**Related issue:** Resolves #43518 Adds a cross-platform alias `FLEET_MDM_ENABLE_DISK_ENCRYPTION` (`mdm.enable_disk_encryption`) for the existing `FLEET_MDM_ENABLE_CUSTOM_FILEVAULT` server configuration. When either option is set, Fleet allows both custom Apple MDM profiles for FileVault and custom Windows configuration profiles for BitLocker. Behavior matches FileVault: no special conflict handling between Fleet's built-in disk encryption controls and a custom profile. The setting remains Fleet Premium only. Both the single-add API/UI path and the batch/GitOps path are covered. The existing `FLEET_MDM_ENABLE_CUSTOM_FILEVAULT` name continues to work for backward compatibility. Demo: https://www.youtube.com/watch?v=5naGaZKLZ8o Docs: https://github.com/fleetdm/fleet/pull/48738/changes # Checklist for submitter - [x] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. - [x] Input data is properly validated, `SELECT *` is avoided, SQL injection is prevented (using placeholders for values in statements), JS inline code is prevented especially for url redirects, and untrusted data interpolated into shell scripts/commands is validated against shell metacharacters. ## Testing - [x] Added/updated automated tests - [x] QA'd all new/changed functionality manually ## New Fleet configuration settings - [x] Setting(s) is/are explicitly excluded from GitOps <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a cross-platform disk encryption setting that can enable custom management for both macOS FileVault and Windows BitLocker profiles. * **Bug Fixes** * Windows BitLocker profile uploads are now accepted when custom disk encryption is enabled. * Startup now disables custom disk encryption management when the license does not support it, and logs a warning. * **Tests** * Added coverage for BitLocker profile handling with custom disk encryption enabled and disabled. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
2 lines
277 B
Plaintext
2 lines
277 B
Plaintext
- Added `FLEET_MDM_ENABLE_CUSTOM_DISK_ENCRYPTION` (`mdm.enable_custom_disk_encryption`) as a cross-platform alias for `FLEET_MDM_ENABLE_CUSTOM_FILEVAULT`. When set, it allows both custom Apple MDM profiles for FileVault and custom Windows configuration profiles for BitLocker.
|