diff --git a/install_newt-msp-site-win_v2.ps1 b/install_newt-msp-site-win_v2.ps1 index 544abf3..e34c1c1 100644 --- a/install_newt-msp-site-win_v2.ps1 +++ b/install_newt-msp-site-win_v2.ps1 @@ -1,11 +1,15 @@ -# ========================================== -# Newt Installer - MAIEREDV -# ========================================== +<# +.SYNOPSIS + Windows-Installer für den Newt-Client (MAIEREDV). + Features: Winget.pro, NSSM, Turbo-BITS, Log-Rotation, Auto-Cleanup & Hard-Kill-Service. +#> param([string]$mode = "install") +# 1. Stabilität & Encoding [Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12 [Console]::OutputEncoding = [System.Text.Encoding]::UTF8 +# 2. Konfiguration $Repo = "fosrl/newt" $InstallDir = "C:\Program Files\me-msp-newt" $ServiceName = "MAIEREDV-Managed-Site-Client" @@ -13,51 +17,93 @@ $Symlink = "$InstallDir\newt_latest.exe" $UpdaterTaskName = "MAIEREDV-Newt-Updater" $GiteaUrl = "https://me-gitea.maieredv.cloud/manuel.maier/update-install-newt/raw/branch/main/install_newt-msp-site-win_v2.ps1" -function Write-Log($msg, $color = "White") { Write-Host "[$(Get-Date -Format 'HH:mm:ss')] $msg" -ForegroundColor $color } +function Write-Log($msg, $color = "White") { + Write-Host "[$(Get-Date -Format 'HH:mm:ss')] $msg" -ForegroundColor $color +} +# 3. Umgebung vorbereiten function Prepare-Environment { if (!(Get-Command winget -ErrorAction SilentlyContinue)) { - try { irm winget.pro | iex } catch { Write-Log "Winget Error" "Red" } - $env:Path = [System.Environment]::GetEnvironmentVariable("Path","Machine") + ";" + [System.Environment]::GetEnvironmentVariable("Path","User") + Write-Log "Winget fehlt. Installiere via winget.pro..." "Cyan" + try { + Invoke-RestMethod -Uri "https://winget.pro/install.ps1" | Invoke-Expression + $env:Path = [System.Environment]::GetEnvironmentVariable("Path","Machine") + ";" + [System.Environment]::GetEnvironmentVariable("Path","User") + } catch { Write-Log "FEHLER: Winget-Basis fehlt." "Red"; exit 1 } } if (!(Get-Command nssm -ErrorAction SilentlyContinue)) { + Write-Log "NSSM wird via Winget geladen..." "Cyan" winget install nssm --silent --accept-package-agreements --accept-source-agreements | Out-Null $env:Path = [System.Environment]::GetEnvironmentVariable("Path","Machine") + ";" + [System.Environment]::GetEnvironmentVariable("Path","User") } } +# 4. Download & Hard-Kill Update function Download-Newt { param($FullVersion) - $Arch = if ([Environment]::Is64BitOperatingSystem) { "windows_amd64.exe" } else { "windows_386.exe" } - $VOnly = $FullVersion.TrimStart('v') - $Url = "https://github.com/$Repo/releases/download/$VOnly/newt_$Arch" - $Target = "$InstallDir\newt_$VOnly.exe" + $ArchSuffix = if ([Environment]::Is64BitOperatingSystem) { "windows_amd64.exe" } else { "windows_386.exe" } + $VersionOnly = $FullVersion.TrimStart('v') + $Url = "https://github.com/${Repo}/releases/download/${VersionOnly}/newt_${ArchSuffix}" + $Target = "${InstallDir}\newt_${VersionOnly}.exe" - if (!(Test-Path $InstallDir)) { New-Item $InstallDir -ItemType Directory -Force | Out-Null } + if (!(Test-Path $InstallDir)) { New-Item -ItemType Directory -Path $InstallDir -Force | Out-Null } if (!(Test-Path $Target)) { - Write-Log "Download $VOnly..." "Cyan" + Write-Log "Downloade Version $VersionOnly..." "Cyan" try { Start-BitsTransfer -Source $Url -Destination $Target -Priority Foreground -ErrorAction Stop } catch { Invoke-WebRequest -Uri $Url -OutFile $Target -UseBasicParsing } } + # --- Dienst-Stopp mit Hard-Kill Fallback --- $Svc = Get-Service $ServiceName -ErrorAction SilentlyContinue $WasRunning = $Svc -and $Svc.Status -eq 'Running' - if ($WasRunning) { Stop-Service $ServiceName -Force } - try { Copy-Item -Path $Target -Destination $Symlink -Force } catch { Write-Log "Copy Error" "Red" } - - if ($WasRunning) { Start-Service $ServiceName } + if ($WasRunning) { + Write-Log "Beende Dienst $ServiceName (Warte max 30s)..." "Yellow" + Stop-Service $ServiceName -Force + + $timeout = 30 + $timer = [System.Diagnostics.Stopwatch]::StartNew() + while (((Get-Service $ServiceName).Status -ne 'Stopped') -and ($timer.Elapsed.TotalSeconds -lt $timeout)) { + Start-Sleep -Seconds 2 + } + $timer.Stop() - # Cleanup: Behalte die neuesten 2 exen - Get-ChildItem $InstallDir -Filter "newt_*.exe" | Where { $_.Name -ne "newt_latest.exe" } | Sort LastWriteTime -Desc | Select -Skip 2 | Remove-Item -Force + # Hard-Kill wenn er immer noch blockiert + if ((Get-Service $ServiceName).Status -ne 'Stopped') { + Write-Log "Dienst klemmt! Erzeinge Abbruch (Hard-Kill)..." "Red" + Stop-Process -Name "newt*" -Force -ErrorAction SilentlyContinue + Start-Sleep -Seconds 2 + } + } + + try { + Copy-Item -Path $Target -Destination $Symlink -Force + Write-Log "Datei erfolgreich auf $VersionOnly getauscht." "Green" + } catch { + Write-Log "FEHLER: Datei $Symlink ist trotz Kill gesperrt!" "Red" + } + + if ($WasRunning) { + Start-Service $ServiceName + Write-Log "Dienst wurde neu gestartet." "Green" + } + + # Cleanup: Behalte die neuesten 2 Versionen + Get-ChildItem -Path $InstallDir -Filter "newt_*.exe" | + Where-Object { $_.Name -ne "newt_latest.exe" } | + Sort-Object LastWriteTime -Descending | + Select-Object -Skip 2 | Remove-Item -Force } function Setup-Service { if (!(Get-Service $ServiceName -ErrorAction SilentlyContinue)) { - $ID = Read-Host "ID"; $Sec = Read-Host "Secret"; $End = Read-Host "Endpoint" - $Args = "--id $ID --secret $Sec --endpoint $End" - & nssm install $ServiceName "$Symlink" $Args + Write-Log "--- Erst-Konfiguration ---" "Yellow" + $PangolinID = Read-Host "Pangolin ID" + $PangolinSecret = Read-Host "Secret" + $PangolinEndpoint = Read-Host "Endpoint" + $ArgList = "--id ${PangolinID} --secret ${PangolinSecret} --endpoint ${PangolinEndpoint}" + + & nssm install $ServiceName "$Symlink" $ArgList & nssm set $ServiceName AppRotateFiles 1 & nssm set $ServiceName AppRotateOnline 1 & nssm set $ServiceName AppRotateBytes 10485760 @@ -66,33 +112,44 @@ function Setup-Service { } function Setup-Task { - $Cmd = "powershell.exe -NoProfile -ExecutionPolicy Bypass -Command `"[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12; & ([scriptblock]::Create((New-Object System.Net.WebClient).DownloadString('$GiteaUrl'))) -mode update`"" - $A = New-ScheduledTaskAction -Execute "powershell.exe" -Argument "-NoProfile -ExecutionPolicy Bypass -Command `"[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12; `$s=(New-Object System.Net.WebClient).DownloadString('$GiteaUrl'); `$b=[scriptblock]::Create(`$s); & `$b -mode update`"" - $T = New-ScheduledTaskTrigger -Daily -At 3am - $P = New-ScheduledTaskPrincipal -UserId "SYSTEM" -LogonType ServiceAccount -RunLevel Highest - Register-ScheduledTask -Action $A -Trigger $T -Principal $P -TaskName $UpdaterTaskName -Force | Out-Null + # Wir nutzen den IEX-Befehl, der manuell funktioniert + $IexCommand = "[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12; iex ((New-Object System.Net.WebClient).DownloadString('$GiteaUrl'))" + + $Action = New-ScheduledTaskAction -Execute "powershell.exe" -Argument "-NoProfile -ExecutionPolicy Bypass -Command `"$IexCommand`"" + $Trigger = New-ScheduledTaskTrigger -Daily -At 3am + $Principal = New-ScheduledTaskPrincipal -UserId "SYSTEM" -LogonType ServiceAccount -RunLevel Highest + + Register-ScheduledTask -Action $Action -Trigger $Trigger -Principal $Principal -TaskName $UpdaterTaskName -Force | Out-Null + Write-Log "Update-Task (03:00 Uhr) via IEX-Methode scharfgeschaltet." "Green" } -# --- Ausführung --- +# --- Main Logic --- Prepare-Environment -if ($mode -eq "install") { - $v = (Invoke-RestMethod "https://api.github.com/repos/$Repo/releases/latest").tag_name +# Wenn die latest.exe fehlt oder wir im Install-Mode sind -> Installieren +if (!(Test-Path $Symlink) -or ($mode -eq "install")) { + $v = (Invoke-RestMethod "https://api.github.com/repos/${Repo}/releases/latest").tag_name Download-Newt $v Setup-Service Setup-Task - Write-Log "Fertig." "Green" + Write-Log "🚀 Fertig installiert!" "Green" } -elseif ($mode -eq "update") { - $v = (Invoke-RestMethod "https://api.github.com/repos/$Repo/releases/latest").tag_name +# Wenn wir nur updaten wollen oder der Task läuft +elseif ($mode -eq "update" -or (Test-Path $Symlink)) { + $v = (Invoke-RestMethod "https://api.github.com/repos/${Repo}/releases/latest").tag_name $vO = $v.TrimStart('v') - if (!(Test-Path "$InstallDir\newt_$vO.exe")) { Download-Newt $v } - else { Write-Log "Aktuell." "Cyan" } + if (!(Test-Path "${InstallDir}\newt_${vO}.exe")) { + Write-Log "Neue Version $vO gefunden. Starte Update..." "Cyan" + Download-Newt $v + } else { + Write-Log "System ist aktuell ($vO)." "Cyan" + if ((Get-Service $ServiceName).Status -ne 'Running') { Start-Service $ServiceName } + } } elseif ($mode -eq "uninstall") { - if (Get-Service $ServiceName -ErrorAction SilentlyContinue) { + if (Get-Service $ServiceName -ErrorAction SilentlyContinue) { Stop-Service $ServiceName -Force & nssm remove $ServiceName confirm } - Unregister-ScheduledTask $UpdaterTaskName -Confirm:$false -ErrorAction SilentlyContinue + Unregister-ScheduledTask -TaskName $UpdaterTaskName -Confirm:$false -ErrorAction SilentlyContinue } \ No newline at end of file