mirror of
https://github.com/netbirdio/netbird.git
synced 2026-09-12 17:59:06 +02:00
This introduces a disabled-by-default allow-remote-jobs setting that controls whether the management server may run jobs (such as debug bundles) on a peer. The flag propagates end to end: through client configuration, the daemon SetConfig and Login requests, authentication, and system info, up to management, where it is stored on the peer and exposed on the peers API as remote_jobs_allowed. The client refuses any management-requested job unless the peer has opted in. Because enabling remote jobs crosses the user-to-root boundary, turning it on requires privilege, mirroring the SSH-server gate. Administrators can enforce the setting through MDM policy on both macOS and Windows, and MDM can also override the debug-bundle upload URL. The change ships policy documentation and generated profile templates, and adds configuration, conflict, and enforcement tests covering the opt-in, privilege, and MDM paths.
58 lines
1.8 KiB
Go
58 lines
1.8 KiB
Go
//go:build windows || darwin
|
|
|
|
package mdm
|
|
|
|
import "strings"
|
|
|
|
// allKeys is the set of recognised MDM keys. Unknown keys in a managed
|
|
// configuration are ignored but logged. Lives in this build-tagged file
|
|
// (windows || darwin) because only desktop loaders need the
|
|
// canonicalisation table that consumes it; including it unconditionally
|
|
// would trigger the `unused` golangci-lint check on platforms that
|
|
// don't import canonical_loaders.go.
|
|
var allKeys = []string{
|
|
KeyManagementURL,
|
|
KeyDisableUpdateSettings,
|
|
KeyDisableProfiles,
|
|
KeyDisableNetworks,
|
|
KeyDisableAdvancedView,
|
|
KeyDisableClientRoutes,
|
|
KeyDisableServerRoutes,
|
|
KeyBlockInbound,
|
|
KeyDisableMetricsCollection,
|
|
KeyAllowServerSSH,
|
|
KeyDisableAutoConnect,
|
|
KeyDisableAutostart,
|
|
KeyPreSharedKey,
|
|
KeyRosenpassEnabled,
|
|
KeyRosenpassPermissive,
|
|
KeyWireguardPort,
|
|
KeyEnableLocalMetrics,
|
|
KeyLocalMetricsAddress,
|
|
KeySplitTunnelMode,
|
|
KeySplitTunnelApps,
|
|
KeyLazyConnection,
|
|
KeyRemoteJobsAllowed,
|
|
KeyBundleUploadURL,
|
|
}
|
|
|
|
// canonicalKey maps the lowercase form of a managed-config value name to
|
|
// its canonical mdm.Key* form. Admins commonly write PascalCase value
|
|
// names in ADMX / Group Policy ("ManagementURL"); the iOS/AppConfig and
|
|
// macOS plist conventions are camelCase ("managementURL"); both must
|
|
// resolve to the same Policy lookup.
|
|
//
|
|
// Lives in a desktop-loader-only file (build tag `windows || darwin`)
|
|
// because no other build path consumes it. Linux / FreeBSD / mobile
|
|
// builds don't ship a platform loader that reads arbitrary-case key
|
|
// names, so they don't need the canonicalisation table — and including
|
|
// the var unconditionally would trigger the `unused` golangci-lint
|
|
// check on those platforms.
|
|
var canonicalKey = func() map[string]string {
|
|
m := make(map[string]string, len(allKeys))
|
|
for _, k := range allKeys {
|
|
m[strings.ToLower(k)] = k
|
|
}
|
|
return m
|
|
}()
|