Compare commits
7 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
b41bab4285 | ||
|
|
b603f4d39c | ||
|
|
526c40403b | ||
|
|
7fc0602818 | ||
|
|
3039562e91 | ||
|
|
91208323ab | ||
|
|
292bd12a4b |
1
.gitignore
vendored
Normal file
1
.gitignore
vendored
Normal file
@@ -0,0 +1 @@
|
||||
dist/
|
||||
16
README.md
16
README.md
@@ -2,15 +2,19 @@
|
||||
|
||||
Windows self-service software catalog backed by `winget`.
|
||||
|
||||
Users install approved software through a small GUI or request helper. A SYSTEM scheduled task runs a named-pipe daemon, authenticates the connecting Windows user, validates requests against Group Policy, then runs `winget install --scope machine`.
|
||||
Users install approved software through a small GUI or request helper. User tools write request files to a controlled drop directory. A SYSTEM scheduled task validates those requests against Group Policy, queues approved work, then runs a SYSTEM `winget` worker.
|
||||
|
||||
## What It Does
|
||||
|
||||
- Reads allowed software from GPO registry policy.
|
||||
- Lets users install/uninstall only catalog entries allowed by policy.
|
||||
- Installs required software automatically.
|
||||
- Blocks user removal of required software.
|
||||
- Queues install, uninstall, and upgrade actions.
|
||||
- Shows current queue task and progress in the GUI.
|
||||
- Runs `winget upgrade --all` every 2 hours.
|
||||
- Tracks installed state from `winget export`, not from request history.
|
||||
- Polls user request files every minute; no long-lived user-facing daemon is required.
|
||||
|
||||
## Policy
|
||||
|
||||
@@ -68,8 +72,16 @@ Generated files are written to:
|
||||
C:\ProgramData\__Softwarekatalog\
|
||||
```
|
||||
|
||||
Runtime request files are written below:
|
||||
|
||||
```text
|
||||
C:\ProgramData\__Softwarekatalog\Requests\
|
||||
C:\ProgramData\__Softwarekatalog\Processed\
|
||||
C:\ProgramData\__Softwarekatalog\Failed\
|
||||
```
|
||||
|
||||
## Notes
|
||||
|
||||
- Requires Windows, Desktop App Installer, and `winget`.
|
||||
- The daemon runs as `LocalSystem`; keep catalog policy restricted to trusted admins.
|
||||
- SYSTEM scheduled tasks validate and execute requests; keep catalog policy restricted to trusted admins.
|
||||
- Package IDs and silent machine-scope support depend on upstream `winget` packages.
|
||||
|
||||
@@ -17,7 +17,7 @@ cat > "$out" <<EOF
|
||||
# ASCII-only bootstrap generated from setup.ps1. Do not edit.
|
||||
[CmdletBinding()]
|
||||
param(
|
||||
[ValidateSet('Install','Daemon','UpgradeAll','ApplyPolicy','ProcessRequest')]
|
||||
[ValidateSet('Install','UpgradeAll','ApplyPolicy','ProcessQueue','ProcessRequest','ProcessRequests')]
|
||||
[string]\$Mode = 'Install',
|
||||
[ValidateSet('Install','Uninstall')]
|
||||
[string]\$RequestAction = 'Install',
|
||||
|
||||
Reference in New Issue
Block a user