ACTIVITIES_WEBHOOK_URL
enable_activities_webhook: true
policies:
- path: ./lib/all/policies/npm-supply-chain-compromised-packages.yml
reports:
- path: ./lib/all/reports/collect-fleetd-information.yml
- path: ./lib/all/reports/collect-operating-system-information.yml
- path: ./lib/all/reports/collect-known-vulnerable-chrome-extensions.yml
- path: ./lib/macos/reports/detect-apns-certificate.yml
- path: ./lib/macos/reports/collect-xprotect-reports.yml
controls:
apple_require_hardware_attestation: true
enable_disk_encryption: true
macos_migration:
enable: true
mode: voluntary
webhook_url: $DOGFOOD_MACOS_MIGRATION_WEBHOOK_URL
windows_enabled_and_configured: true
windows_entra_tenant_ids:
- $DOGFOOD_ENTRA_TENANT_ID
windows_entra_client_ids:
- $DOGFOOD_ENTRA_CLIENT_ID
windows_migration_enabled: true
labels:
- path: ./lib/all/labels/arm-based-windows-hosts.yml
- path: ./lib/all/labels/debian-based-linux-hosts.yml
- path: ./lib/all/labels/macs-with-1password-installed.yml
- path: ./lib/all/labels/rpm-based-linux-hosts.yml
- path: ./lib/all/labels/virtual-machines.yml
- path: ./lib/all/labels/x86-based-windows-hosts.yml
- path: ./lib/all/labels/apple-silicon-macos-hosts.yml
- path: ./lib/all/labels/keynote-14-installed.yml
- path: ./lib/all/labels/macos-compatibility-extension-installed.yml
- path: ./lib/all/labels/macos-screen-lock-exclusions.yml
- path: ./lib/all/labels/windows-screen-lock-exclusions.yml
- path: ./lib/all/labels/team-g-apple-at-work.yml
- path: ./lib/all/labels/team-g-auto-patching.yml
- path: ./lib/all/labels/macs-with-microsoft-autoupdate-installed.yml
- path: ./lib/all/labels/macs-with-fleet-maintained-apps-installed.yml
- path: ./lib/all/labels/macs-with-fleet-desktop-installed.yml
- path: ./lib/all/labels/macs-with-fleet-desktop-launch-agent-profile.yml
- path: ./lib/all/labels/windows-with-fleet-maintained-apps-installed.yml
- path: ./lib/all/labels/departments.yml
- path: ./lib/all/labels/idp-group-saml-aws-vpn.yml
- path: ./lib/all/labels/macs-excluded-from-external-storage-restrictions.yml
- path: ./lib/all/labels/windows-excluded-from-external-storage-restrictions.yml
- path: ./lib/all/labels/linux-excluded-from-external-storage-restrictions.yml
- path: ./lib/all/labels/hosts-with-npm-package-inventory.yml