Skip to content

Add Mdm auto start flag doc - #855

Merged
riccardomanfrin merged 2 commits into
mainfrom
mdm_auto_start_flag
Jul 22, 2026
Merged

Add Mdm auto start flag doc#855
riccardomanfrin merged 2 commits into
mainfrom
mdm_auto_start_flag

Conversation

@riccardomanfrin

@riccardomanfrin riccardomanfrin commented Jul 15, 2026

Copy link
Copy Markdown
Contributor
image image

Summary by CodeRabbit

  • New Features

    • Added a disableAutostart policy for managed NetBird deployments.
    • Administrators can prevent the desktop app from registering as an operating-system login item and remove existing registration when the app next launches.
    • Added support across macOS configuration profiles, Windows Group Policy, and MDM scripts.
  • Documentation

    • Documented the new policy, supported platforms, behavior, and mobile limitations.

@coderabbitai

coderabbitai Bot commented Jul 15, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Warning

Review limit reached

@riccardomanfrin, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 53 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: f357c81d-93f2-48d7-b953-1f6cbb7517d2

📥 Commits

Reviewing files that changed from the base of the PR and between 1c8a098 and 679bb02.

📒 Files selected for processing (7)
  • public/docs-static/files/io.netbird.client.plist
  • public/docs-static/files/netbird-macos.mobileconfig
  • public/docs-static/files/netbird-macos.sh
  • public/docs-static/files/netbird-policy.reg
  • public/docs-static/files/netbird.adml
  • public/docs-static/files/netbird.admx
  • src/pages/client/mdm-integration.mdx
📝 Walkthrough

Walkthrough

Adds the disableAutostart policy to macOS MDM artifacts, Windows Group Policy and registry examples, and the MDM integration documentation, including desktop platform behavior and mobile handling.

Changes

Autostart policy support

Layer / File(s) Summary
macOS policy wiring
public/docs-static/files/io.netbird.client.plist, public/docs-static/files/netbird-macos.mobileconfig, public/docs-static/files/netbird-macos.sh
Adds disableAutostart to managed preferences examples and conditional macOS policy generation.
Windows policy definitions
public/docs-static/files/netbird-policy.reg, public/docs-static/files/netbird.adml, public/docs-static/files/netbird.admx
Adds registry and Group Policy definitions for disabling autostart, including display and help text.
MDM policy reference
src/pages/client/mdm-integration.mdx
Documents desktop behavior, policy removal behavior, and mobile platform handling for disableAutostart.

Estimated code review effort: 2 (Simple) | ~10 minutes

Poem

I’m a rabbit with a policy key,
Keeping login starts where they should be.
Mac and Windows hop in line,
Docs now make the setting shine.
Autostart rests—quite fine by me!

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title matches the PR’s main change: adding MDM autostart flag documentation.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch mdm_auto_start_flag

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@public/docs-static/files/netbird-policy.reg`:
- Line 9: Restore the CRLF line ending for the DisableAutostart entry in the
UTF-16 netbird-policy.reg file, preserving the file’s existing encoding and
ensuring the entry ends with \r\n like the surrounding registry export lines.

In `@src/pages/client/mdm-integration.mdx`:
- Line 74: Update the introductory sentence for the policy reference table to
state that the same 17 keys apply on every platform, keeping the existing table
and platform scope unchanged.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: e18f9fa7-c250-4edc-94cc-5173bd9c7637

📥 Commits

Reviewing files that changed from the base of the PR and between 31f2b6c and 1c8a098.

📒 Files selected for processing (7)
  • public/docs-static/files/io.netbird.client.plist
  • public/docs-static/files/netbird-macos.mobileconfig
  • public/docs-static/files/netbird-macos.sh
  • public/docs-static/files/netbird-policy.reg
  • public/docs-static/files/netbird.adml
  • public/docs-static/files/netbird.admx
  • src/pages/client/mdm-integration.mdx

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Inline review comments failed to post. This is likely due to GitHub's internal server error or limits when posting large numbers of comments. If you are seeing this consistently it is likely a permissions issue. Please check "Moderation" -> "Code review limits" under your organization settings.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@public/docs-static/files/netbird-policy.reg`:
- Line 9: Restore the CRLF line ending for the DisableAutostart entry in the
UTF-16 netbird-policy.reg file, preserving the file’s existing encoding and
ensuring the entry ends with \r\n like the surrounding registry export lines.

In `@src/pages/client/mdm-integration.mdx`:
- Line 74: Update the introductory sentence for the policy reference table to
state that the same 17 keys apply on every platform, keeping the existing table
and platform scope unchanged.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: e18f9fa7-c250-4edc-94cc-5173bd9c7637

📥 Commits

Reviewing files that changed from the base of the PR and between 31f2b6c and 1c8a098.

📒 Files selected for processing (7)
  • public/docs-static/files/io.netbird.client.plist
  • public/docs-static/files/netbird-macos.mobileconfig
  • public/docs-static/files/netbird-macos.sh
  • public/docs-static/files/netbird-policy.reg
  • public/docs-static/files/netbird.adml
  • public/docs-static/files/netbird.admx
  • src/pages/client/mdm-integration.mdx
🛑 Comments failed to post (2)
public/docs-static/files/netbird-policy.reg (1)

9-9: 🗄️ Data Integrity & Integration | 🟡 Minor | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

python - <<'PY'
from pathlib import Path

raw = Path("public/docs-static/files/netbird-policy.reg").read_bytes()
text = raw.decode("utf-16")

line = next(
    line for line in text.splitlines(keepends=True)
    if '"DisableAutostart"' in line
)
assert line.endswith("\r\n"), repr(line)
print("DisableAutostart has a CRLF terminator")
PY

Repository: netbirdio/docs

Length of output: 280


🏁 Script executed:

python3 - <<'PY'
from pathlib import Path

path = Path("public/docs-static/files/netbird-policy.reg")
raw = path.read_bytes()

# Show the BOM/encoding shape and line endings around the target entry.
print("byte_len", len(raw))
print("head_bytes", raw[:24])

for enc in ("utf-16", "utf-16le", "utf-16be"):
    try:
        text = raw.decode(enc)
    except Exception as e:
        print(enc, "decode_error", e)
        continue
    print("\nENC", enc)
    for i, line in enumerate(text.splitlines(keepends=True), 1):
        if i <= 12:
            print(i, repr(line))
    print("contains_crlf", "\r\n" in text)
PY

Repository: netbirdio/docs

Length of output: 2763


Keep the DisableAutostart entry CRLF-terminated.

public/docs-static/files/netbird-policy.reg:9 ends with \n instead of \r\n, unlike the rest of this UTF-16 .reg file. Restore the CRLF ending so the registry export stays consistent.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@public/docs-static/files/netbird-policy.reg` at line 9, Restore the CRLF line
ending for the DisableAutostart entry in the UTF-16 netbird-policy.reg file,
preserving the file’s existing encoding and ensuring the entry ends with \r\n
like the surrounding registry export lines.
src/pages/client/mdm-integration.mdx (1)

74-74: 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win

Update the policy-key count.

After adding disableAutostart, the reference table contains 17 keys, but its introductory sentence still says “The same 16 keys apply on every platform.” Update that count to keep the documentation internally consistent.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@src/pages/client/mdm-integration.mdx` at line 74, Update the introductory
sentence for the policy reference table to state that the same 17 keys apply on
every platform, keeping the existing table and platform scope unchanged.

riccardomanfrin added a commit to netbirdio/netbird that referenced this pull request Jul 22, 2026
… just fresh installs (#6782)

## Describe your changes

`applyAutostartDefault` gated all MDM enforcement behind the one-time
`AutostartInitialized` marker, so MDM `disableAutostart` only affected
fresh installs — a policy pushed after autostart had been enabled could
not
revoke the OS login-item. 

The PR adds follow-up MDM enforcements at the top of
the function: if at any time MDM sets `disableAutostart=true` and the OS
registration is
present, force `SetEnabled(false)` to align it.

Trade-off: once the admin lifts the policy, autostart stays off until
the user re-toggles
in Settings — consistent with "MDM always wins" behavior of the other
managed keys.

## Issue ticket number and link

Follow-up to PR #6738
(introduced
the `disableAutostart` MDM key with fresh-install-only semantics).

## Stack

<!-- branch-stack -->

### Checklist
- [x] Is it a bug fix
- [ ] Is a typo/documentation fix
- [ ] Is a feature enhancement
- [ ] It is a refactor
- [ ] Created tests that fail without the change (if possible)

> By submitting this pull request, you confirm that you have read and
agree to the terms of the [Contributor License
Agreement](https://github.com/netbirdio/netbird/blob/main/CONTRIBUTOR_LICENSE_AGREEMENT.md).

## Documentation
Select exactly one:

- [x] I added/updated documentation for this change
- [ ] Documentation is **not needed** for this change (explain why)

### Docs PR URL (required if "docs added" is checked)
Paste the PR link from https://github.com/netbirdio/docs here:

<netbirdio/docs#855>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Added an administrative policy to disable client autostart (“Disable
Autostart”).
- Added support for configuring this policy via macOS MDM, Windows Group
Policy (ADMX/ADML), and registry settings.
- When enforced, the client prevents new autostart registration on fresh
installs and removes existing autostart on the next GUI launch, keeping
it disabled until the policy is lifted.

- **Bug Fixes**
- Improved enforcement logic for managed autostart defaults so policy
state is applied consistently during startup and first-run setup.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
@riccardomanfrin
riccardomanfrin merged commit accc461 into main Jul 22, 2026
3 checks passed
@riccardomanfrin
riccardomanfrin deleted the mdm_auto_start_flag branch July 22, 2026 09:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants