diff --git a/ansible/deploy_aw_server.yml b/ansible/deploy_aw_server.yml index f553a4c..c741385 100644 --- a/ansible/deploy_aw_server.yml +++ b/ansible/deploy_aw_server.yml @@ -54,6 +54,7 @@ - "{{ aw_server_webui_dir }}" - "{{ aw_server_webui_dir }}/js" - "{{ aw_server_data_dir }}" + - "{{ aw_server_db_path | dirname }}" - "{{ aw_server_data_dir }}/.config" - "{{ aw_server_data_dir }}/.config/activitywatch" - "{{ aw_server_data_dir }}/.config/activitywatch/aw-server-rust" @@ -78,6 +79,7 @@ - "{{ aw_server_webui_dir }}" - "{{ aw_server_webui_dir }}/js" - "{{ aw_server_data_dir }}" + - "{{ aw_server_db_path | dirname }}" - "{{ aw_server_data_dir }}/.config" - "{{ aw_server_data_dir }}/.config/activitywatch" - "{{ aw_server_data_dir }}/.config/activitywatch/aw-server-rust" @@ -293,10 +295,107 @@ AW_SERVER_BIND_HOST={{ aw_server_bind_host }} AW_SERVER_PORT={{ aw_server_port }} AW_SERVER_DATA_DIR={{ aw_server_data_dir }} + AW_SERVER_DB_PATH={{ aw_server_db_path }} AW_SERVER_LOG_DIR={{ aw_server_log_dir }} AW_SERVER_WEBUI_DIR={{ aw_server_webui_dir }} AW_SERVER_USER={{ aw_server_user }} AW_SERVER_GROUP={{ aw_server_group }} + XDG_DATA_HOME={{ aw_server_data_dir }}/.local/share + XDG_CONFIG_HOME={{ aw_server_data_dir }}/.config + + - name: Скопировать merge script AW DB на сервер + ansible.builtin.copy: + src: "{{ aw_repo_root }}/scripts/merge_aw_server_dbs.py" + dest: /usr/local/bin/merge_aw_server_dbs.py + owner: root + group: root + mode: "0755" + + - name: Проверить наличие legacy root DB + ansible.builtin.stat: + path: /root/.local/share/activitywatch/aw-server-rust/sqlite.db + register: aw_legacy_root_db + + - name: Проверить наличие target DB + ansible.builtin.stat: + path: "{{ aw_server_db_path }}" + register: aw_target_db + + - name: Остановить сервис перед merge server DB + ansible.builtin.systemd: + name: activitywatch-server.service + state: stopped + when: aw_legacy_root_db.stat.exists | default(false) + + - name: Создать backup каталоги server DB + ansible.builtin.file: + path: "{{ aw_server_data_dir }}/backups/db" + state: directory + owner: "{{ aw_server_user }}" + group: "{{ aw_server_group }}" + mode: "0755" + when: aw_legacy_root_db.stat.exists | default(false) + + - name: Backup target DB перед merge + ansible.builtin.copy: + remote_src: true + src: "{{ aw_server_db_path }}" + dest: "{{ aw_server_data_dir }}/backups/db/target-before-merge-{{ ansible_date_time.iso8601_basic_short }}.sqlite.db" + owner: "{{ aw_server_user }}" + group: "{{ aw_server_group }}" + mode: "0644" + when: + - aw_legacy_root_db.stat.exists | default(false) + - aw_target_db.stat.exists | default(false) + + - name: Backup legacy root DB перед merge + ansible.builtin.copy: + remote_src: true + src: /root/.local/share/activitywatch/aw-server-rust/sqlite.db + dest: "{{ aw_server_data_dir }}/backups/db/legacy-root-{{ ansible_date_time.iso8601_basic_short }}.sqlite.db" + owner: "{{ aw_server_user }}" + group: "{{ aw_server_group }}" + mode: "0644" + when: aw_legacy_root_db.stat.exists | default(false) + + - name: Merge legacy root DB в target DB + ansible.builtin.command: + argv: + - python3 + - /usr/local/bin/merge_aw_server_dbs.py + - --base + - /root/.local/share/activitywatch/aw-server-rust/sqlite.db + - --overlay + - "{{ aw_server_db_path }}" + - --output + - "{{ aw_server_db_path }}.merged" + when: + - aw_legacy_root_db.stat.exists | default(false) + - aw_target_db.stat.exists | default(false) + + - name: Install merged DB as active target DB + ansible.builtin.copy: + remote_src: true + src: "{{ aw_server_db_path }}.merged" + dest: "{{ aw_server_db_path }}" + owner: "{{ aw_server_user }}" + group: "{{ aw_server_group }}" + mode: "0644" + when: + - aw_legacy_root_db.stat.exists | default(false) + - aw_target_db.stat.exists | default(false) + + - name: Скопировать legacy root DB в target DB если target ещё не существует + ansible.builtin.copy: + remote_src: true + src: /root/.local/share/activitywatch/aw-server-rust/sqlite.db + dest: "{{ aw_server_db_path }}" + owner: "{{ aw_server_user }}" + group: "{{ aw_server_group }}" + mode: "0644" + when: + - aw_legacy_root_db.stat.exists | default(false) + - not (aw_target_db.stat.exists | default(false)) - name: Записать aw-server-rust config.toml с разрешёнными CORS origin ansible.builtin.copy: @@ -437,6 +536,30 @@ status_code: [200, 201] when: aw_apply_worktime_settings | default(false) | bool + - name: Применить always_active_pattern для fallback без AFK + ansible.builtin.uri: + url: "http://127.0.0.1:{{ aw_server_port }}/api/0/settings/always_active_pattern" + method: POST + body: "\"{{ aw_server_always_active_pattern }}\"" + headers: + Content-Type: application/json + status_code: [200, 201] + when: + - aw_apply_worktime_settings | default(false) | bool + - (aw_server_always_active_pattern | default('') | string | length) > 0 + + - name: Применить landingpage профиля + ansible.builtin.uri: + url: "http://127.0.0.1:{{ aw_server_port }}/api/0/settings/landingpage" + method: POST + body: "\"{{ aw_server_landingpage }}\"" + headers: + Content-Type: application/json + status_code: [200, 201] + when: + - aw_apply_worktime_settings | default(false) | bool + - (aw_server_landingpage | default('') | string | length) > 0 + handlers: - name: Перезагрузить systemd ansible.builtin.systemd: diff --git a/ansible/deploy_aw_windows.yml b/ansible/deploy_aw_windows.yml index 349f262..77e9ad2 100644 --- a/ansible/deploy_aw_windows.yml +++ b/ansible/deploy_aw_windows.yml @@ -25,6 +25,7 @@ aw_windows_state_root: "C:\\ProgramData\\AWatch-rus" aw_windows_afk_enabled: true aw_windows_window_enabled: true + aw_windows_file_ops_enabled: true aw_windows_local_agent_logs_enabled: false aw_windows_incident_capture_enabled: true aw_windows_incident_screenshot_enabled: true @@ -77,6 +78,7 @@ - ActivityWatch.Windows.Common.psm1 - browser-domains-native-collector.ps1 - dlp-endpoint-signals-collector.ps1 + - file-operations-collector.ps1 - worktime-session-collector.ps1 - migrate-awatch-rus-paths.ps1 - deploy-domain-users.ps1 @@ -142,6 +144,7 @@ StateRoot = "{{ aw_windows_state_root }}" AfkEnabled = {{ '$true' if (aw_windows_afk_enabled | bool) else '$false' }} WindowEnabled = {{ '$true' if (aw_windows_window_enabled | bool) else '$false' }} + FileOpsEnabled = {{ '$true' if (aw_windows_file_ops_enabled | bool) else '$false' }} LocalAgentLogsEnabled = {{ '$true' if (aw_windows_local_agent_logs_enabled | bool) else '$false' }} IncidentCaptureEnabled = {{ '$true' if (aw_windows_incident_capture_enabled | bool) else '$false' }} IncidentScreenshotEnabled = {{ '$true' if (aw_windows_incident_screenshot_enabled | bool) else '$false' }} @@ -197,61 +200,53 @@ - aw_windows_api_smoke_check_enabled | bool - aw_windows_afk_enabled | bool ansible.builtin.set_fact: - aw_windows_api_smoke_check_bucket_effective: >- - {{ - aw_windows_api_smoke_check_bucket - if (aw_windows_api_smoke_check_bucket | default('') | string | length) > 0 - else 'aw-watcher-afk_' ~ (aw_windows_hostname_result.stdout | trim) - }} + aw_windows_api_smoke_check_bucket_effective: "aw-watcher-afk_{{ aw_windows_hostname_result.stdout | trim }}" - - name: Дождаться свежих AFK событий на AW server + - name: Выполнить AW API smoke-check (проверка наличия свежих событий в AFK бакете) when: - aw_windows_api_smoke_check_enabled | bool - aw_windows_afk_enabled | bool - delegate_to: localhost ansible.builtin.uri: url: "{{ aw_windows_server_scheme }}://{{ aw_windows_server_host }}:{{ aw_windows_server_port }}/api/0/buckets/{{ aw_windows_api_smoke_check_bucket_effective }}/events?limit={{ aw_windows_api_smoke_check_limit }}" method: GET - return_content: true - register: aw_windows_api_smoke - until: > - aw_windows_api_smoke.status == 200 and - (aw_windows_api_smoke.json | length) > 0 and - ( - aw_windows_api_smoke.json - | selectattr('data.status', 'equalto', 'not-afk') - | list - | length - ) > 0 - retries: 10 - delay: 6 + status_code: 200 + register: aw_windows_api_smoke_result + until: aw_windows_api_smoke_result.json | length > 0 + retries: 5 + delay: 5 + ignore_errors: true - - name: Выполнить валидацию и сохранить отчёт на целевом Windows host + - name: Валидировать развёртывание на эндпоинте ansible.windows.win_powershell: script: | $ErrorActionPreference = 'Stop' - $report = & "{{ aw_windows_deploy_root }}\windows\validate-deployment.ps1" ` + $result = & "{{ aw_windows_deploy_root }}\windows\validate-deployment.ps1" ` -ConfigPath "{{ aw_windows_state_root }}\deployment-config.json" - $report | ConvertTo-Json -Depth 12 | Out-File -FilePath "{{ aw_windows_validation_remote_path }}" -Encoding utf8 - if ({{ '$true' if (aw_windows_fail_on_validation_error | bool) else '$false' }} -and -not [bool]$report.overallOk) { - throw "Проверка развёртывания ActivityWatch завершилась ошибкой. Отчёт: {{ aw_windows_validation_remote_path }}" - } + $result | ConvertTo-Json -Depth 8 | Out-File -FilePath "{{ aw_windows_validation_remote_path }}" -Encoding utf8 + return $result - - name: Создать локальный каталог для validation reports + - name: Создать локальную директорию для отчётов валидации ansible.builtin.file: path: "{{ aw_windows_validation_local_dir }}" state: directory mode: "0755" delegate_to: localhost - - name: Забрать validation report - ansible.builtin.fetch: + - name: Стянуть отчёт валидации с эндпоинта + ansible.windows.win_fetch: src: "{{ aw_windows_validation_remote_path }}" dest: "{{ aw_windows_validation_local_dir }}/{{ inventory_hostname }}-aw_validate_ansible.json" flat: true - - name: Показать путь к отчёту - ansible.builtin.debug: - msg: - - "Windows/RDP развёртывание завершено на {{ inventory_hostname }}." - - "Отчёт проверки: {{ aw_windows_validation_local_dir }}/{{ inventory_hostname }}-aw_validate_ansible.json" + - name: Проверить статус валидации + ansible.builtin.shell: | + python3 - <<'PY' + import json, sys + with open('{{ aw_windows_validation_local_dir }}/{{ inventory_hostname }}-aw_validate_ansible.json', 'r') as f: + data = json.load(f) + if not data.get('overallOk', False): + print(f"Validation failed for {{ inventory_hostname }}: {data.get('summary', 'Unknown error')}") + sys.exit(1) + PY + delegate_to: localhost + when: aw_windows_fail_on_validation_error | bool diff --git a/ansible/group_vars/all.example.yml b/ansible/group_vars/all.example.yml index 7da0ad8..2091344 100644 --- a/ansible/group_vars/all.example.yml +++ b/ansible/group_vars/all.example.yml @@ -4,6 +4,7 @@ aw_server_bind_host: "0.0.0.0" aw_server_port: 5600 aw_server_webui_dir: "/opt/activitywatch/webui-ru" aw_server_data_dir: "/var/lib/activitywatch" +aw_server_db_path: "/var/lib/activitywatch/.local/share/activitywatch/aw-server-rust/sqlite.db" aw_server_log_dir: "/var/log/activitywatch" aw_server_user: "activitywatch" aw_server_group: "activitywatch" @@ -30,3 +31,5 @@ aw_server_cors_origins: aw_worktime_from: "08:00" aw_worktime_to: "17:00" aw_worktime_start_of_day: "{{ aw_worktime_from }}" +aw_server_always_active_pattern: "aw-watcher-window" +aw_server_landingpage: "/activity/SHARKON2025/view/" diff --git a/ansible/group_vars/all.yml b/ansible/group_vars/all.yml index 77fbcde..2452c60 100644 --- a/ansible/group_vars/all.yml +++ b/ansible/group_vars/all.yml @@ -4,6 +4,7 @@ aw_server_bind_host: "0.0.0.0" aw_server_port: 5600 aw_server_webui_dir: "/opt/activitywatch/webui-ru" aw_server_data_dir: "/var/lib/activitywatch" +aw_server_db_path: "/var/lib/activitywatch/.local/share/activitywatch/aw-server-rust/sqlite.db" aw_server_log_dir: "/var/log/activitywatch" aw_server_user: "activitywatch" aw_server_group: "activitywatch" @@ -22,3 +23,5 @@ aw_server_cors_origins: aw_worktime_from: "08:00" aw_worktime_to: "17:00" aw_worktime_start_of_day: "{{ aw_worktime_from }}" +aw_server_always_active_pattern: "aw-watcher-window" +aw_server_landingpage: "/activity/SHARKON2025/view/" diff --git a/aw-server/activitywatch-server.service b/aw-server/activitywatch-server.service index 8481021..89d31e3 100755 --- a/aw-server/activitywatch-server.service +++ b/aw-server/activitywatch-server.service @@ -9,7 +9,7 @@ EnvironmentFile=/etc/activitywatch/aw-server.env User=__AW_SERVER_USER__ Group=__AW_SERVER_GROUP__ WorkingDirectory=__AW_SERVER_DATA_DIR__ -ExecStart=/bin/sh -lc 'exec /opt/activitywatch/bin/aw-server-rust --host "$AW_SERVER_BIND_HOST" --port "$AW_SERVER_PORT" --webpath "$AW_SERVER_WEBUI_DIR"' +ExecStart=/bin/sh -lc 'exec /opt/activitywatch/bin/aw-server-rust --host "$AW_SERVER_BIND_HOST" --port "$AW_SERVER_PORT" --dbpath "$AW_SERVER_DB_PATH" --webpath "$AW_SERVER_WEBUI_DIR"' Restart=on-failure RestartSec=5s StateDirectory=activitywatch @@ -17,7 +17,7 @@ LogsDirectory=activitywatch NoNewPrivileges=true PrivateTmp=true ProtectSystem=full -ProtectHome=true +ProtectHome=read-only LimitNOFILE=65535 [Install] diff --git a/scripts/merge_aw_server_dbs.py b/scripts/merge_aw_server_dbs.py new file mode 100644 index 0000000..6b39944 --- /dev/null +++ b/scripts/merge_aw_server_dbs.py @@ -0,0 +1,139 @@ +#!/usr/bin/env python3 +import argparse +import json +import os +import shutil +import sqlite3 +from pathlib import Path + + +def connect(path: Path) -> sqlite3.Connection: + connection = sqlite3.connect(str(path)) + connection.execute("PRAGMA journal_mode=WAL") + connection.execute("PRAGMA synchronous=NORMAL") + return connection + + +def bucket_key(row: sqlite3.Row) -> tuple[str, str, str, str]: + return ( + str(row["name"]), + str(row["type"]), + str(row["client"]), + str(row["hostname"]), + ) + + +def ensure_parent(path: Path) -> None: + path.parent.mkdir(parents=True, exist_ok=True) + + +def load_existing_events(connection: sqlite3.Connection, bucketrow: int) -> set[tuple[int, int, str]]: + cursor = connection.execute( + "select starttime, endtime, data from events where bucketrow = ?", + (bucketrow,), + ) + return {(int(start), int(end), str(data)) for start, end, data in cursor.fetchall()} + + +def main() -> int: + parser = argparse.ArgumentParser() + parser.add_argument("--base", required=True) + parser.add_argument("--output", required=True) + parser.add_argument("--overlay") + args = parser.parse_args() + + base = Path(args.base) + output = Path(args.output) + overlay = Path(args.overlay) if args.overlay else None + + if not base.exists(): + raise SystemExit(f"Base DB not found: {base}") + + ensure_parent(output) + tmp_output = output.with_suffix(output.suffix + ".tmp") + if tmp_output.exists(): + tmp_output.unlink() + shutil.copy2(base, tmp_output) + + dest = connect(tmp_output) + dest.row_factory = sqlite3.Row + + inserted_buckets = 0 + inserted_events = 0 + + if overlay and overlay.exists(): + source = connect(overlay) + source.row_factory = sqlite3.Row + try: + source_buckets = source.execute( + "select rowid as bucketrow, id, name, type, client, hostname, created, data_deprecated, data from buckets order by rowid" + ).fetchall() + + dest_bucket_map = { + bucket_key(row): row["bucketrow"] + for row in dest.execute( + "select rowid as bucketrow, id, name, type, client, hostname, created, data_deprecated, data from buckets order by rowid" + ).fetchall() + } + + for src_bucket in source_buckets: + key = bucket_key(src_bucket) + dest_rowid = dest_bucket_map.get(key) + if dest_rowid is None: + cursor = dest.execute( + """ + insert into buckets (name, type, client, hostname, created, data_deprecated, data) + values (?, ?, ?, ?, ?, ?, ?) + """, + ( + src_bucket["name"], + src_bucket["type"], + src_bucket["client"], + src_bucket["hostname"], + src_bucket["created"], + src_bucket["data_deprecated"], + src_bucket["data"], + ), + ) + dest_rowid = int(cursor.lastrowid) + dest_bucket_map[key] = dest_rowid + inserted_buckets += 1 + + existing_events = load_existing_events(dest, dest_rowid) + for starttime, endtime, data in source.execute( + "select starttime, endtime, data from events where bucketrow = ? order by id", + (src_bucket["bucketrow"],), + ).fetchall(): + event_key = (int(starttime), int(endtime), str(data)) + if event_key in existing_events: + continue + dest.execute( + "insert into events (bucketrow, starttime, endtime, data) values (?, ?, ?, ?)", + (dest_rowid, int(starttime), int(endtime), str(data)), + ) + existing_events.add(event_key) + inserted_events += 1 + + dest.commit() + finally: + source.close() + + dest.close() + os.replace(tmp_output, output) + print( + json.dumps( + { + "base": str(base), + "overlay": str(overlay) if overlay else None, + "output": str(output), + "inserted_buckets": inserted_buckets, + "inserted_events": inserted_events, + }, + ensure_ascii=False, + ) + ) + return 0 + + +if __name__ == "__main__": + raise SystemExit(main()) diff --git a/scripts/prod_backup_restore.sh b/scripts/prod_backup_restore.sh new file mode 100644 index 0000000..a731ae6 --- /dev/null +++ b/scripts/prod_backup_restore.sh @@ -0,0 +1,71 @@ +#!/usr/bin/env bash +set -euo pipefail + +ROOT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)" +cd "$ROOT_DIR" + +if [[ -f "${ROOT_DIR}/secrets/runtime.env" ]]; then + set -a + # shellcheck disable=SC1091 + source "${ROOT_DIR}/secrets/runtime.env" + set +a +fi + +: "${AW_SSH_PASSWORD:?AW_SSH_PASSWORD is required}" +: "${AW_WINRM_PASSWORD:?AW_WINRM_PASSWORD is required}" + +command -v sshpass >/dev/null 2>&1 || { echo "missing sshpass" >&2; exit 127; } +command -v ansible-playbook >/dev/null 2>&1 || { echo "missing ansible-playbook" >&2; exit 127; } + +SERVER_HOST="${AW_SERVER_HOST:-10.10.10.13}" +SERVER_USER="${AW_SERVER_USER:-igor}" +TIMESTAMP="$(date +%Y%m%d-%H%M%S)" +REMOTE_BACKUP_DIR="/var/lib/activitywatch/backups/prod-restore-${TIMESTAMP}" +LEGACY_DB="/root/.local/share/activitywatch/aw-server-rust/sqlite.db" +TARGET_DB="/var/lib/activitywatch/.local/share/activitywatch/aw-server-rust/sqlite.db" +REMOTE_MERGE_SCRIPT="/tmp/merge_aw_server_dbs.py" + +ssh_remote() { + sshpass -p "$AW_SSH_PASSWORD" ssh -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null "${SERVER_USER}@${SERVER_HOST}" "$@" +} + +scp_remote() { + sshpass -p "$AW_SSH_PASSWORD" scp -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null "$@" +} + +scp_remote "${ROOT_DIR}/scripts/merge_aw_server_dbs.py" "${SERVER_USER}@${SERVER_HOST}:${REMOTE_MERGE_SCRIPT}" + +ssh_remote "sudo mkdir -p '${REMOTE_BACKUP_DIR}' && sudo chown root:root '${REMOTE_BACKUP_DIR}'" +ssh_remote "sudo test -f '${LEGACY_DB}'" +ssh_remote "sudo test -f '${TARGET_DB}'" +ssh_remote "sudo cp -a '${LEGACY_DB}' '${REMOTE_BACKUP_DIR}/legacy-root-sqlite.db' && sudo cp -a '${TARGET_DB}' '${REMOTE_BACKUP_DIR}/target-before-merge-sqlite.db'" +ssh_remote "sudo systemctl stop activitywatch-server.service || true" +ssh_remote "sudo python3 '${REMOTE_MERGE_SCRIPT}' --base '${LEGACY_DB}' --overlay '${TARGET_DB}' --output '${REMOTE_BACKUP_DIR}/sqlite.merged.db'" +ssh_remote "sudo install -o activitywatch -g activitywatch -m 0644 '${REMOTE_BACKUP_DIR}/sqlite.merged.db' '${TARGET_DB}'" + +ansible-playbook -i ansible/inventory.ini ansible/deploy_aw_server.yml +ansible-playbook -i ansible/inventory.ini ansible/deploy_aw_windows.yml +ansible-playbook -i ansible/inventory.ini ansible/post_validate_aw_windows.yml + +python3 - <<'PY' +import json, urllib.request +base = 'http://10.10.10.13:5600' +window_payload = { + 'timeperiods': ['2026-04-29T00:00:00+03:00/2026-04-29T23:59:59+03:00'], + 'query': [ + 'window_events = query_bucket(find_bucket("aw-watcher-window_SHARKON2025"));', + 'RETURN = window_events;' + ] +} +req = urllib.request.Request(base + '/api/0/query/', data=json.dumps(window_payload).encode(), method='POST', headers={'Content-Type': 'application/json', 'Origin': 'http://10.10.10.13:5600'}) +with urllib.request.urlopen(req) as response: + data = json.loads(response.read().decode()) +window_count = len(data[0]) if isinstance(data, list) and data else 0 +if window_count <= 0: + raise SystemExit('no historical window data restored for 2026-04-29') +with urllib.request.urlopen(base + '/api/0/settings/') as response: + settings = json.loads(response.read().decode()) +if settings.get('always_active_pattern') != 'aw-watcher-window': + raise SystemExit('always_active_pattern is not configured') +print(json.dumps({'restored_window_events_2026_04_29': window_count, 'always_active_pattern': settings.get('always_active_pattern')}, ensure_ascii=False)) +PY diff --git a/windows/ActivityWatch.Windows.Common.psm1 b/windows/ActivityWatch.Windows.Common.psm1 index c9954f1..137620f 100755 --- a/windows/ActivityWatch.Windows.Common.psm1 +++ b/windows/ActivityWatch.Windows.Common.psm1 @@ -255,6 +255,8 @@ function Copy-ActivityWatchCollectorAssets { [Parameter(Mandatory = $true)] [string]$EndpointCollectorScriptSource, [Parameter(Mandatory = $true)] + [string]$FileCollectorScriptSource, + [Parameter(Mandatory = $true)] [string]$SessionCollectorScriptSource, [Parameter(Mandatory = $true)] [string]$ExampleRulesSource, @@ -270,6 +272,7 @@ function Copy-ActivityWatchCollectorAssets { $collectorTarget = Join-Path $StateRoot 'browser-domains-native-collector.ps1' $endpointCollectorTarget = Join-Path $StateRoot 'dlp-endpoint-signals-collector.ps1' + $fileCollectorTarget = Join-Path $StateRoot 'file-operations-collector.ps1' $sessionCollectorTarget = Join-Path $StateRoot 'worktime-session-collector.ps1' $exampleRulesTarget = Join-Path $StateRoot 'web-category-rules.example.json' $rulesTarget = Join-Path $StateRoot 'web-category-rules.json' @@ -278,6 +281,7 @@ function Copy-ActivityWatchCollectorAssets { Copy-Item -LiteralPath $CollectorScriptSource -Destination $collectorTarget -Force Copy-Item -LiteralPath $EndpointCollectorScriptSource -Destination $endpointCollectorTarget -Force + Copy-Item -LiteralPath $FileCollectorScriptSource -Destination $fileCollectorTarget -Force Copy-Item -LiteralPath $SessionCollectorScriptSource -Destination $sessionCollectorTarget -Force Copy-Item -LiteralPath $ExampleRulesSource -Destination $exampleRulesTarget -Force Copy-Item -LiteralPath $ExamplePolicySource -Destination $examplePolicyTarget -Force @@ -298,6 +302,7 @@ function Copy-ActivityWatchCollectorAssets { return [pscustomobject]@{ CollectorScript = $collectorTarget EndpointCollectorScript = $endpointCollectorTarget + FileCollectorScript = $fileCollectorTarget SessionCollectorScript = $sessionCollectorTarget ExampleRules = $exampleRulesTarget ActiveRules = $rulesTarget @@ -325,6 +330,8 @@ function New-ActivityWatchDeploymentConfig { [Parameter(Mandatory = $true)] [string]$EndpointCollectorScript, [Parameter(Mandatory = $true)] + [string]$FileCollectorScript, + [Parameter(Mandatory = $true)] [string]$SessionCollectorScript, [Parameter(Mandatory = $true)] [string]$RulesPath, @@ -338,6 +345,7 @@ function New-ActivityWatchDeploymentConfig { [int]$RecoveryIntervalSeconds, [bool]$AfkEnabled = $true, [bool]$WindowEnabled = $true, + [bool]$FileOpsEnabled = $true, [bool]$LocalAgentLogsEnabled = $true, [bool]$IncidentCaptureEnabled = $true, [bool]$IncidentScreenshotEnabled = $true, @@ -368,6 +376,7 @@ function New-ActivityWatchDeploymentConfig { logsRoot = $LogsRoot collectorScript = $CollectorScript endpointCollectorScript = $EndpointCollectorScript + fileCollectorScript = $FileCollectorScript sessionCollectorScript = $SessionCollectorScript rulesPath = $RulesPath policyPath = $PolicyPath @@ -381,6 +390,7 @@ function New-ActivityWatchDeploymentConfig { collectors = [pscustomobject]@{ afkEnabled = $AfkEnabled windowEnabled = $WindowEnabled + fileOpsEnabled = $FileOpsEnabled } logging = [pscustomobject]@{ localAgentLogsEnabled = $LocalAgentLogsEnabled @@ -656,6 +666,7 @@ function Start-CollectorScriptIfNeeded { `$script:KnownBuckets = @{} `$collectorScript = [string]`$config.paths.collectorScript `$endpointCollectorScript = if (`$config.paths.PSObject.Properties.Name -contains 'endpointCollectorScript') { [string]`$config.paths.endpointCollectorScript } else { Join-Path `$stateRoot 'dlp-endpoint-signals-collector.ps1' } +`$fileCollectorScript = if (`$config.paths.PSObject.Properties.Name -contains 'fileCollectorScript') { [string]`$config.paths.fileCollectorScript } else { Join-Path `$stateRoot 'file-operations-collector.ps1' } `$sessionCollectorScript = if (`$config.paths.PSObject.Properties.Name -contains 'sessionCollectorScript') { [string]`$config.paths.sessionCollectorScript } else { Join-Path `$stateRoot 'worktime-session-collector.ps1' } `$afkExe = Join-Path `$installRoot 'aw-watcher-afk\aw-watcher-afk.exe' `$windowExe = Join-Path `$installRoot 'aw-watcher-window\aw-watcher-window.exe' @@ -663,6 +674,7 @@ function Start-CollectorScriptIfNeeded { `$powershellExe = Join-Path `$env:SystemRoot 'System32\WindowsPowerShell\v1.0\powershell.exe' `$afkEnabled = if (`$config.PSObject.Properties.Name -contains 'collectors' -and `$config.collectors.PSObject.Properties.Name -contains 'afkEnabled') { [bool]`$config.collectors.afkEnabled } else { `$true } `$windowEnabled = if (`$config.PSObject.Properties.Name -contains 'collectors' -and `$config.collectors.PSObject.Properties.Name -contains 'windowEnabled') { [bool]`$config.collectors.windowEnabled } else { `$true } +`$fileOpsEnabled = if (`$config.PSObject.Properties.Name -contains 'collectors' -and `$config.collectors.PSObject.Properties.Name -contains 'fileOpsEnabled') { [bool]`$config.collectors.fileOpsEnabled } else { `$true } if (`$afkEnabled -and -not (Test-Path -LiteralPath `$afkExe)) { throw "Не найден aw-watcher-afk.exe: `$afkExe" @@ -687,6 +699,9 @@ catch { } Start-CollectorScriptIfNeeded -ScriptPath `$collectorScript -ConfigPath `$ConfigPath -PowerShellExe `$powershellExe -SessionId `$sessionId Start-CollectorScriptIfNeeded -ScriptPath `$endpointCollectorScript -ConfigPath `$ConfigPath -PowerShellExe `$powershellExe -SessionId `$sessionId +if (`$fileOpsEnabled) { + Start-CollectorScriptIfNeeded -ScriptPath `$fileCollectorScript -ConfigPath `$ConfigPath -PowerShellExe `$powershellExe -SessionId `$sessionId +} Start-CollectorScriptIfNeeded -ScriptPath `$sessionCollectorScript -ConfigPath `$ConfigPath -PowerShellExe `$powershellExe -SessionId `$sessionId "@ diff --git a/windows/deploy-domain-users.ps1 b/windows/deploy-domain-users.ps1 index 8518ba5..ae12146 100755 --- a/windows/deploy-domain-users.ps1 +++ b/windows/deploy-domain-users.ps1 @@ -18,6 +18,7 @@ param( [int]$RecoveryIntervalSeconds = 180, [bool]$AfkEnabled = $true, [bool]$WindowEnabled = $true, + [bool]$FileOpsEnabled = $true, [bool]$LocalAgentLogsEnabled = $false, [bool]$IncidentCaptureEnabled = $true, [bool]$IncidentScreenshotEnabled = $true, @@ -44,6 +45,7 @@ $launchScriptPath = Join-Path $StateRoot 'launch-watchers.ps1' $recoveryScriptPath = Join-Path $StateRoot 'recovery-loop.ps1' $collectorSource = Join-Path $PSScriptRoot 'browser-domains-native-collector.ps1' $endpointCollectorSource = Join-Path $PSScriptRoot 'dlp-endpoint-signals-collector.ps1' +$fileCollectorSource = Join-Path $PSScriptRoot 'file-operations-collector.ps1' $sessionCollectorSource = Join-Path $PSScriptRoot 'worktime-session-collector.ps1' $exampleRulesSource = Join-Path $PSScriptRoot 'web-category-rules.example.json' $examplePolicySource = Join-Path $PSScriptRoot 'dlp-policy.example.json' @@ -58,6 +60,7 @@ Get-ActivityWatchExecutableMap -InstallRoot $InstallRoot | Out-Null $assetResult = Copy-ActivityWatchCollectorAssets ` -CollectorScriptSource $collectorSource ` -EndpointCollectorScriptSource $endpointCollectorSource ` + -FileCollectorScriptSource $fileCollectorSource ` -SessionCollectorScriptSource $sessionCollectorSource ` -ExampleRulesSource $exampleRulesSource ` -ExamplePolicySource $examplePolicySource ` @@ -78,6 +81,7 @@ $config = New-ActivityWatchDeploymentConfig ` -LogsRoot $logsRoot ` -CollectorScript $assetResult.CollectorScript ` -EndpointCollectorScript $assetResult.EndpointCollectorScript ` + -FileCollectorScript $assetResult.FileCollectorScript ` -SessionCollectorScript $assetResult.SessionCollectorScript ` -RulesPath $assetResult.ActiveRules ` -PolicyPath $assetResult.ActivePolicy ` @@ -86,6 +90,7 @@ $config = New-ActivityWatchDeploymentConfig ` -RecoveryIntervalSeconds $RecoveryIntervalSeconds ` -AfkEnabled $AfkEnabled ` -WindowEnabled $WindowEnabled ` + -FileOpsEnabled $FileOpsEnabled ` -LocalAgentLogsEnabled $LocalAgentLogsEnabled ` -IncidentCaptureEnabled $IncidentCaptureEnabled ` -IncidentScreenshotEnabled $IncidentScreenshotEnabled ` diff --git a/windows/deploy-ensemble.ps1 b/windows/deploy-ensemble.ps1 index 24c873a..fa6fd75 100644 --- a/windows/deploy-ensemble.ps1 +++ b/windows/deploy-ensemble.ps1 @@ -18,6 +18,7 @@ param( [int]$RecoveryIntervalSeconds = 180, [bool]$AfkEnabled = $true, [bool]$WindowEnabled = $true, + [bool]$FileOpsEnabled = $true, [bool]$LocalAgentLogsEnabled = $false, [bool]$IncidentCaptureEnabled = $true, [bool]$IncidentScreenshotEnabled = $true, @@ -64,6 +65,7 @@ if (-not (Test-Path -LiteralPath $deployScript)) { -RecoveryIntervalSeconds $RecoveryIntervalSeconds ` -AfkEnabled $AfkEnabled ` -WindowEnabled $WindowEnabled ` + -FileOpsEnabled $FileOpsEnabled ` -LocalAgentLogsEnabled $LocalAgentLogsEnabled ` -IncidentCaptureEnabled $IncidentCaptureEnabled ` -IncidentScreenshotEnabled $IncidentScreenshotEnabled ` @@ -86,6 +88,7 @@ if (-not $SkipHardening) { -RecoveryIntervalSeconds $RecoveryIntervalSeconds ` -AfkEnabled $AfkEnabled ` -WindowEnabled $WindowEnabled ` + -FileOpsEnabled $FileOpsEnabled ` -LocalAgentLogsEnabled $LocalAgentLogsEnabled ` -IncidentCaptureEnabled $IncidentCaptureEnabled ` -IncidentScreenshotEnabled $IncidentScreenshotEnabled ` @@ -112,6 +115,7 @@ $report = [ordered]@{ collectors = [ordered]@{ afkEnabled = $AfkEnabled windowEnabled = $WindowEnabled + fileOpsEnabled = $FileOpsEnabled } hardeningApplied = (-not $SkipHardening) } diff --git a/windows/file-operations-collector.ps1 b/windows/file-operations-collector.ps1 new file mode 100644 index 0000000..368a260 --- /dev/null +++ b/windows/file-operations-collector.ps1 @@ -0,0 +1,169 @@ +[CmdletBinding()] +param( + [string]$ConfigPath = 'C:\ProgramData\AWatch-rus\deployment-config.json', + [string]$ServerHost, + [int]$ServerPort, + [ValidateSet('http', 'https')] + [string]$ServerScheme, + [string]$PolicyPath, + [string]$LogPath, + [int]$PollSeconds = 10, + [string[]]$WatchPaths = @('Desktop', 'Documents', 'Downloads') +) + +Set-StrictMode -Version Latest +$ErrorActionPreference = 'Stop' + +# Реестр известных бакетов +$script:KnownBuckets = @{} +$script:Hostname = $env:COMPUTERNAME +$script:SessionId = [System.Diagnostics.Process]::GetCurrentProcess().SessionId + +# Настройка логирования +$script:LogPath = $LogPath +$script:LocalAgentLogsEnabled = [bool]$LogPath + +function Get-DeploymentConfig { + param([string]$Path) + if ($Path -and (Test-Path -LiteralPath $Path)) { + return Get-Content -LiteralPath $Path -Raw | ConvertFrom-Json + } + return $null +} + +function Write-FileCollectorLog { + param([string]$Message) + if (-not $script:LocalAgentLogsEnabled) { return } + try { + Add-Content -LiteralPath $script:LogPath -Value ('{0} [FileCollector] {1}' -f (Get-Date -Format s), $Message) + } catch {} +} + +function Invoke-AwJsonPost { + param( + [Parameter(Mandatory = $true)][string]$Uri, + [Parameter(Mandatory = $true)][string]$Json + ) + $bytes = [Text.Encoding]::UTF8.GetBytes($Json) + Invoke-RestMethod -Method Post -Uri $Uri -ContentType 'application/json; charset=utf-8' -Body $bytes | Out-Null +} + +function Ensure-Bucket { + param( + [string]$BucketId, + [string]$ClientName, + [string]$BucketType + ) + if ($script:KnownBuckets.ContainsKey($BucketId)) { return } + $body = @{ + client = $ClientName + type = $BucketType + hostname = $script:Hostname + } | ConvertTo-Json -Compress + Invoke-AwJsonPost -Uri "$($script:ApiBase)/buckets/$BucketId" -Json $body + $script:KnownBuckets[$BucketId] = $true +} + +function Send-FileOperationEvent { + param( + [string]$Operation, + [string]$FilePath, + [string]$OldFilePath = $null, + [long]$Size = 0 + ) + + $bucketId = 'aw-file-operations_' + $script:Hostname + Ensure-Bucket -BucketId $bucketId -ClientName 'aw-file-operations' -BucketType 'aw.file.operation' + + $data = @{ + operation = $Operation + path = $FilePath + extension = [System.IO.Path]::GetExtension($FilePath) + username = $env:USERNAME + hostname = $script:Hostname + } + if ($OldFilePath) { $data.oldPath = $OldFilePath } + if ($Size -gt 0) { $data.size = $Size } + + # Детекция архивации (упрощенная) + if ($Operation -eq 'Created' -and $data.extension -match '\.(zip|7z|rar|tar|gz)$') { + $data.archiveHint = $true + } + + $payload = @{ + timestamp = (Get-Date).ToUniversalTime().ToString('yyyy-MM-ddTHH:mm:ss.fffZ') + duration = 0 + data = $data + } | ConvertTo-Json -Depth 5 -Compress + + Invoke-AwJsonPost -Uri "$($script:ApiBase)/buckets/$bucketId/heartbeat?pulsetime=15" -Json $payload +} + +# --- Инициализация --- +$config = Get-DeploymentConfig -Path $ConfigPath +$scheme = if ($ServerScheme) { $ServerScheme } elseif ($config.serverScheme) { $config.serverScheme } else { 'http' } +$hostName = if ($ServerHost) { $ServerHost } elseif ($config.serverHost) { $config.serverHost } else { 'localhost' } +$port = if ($ServerPort) { $ServerPort } elseif ($config.serverPort) { $config.serverPort } else { 5600 } +$script:ApiBase = "{0}://{1}:{2}/api/0" -f $scheme, $hostName, $port + +# Разрешение путей для мониторинга +$resolvedPaths = @() +foreach ($p in $WatchPaths) { + $fullPath = $p + if (-not [System.IO.Path]::IsPathRooted($p)) { + try { + # Пробуем через Known Folders или переменные окружения + if ($p -eq 'Desktop') { $fullPath = [Environment]::GetFolderPath('Desktop') } + elseif ($p -eq 'Documents') { $fullPath = [Environment]::GetFolderPath('MyDocuments') } + elseif ($p -eq 'Downloads') { $fullPath = Join-Path $env:USERPROFILE 'Downloads' } + } catch {} + } + if (Test-Path -LiteralPath $fullPath) { + $resolvedPaths += $fullPath + } +} + +if ($resolvedPaths.Count -eq 0) { + Write-FileCollectorLog "Нет доступных путей для мониторинга. Завершение." + exit 0 +} + +Write-FileCollectorLog "Запуск мониторинга путей: $($resolvedPaths -join ', ')" + +$watchers = @() +foreach ($path in $resolvedPaths) { + $watcher = New-Object System.IO.FileSystemWatcher + $watcher.Path = $path + $watcher.IncludeSubdirectories = $true + $watcher.EnableRaisingEvents = $true + + $onChanged = Register-ObjectEvent $watcher "Created" -Action { + $path = $Event.SourceEventArgs.FullPath + $size = 0 + try { if (Test-Path -LiteralPath $path) { $size = (Get-Item -LiteralPath $path).Length } } catch {} + Send-FileOperationEvent -Operation 'Created' -FilePath $path -Size $size + } + $onDeleted = Register-ObjectEvent $watcher "Deleted" -Action { + Send-FileOperationEvent -Operation 'Deleted' -FilePath $Event.SourceEventArgs.FullPath + } + $onRenamed = Register-ObjectEvent $watcher "Renamed" -Action { + Send-FileOperationEvent -Operation 'Renamed' -FilePath $Event.SourceEventArgs.FullPath -OldFilePath $Event.SourceEventArgs.OldFullPath + } + + $watchers += $watcher +} + +Write-FileCollectorLog "Коллектор запущен. Ожидание событий..." + +try { + while ($true) { + Start-Sleep -Seconds $PollSeconds + } +} +finally { + Write-FileCollectorLog "Остановка коллектора..." + foreach ($w in $watchers) { + $w.EnableRaisingEvents = $false + $w.Dispose() + } +}