20-sep: [fix] Sistema completo apagado/encendido remoto - shutdown listener + HA actualizado

This commit is contained in:
juanminsanz
2026-09-20 22:36:58 +02:00
parent a0f99b897d
commit b31279918c
5 changed files with 262 additions and 1 deletions

View File

@@ -0,0 +1,171 @@
# Sistema de Apagado/Encendido Remoto del PC (20-sep-2026)
## Arquitectura del sistema
```
TELEGRAM (iPad/Móvil)
↓ /apagar o /encender
BOT TELEGRAM (PC local - telegram_bot_pc.py)
↓ POST a webhook
HOME ASSISTANT (VPS 185.187.169.109)
↓
├─ APAGAR: POST http://192.168.1.239:5555/shutdown → PC ejecuta shutdown
│ → Espera 30s
│ → Alexa apaga luces (barras + cuartillo)
│ → Alexa apaga regleta (corta corriente)
│
└─ ENCENDER: Alexa enciende regleta
→ Espera 60s (PC arranca físicamente)
→ Wake-on-LAN a 192.168.1.239
```
## Componentes
### 1. Bot Telegram (PC local)
**Archivo:** `INFRAESTRUCTURA/scripts/telegram_bot_pc.py`
**Función:** Interfaz de usuario desde Telegram
**Características:**
- Pide confirmación antes de apagar
- Watchdog automático tras apagar (30s + ping)
- Watchdog automático tras encender (90s + 3 reintentos ping)
- Filtro de autorización por USER_ID
**Arrancar:**
```powershell
cd C:\Users\juanm\Documents\Github\INFRAESTRUCTURA\scripts
python telegram_bot_pc.py
```
### 2. Shutdown Listener (PC local)
**Archivo:** `INFRAESTRUCTURA/scripts/shutdown_listener.py`
**Puerto:** 5555
**Función:** Recibe comandos HTTP de Home Assistant para ejecutar shutdown local
**Seguridad:** Token de autenticación (SHUTDOWN_TOKEN en .env)
**Arrancar:**
```powershell
cd C:\Users\juanm\Documents\Github\INFRAESTRUCTURA\scripts
python shutdown_listener.py
```
**Health check:**
```powershell
Invoke-WebRequest -Uri "http://127.0.0.1:5555/health"
```
**Ejecutar shutdown (requiere token):**
```powershell
Invoke-WebRequest -Uri "http://127.0.0.1:5555/shutdown" `
-Method POST `
-Headers @{ "Authorization" = "Bearer $env:SHUTDOWN_TOKEN" }
```
### 3. Home Assistant (VPS)
**Ubicación:** `root@185.187.169.109:/opt/homeassistant`
**Función:** Orquestador central (recibe webhooks, ejecuta shutdown, controla luces/regleta vía Alexa)
**Archivos de configuración:**
- `/opt/homeassistant/config/automations.yaml` — Webhooks `/apagar-pc-juanjo` y `/encender-pc-juanjo`
- `/opt/homeassistant/config/scripts.yaml` — Scripts `apagar_pc_completo` y `encender_pc_completo`
- `/opt/homeassistant/config/configuration.yaml` — REST command `shutdown_pc_local`
**Reiniciar:**
```bash
cd /opt/homeassistant && docker compose restart homeassistant
```
### 4. Dispositivos Alexa
- **Echo Dot de Nahid:** Ejecuta comandos de voz para luces y regleta
- **Luces:** barras, cuartillo
- **Regleta:** Enchufe inteligente que alimenta el PC
## Flujo de apagado completo
1. Usuario en Telegram: `/apagar` → Botón "🔴 Apagar PC"
2. Bot pide confirmación: "✅ SÍ, apagar" | "❌ Cancelar"
3. Si confirma → Bot envía POST a `http://185.187.169.109:8123/api/webhook/apagar-pc-juanjo`
4. Home Assistant ejecuta `script.apagar_pc_completo`:
- **4.1** POST a `http://192.168.1.239:5555/shutdown` (con token)
- **4.2** PC ejecuta `shutdown /s /t 10`
- **4.3** Espera 30s
- **4.4** Alexa apaga "barras"
- **4.5** Alexa apaga "cuartillo"
- **4.6** Alexa apaga "regleta" (corta corriente al PC)
5. Bot espera 30s y verifica con ping:
- Si responde → "⚠️ APAGADO FALLIDO"
- Si no responde → "✅ PC APAGADO CONFIRMADO"
## Flujo de encendido completo
1. Usuario en Telegram: `/encender` → Botón "🟢 Encender PC"
2. Bot envía POST a `http://185.187.169.109:8123/api/webhook/encender-pc-juanjo`
3. Home Assistant ejecuta `script.encender_pc_completo`:
- **3.1** Alexa enciende "regleta" (da corriente al PC)
- **3.2** Espera 60s (PC arranca físicamente)
- **3.3** Envía Wake-on-LAN a `192.168.1.239` (MAC: `70:85:c2:6b:3a:03`)
4. Bot espera 90s + hasta 3 reintentos (15s cada uno) verificando con ping:
- Si responde → "✅ PC ENCENDIDO CORRECTAMENTE"
- Si no responde → "❌ ENCENDIDO FALLIDO"
5. PC arranca → Windows inicia → **Autologon** → Escritorio listo → Watchers arrancan
## Variables de entorno necesarias (.env)
```bash
# Bot Telegram
TELEGRAM_BOT_PC_TOKEN=<token del bot @juanjo_pc_control_bot>
TELEGRAM_USER_ID=325737724
# Shutdown Listener
SHUTDOWN_TOKEN=H7iLGJixPp3J3pthCmnR2Ibq0tvERD5THyr_foAeN_8
```
## Tareas programadas recomendadas
### Shutdown Listener (arrancar al iniciar Windows)
```xml
Nombre: Shutdown Listener
Descripción: Listener HTTP para apagado remoto del PC
Acción: python C:\Users\juanm\Documents\Github\INFRAESTRUCTURA\scripts\shutdown_listener.py
Desencadenador: Al iniciar sesión
Usuario: juanm
```
### Bot Telegram (arrancar al iniciar Windows)
```xml
Nombre: Bot Telegram Control PC
Descripción: Bot de Telegram para control remoto del PC
Acción: python C:\Users\juanm\Documents\Github\INFRAESTRUCTURA\scripts\telegram_bot_pc.py
Desencadenador: Al iniciar sesión
Usuario: juanm
```
Script de instalación: `INFRAESTRUCTURA/scripts/instalar_watchers.ps1` (añadir estas tareas)
## Troubleshooting
### El apagado no funciona
1. Verificar que el shutdown listener está corriendo: `http://127.0.0.1:5555/health`
2. Verificar token en `.env` (SHUTDOWN_TOKEN)
3. Revisar logs de Home Assistant: `ssh root@185.187.169.109 "docker logs homeassistant -f"`
4. Probar shutdown manual: `Invoke-WebRequest -Uri "http://127.0.0.1:5555/shutdown" -Method POST -Headers @{ "Authorization" = "Bearer TOKEN" }`
### El encendido no funciona
1. Verificar que la regleta enciende (luz física)
2. Verificar Wake-on-LAN habilitado en BIOS
3. Verificar MAC del PC correcta en HA: `70:85:c2:6b:3a:03`
4. Probar WoL manual: `wakeonlan 70:85:c2:6b:3a:03`
### El bot no responde
1. Verificar que está corriendo: `Get-CimInstance Win32_Process | Where-Object { $_.CommandLine -match "telegram_bot_pc" }`
2. Revisar logs: `C:\Users\juanm\Documents\Github\INFRAESTRUCTURA\scripts\telegram_bot_pc.log`
3. Verificar token: `TELEGRAM_BOT_PC_TOKEN` en `.env`
4. Verificar USER_ID autorizado: `TELEGRAM_USER_ID=325737724`
## Seguridad
- ✅ Bot solo responde a USER_ID autorizado (325737724)
- ✅ Shutdown listener requiere token de autenticación
- ✅ Listener solo acepta conexiones locales (bind a 0.0.0.0 pero firewall protege)
- ✅ Home Assistant en VPS con IP fija conocida
- ⚠️ Token en `.env` en texto plano (mitigar con permisos de archivo)
- ⚠️ Autologon guarda contraseña en registro (mitigar con BitLocker + bloqueo automático)