From 05029c9fb2e2de8d6a5a20bb0baca461897490bd Mon Sep 17 00:00:00 2001 From: OfficeCom Codex Date: Fri, 17 Jul 2026 01:12:38 +0200 Subject: [PATCH] Track internal Postgres target in release process --- README.md | 3 +++ docs/ocsentinel-architecture.md | 9 +++++++++ docs/ocsentinel-n8n-contract.md | 6 ++++++ docs/release-checklist.md | 25 +++++++++++++++++++++++++ infra/postgres-target.example.json | 10 ++++++++++ 5 files changed, 53 insertions(+) create mode 100644 docs/release-checklist.md create mode 100644 infra/postgres-target.example.json diff --git a/README.md b/README.md index 61188b7..914684c 100644 --- a/README.md +++ b/README.md @@ -9,7 +9,10 @@ OfficeCom Sentinel is the hardened endpoint client for Windows event correlation - Ninja monitor wrapper: `scripts/run-ocsentinel-monitor.ps1` - packaged installer runtime: `installer/runtime-run-ocsentinel.ps1` - package builder: `build/build-client-package.ps1` +- setup EXE builder: `build/build-client-installer.ps1` - update manifest builder: `build/build-release-manifest.ps1` +- release checklist: `docs/release-checklist.md` +- internal server-side target example: `infra/postgres-target.example.json` ## Build diff --git a/docs/ocsentinel-architecture.md b/docs/ocsentinel-architecture.md index 40a1c56..03a455f 100644 --- a/docs/ocsentinel-architecture.md +++ b/docs/ocsentinel-architecture.md @@ -19,6 +19,15 @@ The repository now keeps only the client-side architecture: - optional n8n upload - packaged ZIP release flow for NinjaOne deployment +The client must not depend on a PostgreSQL IP or hostname. PostgreSQL stays a server-side concern behind the ingest or n8n layer. + +## PostgreSQL Handling + +- PostgreSQL is not contacted directly by endpoint clients. +- The PostgreSQL host or IP should be tracked in the repository only as internal deployment metadata. +- Review that internal target on every release before publishing. +- Keep the actual production value in a private operational copy if it should not be visible in the public repository. + ## Removed Model The following older pieces are intentionally no longer part of the repo: diff --git a/docs/ocsentinel-n8n-contract.md b/docs/ocsentinel-n8n-contract.md index 5888514..9d163a4 100644 --- a/docs/ocsentinel-n8n-contract.md +++ b/docs/ocsentinel-n8n-contract.md @@ -25,3 +25,9 @@ n8n is responsible for: - storage in the central backend - organization-wide aggregation - NinjaOne organization API updates + +## PostgreSQL Scope + +- The client only knows its outward upload destination. +- PostgreSQL connection details belong to the internal ingest or n8n side. +- If the PostgreSQL IP changes, update the internal server-side configuration and review it during the next release. diff --git a/docs/release-checklist.md b/docs/release-checklist.md new file mode 100644 index 0000000..3d20954 --- /dev/null +++ b/docs/release-checklist.md @@ -0,0 +1,25 @@ +# Release Checklist + +## Goal + +Use this checklist before publishing every OfficeCom Sentinel release. + +## Infrastructure Check + +1. Confirm the internal PostgreSQL target is still correct in `infra/postgres-target.example.json` or its private production counterpart. +2. Confirm the n8n internal base URL is still correct. +3. Confirm the public client ingest URL still forwards to the intended internal service. +4. Confirm no internal PostgreSQL host or IP is embedded in client configuration, installer output, or public release artifacts. + +## Build Check + +1. Build `OCSentinelClient-win-x64.zip`. +2. Build `OCSentinelSetup.exe`. +3. Generate `version.json`. +4. Verify SHA-256 output matches the released ZIP. + +## Publish Check + +1. Upload the ZIP, SHA256 file, and setup EXE to the release. +2. Update `release/stable/version.json` so NinjaOne keeps a version-independent manifest URL. +3. If infrastructure changed, update the internal Postgres target record in the repo at the same time. diff --git a/infra/postgres-target.example.json b/infra/postgres-target.example.json new file mode 100644 index 0000000..1cfd7ea --- /dev/null +++ b/infra/postgres-target.example.json @@ -0,0 +1,10 @@ +{ + "role": "server-side-only", + "environment": "production", + "postgresHost": "10.0.0.25", + "postgresPort": 5432, + "postgresDatabase": "ocsentinel", + "postgresSslMode": "require", + "n8nInternalBaseUrl": "http://n8n.internal:5678", + "notes": "This file is for the internal ingest or n8n side only. Do not deploy this file to endpoint clients." +}