diff --git a/docs/ocsentinel-deployment.md b/docs/ocsentinel-deployment.md index 25566c2..40fe14d 100644 --- a/docs/ocsentinel-deployment.md +++ b/docs/ocsentinel-deployment.md @@ -130,9 +130,10 @@ The script has no script variables and does the following safely: 2. stores the current NinjaOne organization, location, node, and machine values; 3. starts one signed status scan and upload using that stored context. -Expected output includes `OCSENTINEL_NINJA_CONTEXT=updated`. Do not run this -script from an interactive PowerShell session, because NinjaOne does not expose -the required environment values there. +Expected output includes `OCSENTINEL_NINJA_CONTEXT=updated`; this is emitted +only after the immediate upload succeeds. Do not run this script from an +interactive PowerShell session, because NinjaOne does not expose the required +environment values there. ## Secret Bootstrap diff --git a/scripts/refresh-ocsentinel-ninja-context.ps1 b/scripts/refresh-ocsentinel-ninja-context.ps1 index d4451a9..2cdec70 100644 --- a/scripts/refresh-ocsentinel-ninja-context.ps1 +++ b/scripts/refresh-ocsentinel-ninja-context.ps1 @@ -88,20 +88,23 @@ if ($missing.Count -gt 0) { $clientConfig | ConvertTo-Json -Depth 10 | Set-Content -LiteralPath $clientConfigPath -Encoding UTF8 Write-Host "OCSentinel NinjaOne context captured: $captured of $($mappings.Count) values." -if ((Test-Path -LiteralPath $secretPath) -and -not [string]::IsNullOrWhiteSpace([string]$clientConfig.n8nWebhookUrl)) { - Write-Host "Running an immediate status scan and upload with the refreshed NinjaOne context." - & powershell.exe -NoProfile -ExecutionPolicy Bypass -File $monitorPath ` - -Mode status ` - -ClientConfigPath $clientConfigPath ` - -SecretPath $secretPath ` - -UploadMode required ` - -SuppressTriggerExit - if ($LASTEXITCODE -ne 0) { - throw "OCSentinel context refresh scan exited with code $LASTEXITCODE" - } +if ([string]::IsNullOrWhiteSpace([string]$clientConfig.n8nWebhookUrl)) { + throw "NinjaOne context was stored, but this client has no configured n8n webhook URL. Run the OCSentinel installation/configuration automation with its WebhookUrl variable first." } -else { - Write-Warning "Context was stored, but the upload configuration or protected secret is missing. The next configured scan will use the stored context." + +if (-not (Test-Path -LiteralPath $secretPath)) { + throw "NinjaOne context was stored, but the protected upload secret is missing. Run the OCSentinel installation/configuration automation with its SecretValue variable first." +} + +Write-Host "Running an immediate status scan and upload with the refreshed NinjaOne context." +& powershell.exe -NoProfile -ExecutionPolicy Bypass -File $monitorPath ` + -Mode status ` + -ClientConfigPath $clientConfigPath ` + -SecretPath $secretPath ` + -UploadMode required ` + -SuppressTriggerExit +if ($LASTEXITCODE -ne 0) { + throw "OCSentinel context refresh scan exited with code $LASTEXITCODE" } Write-Host "OCSENTINEL_NINJA_CONTEXT=updated"