<# .SYNOPSIS Windows-Installer für den Newt-Client (MAIEREDV). Features: Winget.pro, NSSM, Hard-Kill (Stopping-Fix), 10MB Log-Rotation, Auto-Cleanup. #> param([string]$mode = "install") # 1. Stabilität & Encoding [Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12 [Console]::OutputEncoding = [System.Text.Encoding]::UTF8 # 2. Konfiguration $Repo = "fosrl/newt" $InstallDir = "C:\Program Files\me-msp-newt" $ServiceName = "MAIEREDV-Managed-Site-Client" $Symlink = "$InstallDir\newt_latest.exe" $LogFile = "$InstallDir\newt_service.log" $UpdaterTaskName = "MAIEREDV-Newt-Updater" $GiteaUrl = "https://me-gitea.maieredv.cloud/manuel.maier/update-install-newt/raw/branch/main/install_newt-msp-site-win_v2.ps1" function Write-Log($msg, $color = "White") { Write-Host "[$(Get-Date -Format 'HH:mm:ss')] $msg" -ForegroundColor $color } # 3. Umgebung vorbereiten function Prepare-Environment { if (!(Get-Command winget -ErrorAction SilentlyContinue)) { Write-Log "Winget fehlt. Installiere via winget.pro..." "Cyan" try { Invoke-RestMethod -Uri "https://winget.pro/install.ps1" | Invoke-Expression $env:Path = [System.Environment]::GetEnvironmentVariable("Path","Machine") + ";" + [System.Environment]::GetEnvironmentVariable("Path","User") } catch { Write-Log "FEHLER: Winget-Basis fehlt." "Red"; exit 1 } } if (!(Get-Command nssm -ErrorAction SilentlyContinue)) { Write-Log "NSSM wird via Winget geladen..." "Cyan" winget install nssm --silent --accept-package-agreements --accept-source-agreements | Out-Null $env:Path = [System.Environment]::GetEnvironmentVariable("Path","Machine") + ";" + [System.Environment]::GetEnvironmentVariable("Path","User") } } # 4. Download & Verbesserter Hard-Kill (Stopping-Fix) function Download-Newt { param($FullVersion) $ArchSuffix = if ([Environment]::Is64BitOperatingSystem) { "windows_amd64.exe" } else { "windows_386.exe" } $VersionOnly = $FullVersion.TrimStart('v') $Url = "https://github.com/${Repo}/releases/download/${VersionOnly}/newt_${ArchSuffix}" $Target = "${InstallDir}\newt_${VersionOnly}.exe" if (!(Test-Path $InstallDir)) { New-Item -ItemType Directory -Path $InstallDir -Force | Out-Null } if (!(Test-Path $Target)) { Write-Log "Downloade Version $VersionOnly..." "Cyan" try { Start-BitsTransfer -Source $Url -Destination $Target -Priority Foreground -ErrorAction Stop } catch { Invoke-WebRequest -Uri $Url -OutFile $Target -UseBasicParsing } } # --- Dienst-Stopp mit verbessertem Hard-Kill --- $Svc = Get-Service $ServiceName -ErrorAction SilentlyContinue if ($Svc) { $WasRunning = $true # Wir gehen davon aus, dass wir ihn nachher wieder starten wollen if ($Svc.Status -ne 'Stopped') { Write-Log "Dienst $ServiceName ist im Status '$($Svc.Status)'. Versuche Stop..." "Yellow" Stop-Service $ServiceName -Force -ErrorAction SilentlyContinue $timeout = 30 $timer = [System.Diagnostics.Stopwatch]::StartNew() while (((Get-Service $ServiceName).Status -ne 'Stopped') -and ($timer.Elapsed.TotalSeconds -lt $timeout)) { Start-Sleep -Seconds 2 } $timer.Stop() } # Wenn er immer noch nicht Stopped ist (z.B. hängt in 'Stopping') -> TASKKILL if ((Get-Service $ServiceName).Status -ne 'Stopped') { Write-Log "Dienst reagiert nicht (Status: $((Get-Service $ServiceName).Status)). Erzeuge Hard-Kill!" "Red" $NewtProcs = Get-Process -Name "newt*" -ErrorAction SilentlyContinue if ($NewtProcs) { $NewtProcs | Stop-Process -Force -ErrorAction SilentlyContinue Write-Log "Prozesse hart beendet." "Yellow" Start-Sleep -Seconds 2 } } } else { $WasRunning = $false } try { Copy-Item -Path $Target -Destination $Symlink -Force Write-Log "Datei erfolgreich auf $VersionOnly getauscht." "Green" } catch { Write-Log "FEHLER: Datei $Symlink ist trotz Kill gesperrt! Eventuell manueller Zugriff?" "Red" } if ($WasRunning) { Start-Service $ServiceName Write-Log "Dienst wurde neu gestartet." "Green" } # Cleanup: Behalte die neuesten 2 Versionen Get-ChildItem -Path $InstallDir -Filter "newt_*.exe" | Where-Object { $_.Name -ne "newt_latest.exe" } | Sort-Object LastWriteTime -Descending | Select-Object -Skip 2 | Remove-Item -Force } function Setup-Service { if (!(Get-Service $ServiceName -ErrorAction SilentlyContinue)) { Write-Log "--- Erst-Konfiguration ---" "Yellow" $PangolinID = Read-Host "Pangolin ID" $PangolinSecret = Read-Host "Secret" $PangolinEndpoint = Read-Host "Endpoint" $ArgList = "--id ${PangolinID} --secret ${PangolinSecret} --endpoint ${PangolinEndpoint}" & nssm install $ServiceName "$Symlink" $ArgList & nssm set $ServiceName AppStdout "$LogFile" & nssm set $ServiceName AppStderr "$LogFile" & nssm set $ServiceName AppRotateFiles 1 & nssm set $ServiceName AppRotateOnline 1 & nssm set $ServiceName AppRotateBytes 10485760 Start-Service $ServiceName Write-Log "Dienst aktiv. Logs: $LogFile" "Green" } else { # Log-Pfade nachrüsten falls nötig & nssm set $ServiceName AppStdout "$LogFile" & nssm set $ServiceName AppStderr "$LogFile" & nssm set $ServiceName AppRotateFiles 1 & nssm set $ServiceName AppRotateOnline 1 & nssm set $ServiceName AppRotateBytes 10485760 } } function Setup-Task { $IexCommand = "[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12; iex ((New-Object System.Net.WebClient).DownloadString('$GiteaUrl'))" $Action = New-ScheduledTaskAction -Execute "powershell.exe" -Argument "-NoProfile -ExecutionPolicy Bypass -Command `"$IexCommand`"" $Trigger = New-ScheduledTaskTrigger -Daily -At 3am $Principal = New-ScheduledTaskPrincipal -UserId "SYSTEM" -LogonType ServiceAccount -RunLevel Highest Register-ScheduledTask -Action $Action -Trigger $Trigger -Principal $Principal -TaskName $UpdaterTaskName -Force | Out-Null Write-Log "Update-Task (03:00 Uhr) registriert." "Green" } # --- Main Logic --- Prepare-Environment if (!(Test-Path $Symlink) -or ($mode -eq "install")) { $v = (Invoke-RestMethod "https://api.github.com/repos/${Repo}/releases/latest").tag_name Download-Newt $v Setup-Service Setup-Task Write-Log "🚀 Installation abgeschlossen!" "Green" } elseif ($mode -eq "update" -or (Test-Path $Symlink)) { $v = (Invoke-RestMethod "https://api.github.com/repos/${Repo}/releases/latest").tag_name $vO = $v.TrimStart('v') if (!(Test-Path "${InstallDir}\newt_${vO}.exe")) { Write-Log "Update auf $vO verfügbar..." "Cyan" Download-Newt $v } else { Write-Log "System ist aktuell ($vO)." "Cyan" Setup-Service # Sicherstellen, dass Logs & Rotation stimmen if ((Get-Service $ServiceName).Status -ne 'Running') { Start-Service $ServiceName } } } elseif ($mode -eq "uninstall") { Write-Log "Entferne Dienst..." "Yellow" if (Get-Service $ServiceName -ErrorAction SilentlyContinue) { # Auch hier Hard-Kill Fallback nutzen Stop-Service $ServiceName -Force -ErrorAction SilentlyContinue $NewtProcs = Get-Process -Name "newt*" -ErrorAction SilentlyContinue if ($NewtProcs) { $NewtProcs | Stop-Process -Force } & nssm remove $ServiceName confirm } Unregister-ScheduledTask -TaskName $UpdaterTaskName -Confirm:$false -ErrorAction SilentlyContinue Write-Log "Deinstallation fertig." "Green" }