Deploying

The deployment bundle

What a bundle folder contains, its manifest, and the transform bundle for configurations that need no secrets.

A bundle is a folder dp-deploy produces once, on a workstation, and that you copy to a share your machines can read. dp-deploy — shipped signed beside the installer — builds two kinds:

KindBuilt byCarriesSecrets
The deployment MSI bundledp-deploy build-msiOne installer package with the captured configuration, certificates, secrets, console password and a list of licence keys inside itEncrypted in the package, under a deployment key you deliver separately
The transform bundledp-deploy bundleThe signed product MSI, unchanged, plus a transform (.mst) that carries a validated configuration and one licence keyNone — the configuration must refer to no secrets

Both are checked with dp-deploy verify DIR (every file re-hashed and, on Windows, the package's rows read back) and described by dp-deploy inspect DIR. Nothing in either is secret. Integrity is the share's permissions and your change control plus dp-deploy verify; the manifest is not signed.

The deployment MSI bundle

How to make one, and what the installer does with it, is under The deployment MSI. This is what the folder contains.

dp-deploy build-msi --payload C:\deploy\capture-1 --msi dplens-1.0.912.msi --out C:\deploy\bundle-1 `
    --licence corp.lic --licence lab-01.lic
OptionMeaning
--payload DIRThe capture folder from dp-deploy capture (deploy.payload, and capture.json if present). A capture past its expiry is refused.
--msi FILEThe signed product MSI. Read, never modified; the derived package is a copy with two rows added.
--out DIRThe bundle folder (created).
--licence FILEA key to include; repeat for each. Every key is verified against the publisher key before it goes in — an expired or altered key is refused, a repeated key is refused — and its binding is printed in words.
--no-comWrite everything except the package, plus the one command that builds it on any Windows machine. The default builds it here.

Files in a deployment MSI bundle

FileContent
dplens-<version>-deploy.msiThe deployment MSI: the product MSI plus two rows — the encrypted capture and the licence key list. Unsigned; sign it before distribution.
deploy.payloadThe encrypted capture, exactly the bytes embedded in the package. Kept beside it for updates.
capture.jsonWhat was captured: host, agent version, configuration epoch, the names of the secret handles and certificate files, the acknowledged findings, whether the console certificate rode along. No values.
licence-keys.dpllThe licence keys as one list. Signed public tokens, not secrets.
Stage-DeployKey.ps1Puts the deployment key on a target at one of the three locations the installer reads, with the right permissions, in one step.
Make-DerivedMsi.ps1, Verify-DerivedMsi.ps1Build and read back the package through the Windows Installer interface present on every Windows; dp-deploy verify runs the second.
Push-Host.ps1, Push-Credential.ps1Written the first time you push from this bundle.
README.mdThe instructions for this bundle: the key, the locations, the msiexec line, the expiry.
bundle.jsonThe manifest (format 2).

The deployment MSI manifest

{
  "format": 2,
  "created": "2026-09-16T12:00:00Z",
  "tool": "dp-deploy 1.0.0",
  "source_msi": { "file": "dplens-1.0.912.msi", "sha256": "…" },
  "msi": { "file": "dplens-1.0.912-deploy.msi", "sha256": "…", "product_version": "1.0.912",
           "product_code": "{…}", "upgrade_code": "{…}" },
  "payload": { "file": "deploy.payload", "sha256": "…", "bytes": 3030, "bundle_id": "…",
               "created": 1789000000, "not_after": 1791592000, "envelopes": 1 },
  "licence_keys": { "file": "licence-keys.dpll", "sha256": "…",
                    "keys": [ { "key_id": "…", "licence_id": "…", "customer": "…", "expiry": "2027-09-16",
                                "binding_kind": "domains", "binding": ["corp.example"] } ] },
  "capture": { "host": "ref-01", "agent_version": "1.0.912", "epoch": 202609161200,
               "secret_handles": ["secret://splunk/hec-token"], "cert_files": ["ca.pem"],
               "acknowledged": [], "include_console_cert": false },
  "binary_rows": { "DpLensPayload": "…", "DpLensLicenceKeys": "…" },
  "files": { "deploy.payload": "…", "licence-keys.dpll": "…", "…": "…" }
}

not_after is absent when the capture had no expiry. Unknown fields are rejected, so a manifest of one format is refused by a tool that only knows the other, by name.

The transform bundle

Use it when your configuration refers to no secrets and you deploy with Group Policy Software Installation: the product MSI stays byte-for-byte the signed download, and a transform beside it carries the configuration and the licence. Nothing runs on the target but the installer. The recipe is Group Policy — Recipe B.

dp-deploy bundle --config agent.yaml --msi dplens-1.0.912.msi --out \\files\dplens\bundle-42 `
    --licence corp.lic --console off --service-account vsa --epoch 42 --no-script
OptionMeaning
--config FILEThe agent document. Validated with the agent's real validator (parse, semantics, allowlists). It may reference no secret://… handle.
--msi FILEThe signed product MSI. Copied byte-for-byte; never modified (its signature stays valid).
--out DIRThe bundle folder (created).
--licence FILEOne key. Signature, expiry, key id and revocation are verified; the binding is reported in words.
--console on|off, --ui-port NWritten INTO the document's settings.ui (the MSI refuses CONFIG_YAML together with UI_PORT/CONSOLE, so the bundle never uses those properties). Re-renders the document: comments are lost.
--service-account vsa|localsystemThe service identity (default vsa).
--epoch NThe configuration epoch for change control; default = the UTC minute YYYYMMDDHHMM.
--agent-exe FILEOptional deep validation: runs an installed dplens.exe --validate-only over the rendered document, the same check the target will make.
--no-scriptAlways give it. Earlier preview releases emitted a Group Policy startup script that fetched secret values from your vault at boot; that recipe is withdrawn — a configuration that references a secret belongs in a deployment MSI.
--no-transformEmit the transform inputs without building the .mst (it builds on Windows only).

dp-deploy properties --config … [--licence …] prints the non-secret PROP="value" string for a one-host msiexec /i dplens.msi /qn … without a transform.

Files in a transform bundle

FileContent
dplens-<version>.msiThe signed product MSI, unchanged
dplens.mstThe transform: rows CONFIG_YAML (the document, base64url), LICENCE_KEY (when supplied), SERVICE_ACCOUNT. Validated against the MSI's product and upgrade codes — a new MSI needs a new bundle. Built by Make-Transform.ps1 through the Windows Installer interface present on every Windows.
transform-rows.jsonThe rows above, as Make-Transform.ps1 reads them
agent.yamlThe validated document exactly as the target installs it
licence.licThe token (public, signed — not secret material)
Make-Transform.ps1, Verify-Transform.ps1Rebuild / prove the transform on any Windows box
README.mdThe Group Policy recipe for this bundle
bundle.jsonThe manifest (format 1)

The transform bundle manifest

{
  "format": 1,
  "created": "2026-09-09T12:00:00Z",
  "tool": "dp-deploy 1.0.0",
  "epoch": 42,
  "msi": { "file": "dplens-1.0.912.msi", "sha256": "…", "product_version": "1.0.912", "product_code": "{…}", "upgrade_code": "{…}" },
  "transform": { "file": "dplens.mst", "sha256": "…" },
  "config": { "file": "agent.yaml", "sha256": "…", "bytes": 1234, "console_enabled": false, "ui_port": 8443,
              "service_account": "vsa", "secret_handles": [] },
  "licence": { "file": "licence.lic", "sha256": "…", "key_id": "…", "licence_id": "…", "customer": "…",
               "expiry": "2027-09-09", "binding_kind": "domains", "binding": ["corp.example"] },
  "transform_properties": { "CONFIG_YAML": "(agent.yaml, base64url; sha256 …)", "LICENCE_KEY": "DPL1.…", "SERVICE_ACCOUNT": "vsa" },
  "files": { "agent.yaml": "…", "dplens-1.0.912.msi": "…", "…": "…" }
}

dp-deploy verify DIR re-hashes every file, re-validates the document and (on Windows) re-applies the transform to prove it still changes exactly the recorded rows.

Change control

Rebuild whenever the document, the licence keys or the MSI change and replace the folder's contents — a new capture and a new --licence set for a deployment MSI bundle, a new --epoch for a transform bundle. Keep the previous bundle: for a fleet updated by push it is the rollback. The installer refuses downgrades, and a configuration that fails validation on the target fails the install loudly rather than installing something wrong.