Running in production
For actual day-to-day use, publish a self-contained single-file build rather than running from
bin\Debug: it doesn't need the .NET runtime installed, it's a single .exe you can drop
anywhere, and it's what you'd point a Startup shortcut at.
dotnet publish src\OncallAgent\OncallAgent.csproj -c Release -r win-x64 --self-contained -p:PublishSingleFile=true -p:IncludeNativeLibrariesForSelfExtract=true -o publish
If this fails with
MSB3094: "DestinationFiles" refers to 1 item(s), and "SourceFiles" refers to N item(s), the repo (or the-ooutput path) is sitting under a Windows user profile folder whose name contains an apostrophe (C:\Users\O'Brien\...). The .NET SDK's publish targets mis-batch file copies when an apostrophe appears anywhere in the path. Publish from (or to) a path without one, e.g.-o C:\publish\oncall-busybar-agent.
Copy publish\OncallAgent.exe and publish\appsettings.json wherever you want to run it from
(they must stay in the same folder), edit appsettings.json there per Configuration,
then run the exe directly. A tray icon appears, with no console window. Right click it to sign in
the first time; after that, your token is cached and refreshed silently.
Right click the tray icon and check Start with Windows to add a shortcut to the exe in your Startup folder, so it launches automatically at login. This uses a Startup-folder shortcut rather than a registry Run key deliberately: Run keys are the autorun technique most heavily scrutinized by security/EDR tooling, and a shortcut achieves the same result without tripping it. Unchecking it removes the shortcut.
Code signing
The published exe is unsigned. Unsigned executables commonly trigger SmartScreen warnings on
first run and may be blocked outright by endpoint security policy in managed environments. If
that's a problem for your organization, sign OncallAgent.exe with your own code-signing
certificate (e.g. via signtool sign) as part of your build/deployment process. That's outside
the scope of this repo.
If this app is installed from the Microsoft Store as an MSIX package instead, this doesn't apply: the Store signs the package automatically as part of certification, at no cost.