Files
oc-sentinel/docs/ocsentinel-architecture.md
OfficeCom Codex 05029c9fb2
Some checks failed
OfficeCom Sentinel Client / build-client (push) Has been cancelled
Track internal Postgres target in release process
2026-07-17 01:12:38 +02:00

1.3 KiB

OfficeCom Sentinel Architecture

Goal

OfficeCom Sentinel is a Windows endpoint client that:

  • runs on every monitored device
  • reads local attack telemetry and optional local vulnerability exports
  • writes NinjaOne device custom fields locally
  • uploads signed JSON reports to n8n
  • receives updates through NinjaOne tasks from Gitea-hosted releases

Current Model

The repository now keeps only the client-side architecture:

  • endpoint scan and correlation
  • local NinjaOne field publishing
  • optional n8n upload
  • packaged ZIP release flow for NinjaOne deployment

The client must not depend on a PostgreSQL IP or hostname. PostgreSQL stays a server-side concern behind the ingest or n8n layer.

PostgreSQL Handling

  • PostgreSQL is not contacted directly by endpoint clients.
  • The PostgreSQL host or IP should be tracked in the repository only as internal deployment metadata.
  • Review that internal target on every release before publishing.
  • Keep the actual production value in a private operational copy if it should not be visible in the public repository.

Removed Model

The following older pieces are intentionally no longer part of the repo:

  • share-based organization aggregation
  • dedicated server-side collector package
  • server-side NinjaOne organization field updater