Install once.Manage visually.
TautWeekly-Setup.exe installs the self-contained Windows Manager. Configure services, verify connections, choose libraries and delivery exclusions, inspect previews, protect local access, and own the weekly task without using the BAT setup wizard.
What the Windows host needs
Plex and Tautulli may run on the same computer, another LAN server, a NAS, or a container host.
- 64-bit Windows 10 or 11
- Windows PowerShell 5.1 or newer
- Tautulli URL and API key
- SMTP host with STARTTLS support
- Recommended direct Plex URL and token
Use an address reachable from this PC
Use 127.0.0.1 only when the target service is on this computer. For another LAN host, use its resolvable hostname or private address. Setup needs no separate Go, Node.js, Docker, or web-server installation.
Administrator approval is requested only when the Manager changes the optional Windows Scheduled Task.
Download, verify, and run Setup
The installer owns application files while leaving configuration and generated data private and update-safe.
Download both release files
Get TautWeekly-Setup.exe and SHA256SUMS.txt from the same latest release.
Verify the SHA-256 value
Get-FileHash .\TautWeekly-Setup.exe -Algorithm SHA256
Match the result to the Setup line in SHA256SUMS.txt.
Choose a permanent folder
Run Setup, select an empty permanent writable folder, and confirm the action reads Install. The default is %LOCALAPPDATA%\Programs\TautWeekly.
Open the Manager
Setup always adds the Start Menu launcher and adds a Desktop launcher when Windows exposes a usable Desktop. It registers uninstall information, starts the local Manager, and opens it at 127.0.0.1:8788.
Windows SmartScreen may report an unknown publisher. Confirm the official SHA-256 value before choosing Run anyway.
Start on the Dashboard
Windows trusted-local access opens directly. No pairing token or password is required for initial configuration.
First time setup
A fresh installation shows a glowing blue First time setup card. Select Setup to open Config.
Existing configuration
A migrated config.json is loaded with stored secrets preserved. Review it and validate without retyping unchanged credentials.
Optional lock later
The header lock icon links to Settings. Add a password only when other people can use the same Windows account.
Configure without touching JSON
Enter new values or review an existing configuration. Stored secrets remain write-only and are preserved unless explicitly replaced or cleared.
| Config area | What belongs there | Why it matters |
|---|---|---|
| Connections | Tautulli URL and API key; optional direct Plex URL and token | Tautulli supplies activity. Direct Plex improves provider ratings and artwork. |
Sender name/address, optional reply-to, controlled TestEmail | Test delivery remains separated from production recipients. | |
| SMTP | Host, STARTTLS port, authentication, username, application password | The safe preflight stops before credentials or message submission. |
| Newsletter | Lookback, card limits, branding, and supported renderer settings | Controls content without manual JSON edits. |
| Custom text card | Optional border, title, six-choice local title GIF, and subheading plus a required body when enabled | Appears before the release-count/date block in previews and delivery. |
| Schedule | Desired local Windows day and time | Saving does not install automation; Schedule remains a separate action. |
| Library selection and user exclusions | Included movie/TV libraries and users excluded from every personalized mode | Selections persist in the saved configuration; excluded users remain visible for policy review but cannot be previewed, tested, welcomed, or sent a newsletter. |
| Managed-user delivery addresses | Private fallback addresses shown only for active Tautulli users without native email | Native email always wins, shared inboxes are allowed, exclusions still apply, and TestEmail remains isolated. |
A private timestamped backup is created before config.json is replaced. The newest 10 are retained automatically. Configuration backups can be restored, or one can be permanently deleted only after Confirm delete; deletion leaves the live configuration unchanged.
Validate, save, and verify
The Manager runs every applicable non-intrusive setup check, records the results, and does not send email.
Libraries and users
Loads active movie/TV libraries plus sanitized user IDs, friendly names, and roles for guided selection.
Tautulli and Plex
Verifies the saved Tautulli API and configured direct Plex identity and authenticated library access.
SMTP preflight
Checks DNS/TCP, greeting, EHLO, and certificate-validated STARTTLS without authenticating or submitting a message.
Local previews
Starts all six local states when one unambiguous owner/admin ID and required metadata are available.
Deleted-item cache
Reports disabled, unseeded, healthy, recoverable, or failed local state with aggregate counts only. Use 19-CACHE-DIAGNOSTICS.bat for the same share-safe summary.
Enabling the cache or changing its coverage and selecting Validate, save, and verify starts a separate no-email refresh for every production-eligible included user and selected movie/TV library. It captures only qualifying live newsletter-window items by exact stable GUID and usable poster; it does not crawl the whole library or depend on PreviewAll. Use 20-REFRESH-DELETED-ITEM-CACHE.bat for an explicit refresh. Unseeded means no qualifying live refresh or render has written an entry. Disabling the cache stops reads and writes but does not erase retained entries.
The first four survive browser refresh and Manager restart for the current saved configuration. Cache health is recomputed locally and all five appear together in Dashboard Config status.
It never authenticates to SMTP, sends email, changes welcome state, or installs a schedule.
Preview first, TestEmail second
Every preview uses the production renderer: manual welcome, two new-user states, and normal, quiet, and warm-up established-user states.
Inspect local HTML
Review artwork, ratings, summaries, conditional sections, personal statistics, and responsive behavior. No mail is sent.
Send a controlled test
Select the owner/admin user and confirm Send six test messages. Every message goes only to the configured TestEmail.
Verify all six messages in a real mail client before scheduling production delivery.
Install automation last
The Manager reports observed Task Scheduler state and exposes only four typed lifecycle actions.
Select Install
Approve the narrow Windows UAC prompt only after Config, previews, and TestEmail are accepted.
Verify the observed task
Confirm ownership is Verified, state is Ready, and the upcoming local run is correct.
Refresh after task-relevant changes
Once installed, the primary button smoothly changes from Install to Refresh. Enable, Disable, and Remove remain separate actions.
The helper validates the saved revision and exact task ownership before changing Windows Task Scheduler.
Check, Install, Update, or Migrate
Start in Settings > Updates. It reports the running application and installed package separately, renders cached status immediately, and performs one bounded background refresh only when the last successful check is missing or at least 24 hours old and backoff permits. The main header Refresh reloads local status first and then starts that check only when the new typed status recommends it; it never waits for GitHub, while scoped refresh controls stay isolated. Successful results are reused for five minutes; Check now then explicitly refreshes the same endpoint. Current retains its green glow, every non-current status gives the update card an attention glow, and the purple header SVG appears only after a successful check validates a newer running application. Normal health remains offline-capable.
After a fresh verified check and separate confirmation, the Manager starts the existing fixed updater. It accepts no browser-supplied URL, path, version, command, or arguments; Windows elevation, checksums, the internal manifest, backup, health verification, and rollback still apply. No unattended updater is installed.
| Your current installation | Folder choice | Required action |
|---|---|---|
| Fresh | Choose an empty permanent folder. | Install |
| Installed by Setup | Setup reads the validated current-user registration and uses that folder directly; no folder picker is needed. | Update |
| Older portable/BAT release | Choose the exact old portable folder for Migrate; it must contain the valid release ownership manifest. | Migrate |
The native Windows Registry API supplies the validated registered folder directly. New and unresolved installs still require a folder choice.
Cancel and select the exact folder containing the old config.json and numbered BAT files. Setup does not scan drives or guess.
Private backup
Setup creates a timestamped sibling backup before replacement. It can contain credentials.
Preserved data
Config, state, output, logs, cache, custom assets, Manager history, and compatible task state remain.
Automatic rollback
Release-owned files are restored if post-install verification fails. No periodic update task is installed.
Public HTTPS through Tailscale Funnel
Open the password-protected Manager from an ordinary remote browser while the backend remains bound to loopback.
Host prerequisite
Install the official Tailscale Windows client, start it, and sign in on this host. Confirm MagicDNS, HTTPS certificates, and a Funnel node attribute that targets this device. TautWeekly does not install, authenticate, or edit tailnet policy. Remote viewers need no Tailscale client or VPN.
Enable and verify
Create a unique Manager password, enable Funnel, approve the fixed Windows helper and any one-time Tailscale page, then verify the exact generated https://…ts.net address. Local Funnel on is insufficient: green Active requires independent public DNS and trusted TLS; a gold Publication pending card means only the exact local route is confirmed.
Manager remains on 127.0.0.1; no router or firewall ingress port is opened. Verification uses the system nslookup.exe against the fixed 1.1.1.1 resolver so Windows NRPT/MagicDNS cannot intercept the intended-public query, rejects non-public answers, and validates TLS without storing DNS or certificate details. Remote sessions have full administration. Use a unique password because Internet brute-force risk remains. Password-lock disable, access reset, and uninstall first turn off and verify only the TautWeekly Funnel or refuse safely.
Local access, your way
Windows trusts the current account by default. Add the browser lock only when that extra boundary is useful.
Unlocked by default
No first-run pairing token is required. A gold unlocked icon reports Browser access unlocked and links to Settings.
Optional password lock
Use at least 8 characters. Enable or change the lock under Settings. A green icon reports Browser access locked. Passwords are stored only as a salted local verifier.
Use the Start Menu Reset TautWeekly Manager Access shortcut or Reset-TautWeekly-Access.cmd. It first disables and verifies the exact owned Funnel, then disables only the Manager lock. If Funnel shutdown cannot be verified, recovery stops safely. Configuration, credentials, schedules, history, and previews remain.
Know what is preserved
Do not commit, publish, or attach live configuration, tokens, recipient identity, viewing history, generated newsletters, logs, or backups.
Application data
config.json, state, cache, output, previews, logs, and custom assets remain private and update-safe.
Manager data
Access policy and sanitized history live under %LOCALAPPDATA%\TautWeekly\data.
Diagnostics
Review sanitized support codes under Settings > Build and diagnostics. Setup logs to %LOCALAPPDATA%\TautWeekly\installer.log.
Refresh Plex, then Tautulli
Use this after first setup, after changing a metadata agent or Ratings Source, or when ratings and artwork remain stale.
Confirm Ratings Source
In every included Plex Movie library, review Edit > Advanced > Ratings Source.
Refresh Plex
Run Manage Library > Refresh All Metadata for every included movie and TV library and wait.
Refresh Tautulli per-library
Open each same Library > Media Info page, select Refresh media info, and wait.
Validate again
Return to Config, select Validate, save, and verify, and inspect the replaced local previews.
Do not refresh unrelated music or photo libraries. Routine TautWeekly updates do not require a full refresh when current output is already correct.
Portable recovery and advanced tools
The numbered launchers still ship for terminal recovery, scripting, and detailed isolation. They are not required for the installed Manager flow.
Portable Manager
Download and verify TautWeekly-windows.zip, extract it, then use 00-OPEN-MANAGER.bat.
Recovery launchers
Direct verification, preview, schedule, scope, update, and access-reset tools remain in the portable package.
Real-send tools
Some expert launchers can send to real users. Read their warnings and confirmation gates before use.
See Portable recovery and advanced tools in the detailed Windows reference.
When a step needs review
Use the persistent Config cards, Verify evidence, Schedule observation, and sanitized support codes to isolate the boundary.
Setup does not show Migrate
Cancel. Select the exact extracted release folder with its ownership manifest, not the parent folder or another non-empty directory.
A service works on another PC only
Confirm its firewall, listening address, and URL are reachable from the Windows computer running TautWeekly.
Previews were skipped
Complete metadata readiness, confirm one unambiguous owner/admin ID, then validate again.
Schedule action was interrupted
Refresh Schedule and review observed Windows state before retrying the explicit action.