MeshWatch Central 1.3.8 — running it on Windows Server with Node
================================================================

Read LICENCE.txt first. This is licensed software, not open source.
You may run it on your own servers. You may not redistribute it.

Why this bundle exists
----------------------
The Docker image is a Linux image. Windows Server's own container mode runs
Windows containers, so it cannot run that image without WSL 2 or a Linux VM.
Node runs natively on Windows Server, so this is the shorter road there.

There are no npm dependencies. Nothing is downloaded at install time.


1. Install Node.js 18 or newer
------------------------------
   https://nodejs.org/  (LTS is fine. Verified on 18 and 22.)

   Then open a NEW PowerShell window and check:

       node --version


2. Put this folder somewhere permanent
--------------------------------------
   For example  C:\MeshWatchCentral


3. Start it
-----------
   In PowerShell, FIRST change into that folder, then start it. Missing that
   first line is the usual mistake — Node then looks for src\server.js in
   whatever folder you happen to be in and says "Cannot find module".

       cd C:\MeshWatchCentral\mwc-1.3.8
       $env:MWC_DATA_DIR = "C:\ProgramData\meshwatch-central"
       node src\server.js

   MWC_DATA_DIR is where the database and settings are written. Pick a path
   that is backed up and that the account running Node can write to.

   If something already uses port 8443 on this server, change it:

       $env:MWC_PORT = "9443"

   Then use that number everywhere below instead of 8443 — the browser
   address, the firewall rule, and the Central URL you give each product.

   Other settings, all optional:

       MWC_PORT             8443       port to listen on
       MWC_HOST             0.0.0.0    address to bind
       MWC_SECURE_COOKIES   0          set to 1 only when behind HTTPS


4. Open it
----------
       http://localhost:8443

   Note http:// — NOT https://. Port 8443 usually means HTTPS, but Central
   speaks plain HTTP until you put a reverse proxy in front of it. From
   another machine use http://<this-server>:8443, and open port 8443 in
   Windows Firewall.

   The first screen asks you to create the administrator account. It only
   ever appears once.


If nobody can sign in
---------------------

The first person to open Central creates the administrator. After that, the sign-in
screen no longer offers to create one. If the password is lost, open a Command Prompt
in this folder and run:

    node src\server.js --reset-password <username>

If you do not know the username, run it with any name -- it will refuse and list the
accounts that exist. It asks for the new password twice and does not show it on
screen. Sessions that were open are closed.

5. Connect your products — nothing appears until you do
-------------------------------------------------------
   Central does not find your products by itself. The dashboard stays at
   zero until each product is pointed at it.

   a) Open port 8443 so the products can reach this server:

          New-NetFirewallRule -DisplayName "MeshWatch Central 8443" `
            -Direction Inbound -LocalPort 8443 -Protocol TCP -Action Allow

   b) Find this server's address:

          ipconfig | Select-String IPv4

   c) In Central, open the Agents tab and issue a token for a product.
      It is shown once — copy it then.

      A token belongs to the product you picked in the dropdown, and to
      no other. Central records every report under the product the token
      was issued for, whatever the sending application is. So a
      DeviceWatch installation given a SyslogWatch token still reports
      successfully, and everything it sends is filed under SyslogWatch:
      the DeviceWatch row stays empty and no error is shown anywhere.
      Issue one token per product, and check the badge in the Agents row
      to see which product a token actually belongs to.

   d) In that product's own Settings, find MeshWatch Central and fill in:

          Central URL   http://<this-server-ip>:8443
          Token         the mwc_... value you just copied

      Use the server's IP, not localhost — the product is running on a
      different machine.

      Type the address carefully. Most mistyped addresses are still
      valid addresses: 127.0.0.01 is read as 127.0.0.1 and 192.168.001.5
      as 192.168.1.5, so the connection simply goes somewhere else and
      the product reports that Central cannot be reached.

   e) Press Test connection in the product. It should say it is
      connected and name the agent. If it names a different product,
      the token belongs to that one — issue a new token and revoke this.

   f) Repeat for each product. Central accepts these, at these versions
      or newer:

          SyslogWatch  1.3.0      CertWatch    0.3.0
          DeviceWatch  1.2.0      ConfigWatch  0.3.0
          TrafficWatch 1.1.0      TrapWatch    0.1.0

      TrapWatch needs Central 1.3.4 or newer to appear in the Agents
      tab. This bundle is newer than that, so it is there.

   Alerts raised from then on appear in Central. Past alerts are not
   backfilled. A correlated incident appears when two different products
   report on the same device within 30 minutes.

   In the Agents tab a row is "waiting" until the token has contacted
   Central at all, "connected" once the product's Test connection has
   succeeded but nothing has been sent yet, and "reporting" once it has
   sent an alert or a device. "connected" is normal for a while:
   ConfigWatch becomes "reporting" after one backup run and TrapWatch
   when the first trap arrives. There is no "down" state - products do
   not send a heartbeat - so read the "Last contact" column instead.


6. Keeping it running after logout or reboot
--------------------------------------------
   Started from a PowerShell window, it stops when that window closes.
   For a real deployment register it as a service — NSSM, or a scheduled
   task set to run at startup, whichever your shop already uses.


Notes
-----
* The 30-day trial starts on first run. No card, no account, nothing is
  sent anywhere.
* Everything lives in MWC_DATA_DIR. Back that folder up and you have backed
  up Central.
* HTTPS: put a reverse proxy in front, then set MWC_SECURE_COOKIES=1.
  Setting it without HTTPS in place will break login.

Questions: support@meshwatch.app
