Skip to content

Remove experimental tag from "macOS local account: initial account creation and sync password based on IdP credentials from any IdP" #46597

Description

@noahtalerman

Goal

User story
As an IT admin (Fleet customer),
I want Fleet to automatically create my end user's macOS local account and sync the password w/ their IdP credentials
so that my end users have one password, that meets organization criteria, to log into their Mac and third-party tools.

Changes

Product

  • Changes: After we load test and confirm we can support customers at scale with this feature, remove any experimental flags for this feature.
  • UI changes: No changes
  • CLI (fleetctl) usage changes: No changes
  • YAML changes: No changes
  • REST API changes: No changes
  • Fleet's agent (fleetd) changes: No changes
  • Fleet server configuration changes: No changes
  • Exposed, public API endpoint changes: No changes
  • fleetdm.com changes: No changes
  • GitOps mode UI changes: No changes
  • GitOps generation changes: No changes
  • Activity changes: No changes
  • Permissions changes: No changes
  • Changes to paid features or tiers: Update isExperimental to false
  • My device and fleetdm.com/better changes: No changes
  • Usage statistics: No changes
  • Other reference documentation changes:
    • Confirm we document with best practices
  • First draft of test plan added
  • Once shipped, requester has been notified
  • Once shipped, dogfooding issue has been filed

Engineering

  • Test plan is finalized
  • Contributor API changes: No changes
  • Feature guide changes: None
  • Load testing: Load test with 1000 macOS hosts psso_interval set to 2h, psso_wrong_password_prob=0.25, psso_key_exchange_prob=0.10 and Okta configured as the ROPG IdP. Once the load test is reasonably steady state, upload a PSSO configuration profile. Let the load test run 24 hours. Do we exceed Okta's quotas?
  • Pre-QA load test: Load test aboev
  • Load testing/osquery-perf improvements: In prior story
  • This is a premium only feature: Yes

ℹ️  Please read this issue carefully and understand it. Pay special attention to UI wireframes, especially "dev notes".

Risk assessment

  • Requires testing in a hosted environment: Yes
  • Requires load testing: See above
  • Risk level: High
  • Risk description: If this feature stops working it could block logins and have relatively catastrophic results

Test plan

Make sure to go through the list and consider all events that might be related to this story, so we catch edge cases earlier.

Core flow

  • Run the load testing described above

Edge cases

  • TODO
  • TODO
  • TODO

Supplemental testing

Testing notes

Confirmation

  1. Engineer: Added comment to user story confirming successful completion of test plan (include any special setup, test data, or configuration used during development/testing if applicable).
  2. QA: Added comment to user story confirming successful completion of test plan.
  3. QA: Determined whether this story needs Playwright automation.
    • Needs automation: Yes / No
    • If yes, filed a follow-up issue in the :help-qa project with status "Needs automation": TODO

Metadata

Metadata

Labels

#g-apple-at-workProduct group focused on Apple devicesstoryA user story defining an entire feature~macos-workstationProduct maturity category~product-maturityContributes to Fleet's product maturity goals for the current year

Type

No type

Projects

Status
No status
Status
✅ Ready for release

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions