Deploy One OTserver Otter per Production Line

Placement and scope

Place a scanner host at each approved production line or cell boundary. Set each configuration’s interface and target list to one boundary, and map its output to the matching OTserver site. A host connected to multiple approved segments can hold multiple named configurations; Layer 2 discovery still remains local while the manager stays central.

Scanner configuration

Create otter.json beside each scanner binary. A single object still handles one line; an ordered array handles several lines sequentially:

Every array entry needs a unique non-empty name and unique resolved output path. Add apiKey to each entry or provide one shared OTSERVER_API_KEY to the process. Restrict otter.json when it contains credentials. Run once for an authorized baseline:

1
OTSERVER_API_KEY='...' otserver-otter scan --ack-authorized

On Windows, keep the same otter.json beside otserver-otter.exe and run:

1
2
$env:OTSERVER_API_KEY = '...'
.\otserver-otter.exe scan --ack-authorized

The Windows GUI can add configurations by cloning the selected entry, then run the selected line or all lines sequentially with the same protocol and authorization controls. Use Task Scheduler for the weekly unattended command and keep --ack-authorized in the task arguments.

The scanner validates each JSON file, uploads it to the configured site, and keeps the local file if upload fails. CLI and GUI batches continue after an individual configuration, scan, or upload failure; stopping a GUI batch writes partial output when possible and skips the pending entries. Command-line values override the file, so the authorization flag remains visible in scheduled commands.

For a weekly Linux schedule, use a systemd oneshot service with ExecStart=/opt/otserver-otter/otserver-otter scan --ack-authorized and a timer with OnCalendar=weekly.

Windows Task Scheduler

Run PowerShell as Administrator on the scanner host:

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
$otterDir = 'C:\OTserver Otter'

$action = New-ScheduledTaskAction `
  -Execute "$otterDir\otserver-otter.exe" `
  -Argument 'scan --ack-authorized' `
  -WorkingDirectory $otterDir

$trigger = New-ScheduledTaskTrigger -Weekly -DaysOfWeek Sunday -At '02:00'
$principal = New-ScheduledTaskPrincipal `
  -UserId 'SYSTEM' `
  -LogonType ServiceAccount `
  -RunLevel Highest

Register-ScheduledTask `
  -TaskName 'OTserver Otter - Line 10' `
  -Description 'Authorized weekly OT discovery scan for production line 10' `
  -Action $action `
  -Trigger $trigger `
  -Principal $principal

Keep otter.json beside the executable and restrict access to it when it contains SNMP or OPC UA credentials. If the upload key is supplied through OTSERVER_API_KEY, make it available to the scheduled task’s service account.

Verify the result

Confirm that each configuration writes a different file, each line’s site receives only its own assets, the import warning count is reviewed, and the scanner host’s API key has read/write access only to the intended sites.

Plan isolated collection or structure the site tree.