<# .SYNOPSIS Windows-Installer für den Newt-Client (MAIEREDV Managed Site Client). Features: Winget.pro, NSSM-Service, Turbo-BITS, Log-Rotation & Safe-Update. #> param([string]$mode = "install") # 1. Stabilität & Encoding [Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12 [Console]::OutputEncoding = [System.Text.Encoding]::UTF8 # 2. Konfiguration $Repo = "fosrl/newt" $InstallDir = "C:\Program Files\me-msp-newt" $ServiceName = "MAIEREDV-Managed-Site-Client" $Symlink = "$InstallDir\newt_latest.exe" $UpdaterTaskName = "MAIEREDV-Newt-Updater" $GiteaUrl = "https://me-gitea.maieredv.cloud/manuel.maier/update-install-newt/raw/branch/main/install_newt-msp-site-win_v2.ps1" function Write-Log($msg, $color = "White") { Write-Host "[$(Get-Date -Format 'HH:mm:ss')] $msg" -ForegroundColor $color } # 3. Umgebung vorbereiten (Winget & NSSM) function Prepare-Environment { if (!(Get-Command winget -ErrorAction SilentlyContinue)) { Write-Log "Winget fehlt. Installiere via winget.pro..." "Cyan" try { Invoke-RestMethod -Uri "https://winget.pro/install.ps1" | Invoke-Expression $env:Path = [System.Environment]::GetEnvironmentVariable("Path","Machine") + ";" + [System.Environment]::GetEnvironmentVariable("Path","User") } catch { Write-Log "FEHLER: Winget Installation fehlgeschlagen." "Red"; exit 1 } } if (!(Get-Command nssm -ErrorAction SilentlyContinue)) { Write-Log "NSSM wird via Winget bereitgestellt..." "Cyan" winget install nssm --silent --accept-package-agreements --accept-source-agreements | Out-Null $env:Path = [System.Environment]::GetEnvironmentVariable("Path","Machine") + ";" + [System.Environment]::GetEnvironmentVariable("Path","User") } } function Get-LatestVersion { try { $url = "https://api.github.com/repos/${Repo}/releases/latest" $json = Invoke-RestMethod -Uri $url -UseBasicParsing return $json.tag_name } catch { Write-Log "FEHLER: GitHub API nicht erreichbar." "Red"; exit 1 } } function Download-Newt { param($FullVersion) $ArchSuffix = if ([Environment]::Is64BitOperatingSystem) { "windows_amd64.exe" } else { "windows_386.exe" } $VersionOnly = $FullVersion.TrimStart('v') $Url = "https://github.com/${Repo}/releases/download/${VersionOnly}/newt_${ArchSuffix}" $Target = "${InstallDir}\newt_${VersionOnly}.exe" if (!(Test-Path $InstallDir)) { New-Item -ItemType Directory -Path $InstallDir -Force | Out-Null } Write-Log "Prüfe/Downloade Version $VersionOnly..." "Cyan" # Download nur wenn Datei noch nicht existiert if (!(Test-Path $Target)) { try { Start-BitsTransfer -Source $Url -Destination $Target -Priority Foreground -ErrorAction Stop Write-Log "Download erfolgreich." "Green" } catch { Write-Log "BITS fehlgeschlagen. Versuche Web-Fallback..." "Yellow" Invoke-WebRequest -Uri $Url -OutFile $Target -UseBasicParsing } } # Datei-Update (Safe-Swap) $Service = Get-Service $ServiceName -ErrorAction SilentlyContinue $WasRunning = $Service -and $Service.Status -eq 'Running' if ($WasRunning) { Write-Log "Stoppe Dienst für Datei-Update..." "Yellow" Stop-Service $ServiceName -Force } try { Copy-Item -Path $Target -Destination $Symlink -Force Write-Log "newt_latest.exe wurde auf Stand $VersionOnly aktualisiert." "Green" } catch { Write-Log "FEHLER: Konnte Symlink nicht überschreiben. Datei evtl. blockiert." "Red" } if ($WasRunning) { Start-Service $ServiceName Write-Log "Dienst wieder gestartet." "Green" } } function Setup-Service { if (!(Get-Service $ServiceName -ErrorAction SilentlyContinue)) { Write-Log "--- Dienst-Konfiguration ---" "Yellow" $PangolinID = Read-Host "Bitte Pangolin ID eingeben" $PangolinSecret = Read-Host "Bitte Secret eingeben" $PangolinEndpoint = Read-Host "Bitte Endpoint eingeben" if ([string]::IsNullOrWhiteSpace($PangolinID)) { Write-Log "FEHLER: ID darf nicht leer sein!" "Red"; exit 1 } $ArgList = "--id ${PangolinID} --secret ${PangolinSecret} --endpoint ${PangolinEndpoint}" Write-Log "Erstelle Dienst mit NSSM..." "Cyan" & nssm install $ServiceName "$Symlink" $ArgList & nssm set $ServiceName Description "MAIEREDV Managed Site Client" & nssm set $ServiceName AppExit Default Restart & nssm set $ServiceName AppRestartDelay 5000 $LogFile = "${InstallDir}\newt_service.log" & nssm set $ServiceName AppStdout "$LogFile" & nssm set $ServiceName AppStderr "$LogFile" & nssm set $ServiceName AppRotateFiles 1 & nssm set $ServiceName AppRotateOnline 1 & nssm set $ServiceName AppRotateBytes 10485760 Start-Service $ServiceName Write-Log "Dienst erfolgreich gestartet." "Green" } else { Write-Log "Dienst vorhanden. Führe Update-Check aus..." "Yellow" } } function Setup-UpdaterTask { $ActionCommand = "powershell.exe -NoProfile -ExecutionPolicy Bypass -Command `"[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12; & ([scriptblock]::Create((New-Object System.Net.WebClient).DownloadString('$GiteaUrl'))) -mode update`"" $Action = New-ScheduledTaskAction -Execute "powershell.exe" -Argument $ActionCommand $Trigger = New-ScheduledTaskTrigger -Daily -At 3am Register-ScheduledTask -Action $Action -Trigger $Trigger -TaskName $UpdaterTaskName -User "SYSTEM" -Force | Out-Null Write-Log "Update-Task registriert." "Green" } # --- Main --- Prepare-Environment switch ($mode) { "install" { $v = Get-LatestVersion Download-Newt $v Setup-Service Setup-UpdaterTask Write-Log "🚀 Installation abgeschlossen!" "Green" } "update" { $v = Get-LatestVersion $vOnly = $v.TrimStart('v') $TargetVersionPath = "${InstallDir}\newt_${vOnly}.exe" $NeedsUpdate = $false if (!(Test-Path $TargetVersionPath)) { $NeedsUpdate = $true } elseif (Test-Path $Symlink) { # Hash-Vergleich um sicherzugehen, dass latest.exe wirklich die neue Version ist $HashLatest = (Get-FileHash $Symlink).Hash $HashTarget = (Get-FileHash $TargetVersionPath).Hash if ($HashLatest -ne $HashTarget) { $NeedsUpdate = $true } } else { $NeedsUpdate = $true } if ($NeedsUpdate) { Download-Newt $v Write-Log "🚀 Update auf $v durchgeführt." "Green" } else { Write-Log "System ist bereits aktuell ($vOnly)." "Cyan" # Falls der Dienst aus irgendeinem Grund steht, starten wir ihn hier if ((Get-Service $ServiceName).Status -ne 'Running') { Start-Service $ServiceName } } } "uninstall" { if (Get-Service $ServiceName -ErrorAction SilentlyContinue) { Stop-Service $ServiceName -Force & nssm remove $ServiceName confirm } Unregister-ScheduledTask -TaskName $UpdaterTaskName -Confirm:$false -ErrorAction SilentlyContinue Write-Log "Deinstalliert." "Green" } }