ceterion Deployment Framework 2605: Service account automation, software inventory, and granular API keys

The ceterion Deployment Framework 2605 is now available—featuring enhancements to the Install Agent and Web Console, including automated service account configuration, a new software inventory, and granular API keys.

More automation. More security. More control in Agent, Web Console, and REST API.

Highlights

Service Account Automation (ceterion Install Agent)

Two new parameters now handle the setup of service accounts, which previously had to be done manually.

  • ConfigureLogonAsService – automatically assigns the "Register as a service" right to the user specified in the parameter AccountName funded account
  • AddAccountToLocalAdmin – automatically adds the account to the local Administrators group

Software Inventory (ceterion Install Agent)

Agents now collect software inventory data independently of other processes.

  • The software inventory runs on its own timer
  • Can be disabled via SoftwareDiscoveryEnabled (Default: true)
  • Interval configurable via SoftwareDiscoveryIntervalSeconds (Default: 3,600 seconds)
  • Agent status reporting via AgentStatusReportingEnabled controllable

Granular API keys (Web Console)

API keys can now be restricted to specific elements.

  • Scope to a folder or to a single object, a job, a script, a script set, or a package.
  • Read or write permissions can be configured
  • Return queries that are outside the scope 403 Forbidden

New API feature: get-objectapikey

With the new endpoint POST api/get-objectapikey You can retrieve the most recent object-specific API key—and generate it automatically if one does not yet exist.

Parameters

  • Name – Name of the infrastructure object
  • Permission – read or write (Default: "read")
  • Refresh – at true A new key is generated and the old one is deactivated (default: false)

Requirement: Authorization ApiGetKeyPermission, configured in appsettings.json.

Load Tests & Performance Recommendations (Web Console)

Version 2605 of the Web Console has undergone extensive load testing. For operation under heavy load, we recommend the following IIS settings as guidelines:

  • Default App Pool → Recycling → Specific Time: 0:00
  • Default App Pool → Queue Length: 10,000
  • IIS Configuration Editor → system.webServer/serverRuntime → appConcurrentRequestLimit: 10000

These values should be considered recommended starting points for environments with high request volumes and can be adjusted to suit the specific infrastructure.


Further improvements

ceterion Install Agent

  • Intelligent reconfiguration: The parameter ReconfigureAgent Not applicable – the requirement is automatically determined based on the AccountName-parameter determined
  • More stable logic in the ceterion Install Agent: WMI resilience, more robust return codes, locale-safe local admin detection via SID

Web Console

  • More stable API request logging, improved thread safety, and correctly set edit locks for global parameters
  • Extended API endpoints for computer principals: run-object and cancel-object is now also available
  • New option ChangeLogExemptions In appsettings.json: individual parameters can be excluded from the change log—if only excluded parameters have been changed, no change log entry is generated at all
  • Expanded UI designs: Custom designs can be configured for specific users or user groups, such as high-contrast and color-blind-friendly layouts
  • Various GUI fixes (Favorites + Search, case-insensitive parameter inheritance, clipboard fallback for API keys)


With version 2605, the ceterion Deployment Framework continues to evolve—toward greater automation, enhanced security, and granular control.