Documentation PI Nexus+ Documentation

PI Nexus+ / Reference

Installer and Script Parameters

This reference lists the installer's pages and properties, how it behaves on upgrade, repair and removal, and the parameters of the setup and recovery scripts.

Overview

This reference lists the installer's pages and properties, how it behaves on upgrade, repair and removal, and the parameters of the setup and recovery scripts.

Setup program

PI-Nexus-Setup-<version>.exe installs, in this order, the Visual C++ 2015–2022 Redistributable (x64), the PI Nexus+ MSI and the .NET 10 Hosting Bundle. The Hosting Bundle comes last so that it finds IIS, which the MSI turns on. The setup program does not pass properties to the MSI, so /quiet alone cannot set the service account. For a silent installation, extract the packages with /layout <folder> and run them in the same order: vc_redist.x64.exe /install /quiet /norestart, then msiexec with the properties below, then dotnet-hosting-10-win.exe /quiet /norestart (see Run the Installer in the Installation Guide). Use /log "<path>" to choose the setup log.

Wizard pages (first installation)

PageFieldDefaultNotes
License agreement, installation folderC:\Program Files\Software Athlete\PI Nexus+
Choose componentsWeb application (IIS), Scanner serviceBoth tickedAt least one is required
Configure PI Nexus+Service accountEmptyDOMAIN\User, .\User, user@domain, or a gMSA as DOMAIN\Account$
Service passwordEmptyRequired except for a gMSA
IIS HTTP port5139Shown only with the web application
Write SQL bootstrap configuration nowTickedAlways on for a scanner-only installation
SQL ServerEmptyRequired while Write SQL bootstrap configuration now is ticked
SQL databasePINexus
Secret certificateEmptyThumbprint; spaces and hidden characters are removed. Empty keeps Windows DPAPI
Last pageRun PI Nexus+ Database Setup nowTickedFirst installation only

An upgrade shows none of the component or configuration pages; it keeps the installed settings.

MSI properties

PropertyMeaningDefault
ADDLOCALComponents to install: WebApplication, ScannerService or both, comma-separatedBoth
REMOVEComponents to remove in a maintenance installationNone
SERVICEACCOUNTService accountRequired
SERVICEPASSWORDIts password; omit for a gMSARequired otherwise
IISPORTHTTP port of the site5139, or the remembered port
SQLSERVERSQL Server instance for bootstrap.jsonEmpty; required when CONFIGURESQLBOOTSTRAP is 1
SQLDATABASEDatabase for bootstrap.jsonPINexus
CONFIGURESQLBOOTSTRAP1 writes bootstrap.json, 0 skips it. Never 0 for a scanner-only installation1
SECRETCERTIFICATETHUMBPRINTSecret certificate thumbprint written to bootstrap.jsonEmpty
INSTALLFOLDERInstallation folderC:\Program Files\Software Athlete\PI Nexus+

bootstrap.json is written only if it does not exist yet. A thumbprint given at installation is added to an existing file without changing its SQL settings.

Silent installation examples

msiexec /i PINexus.Setup.msi /qn /l*v "%TEMP%\PINexus-msi.log" ADDLOCAL=WebApplication,ScannerService SERVICEACCOUNT="DOMAIN\svc-pinexus" SERVICEPASSWORD="..." IISPORT=5139 SQLSERVER="SQL01" SQLDATABASE="PINexus"

msiexec /i PINexus.Setup.msi /qn ADDLOCAL=WebApplication SERVICEACCOUNT="DOMAIN\svc-pinexus-web" SERVICEPASSWORD="..." IISPORT=5139 SQLSERVER="SQL01" SQLDATABASE="PINexus" SECRETCERTIFICATETHUMBPRINT="<thumbprint>"

msiexec /i PINexus.Setup.msi /qn ADDLOCAL=ScannerService SERVICEACCOUNT="DOMAIN\svc-pinexus-scan" SERVICEPASSWORD="..." SQLSERVER="SQL01" SQLDATABASE="PINexus" SECRETCERTIFICATETHUMBPRINT="<thumbprint>"

msiexec /i PINexus.Setup.msi /qn SERVICEACCOUNT="DOMAIN\svc-pinexus$" SQLSERVER="SQL01" SQLDATABASE="PINexus"

Leave out SECRETCERTIFICATETHUMBPRINT when no OpenID Connect target is used.

Installer behaviour

OperationWhat happens
First installationTurns on IIS (web application), creates the site, app pool and service under the account, grants folder rights, writes bootstrap.json
UpgradeStops the scanner service, site and app pool; replaces files; starts them again. Keeps components, identities, bindings and bootstrap.json. Passing ADDLOCAL or REMOVE on an upgrade switches off the component carry-over; don't
Upgrade from 1.6.x or earlierInstalls both components, as before
DowngradeRefused: A newer version of PI Nexus+ is already installed.
RepairRestores files; leaves the site, app pool, service and identities as they are
Add a component (msiexec /i {ProductCode} ADDLOCAL=...)Creates its site or service; needs SERVICEACCOUNT and SERVICEPASSWORD
Remove a component (msiexec /i {ProductCode} REMOVE=...)Deletes its site or service and files; keeps the other component, bootstrap.json, logs and database
UninstallRemoves the site, app pool, service and program files; keeps bootstrap.json, logs and database

The product code is in the installer log and under the Windows uninstall registry key. IIS and service configuration steps time out after 5 and 3 minutes.

Setup-Database.ps1

Run from C:\Program Files\Software Athlete\PI Nexus+\Admin. Without parameters it asks for each value.

ParameterMeaningDefault
-SqlServerSQL Server instanceAsked
-DatabaseDatabase nameAsked, PINexus
-ServiceAccountService account, DOMAIN\User or user@domainAsked
-SecondServiceAccountSecond account on a split deployment; gets the same grantsAsked only in interactive use
-BootstrapPathWhere to write bootstrap.jsonC:\ProgramData\Software Athlete\PI Nexus+\bootstrap.json
-MigrationsPathFolder with the migration filesAdmin\Migrations
-WorkerServiceNameService to start afterwardsPI Nexus+ Scanner
-SkipWorkerStartDon't start the scanner serviceOff
-SkipBootstrapWriteLeave bootstrap.json unchangedOff

Example, giving a second server's account access to an existing database:

powershell.exe -NoProfile -ExecutionPolicy Bypass -File "C:\Program Files\Software Athlete\PI Nexus+\Admin\Setup-Database.ps1" -SqlServer SQL01 -Database PINexus -ServiceAccount DOMAIN\svc-pinexus -SecondServiceAccount DOMAIN\svc-pinexus-scan -SkipBootstrapWrite

The script keeps an existing secretCertificateThumbprint when it rewrites bootstrap.json.

Recover-AdminAccess.ps1

The parameters of the Admin access recovery script are listed under Recover Admin access in Roles and Permissions.