igor04091968
28a4dae67f
feat(dlp): implement case management service and DLP Review integration
2026-05-13 03:08:53 +03:00
igor04091968
bc44052391
fix(health): treat stale file-operations buckets as warning by default
2026-05-13 02:35:59 +03:00
igor04091968
fd2e9ac59d
feat(dlp): implement SIEM/SOAR integrations (CEF, webhook, syslog, systemd timers)
2026-05-13 02:30:52 +03:00
igor04091968
067457198d
fix(webui): avoid category-builder crash on aw-watcher-window_unknown buckets
2026-05-13 02:10:04 +03:00
igor04091968
8619c14735
fix(deploy): make AW DB merge idempotent and non-fatal on name-unique conflicts
2026-05-13 02:04:28 +03:00
igor04091968
0bc0fe7d78
fix(webui): rewrite unknown watcher buckets for all query routes
2026-05-12 16:57:03 +03:00
igor04091968
4e99100e6c
fix(worktime): add API self-heal and bot worktime remediation deploy vars
2026-05-12 16:48:30 +03:00
igor04091968
bfa7c5bff2
fix(worktime): normalize bridge durations and tighten autoheal backfill window
2026-05-12 06:06:14 +03:00
igor04091968
64158e97a4
feat(worktime): add automatic self-heal timer for zero-activity regressions
2026-05-12 06:01:07 +03:00
igor04091968
012bfb266f
fix(worktime): compute non-zero bridge durations from timestamp deltas
2026-05-12 05:25:14 +03:00
igor04091968
f180e2c3dc
feat(ops): add diagnostics and manual restart script for AW stack
2026-05-12 05:19:37 +03:00
igor04091968
c624db5dd7
feat(dlp-policy): add approval workflow, full audit trail, and CRUD documentation
2026-05-12 01:11:01 +03:00
igor04091968
518c445157
feat(dlp-policy): add agent heartbeat/desired refresh channel for push-pull policy sync
2026-05-12 01:01:08 +03:00
igor04091968
d812a8bb80
fix(dlp): enforce server policy mode and preserve policy-engine settings in hardening
2026-05-12 00:07:05 +03:00
igor04091968
b213552d9d
feat(dlp): add enterprise phase scaffolds (policy role, content analysis, siem, case, compliance, cli)
2026-05-11 23:18:20 +03:00
igor04091968
8be0de1c85
feat(ansible): add post-deploy aw-health-check gate
2026-05-11 22:57:57 +03:00
igor04091968
9342e8b907
feat(ops): extend aw health check with dlp transport freshness
2026-05-11 22:36:52 +03:00
igor04091968
5d7137379c
docs(runbook): add deterministic WAL failover test for windows collectors
2026-05-11 22:32:58 +03:00
igor04091968
544304765f
feat(dlp): add WAL transport and collector health telemetry
2026-05-11 21:57:23 +03:00
igor04091968
e0561bf865
fix(windows): disable outlook popup and enforce smtp-only email monitoring
2026-05-11 20:46:39 +03:00
igor04091968
24dd5ae2b4
fix(worktime): add fallback heartbeat when query user returns no sessions
2026-05-10 10:59:21 +03:00
igor04091968
4b5c75bdbb
feat(dlp): deploy hayabusa IOC refresh on aw-server with post-deploy checks
2026-05-10 03:13:28 +03:00
igor04091968
c43f9b8708
feat(dlp): add hayabusa sigma IOC extraction pipeline
2026-05-09 17:02:31 +03:00
igor04091968
249ba67511
fix(ansible): align validation report dir defaults across windows playbooks
2026-05-09 13:07:27 +03:00
igor04091968
ce428fb5f8
fix(worktime-bridge): do not let active=false mask unknown-session fallback
2026-05-09 12:31:16 +03:00
igor04091968
2bf667fccc
fix(worktime-bridge): treat unknown non-system RDP sessions as active
2026-05-09 12:29:42 +03:00
igor04091968
380983b546
fix(worktime-api): count unknown RDP sessions with valid user/session as active
2026-05-09 12:28:37 +03:00
igor04091968
6ab29a9590
fix(worktime): harden query-user parsing and skip unknown fallback
2026-05-09 12:24:52 +03:00
igor04091968
f22cd27e31
fix(ansible): harden WinRM deploy wrapper with md4+retry
2026-05-09 11:00:59 +03:00
igor04091968
c9df042d96
tools(ansible): add no-proxy wrapper for WinRM deploy
2026-05-09 10:13:58 +03:00
igor04091968
aa0ccc4ecf
fix(ansible): run smoke-check on controller + per-user validation dir
2026-05-09 09:42:36 +03:00
igor04091968
2997e7430a
fix(ansible): always enable launch tasks + validate window bucket
2026-05-09 08:48:05 +03:00
igor04091968
7a320d7862
fix(windows): stabilize standalone agent + DLP/worktime collectors
2026-05-09 08:29:18 +03:00
igor04091968
5ddceb4dc3
chore: добавить артефакты анализа кода в .gitignore
2026-05-09 08:29:18 +03:00
igor04091968
230a9c6936
fix(windows): harden worktime session collector encoding and query parsing
2026-05-08 10:54:18 +03:00
igor04091968
6a36febfeb
docs: capture todo - deploy standalone agent on SHARKON2025
2026-05-08 08:15:53 +03:00
igor04091968
e80272a55f
docs(installer): document standalone service mode and minimal host/port setup
2026-05-08 00:44:48 +03:00
igor04091968
1c3d7896cd
feat(installer): add standalone Windows service deployment for DLP agent
2026-05-08 00:41:00 +03:00
igor04091968
211a6a6eac
fix(windows-deploy): enforce awHostname override and safe single-instance collector restart
2026-05-08 00:41:00 +03:00
igor04091968
6f5e5eb751
Revert "merge: apply windows standalone service installer and awHostname hardening"
...
This reverts commit e643576aa9 , reversing
changes made to 669501f20a .
2026-05-08 00:41:00 +03:00
igor04091968
e643576aa9
merge: apply windows standalone service installer and awHostname hardening
2026-05-08 00:40:19 +03:00
igor04091968
f5f4f84bef
feat(installer): add standalone Windows service deployment for DLP agent
2026-05-08 00:39:28 +03:00
igor04091968
693e6832a6
fix(windows-deploy): enforce awHostname override and safe single-instance collector restart
2026-05-08 00:34:52 +03:00
igor04091968
538ff74611
feat(dlp): add health status and graceful shutdown for browser collector
2026-05-07 23:54:52 +03:00
igor04091968
b992ad2234
feat(dlp): graceful shutdown and COM cleanup for email collector
2026-05-07 23:52:03 +03:00
igor04091968
ac59d44719
feat(dlp): add WAL buffering and health snapshots for collectors
2026-05-07 23:47:03 +03:00
igor04091968
f3c5e9ea53
feat(dlp-hardening): secure inventory and extend aggregator sources
2026-05-07 23:38:20 +03:00
igor04091968
38107b3c84
ansible: remove per-host passwords from inventory\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-05-07 23:37:47 +03:00
igor04091968
8ad02ae194
docs(gsd): bootstrap planning and phase-1 discussion artifacts
2026-05-07 21:39:32 +03:00
igor04091968
2fd0ca8eda
docs: add copilot instructions
2026-05-07 21:37:42 +03:00
igor04091968
9c59f74928
chore(install-kit): sync package payload with current repo baseline
2026-05-07 19:50:07 +03:00
igor04091968
0c5069c255
chore(ops): harden rollout gates and sanitize generated artifacts
2026-05-07 19:50:02 +03:00
igor04091968 and Copilot
f0db2a227b
revert(pssa): restore validate-deployment.ps1 from commit 63904d2 (stable)
...
Restored clean version to fix corruption introduced earlier.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
2026-05-07 19:22:05 +03:00
igor04091968 and Copilot
e37c3886ba
revert(pssa): restore files corrupted by automatic fixes (ActivityWatch.Windows.Common.psm1, email-outbound-collector.ps1, file-operations-collector.ps1)
...
Restored previous versions for files that were corrupted by the automated PSScriptAnalyzer fixes. Please review and reapply safe fixes manually.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
2026-05-07 18:10:12 +03:00
igor04091968 and Copilot
429501d4fe
chore(pssa): apply safe PSScriptAnalyzer fixes (BOM, empty catch -> Write-Error, Write-Host -> Write-Output)
...
Applied automatic, low-risk fixes for PSScriptAnalyzer warnings. Please review changes for behavior-sensitive code.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
2026-05-07 12:50:35 +03:00
igor04091968
3e8a6981f5
fix(shell): silence remaining ShellCheck warnings for validate_install_kit and install_aw_linux_remote_worker\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-05-07 12:39:32 +03:00
igor04091968
c9f3aad89c
fix(shell): address ShellCheck warnings (remove SC2181 checks, safer prompt_secret, add selective suppressions)\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-05-07 12:35:23 +03:00
igor04091968
669501f20a
fix(worktime): treat russian session state 'Активно' as active
2026-05-07 09:07:19 +03:00
igor04091968
cd5fd95faf
fix(aw): stabilize ui bridge and restore dlp endpoint collector
2026-05-07 08:57:36 +03:00
igor04091968
8b92b1136f
chore: merge main into PR #15
2026-05-07 07:34:36 +03:00
igor04091968
8571832615
chore: merge main into PR #19
2026-05-07 07:33:53 +03:00
igor04091968
8849354dda
fix(worktime): codify ui-bridge in ansible and install flow
2026-05-07 07:20:14 +03:00
igor04091968
d91a396c00
feat(webui): add HTML and panel view for worktime reports
2026-05-07 06:41:42 +03:00
igor04091968
8a91734a27
fix(worktime): use Europe/Moscow day boundary for aw-rus today reports
2026-05-07 06:30:12 +03:00
igor04091968
1df0e18a95
fix(collectors): stabilize browser+DLP collectors and add rdp worktime report script
2026-05-06 23:32:03 +03:00
igor04091968
a6a05b82a9
fix(webui): persist worktime report links to :5610 in ansible/installkit
2026-05-06 23:24:52 +03:00
igor04091968
03fefcc257
fix(deploy): harden windows rollout, validation and installkit payload
2026-05-06 20:14:51 +03:00
igor04091968
9eb02185dd
fix(windows): stabilize AW deploy/validate and watcher launch script
2026-05-06 20:05:43 +03:00
igor04091968
82ee9ab4fa
tools: add AW health checks and test DLP policy
2026-05-05 06:38:04 +03:00
igor04091968 and Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
eb83a8b08f
docs(wiki): add GitHub wiki pages for documentation
...
- Home page with navigation and quick start
- Architecture overview with layers and data flows
- Components documentation for all system parts
- Interactive map guide with usage instructions
- DLP Endpoint Monitoring detailed guide
- Browser Domains Monitoring guide
- WebUI Russian Patches documentation
- Windows Installation guide
- Server Setup guide
- Monitoring Setup with Prometheus/Grafana
Generated with [Devin](https://cli.devin.ai/docs )
Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-05-05 01:56:30 +03:00
igor04091968 and Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
7a89f33e3b
docs(diagrams): add interactive architecture map HTML
...
- Interactive component map with visual connections
- Click to see component details and data flows
- Search functionality for quick component lookup
- Connection highlighting when selecting components
- Responsive design with color-coded layers
- Component information panel with ports, protocols, flows
Generated with [Devin](https://cli.devin.ai/docs )
Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-05-05 01:51:25 +03:00
igor04091968 and Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
d8320799e6
docs(diagrams): add component-level architecture diagrams
...
- DLP Endpoint Monitoring diagram with data flows
- Browser Domains Monitoring with categorization
- WebUI Russian Localization patches structure
- DLP Events Aggregation pipeline
- Prometheus Metrics Exporter architecture
- System overview with all components and connections
Generated with [Devin](https://cli.devin.ai/docs )
Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-05-05 01:49:55 +03:00
igor04091968 and Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
db1998c428
docs(architecture): add readable architecture diagrams
...
- Add Mermaid diagram for high-level architecture
- Add simple ASCII architecture for quick understanding
- Document data flows for all monitoring scenarios
- Include deployment steps and port mappings
- Add quick start guide and key scenarios
Generated with [Devin](https://cli.devin.ai/docs )
Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-05-05 01:46:50 +03:00
igor04091968 and Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
f6074facf5
docs(graphify): add detailed knowledge graph documentation for wiki
...
- Explain what knowledge graph is and why it's useful
- Document all 27 communities with purposes
- Describe key components: DLP monitoring, WebUI patches, collectors
- Provide usage guide for interactive visualization
- Include statistics and architecture recommendations
Generated with [Devin](https://cli.devin.ai/docs )
Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-05-05 01:45:32 +03:00
igor04091968 and Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
3f3e3a953f
docs(graphify): add ActivityWatch knowledge graph visualization
...
- Generate AST-based knowledge graph with 404 nodes and 933 edges
- 27 communities showing code structure and relationships
- Interactive HTML visualization for exploring code architecture
- Report documenting main functional clusters
Generated with [Devin](https://cli.devin.ai/docs )
Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-05-05 01:44:27 +03:00
igor04091968 and Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
d5735ba127
feat(grafana): add ActivityWatch Prometheus exporter and dashboards
...
- Add Python exporter for ActivityWatch API metrics collection
- Configure Prometheus to scrape ActivityWatch exporter
- Create Grafana dashboard for ActivityWatch overview
- Integrate ActivityWatch monitoring into existing docker-compose stack
- Add Prometheus datasource for ActivityWatch metrics
Generated with [Devin](https://cli.devin.ai/docs )
Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-05-05 01:32:50 +03:00
igor04091968 and Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
10c22a6c88
fix(windows): add STA parameter for DLP collector and use TEMP for lock files
...
- Add -STA parameter when launching endpoint-signals collector for clipboard access
- Move launch-watchers lock files from ProgramData to TEMP to avoid permission issues
- This fixes DLP endpoint collector startup in RDP sessions
Generated with [Devin](https://cli.devin.ai/docs )
Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-05-05 00:55:04 +03:00
igor04091968 and Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
9e5cb144d4
fix(windows): standardize config paths to AWatch-rus and add bucket hostname filter
...
- Replace default config paths from C:\ProgramData\ActivityWatch to C:\ProgramData\AWatch-rus
in dlp-endpoint-signals-collector.ps1 and email-outbound-collector.ps1
- Add isLikelyClientHost() function to reject IP/localhost as valid hostname
for bucket selection in aw-ru-patch.js
- Add docs/dlp-reliability-roadmap.md and docs/powershell-analysis.md
- Update README.md with links to new documentation
Generated with [Devin](https://cli.devin.ai/docs )
Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-05-04 23:24:49 +03:00
igor04091968
bfee99d679
fix(windows): prevent collector process storms and scope query patch
2026-05-04 21:05:44 +03:00
igor04091968
5a2684fb3b
fix: proper single UTF-8 BOM
2026-05-04 07:24:14 +03:00
igor04091968
e2b2f805fb
Merge remote-tracking branch 'origin/devin/1777752962-file-collector-bucket'
2026-05-04 06:05:39 +03:00
igor04091968
6578f6341f
fix: add UTF-8 BOM for PS 5.1
2026-05-04 00:22:15 +03:00
igor04091968
cc33ffa3dc
fix: add UTF-8 BOM for PowerShell 5.1 compatibility
2026-05-04 00:14:32 +03:00
igor04091968
ff548a5840
Merge PR #14 : feat(dlp) enforcement + email outbound collector
2026-05-03 23:41:00 +03:00
igor04091968
3e565b7a2e
fix: create /root/bootstrap directory before copying files
...
Add ansible.builtin.file task to ensure /root/bootstrap exists
before copying RU patch files to it (prevents first-deploy failure)
2026-05-03 23:08:48 +03:00
igor04091968
3fa15f826d
fix: env file before hotfixes + improved error handling
...
- Move env file creation before apply_webui_ru_patch.sh execution
- Replace ignore_errors with failed_when: false + register + debug output
- Provides visible feedback on hotfix script execution result
2026-05-03 22:56:31 +03:00
igor04091968
08ba731345
fix: apply WebUI hotfixes via apply_webui_ru_patch.sh + filter undefined hostname
...
- Add CATEGORY_HELPER filter for 'undefined' in addition to 'unknown'
- Add copy of apply_webui_ru_patch.sh to /opt/activitywatch/aw-server/
- Add task to run apply_webui_ru_patch.sh for Trends/Timespiral/Category helper hotfixes
- Fix in both deploy_aw_server.yml (ansible and install-kit)
2026-05-03 22:52:39 +03:00
igor04091968
df497839f6
Merge remote-tracking branch 'origin/main' into devin/1777752962-file-collector-bucket
2026-05-03 22:28:37 +03:00
igor04091968
3971c459ef
Feat: implement automated DLP incident aggregation on server (timer + service)
2026-05-03 01:50:17 +03:00
igor04091968
c97ffe2cbd
Fix: ensure file collector robustness (HttpClient, TLS 1.2, English logs)
2026-05-02 23:42:14 +03:00
igor04091968
b6f019982d
gemeni-3-light
2026-05-02 23:09:54 +03:00
igor04091968 and Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
fae2e2ca14
Feat & Fix: implement File Telemetry, restore DB history, and stabilize production
...
- Added File Operations Collector (Plan A) for Windows endpoints
- Restored historical server DB via merging and moved to durable /var/lib/activitywatch path
- Forced XDG_DATA_HOME and XDG_CONFIG_HOME for aw-server-rust in environment and systemd
- Updated Ansible playbooks to handle new file collector and durable server paths
- Added DB merge and backup-restore automation scripts
- Fixed CORS and RU WebUI persistence in production deployment
Generated with [Devin](https://cli.devin.ai/docs )
Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-05-02 20:59:08 +03:00
igor04091968
f436950bda
Update after codex restore
2026-05-02 19:36:25 +03:00
igor04091968
d7fedde69d
After deploy from hand restore
2026-05-02 17:54:36 +03:00
igor04091968
7f58a49c0a
Разворачивание деплоя
2026-05-02 17:28:49 +03:00
igor04091968
f7cf5556a0
Ofline install InnoSetup
2026-05-02 10:01:39 +03:00
igor04091968
65da55be7a
Patch files Innosetup
2026-05-02 04:12:14 +03:00
igor04091968
8278d51840
feat(worktime): add linux remote worker and pve headless tracking
2026-04-30 15:48:09 +03:00
igor04091968
fa4bf96ebf
feat(ansible): add full-stack installer playbook
2026-04-28 07:10:44 +03:00
igor04091968
b28cfabd57
fix(windows-phase2): codify SHARKON2025 recovery and harden rollout checks
2026-04-28 07:09:29 +03:00