Le wiki sort de l'espace de travail

Il est passé dans ~/Projects/alpinux.wiki : dépôt distinct, déploiement
automatique par webhook, et plus rien de commun avec les applications Flask
rangées ici. Le tableau des projets et les procédures de déploiement sont mis à
jour en conséquence.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PcZ7hL9aVvMhRuzxXLT2DG
This commit is contained in:
Cédrix 2026-09-19 22:12:02 +02:00
parent f45f67a131
commit 046321b0e2

119
README.md
View file

@ -17,9 +17,13 @@ Ce dossier racine est un espace de travail local — il n'a pas de remote git.
| `home/` | alpinux.org | HTML statique | [alpinux-home](https://gitea.alpinux.org/alpinux.cedrica5l/alpinux-home) | | `home/` | alpinux.org | HTML statique | [alpinux-home](https://gitea.alpinux.org/alpinux.cedrica5l/alpinux-home) |
| `portail/` | portail.alpinux.org | en construction | [alpinux-portail](https://gitea.alpinux.org/alpinux.cedrica5l/alpinux-portail) | | `portail/` | portail.alpinux.org | en construction | [alpinux-portail](https://gitea.alpinux.org/alpinux.cedrica5l/alpinux-portail) |
| `static/` | static.alpinux.org | Flask + AlpID + CDN | [alpinux-static](https://gitea.alpinux.org/alpinux.cedrica5l/alpinux-static) | | `static/` | static.alpinux.org | Flask + AlpID + CDN | [alpinux-static](https://gitea.alpinux.org/alpinux.cedrica5l/alpinux-static) |
| `wiki/` | wiki.alpinux.org | MkDocs Material | [alpinux-wiki](https://gitea.alpinux.org/alpinux.cedrica5l/alpinux-wiki) |
| `infra/` | — | Configs Apache + systemd | dépôt git local séparé | | `infra/` | — | Configs Apache + systemd | dépôt git local séparé |
Le wiki (`wiki.alpinux.org`, dépôt
[alpinux-wiki](https://gitea.alpinux.org/alpinux.cedrica5l/alpinux-wiki)) a sa propre
place : **`~/Projects/alpinux.wiki`**. Il se déploie tout seul et n'a rien à partager avec
les applications Flask ci-dessus.
Gitea : **https://gitea.alpinux.org/alpinux.cedrica5l** Gitea : **https://gitea.alpinux.org/alpinux.cedrica5l**
ISPConfig : **https://owni.alpinux.org:8080** ISPConfig : **https://owni.alpinux.org:8080**
AlpID (SSO) : **https://alpid.alpinux.org** — realm `master` AlpID (SSO) : **https://alpid.alpinux.org** — realm `master`
@ -28,43 +32,52 @@ AlpID (SSO) : **https://alpid.alpinux.org** — realm `master`
## Procédure de déploiement ## Procédure de déploiement
### Principe ### Vue d'ensemble
``` | Projet | Méthode | Commande |
poste local → git push → Gitea → serveur (git pull + restart) |--------|---------|----------|
``` | `home` | git pull sur serveur | `ssh alpinux.org "cd <web root> && git pull"` |
| `admin` | rsync local + restart | `cd admin && ./scripts/deploy.sh` |
| `dynamic` | rsync local + restart | `cd dynamic && ./scripts/deploy.sh` |
| `static` (app) | rsync local + restart | `cd static && scripts/deploy-app.sh` |
| `static` (assets) | rsync local | `cd static && scripts/push-assets.sh` |
| `wiki` | automatique | `git push` depuis `~/Projects/alpinux.wiki` |
Les mises à jour passent exclusivement par git. Dans tous les cas : versionner avec `git push` **avant** de déployer.
La configuration d'environnement (`.env`) est la seule opération manuelle tolérée sur le serveur.
### Flask (admin, dynamic, static) ### Flask — admin et dynamic
```bash ```bash
# Poste local # 1. Poste local
git push origin main git push origin main
# Serveur (via SSH ponctuel) # 2. Déployer (rsync depuis le dépôt local + restart service)
ssh alpinux.org cd admin # ou dynamic
cd /opt/<service> ./scripts/deploy.sh
git pull ```
source venv/bin/activate && pip install -r requirements.txt
sudo systemctl restart <service> ### static.alpinux.org — app Flask
```bash
# 1. Poste local
git push origin main
# 2. Déployer (rsync depuis le dépôt local + restart service)
cd static
scripts/deploy-app.sh
```
### static.alpinux.org — assets CDN
```bash
cd static
scripts/push-assets.sh # rsync logo/, wiki/, stats/, error/ → web root ISPConfig
``` ```
### Wiki ### Wiki
```bash Rien à faire : un webhook Gitea construit et met en ligne à chaque push sur `main`.
cd wiki Voir https://wiki.alpinux.org/technique/deploiement-wiki/
mkdocs build --strict
rsync -rlcz --delete site/ alpinux.org:/var/www/wiki.alpinux.org/web/
```
### Assets CDN (static.alpinux.org)
```bash
cd static
scripts/push-assets.sh # rsync vers /var/www/clients/.../web/
```
--- ---
@ -72,9 +85,8 @@ scripts/push-assets.sh # rsync vers /var/www/clients/.../web/
| Projet | Commande | URL | | Projet | Commande | URL |
|--------|----------|-----| |--------|----------|-----|
| `wiki` | `mkdocs serve` | http://localhost:8000 | | `dynamic` | `flask run --port 5001` | http://localhost:5001 |
| `dynamic` | `flask run --port 5000` | http://localhost:5000 | | `admin` | `flask run --port 5002` | http://localhost:5002 |
| `admin` | `flask run --port 5001` | http://localhost:5001 |
| `static` | `python app/app.py` | http://localhost:5003 | | `static` | `python app/app.py` | http://localhost:5003 |
```bash ```bash
@ -119,24 +131,54 @@ Lancer Claude depuis le sous-dossier du projet pour limiter le contexte :
cd ~/Projects/org.alpinux.owni/static && claude cd ~/Projects/org.alpinux.owni/static && claude
cd ~/Projects/org.alpinux.owni/admin && claude cd ~/Projects/org.alpinux.owni/admin && claude
cd ~/Projects/org.alpinux.owni/dynamic && claude cd ~/Projects/org.alpinux.owni/dynamic && claude
cd ~/Projects/org.alpinux.owni/wiki && claude cd ~/Projects/alpinux.wiki && claude
``` ```
--- ---
## Accès SSH et rôle d'abonnelc ## Comptes personnels vs comptes de service
Alias SSH : `alpinux.org` → compte `abonnelc`. Alias SSH : `alpinux.org` → compte `abonnelc`.
`abonnelc` est un **compte d'administration ponctuelle**, pas un compte de service. ### Règle absolue
Son rôle se limite à :
Un compte personnel (`abonnelc` ou tout autre) ne doit jouer **aucun rôle dans le fonctionnement à long terme** des services :
- pas `User=` dans un unit systemd
- pas propriétaire des fichiers de l'app ou des logs
- pas dans la liste des groupes dont dépend un service en production
- pas référencé dans un `chown`, `setfacl`, ou cron de production
Si un service dépend d'un compte personnel, sa disparition (départ, suppression du compte, changement de login) fait tomber le service en production.
### Rôle d'abonnelc
`abonnelc` est un **compte d'administration ponctuelle**, limité à :
- créer ou modifier les fichiers `.env` sur le serveur - créer ou modifier les fichiers `.env` sur le serveur
- redémarrer un service après un `git pull` - redémarrer un service après un déploiement
- effectuer des opérations admin exceptionnelles - effectuer des opérations admin exceptionnelles
Les services tournent sous leurs propres utilisateurs système. ### Comptes de service
Les scripts ne doivent pas être couplés à `abonnelc`.
Chaque service tourne sous son propre utilisateur système dédié (ex. `static-cdn` pour `static-cdn.service`).
C'est ce compte qui possède les fichiers, les logs, et les droits nécessaires — pas `abonnelc`.
---
## Serveur
| | |
|---|---|
| **Hostname** | `owni.alpinux.org` |
| **OS** | Debian 12 (bookworm) |
| **IPv4** | `51.91.79.148` |
| **IPv6** | `2001:41d0:404:200::3f85/128` |
| **Passerelle IPv6** | `2001:41d0:404:200::1` |
| **SSH** | `ssh alpinux.org` (alias → `abonnelc@owni.alpinux.org`) |
Config IPv6 persistante : `/etc/network/interfaces.d/60-ipv6.cfg`
Cloud-init réseau désactivé : `/etc/cloud/cloud.cfg.d/99-disable-network-config.cfg`
--- ---
@ -151,3 +193,6 @@ infra/
├── services/ → Units systemd ├── services/ → Units systemd
└── docs/ → Documentation déploiement par service └── docs/ → Documentation déploiement par service
``` ```
ne pas mentionner "sonnet" ou "claude"