📝 CodeRabbit Chat: Fix NetBird configuration and deployment files

This commit is contained in:
coderabbitai[bot]
2026-06-19 20:32:31 +00:00
committed by GitHub
parent 2aa5f3918e
commit ebcdb81e09
5 changed files with 13 additions and 17 deletions
@@ -19,16 +19,16 @@
For MDM platforms that expect a full Configuration Profile instead For MDM platforms that expect a full Configuration Profile instead
of a bare plist (Custom Configuration Profile / .mobileconfig upload), of a bare plist (Custom Configuration Profile / .mobileconfig upload),
use docs/netbird-macos.mobileconfig — same keys, additional Payload* use netbird-macos.mobileconfig — same keys, additional Payload*
envelope. envelope.
Editing this file: Editing this file:
- Remove or comment out any key you do NOT want to enforce. The - Remove or comment out any key you do NOT want to enforce. The
daemon treats an absent key as "no enforcement" for that field. daemon treats an absent key as "no enforcement" for that field.
- Keep the document well-formed XML. Validate locally with: - Keep the document well-formed XML. Validate locally with:
plutil -lint docs/io.netbird.client.plist plutil -lint io.netbird.client.plist
- Keys are camelCase; values are typed (<string>, <true/>, <false/>, - Keys are camelCase; values are typed (<string>, <true/>, <false/>,
<integer>). See docs/src/pages/client/mdm-integration.mdx (the <integer>). See src/pages/client/mdm-integration.mdx (the
public docs page) for the full reference. public docs page) for the full reference.
Persistence caveat: Persistence caveat:
@@ -9,7 +9,7 @@
Read at runtime by the netbird daemon's macOS loader Read at runtime by the netbird daemon's macOS loader
(client/mdm/policy_darwin.go — Phase 2). Key names match the canonical (client/mdm/policy_darwin.go — Phase 2). Key names match the canonical
lowerCamelCase form used in docs/netbird.admx and the mdm.Key* lowerCamelCase form used in netbird.admx and the mdm.Key*
constants in client/mdm/policy.go. constants in client/mdm/policy.go.
Bundle identifier: io.netbird.client Bundle identifier: io.netbird.client
@@ -36,7 +36,7 @@
UserDefaults[com.apple.configuration.managed] under a different UserDefaults[com.apple.configuration.managed] under a different
payload type (com.apple.app.configuration.managed); the wrapper payload type (com.apple.app.configuration.managed); the wrapper
structure is the same but the inner payload dictionary differs. structure is the same but the inner payload dictionary differs.
See docs/netbird-ios.mobileconfig (Phase 5) when shipped. See netbird-ios.mobileconfig (not yet shipped) when available.
--> -->
<plist version="1.0"> <plist version="1.0">
<dict> <dict>
+4 -4
View File
@@ -4,7 +4,7 @@
# Push the NetBird MDM policy to a macOS device via JumpCloud Commands. # Push the NetBird MDM policy to a macOS device via JumpCloud Commands.
# #
# DESCRIPTION # DESCRIPTION
# This is the macOS counterpart of docs/netbird-policy.reg.ps1. # This is the macOS counterpart of netbird-policy.reg.ps1.
# It writes the values declared in the "POLICY VALUES" block below to # It writes the values declared in the "POLICY VALUES" block below to
# the managed-preferences plist that the NetBird daemon's # the managed-preferences plist that the NetBird daemon's
# client/mdm/policy_darwin.go loader reads on every 1-minute MDM # client/mdm/policy_darwin.go loader reads on every 1-minute MDM
@@ -25,7 +25,7 @@
# IMPORTANT: PERSISTENCE # IMPORTANT: PERSISTENCE
# macOS wipes /Library/Managed Preferences/ at every boot on devices # macOS wipes /Library/Managed Preferences/ at every boot on devices
# that are NOT MDM-enrolled. For a persistent fleet rollout, push the # that are NOT MDM-enrolled. For a persistent fleet rollout, push the
# companion docs/netbird-macos.mobileconfig as a Custom Configuration # companion netbird-macos.mobileconfig as a Custom Configuration
# Profile (Admin Console -> MDM -> Mac Custom Configuration Profiles) # Profile (Admin Console -> MDM -> Mac Custom Configuration Profiles)
# instead of this script. Use this script when: # instead of this script. Use this script when:
# - the device is MDM-enrolled (file survives reboots), or # - the device is MDM-enrolled (file survives reboots), or
@@ -49,8 +49,8 @@ set -euo pipefail
# #
# Reference for key names + accepted values: # Reference for key names + accepted values:
# client/mdm/policy.go (Key* constants) # client/mdm/policy.go (Key* constants)
# docs/netbird-macos.mobileconfig (sample profile) # netbird-macos.mobileconfig (sample profile)
# docs/netbird.admx + .adml (Windows ADMX schema) # netbird.admx + netbird.adml (Windows ADMX schema)
# #
NULL='__UNSET__' NULL='__UNSET__'
managementURL='https://api.netbird.io:443' managementURL='https://api.netbird.io:443'
@@ -5,7 +5,7 @@
by importing a sidecar netbird-policy.reg file. by importing a sidecar netbird-policy.reg file.
.DESCRIPTION .DESCRIPTION
Windows counterpart of docs/netbird-macos.sh. Outcome: Windows counterpart of netbird-macos.sh. Outcome:
HKLM\Software\Policies\NetBird populated from the attached HKLM\Software\Policies\NetBird populated from the attached
netbird-policy.reg file, daemon picks up the change via the netbird-policy.reg file, daemon picks up the change via the
1-minute MDM reload ticker. 1-minute MDM reload ticker.
@@ -85,11 +85,7 @@ if ($LASTEXITCODE -ne 0) {
# Audit dump so the JumpCloud per-execution log captures the applied state. # Audit dump so the JumpCloud per-execution log captures the applied state.
Write-Host "[netbird-mdm] final policy state under $RegKey :" Write-Host "[netbird-mdm] final policy state under $RegKey :"
if (Test-Path "Registry::$RegKey") { & reg.exe query $RegKey /s
& reg.exe query $RegKey /s
} else {
Write-Host "[netbird-mdm] no policy values present under $RegKey"
}
# Daemon's 1-min reload ticker picks up the change automatically. # Daemon's 1-min reload ticker picks up the change automatically.
# Uncomment to force immediate convergence (skips the ticker wait): # Uncomment to force immediate convergence (skips the ticker wait):
+2 -2
View File
@@ -163,11 +163,11 @@
<item displayName="$(string.SplitTunnel_Allow)"><value><string>allow</string></value></item> <item displayName="$(string.SplitTunnel_Allow)"><value><string>allow</string></value></item>
<item displayName="$(string.SplitTunnel_Disallow)"><value><string>disallow</string></value></item> <item displayName="$(string.SplitTunnel_Disallow)"><value><string>disallow</string></value></item>
</enum> </enum>
<text id="SplitTunnel_Apps" valueName="SplitTunnelApps" required="true" /> <text id="SplitTunnel_Apps" valueName="SplitTunnelApps" required="false" />
</elements> </elements>
</policy> </policy>
<!-- ============================================================ -->
<!-- UI: visibility / UX kill switches --> <!-- UI: visibility / UX kill switches -->
<!-- ============================================================ --> <!-- ============================================================ -->