A bundle is a folder dp-deploy produces once, on a workstation, and that you copy to a share your machines can read. dp-deploy — shipped signed beside the installer — builds two kinds:
| Kind | Built by | Carries | Secrets |
|---|---|---|---|
| The deployment MSI bundle | dp-deploy build-msi | One installer package with the captured configuration, certificates, secrets, console password and a list of licence keys inside it | Encrypted in the package, under a deployment key you deliver separately |
| The transform bundle | dp-deploy bundle | The signed product MSI, unchanged, plus a transform (.mst) that carries a validated configuration and one licence key | None — the configuration must refer to no secrets |
Both are checked with dp-deploy verify DIR (every file re-hashed and, on Windows, the package's rows read back) and described by dp-deploy inspect DIR. Nothing in either is secret. Integrity is the share's permissions and your change control plus dp-deploy verify; the manifest is not signed.
The deployment MSI bundle
How to make one, and what the installer does with it, is under The deployment MSI. This is what the folder contains.
dp-deploy build-msi --payload C:\deploy\capture-1 --msi dplens-1.0.912.msi --out C:\deploy\bundle-1 `
--licence corp.lic --licence lab-01.lic
| Option | Meaning |
|---|---|
--payload DIR | The capture folder from dp-deploy capture (deploy.payload, and capture.json if present). A capture past its expiry is refused. |
--msi FILE | The signed product MSI. Read, never modified; the derived package is a copy with two rows added. |
--out DIR | The bundle folder (created). |
--licence FILE | A key to include; repeat for each. Every key is verified against the publisher key before it goes in — an expired or altered key is refused, a repeated key is refused — and its binding is printed in words. |
--no-com | Write everything except the package, plus the one command that builds it on any Windows machine. The default builds it here. |
Files in a deployment MSI bundle
| File | Content |
|---|---|
dplens-<version>-deploy.msi | The deployment MSI: the product MSI plus two rows — the encrypted capture and the licence key list. Unsigned; sign it before distribution. |
deploy.payload | The encrypted capture, exactly the bytes embedded in the package. Kept beside it for updates. |
capture.json | What was captured: host, agent version, configuration epoch, the names of the secret handles and certificate files, the acknowledged findings, whether the console certificate rode along. No values. |
licence-keys.dpll | The licence keys as one list. Signed public tokens, not secrets. |
Stage-DeployKey.ps1 | Puts the deployment key on a target at one of the three locations the installer reads, with the right permissions, in one step. |
Make-DerivedMsi.ps1, Verify-DerivedMsi.ps1 | Build and read back the package through the Windows Installer interface present on every Windows; dp-deploy verify runs the second. |
Push-Host.ps1, Push-Credential.ps1 | Written the first time you push from this bundle. |
README.md | The instructions for this bundle: the key, the locations, the msiexec line, the expiry. |
bundle.json | The manifest (format 2). |
The deployment MSI manifest
{
"format": 2,
"created": "2026-09-16T12:00:00Z",
"tool": "dp-deploy 1.0.0",
"source_msi": { "file": "dplens-1.0.912.msi", "sha256": "…" },
"msi": { "file": "dplens-1.0.912-deploy.msi", "sha256": "…", "product_version": "1.0.912",
"product_code": "{…}", "upgrade_code": "{…}" },
"payload": { "file": "deploy.payload", "sha256": "…", "bytes": 3030, "bundle_id": "…",
"created": 1789000000, "not_after": 1791592000, "envelopes": 1 },
"licence_keys": { "file": "licence-keys.dpll", "sha256": "…",
"keys": [ { "key_id": "…", "licence_id": "…", "customer": "…", "expiry": "2027-09-16",
"binding_kind": "domains", "binding": ["corp.example"] } ] },
"capture": { "host": "ref-01", "agent_version": "1.0.912", "epoch": 202609161200,
"secret_handles": ["secret://splunk/hec-token"], "cert_files": ["ca.pem"],
"acknowledged": [], "include_console_cert": false },
"binary_rows": { "DpLensPayload": "…", "DpLensLicenceKeys": "…" },
"files": { "deploy.payload": "…", "licence-keys.dpll": "…", "…": "…" }
}
not_after is absent when the capture had no expiry. Unknown fields are rejected, so a manifest of one format is refused by a tool that only knows the other, by name.
The transform bundle
Use it when your configuration refers to no secrets and you deploy with Group Policy Software Installation: the product MSI stays byte-for-byte the signed download, and a transform beside it carries the configuration and the licence. Nothing runs on the target but the installer. The recipe is Group Policy — Recipe B.
dp-deploy bundle --config agent.yaml --msi dplens-1.0.912.msi --out \\files\dplens\bundle-42 `
--licence corp.lic --console off --service-account vsa --epoch 42 --no-script
| Option | Meaning |
|---|---|
--config FILE | The agent document. Validated with the agent's real validator (parse, semantics, allowlists). It may reference no secret://… handle. |
--msi FILE | The signed product MSI. Copied byte-for-byte; never modified (its signature stays valid). |
--out DIR | The bundle folder (created). |
--licence FILE | One key. Signature, expiry, key id and revocation are verified; the binding is reported in words. |
--console on|off, --ui-port N | Written INTO the document's settings.ui (the MSI refuses CONFIG_YAML together with UI_PORT/CONSOLE, so the bundle never uses those properties). Re-renders the document: comments are lost. |
--service-account vsa|localsystem | The service identity (default vsa). |
--epoch N | The configuration epoch for change control; default = the UTC minute YYYYMMDDHHMM. |
--agent-exe FILE | Optional deep validation: runs an installed dplens.exe --validate-only over the rendered document, the same check the target will make. |
--no-script | Always give it. Earlier preview releases emitted a Group Policy startup script that fetched secret values from your vault at boot; that recipe is withdrawn — a configuration that references a secret belongs in a deployment MSI. |
--no-transform | Emit the transform inputs without building the .mst (it builds on Windows only). |
dp-deploy properties --config … [--licence …] prints the non-secret PROP="value" string for a one-host msiexec /i dplens.msi /qn … without a transform.
Files in a transform bundle
| File | Content |
|---|---|
dplens-<version>.msi | The signed product MSI, unchanged |
dplens.mst | The transform: rows CONFIG_YAML (the document, base64url), LICENCE_KEY (when supplied), SERVICE_ACCOUNT. Validated against the MSI's product and upgrade codes — a new MSI needs a new bundle. Built by Make-Transform.ps1 through the Windows Installer interface present on every Windows. |
transform-rows.json | The rows above, as Make-Transform.ps1 reads them |
agent.yaml | The validated document exactly as the target installs it |
licence.lic | The token (public, signed — not secret material) |
Make-Transform.ps1, Verify-Transform.ps1 | Rebuild / prove the transform on any Windows box |
README.md | The Group Policy recipe for this bundle |
bundle.json | The manifest (format 1) |
The transform bundle manifest
{
"format": 1,
"created": "2026-09-09T12:00:00Z",
"tool": "dp-deploy 1.0.0",
"epoch": 42,
"msi": { "file": "dplens-1.0.912.msi", "sha256": "…", "product_version": "1.0.912", "product_code": "{…}", "upgrade_code": "{…}" },
"transform": { "file": "dplens.mst", "sha256": "…" },
"config": { "file": "agent.yaml", "sha256": "…", "bytes": 1234, "console_enabled": false, "ui_port": 8443,
"service_account": "vsa", "secret_handles": [] },
"licence": { "file": "licence.lic", "sha256": "…", "key_id": "…", "licence_id": "…", "customer": "…",
"expiry": "2027-09-09", "binding_kind": "domains", "binding": ["corp.example"] },
"transform_properties": { "CONFIG_YAML": "(agent.yaml, base64url; sha256 …)", "LICENCE_KEY": "DPL1.…", "SERVICE_ACCOUNT": "vsa" },
"files": { "agent.yaml": "…", "dplens-1.0.912.msi": "…", "…": "…" }
}
dp-deploy verify DIR re-hashes every file, re-validates the document and (on Windows) re-applies the transform to prove it still changes exactly the recorded rows.
Change control
Rebuild whenever the document, the licence keys or the MSI change and replace the folder's contents — a new capture and a new --licence set for a deployment MSI bundle, a new --epoch for a transform bundle. Keep the previous bundle: for a fleet updated by push it is the rollback. The installer refuses downgrades, and a configuration that fails validation on the target fails the install loudly rather than installing something wrong.