Context
Three iPads were managed by a previous provider through Cisco Meraki. The provider has released them: removed from their Apple Business Manager, deleted from their Meraki dashboard, Activation Lock cleared. The iPads leave the building on 2026-08-20. After that there is no physical access. All takeover work that needs hands must happen on 2026-08-19.
Goal
Bring the three iPads under our own remote management (supervised + MDM), so we can install and operate hydraheadipad on them fully remotely after they leave.
Plan
Remote steps (Claude can run these via web/API)
- MDM setup: sign up for SimpleMDM (30-day trial, has a full REST API). Create device group
hydra-ipad-heads. Build profiles: venue Wi-Fi, single app mode settings, block OS-update prompts. Generate per-device enrollment.
- Supervision via cfgutil: with the iPads plugged into cederikmini over USB, run
cfgutil erase / cfgutil prepare remotely (cederikmini is exec-reachable) to wipe, supervise, and enroll each device into the MDM in one pass.
- hydracluster prep: pre-check that the head names are free on BOTH hydracluster and HydraGuard before each enrollment. The app enrolls every device under the default name
ipad-head; a HydraGuard name collision leaves a device silently without WireGuard config. Enroll one device at a time. Procedure: hydracluster/docs/runbooks/runbook.md, section Head Management.
- Build check: confirm a VALID hydraheadipad build on hydrapipelineapple.experiencenet.com before install.
- ABM application: start Apple Business Manager signup (D-U-N-S) this week. Goal: move app distribution from TestFlight to Custom Apps, because TestFlight builds expire after 90 days, which is unacceptable for unattended kiosks.
Hands-on steps (must happen 2026-08-19, before the devices leave)
- Plug the three iPads into cederikmini via USB; a few Setup Assistant taps per device.
- Scan the hydracluster enrollment QR on each device.
- Later: answer Apple's ABM verification contact (company side).
Definition of done
- All 3 iPads supervised and visible in the MDM, remote Single App Mode verified.
- All 3 enrolled in hydracluster with unique head names and working WireGuard config.
- hydraheadipad installed and streaming verified on at least one device.
- ABM application submitted (follow-up: Custom App distribution).
Progress 2026-08-19 (evening)
Done remotely:
- SimpleMDM account "Hydra experiencenet" live (created by Cederik), API key stored in Claude memory.
- Device group
hydra-ipad-heads (id 2425035) + group enrollment "ipad-heads-usb-2026-08" (id 346255).
- Apple Configurator installed on cederikmini (manual App Store click by Cederik); cfgutil 2.20 verified over hydracluster exec.
- Supervision identity generated (openssl, 10y) at
~/ipad-takeover/supervision-*.{der,pem} on cederikmini. BACK THIS UP; it is the tethered-management key for these devices.
- Run script staged:
~/ipad-takeover/takeover-ipads.sh (erase -> prepare supervised -> install SimpleMDM enrollment profile).
Open:
- Venue Wi-Fi SSID + passphrase for the Wi-Fi profile (needed so the iPads have network after the wipe).
- Physical: plug 3 iPads into cederikmini via USB, run the script (or Claude runs it via exec).
- Later: hydracluster enrollment one device at a time (QR), ABM application, store country US -> BE.
Progress 2026-08-19 (night) — TAKEOVER COMPLETE
All 3 iPads (iPad Pro 11" M4) supervised + enrolled + grouped, done same day:
| SimpleMDM id |
Serial |
ECID |
Name |
| 2373770 |
CD41QG5C44 |
0x197119340B801C |
ipad-head-1-CD41QG5C44 |
| 2373882 |
CPQD0CW7CG |
0xA14A10EE3801C |
ipad-head-2-CPQD0CW7CG |
| 2373883 |
FQ70X0JHF6 |
0xA241A1E7B801C |
ipad-head-3-FQ70X0JHF6 |
All supervised by "Hydra ExperienceNet" (identity at cederikmini ~/ipad-takeover/supervision-*.der — BACK UP), enrolled in SimpleMDM, in group hydra-ipad-heads (assignment_group 2425035) with the venue Wi-Fi profile. Devices can leave the building; management is remote from here on.
Key API learning: the v2 UI "Groups" are assignment_groups in the API, not device_groups. Enrollment installs need device internet (Setup Assistant blocks Wi-Fi until its pane is passed; error 4001 = no network).
Remaining follow-ups (this issue stays open):
- Back up the supervision identity off cederikmini.
- TestFlight/hydraheadipad install once a VALID build is confirmed; then hydracluster enrollment one device at a time (name collision runbook).
- Single App Mode config in SimpleMDM once hydraheadipad is on the devices.
- ABM application (D-U-N-S) -> Custom App distribution to replace TestFlight (90-day expiry).
- Store country US -> BE in SimpleMDM account settings.
Progress 2026-08-19 (late night) — hydracluster enrollment COMPLETE
- Distribution moved OFF TestFlight: ad hoc IPA lane in release.yml, pushed via SimpleMDM (working since v0.2.157/build 189; upload bug fixed same night). Developer Mode enabled by hand on each device (ad hoc requirement; goes away with #518).
- v0.2.158 fixed the enrollment name collision app-side: unique default head name ipad-head- instead of hardcoded "ipad-head" (hydracluster #449 context). Delivered to all three iPads via the MDM lane.
- All three enrolled in hydracluster with per-device HydraGuard WireGuard configs:
ipad-head-9dfddd = node-fe6e7808, ipad-head-252bbc = node-e0528a7e, ipad-head-daffbf = node-a57ee1a7. All online, v0.2.158.
- Supervision identity backed up (verified) to Storage Box u645590: hydramdm-backups/supervision-identity-2026-08-19/.
- Remaining before devices leave: tap "Allow VPN Configurations" once per device so the WireGuard tunnel is installed (diagnostics currently show wireguard: not-installed).
- Serial-to-head-name mapping not yet recorded; capture it when known.
CLOSED 2026-08-20
Definition of done met in full: 3 iPads supervised + SimpleMDM-enrolled in hydra-ipad-heads, enrolled in hydracluster with unique names + working WireGuard (map-35/37/39), HydraHeadiPad delivered via the MDM ad hoc lane (v0.2.158/build 190) and portrait streaming VERIFIED on both production bodies. Follow-ups moved out: ABM -> #518, fleet hardening (Single App Mode, store country, paid plan, serial mapping, VDD dedupe) -> #532, selection race -> #530, uniqueid -> #531.