PI Nexus+ / Reference
Installer and Script Parameters
This reference lists the installer's pages and properties, how it behaves on upgrade, repair and removal, and the parameters of the setup and recovery scripts.
Overview
This reference lists the installer's pages and properties, how it behaves on upgrade, repair and removal, and the parameters of the setup and recovery scripts.
Setup program
PI-Nexus-Setup-<version>.exe installs, in this order, the Visual C++ 2015–2022 Redistributable (x64), the PI Nexus+ MSI and the .NET 10 Hosting Bundle. The Hosting Bundle comes last so that it finds IIS, which the MSI turns on. The setup program does not pass properties to the MSI, so /quiet alone cannot set the service account. For a silent installation, extract the packages with /layout <folder> and run them in the same order: vc_redist.x64.exe /install /quiet /norestart, then msiexec with the properties below, then dotnet-hosting-10-win.exe /quiet /norestart (see Run the Installer in the Installation Guide). Use /log "<path>" to choose the setup log.
Wizard pages (first installation)
| Page | Field | Default | Notes |
|---|---|---|---|
| License agreement, installation folder | C:\Program Files\Software Athlete\PI Nexus+ | ||
| Choose components | Web application (IIS), Scanner service | Both ticked | At least one is required |
| Configure PI Nexus+ | Service account | Empty | DOMAIN\User, .\User, user@domain, or a gMSA as DOMAIN\Account$ |
| Service password | Empty | Required except for a gMSA | |
| IIS HTTP port | 5139 | Shown only with the web application | |
| Write SQL bootstrap configuration now | Ticked | Always on for a scanner-only installation | |
| SQL Server | Empty | Required while Write SQL bootstrap configuration now is ticked | |
| SQL database | PINexus | ||
| Secret certificate | Empty | Thumbprint; spaces and hidden characters are removed. Empty keeps Windows DPAPI | |
| Last page | Run PI Nexus+ Database Setup now | Ticked | First installation only |
An upgrade shows none of the component or configuration pages; it keeps the installed settings.
MSI properties
| Property | Meaning | Default |
|---|---|---|
ADDLOCAL | Components to install: WebApplication, ScannerService or both, comma-separated | Both |
REMOVE | Components to remove in a maintenance installation | None |
SERVICEACCOUNT | Service account | Required |
SERVICEPASSWORD | Its password; omit for a gMSA | Required otherwise |
IISPORT | HTTP port of the site | 5139, or the remembered port |
SQLSERVER | SQL Server instance for bootstrap.json | Empty; required when CONFIGURESQLBOOTSTRAP is 1 |
SQLDATABASE | Database for bootstrap.json | PINexus |
CONFIGURESQLBOOTSTRAP | 1 writes bootstrap.json, 0 skips it. Never 0 for a scanner-only installation | 1 |
SECRETCERTIFICATETHUMBPRINT | Secret certificate thumbprint written to bootstrap.json | Empty |
INSTALLFOLDER | Installation folder | C:\Program Files\Software Athlete\PI Nexus+ |
bootstrap.json is written only if it does not exist yet. A thumbprint given at installation is added to an existing file without changing its SQL settings.
Silent installation examples
msiexec /i PINexus.Setup.msi /qn /l*v "%TEMP%\PINexus-msi.log" ADDLOCAL=WebApplication,ScannerService SERVICEACCOUNT="DOMAIN\svc-pinexus" SERVICEPASSWORD="..." IISPORT=5139 SQLSERVER="SQL01" SQLDATABASE="PINexus"
msiexec /i PINexus.Setup.msi /qn ADDLOCAL=WebApplication SERVICEACCOUNT="DOMAIN\svc-pinexus-web" SERVICEPASSWORD="..." IISPORT=5139 SQLSERVER="SQL01" SQLDATABASE="PINexus" SECRETCERTIFICATETHUMBPRINT="<thumbprint>"
msiexec /i PINexus.Setup.msi /qn ADDLOCAL=ScannerService SERVICEACCOUNT="DOMAIN\svc-pinexus-scan" SERVICEPASSWORD="..." SQLSERVER="SQL01" SQLDATABASE="PINexus" SECRETCERTIFICATETHUMBPRINT="<thumbprint>"
msiexec /i PINexus.Setup.msi /qn SERVICEACCOUNT="DOMAIN\svc-pinexus$" SQLSERVER="SQL01" SQLDATABASE="PINexus"
Leave out SECRETCERTIFICATETHUMBPRINT when no OpenID Connect target is used.
Installer behaviour
| Operation | What happens |
|---|---|
| First installation | Turns on IIS (web application), creates the site, app pool and service under the account, grants folder rights, writes bootstrap.json |
| Upgrade | Stops the scanner service, site and app pool; replaces files; starts them again. Keeps components, identities, bindings and bootstrap.json. Passing ADDLOCAL or REMOVE on an upgrade switches off the component carry-over; don't |
| Upgrade from 1.6.x or earlier | Installs both components, as before |
| Downgrade | Refused: A newer version of PI Nexus+ is already installed. |
| Repair | Restores files; leaves the site, app pool, service and identities as they are |
Add a component (msiexec /i {ProductCode} ADDLOCAL=...) | Creates its site or service; needs SERVICEACCOUNT and SERVICEPASSWORD |
Remove a component (msiexec /i {ProductCode} REMOVE=...) | Deletes its site or service and files; keeps the other component, bootstrap.json, logs and database |
| Uninstall | Removes the site, app pool, service and program files; keeps bootstrap.json, logs and database |
The product code is in the installer log and under the Windows uninstall registry key. IIS and service configuration steps time out after 5 and 3 minutes.
Setup-Database.ps1
Run from C:\Program Files\Software Athlete\PI Nexus+\Admin. Without parameters it asks for each value.
| Parameter | Meaning | Default |
|---|---|---|
-SqlServer | SQL Server instance | Asked |
-Database | Database name | Asked, PINexus |
-ServiceAccount | Service account, DOMAIN\User or user@domain | Asked |
-SecondServiceAccount | Second account on a split deployment; gets the same grants | Asked only in interactive use |
-BootstrapPath | Where to write bootstrap.json | C:\ProgramData\Software Athlete\PI Nexus+\bootstrap.json |
-MigrationsPath | Folder with the migration files | Admin\Migrations |
-WorkerServiceName | Service to start afterwards | PI Nexus+ Scanner |
-SkipWorkerStart | Don't start the scanner service | Off |
-SkipBootstrapWrite | Leave bootstrap.json unchanged | Off |
Example, giving a second server's account access to an existing database:
powershell.exe -NoProfile -ExecutionPolicy Bypass -File "C:\Program Files\Software Athlete\PI Nexus+\Admin\Setup-Database.ps1" -SqlServer SQL01 -Database PINexus -ServiceAccount DOMAIN\svc-pinexus -SecondServiceAccount DOMAIN\svc-pinexus-scan -SkipBootstrapWrite
The script keeps an existing secretCertificateThumbprint when it rewrites bootstrap.json.
Recover-AdminAccess.ps1
The parameters of the Admin access recovery script are listed under Recover Admin access in Roles and Permissions.
