Files
fleet/articles/fleet-variables.md
T
Nico 01bb250741 Add custom host vitals guide (#49355)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #48811

This adds a "Use custom host vitals in scripts and configuration
profiles" guide and cross-links it from the built-in variables and
custom variables (secrets) guides.


## Testing

- [ ] QA'd all new/changed functionality manually
2026-07-16 14:17:30 -03:00

6.3 KiB

Built-in variables

Available in Fleet Premium

Fleet supports built-in variables (prefixed with $FLEET_VAR_) to inject host vitals into configuration profiles or iOS/iPadOS managed app configurations.

You can also create custom variables (prefixed with $FLEET_SECRET_) to define your own key-value pairs.

To store a different value per host, create custom host vitals (prefixed with $FLEET_HOST_VITAL_) and reference them in scripts and configuration profiles.

For macOS configuration profiles, you can also use any of Apple's built-in variables in Automated Certificate Management Environment (ACME), Simple Certificate Enrolment Protocol (SCEP), or VPN payloads.

When the variable's value changes, Fleet automatically resends configuration profiles. For managed app configurations, changes apply on next app install or update.

Built-in variables:

Name Configuration profiles Managed app configuration Description
$FLEET_VAR_NDES_SCEP_CHALLENGE macOS, iOS, iPadOS None Fleet-managed one-time NDES challenge password used during SCEP certificate configuration profile deployment.
$FLEET_VAR_NDES_SCEP_PROXY_URL macOS, iOS, iPadOS None Fleet-managed NDES SCEP proxy endpoint URL used during SCEP certificate configuration profile deployment.
$FLEET_VAR_HOST_END_USER_IDP_USERNAME macOS, iOS, iPadOS, Windows iOS and iPadOS Host's IdP username (e.g. "user@example.com"). When this changes, Fleet will automatically resend the profile.
$FLEET_VAR_HOST_END_USER_IDP_FULL_NAME macOS, iOS, iPadOS, Windows iOS and iPadOS Host's IdP full name. When this changes, Fleet will automatically resend the profile.
$FLEET_VAR_HOST_END_USER_IDP_USERNAME_LOCAL_PART macOS, iOS, iPadOS, Windows iOS and iPadOS Local part of the email (e.g. john from john@example.com). When this changes, Fleet will automatically resend the profile.
$FLEET_VAR_HOST_END_USER_IDP_GROUPS macOS, iOS, iPadOS, Windows iOS and iPadOS Comma separated IdP groups that host belongs to. When these change, Fleet will automatically resend the profile.
$FLEET_VAR_HOST_END_USER_IDP_DEPARTMENT macOS, iOS, iPadOS, Windows iOS and iPadOS Host's IdP department. When this changes, Fleet will automatically resend the profile.
$FLEET_VAR_HOST_HARDWARE_SERIAL macOS, iOS, iPadOS, Windows iOS and iPadOS Host's hardware serial number. Not available for user enrolled iOS and iPadOS hosts with Managed Apple Account.
$FLEET_VAR_HOST_UUID macOS, iOS, iPadOS, Windows iOS and iPadOS Host's hardware UUID, or Enrollment ID for user enrolled iOS and iPadOS hosts.
$FLEET_VAR_HOST_PLATFORM macOS, iOS, iPadOS, Windows iOS and iPadOS Host's platform. Values are "macos", "ios", "ipados", and "windows".
$FLEET_VAR_CUSTOM_SCEP_CHALLENGE_<CA_NAME> macOS, iOS, iPadOS, Windows None Fleet-managed one-time challenge password used during SCEP certificate configuration profile deployment. <CA_NAME> should be replaced with name of the custom SCEP certificate authority configured in Settings > Integrations > Certificate authorities.
$FLEET_VAR_CUSTOM_SCEP_PROXY_URL_<CA_NAME> macOS, iOS, iPadOS, Windows None Fleet-managed SCEP proxy endpoint URL used during SCEP certificate configuration profile deployment.
$FLEET_VAR_CERTIFICATE_RENEWAL_ID macOS, iOS, iPadOS, Windows Fleet-managed ID that's required to automatically renew certificates. The ID must be specified in the Organizational Unit (OU) field in the configuration profile.
$FLEET_VAR_DIGICERT_PASSWORD_<CA_NAME> macOS, iOS, iPadOS None Fleet-managed password required to decode the base64-encoded certificate data issued by a specified DigiCert certificate authority during PKCS12 profile deployment. <CA_NAME> should be replaced with name of the DigiCert certificate authority configured in Settings > Integrations > Certificate authorities.
$FLEET_VAR_DIGICERT_DATA_<CA_NAME> macOS, iOS, iPadOS None Fleet-managed base64-encoded certificate data issued by a specified DigiCert certificate authority during PKCS12 profile deployment. <CA_NAME> should be replaced with name of the DigiCert certificate authority configured in Settings > Integrations > Certificate authorities.
$FLEET_VAR_SCEP_WINDOWS_CERTIFICATE_ID Windows None ID used for SCEP configuration profile on Windows. It must be included in the <LocURI> field.
$FLEET_VAR_SMALLSTEP_SCEP_CHALLENGE_<CA_NAME> macOS, iOS, iPadOS None Fleet-managed one-time Smallstep challenge password used during SCEP certificate configuration profile deployment. <CA_NAME> should be replaced with name of the Smallstep certificate authority configured in Settings > Integrations > Certificate authorities.
$FLEET_VAR_SMALLSTEP_SCEP_PROXY_URL_<CA_NAME> macOS, iOS, iPadOS None Fleet-managed Smallstep SCEP proxy endpoint URL used during SCEP certificate configuration profile deployment.

If certificate authority (CA) variables (ex. $FLEET_VAR_DIGICERT_DATA_<CA_NAME>) don't exist, GitOps dry runs will succeed but GitOps runs will fail.

Profiles that use IdP variables will trigger a resend when the IdP user is removed from the host, but will fail sending a new profile due to missing variables, leaving the old one on the device. Once the host has a new IdP user it will be resent again with fresh values.