Files
oc-sentinel/docs/ocsentinel-deployment.md
OfficeCom Codex e8b7a2831d
Some checks failed
OfficeCom Sentinel Client / build-client (push) Has been cancelled
Document manual NinjaOne rollout for v1.2.3
2026-07-17 01:00:34 +02:00

2.4 KiB

OfficeCom Sentinel Deployment

Goal

Deploy and update the endpoint client through NinjaOne while hosting release artifacts in Gitea.

Release Assets

Each Gitea release should publish:

  • OCSentinelClient-win-x64.zip
  • OCSentinelClient-win-x64.zip.sha256
  • version.json

Build these locally with:

powershell -ExecutionPolicy Bypass -File .\build\build-client-package.ps1
powershell -ExecutionPolicy Bypass -File .\build\build-release-manifest.ps1 `
  -ArtifactUrl "https://gitea.officecom.cloud/officecom/oc-sentinel/releases/download/v1.2.3/OCSentinelClient-win-x64.zip"

Installed Layout

  • app\OCSentinelCli.exe
  • scripts\run-ocsentinel.ps1
  • scripts\run-ocsentinel-monitor.ps1
  • scripts\update-ocsentinel.ps1
  • scripts\protect-ocsentinel-secret.ps1
  • config\ocsentinel-settings.json
  • config\ocsentinel-client.json

NinjaOne Tasks

Initial install/update:

& "C:\Program Files\OCSentinel\scripts\update-ocsentinel.ps1" `
  -ManifestUrl "https://gitea.officecom.cloud/officecom/oc-sentinel/releases/download/v1.2.3/version.json" `
  -Force

Routine update:

& "C:\Program Files\OCSentinel\scripts\update-ocsentinel.ps1" `
  -ManifestUrl "https://gitea.officecom.cloud/officecom/oc-sentinel/releases/download/v1.2.3/version.json"

Runtime:

& "C:\Program Files\OCSentinel\scripts\run-ocsentinel-monitor.ps1" `
  -Mode status `
  -OutputPath "..\reports\ocsentinel-summary.json"

Secret Bootstrap

& "C:\Program Files\OCSentinel\scripts\protect-ocsentinel-secret.ps1" `
  -SecretValue "<shared-ingest-secret>"

This writes:

  • C:\ProgramData\OCSentinel\secrets\ocsentinel-upload-secret.dat

Current Manual Release State

As of July 16, 2026, the first manual release is already published:

  • tag: v1.2.3
  • release URL: https://gitea.officecom.cloud/officecom/oc-sentinel/releases/tag/v1.2.3
  • manifest URL: https://gitea.officecom.cloud/officecom/oc-sentinel/releases/download/v1.2.3/version.json

This means NinjaOne rollout can start immediately without waiting for a Gitea runner.

Later Automation

When a Gitea runner is added later, the usual next step is:

  1. connect to the runner host through SSH or RDP, depending on the server type
  2. install and register the Gitea runner
  3. let .gitea/workflows/client-build.yml publish future release artifacts automatically