> ## Documentation Index
> Fetch the complete documentation index at: https://silmaril.dev/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Fleet

> Deploy Silmaril with a configuration profile and a custom software package.

export const macosRelease = {
  "version": "0.3.22",
  "build": "1077",
  "guardianEnabled": false,
  "minimumOS": "macOS 14 or later",
  "dmgUrl": "https://downloads.silmaril.dev/macos/releases/0.3.22/1077/Silmaril-0.3.22-1077-guardian-disabled.dmg",
  "pkgUrl": "https://downloads.silmaril.dev/macos/releases/0.3.22/1077/Silmaril-0.3.22-1077-guardian-disabled.pkg",
  "mdmZipUrl": "https://downloads.silmaril.dev/macos/releases/0.3.22/1077/Silmaril-0.3.22-1077-guardian-disabled-MDM.zip",
  "mdmChecksumUrl": "https://downloads.silmaril.dev/macos/releases/0.3.22/1077/Silmaril-0.3.22-1077-guardian-disabled-MDM.zip.sha256",
  "mdmSHA256": "86efaf60414339c97c5fcaac86d98b215f44010798f58e83ea3850b1243fd92a"
};

<a id="fleet" />

Deploy Stable {macosRelease.version} (build {macosRelease.build}) as a configuration profile and a custom software package assigned to the same hosts.

## Deploy with Fleet

<Steps>
  <Step title="Prepare">
    Have administrator access, an enrolled Mac running {macosRelease.minimumOS}, and the vendor management agent where required. Download the Stable {macosRelease.version} ({macosRelease.build}) Guardian Disabled PKG and complete the required configuration before upload.

    **Expected result**<br />
    The completed `Silmaril-Managed.mobileconfig` has passed validation, and the package is the <a href={macosRelease.pkgUrl}>Stable PKG</a>.

    **If this differs**<br />
    Finish the [rollout plan](/docs/macos/managed-deployment) before adding the Fleet profile or package.
  </Step>

  <Step title="Add the profile">
    Open Controls > OS settings > Configuration profiles and stay in the Mac's current fleet. Choose Add profile and upload the completed `Silmaril-Managed.mobileconfig`. Fleet signs uploaded profiles.

    Do not move the host to another fleet. Do not broaden this profile to all hosts to work around unavailable targeting. Label-based targeting requires Fleet Premium. Confirm a supported target for the intended hosts before upload. If that target is unavailable, stop and establish a supported scoped rollout before uploading.

    For replacement, edit the existing row and keep both the same PayloadIdentifier and PayloadDisplayName, along with all supplied UUIDs and permissions.

    **Expected result**<br />
    The profile row keeps PayloadIdentifier `dev.silmaril.mdm.managed` and PayloadDisplayName `Silmaril Managed`, plus the supplied UUIDs and permission payloads.

    **If this differs**<br />
    Edit that existing row instead of adding a second identity. Keep the supplied PayloadIdentifier, PayloadDisplayName, UUIDs, and permissions.
  </Step>

  <Step title="Confirm profile installation">
    Confirm the configuration profile is installed on the pilot hosts before distributing the app. For a later cohort, wait until those hosts show the profile installed before installing the package. Adding hosts to a label that already installs the package does not recreate that order.

    **Expected result**<br />
    Pilot hosts show the profile installed.

    **If this differs**<br />
    Wait for installation before adding or installing the package on those hosts.
  </Step>

  <Step title="Configure package installation">
    With Fleet software management and scripts enabled, open Software, stay in the current fleet, select Add software > Custom package, and upload the Stable PKG. Software cannot be added to All fleets.

    Match the package to the same devices that receive the profile. Where software labels are supported, use the same label as the profile.

    For a pilot, open Hosts > the Mac > Software > Library, find Silmaril under Available for install, and select Install. Check Status or device Activity. Use the linked automatic-install policy workflow for broader rollout. Use Fleet's supported software/package status for deployment, then verify version {macosRelease.version}, build {macosRelease.build}, and Guardian Disabled inside Silmaril.

    **Expected result**<br />
    Package status shows the Stable PKG deployed to the same targets as the profile, and Silmaril shows that version, build, and Guardian Disabled.

    **If this differs**<br />
    A package added under All fleets is outside this guide. Fleet deployment status is only the package result. Continue to launch and verify before calling the endpoint protected.
  </Step>

  <Step title="Launch and verify">
    Open Silmaril on a pilot Mac and complete [endpoint verification](/docs/macos/verify). The profile supplies the connection values. Package success or a Managed label alone does not confirm protection.

    **Expected result**<br />
    Endpoint verification shows the app identity, a Managed connection, and fresh Protection activity from a new agent session.

    **If this differs**<br />
    Keep the rollout on the pilot. Use [troubleshooting](/docs/macos/troubleshooting). Restart required means fully quit and reopen the affected agent, then start a new session.
  </Step>

  <Step title="Update or replace policy">
    For an update, deploy only the intended Guardian Disabled version and update supported app/package metadata at the same time. Replace the existing profile while preserving all supplied profile and payload identifiers, UUIDs, and permissions. Never invent identifiers to bypass a conflict. Removing managed keys restores saved local preferences. Removing the profile does not uninstall Silmaril.

    **Expected result**<br />
    The replacement profile keeps its supplied identity, and the installed app is the intended Guardian Disabled build.

    **If this differs**<br />
    Put the supplied identifiers back and [verify](/docs/macos/verify) on a pilot host. Removing managed keys returns those settings to any saved local value. Removing the profile leaves Silmaril installed.
  </Step>

  <Step title="Uninstall">
    Pause every Silmaril software install for the target Macs so Fleet cannot reinstall the app. Leave the fleet and other software in place.

    Removing a label does not uninstall the app.

    Run the shared [Uninstall through MDM](/docs/macos/uninstall) script as root with the affected user signed in, and retain the JSON receipt and exit code. Exit 2 reports remaining items to review. It does not identify Guardian residue.

    Follow the shared result-handling instructions and remove only the Silmaril profile when policy should no longer apply. Leave baseline assignments and controls in place. Do not remove the fleet.

    Upload the script in Controls > Scripts, select the Mac under Hosts, then use Actions > Run script. Inspect the result in the host activity feed. Use a manual run rather than recurring policy automation for this removal. The removal action for this guide is the shared script. An action that only deletes the app bundle leaves the rest of the documented cleanup undone.

    **If this differs**<br />
    Read that exit code before running the script again. Keep this run manual.
  </Step>
</Steps>

## Vendor references

* [Custom OS settings](https://fleetdm.com/guides/custom-os-settings)
* [Managing labels in Fleet](https://fleetdm.com/guides/managing-labels-in-fleet)
* [Deploy software packages](https://fleetdm.com/guides/deploy-software-packages)
* [Run scripts](https://fleetdm.com/guides/scripts)
* [Automatic software installation](https://fleetdm.com/guides/automatic-software-install-in-fleet)
