# OfficeCom Sentinel Deployment ## Goal Deploy and update the endpoint client through NinjaOne while hosting release artifacts in Gitea. ## Release Assets Each Gitea release should publish: - `OCSentinelClient-win-x64.zip` - `OCSentinelClient-win-x64.zip.sha256` - `version.json` Build these locally with: ```powershell powershell -ExecutionPolicy Bypass -File .\build\build-client-package.ps1 powershell -ExecutionPolicy Bypass -File .\build\build-release-manifest.ps1 ` -ArtifactUrl "https://gitea.officecom.cloud/officecom/oc-sentinel/releases/download/v1.2.3/OCSentinelClient-win-x64.zip" ``` ## Installed Layout - `app\OCSentinelCli.exe` - `scripts\run-ocsentinel.ps1` - `scripts\run-ocsentinel-monitor.ps1` - `scripts\update-ocsentinel.ps1` - `scripts\protect-ocsentinel-secret.ps1` - `config\ocsentinel-settings.json` - `config\ocsentinel-client.json` ## NinjaOne Tasks Initial install/update: ```powershell & "C:\Program Files\OCSentinel\scripts\update-ocsentinel.ps1" ` -ManifestUrl "https://gitea.officecom.cloud/officecom/oc-sentinel/releases/download/v1.2.3/version.json" ` -Force ``` Routine update: ```powershell & "C:\Program Files\OCSentinel\scripts\update-ocsentinel.ps1" ` -ManifestUrl "https://gitea.officecom.cloud/officecom/oc-sentinel/releases/download/v1.2.3/version.json" ``` Runtime: ```powershell & "C:\Program Files\OCSentinel\scripts\run-ocsentinel-monitor.ps1" ` -Mode status ` -OutputPath "..\reports\ocsentinel-summary.json" ``` ## Secret Bootstrap ```powershell & "C:\Program Files\OCSentinel\scripts\protect-ocsentinel-secret.ps1" ` -SecretValue "" ``` This writes: - `C:\ProgramData\OCSentinel\secrets\ocsentinel-upload-secret.dat` ## Current Manual Release State As of July 16, 2026, the first manual release is already published: - tag: `v1.2.3` - release URL: `https://gitea.officecom.cloud/officecom/oc-sentinel/releases/tag/v1.2.3` - manifest URL: `https://gitea.officecom.cloud/officecom/oc-sentinel/releases/download/v1.2.3/version.json` This means NinjaOne rollout can start immediately without waiting for a Gitea runner. ## Later Automation When a Gitea runner is added later, the usual next step is: 1. connect to the runner host through SSH or RDP, depending on the server type 2. install and register the Gitea runner 3. let `.gitea/workflows/client-build.yml` publish future release artifacts automatically