runbook: audit total NAS 30/08 -- gotenberg gsparc clarifie, hermes-mail-browser/reglement-mcp/hermes-watchdog-telegram documentes, ports-registry.md sync
This commit is contained in:
@@ -1,5 +1,5 @@
|
||||
# Ports Registry — NAS Synology DS920+
|
||||
# Derniere mise a jour : 12/07/2026 (resync etat REEL, 41 containers)
|
||||
# Derniere mise a jour : 30/08/2026 (Audit total : 55 containers confirmes, gotenberg gsparc clarifie, hermes-mail-browser, reglement-mcp, hermes-watchdog-telegram documentes)
|
||||
# LIRE CE FICHIER AVANT TOUT NOUVEAU DEPLOIEMENT
|
||||
# Mettre a jour apres chaque ajout/suppression de service
|
||||
|
||||
@@ -36,16 +36,18 @@ Colonne Exposition = binding reel constate. Restart/Health signales quand a risq
|
||||
| bifrost-proxy | 3086->80 | - | n8n | 0.0.0.0 | unless-stopped | **none** | Auth rewrite + cap 16384 tokens ; PAS de healthcheck |
|
||||
| hermes-workspace-tt | 3010->3000 | hermes-tt.bolbol.tn | hermes-tt-net,n8n | 0.0.0.0 | unless-stopped | healthy | Workspace TT (agent=8650 interne) |
|
||||
| hermes-workspace-nyora | 3020->3000 | hermes-nyora.bolbol.tn | hermes-nyora-net,n8n | 0.0.0.0 | unless-stopped | healthy | Workspace Nyora (agent=8660 interne) |
|
||||
| hermes-workspace-perso | 3031->3000 | hermes-perso.bolbol.tn | hermes-perso-net,n8n | 0.0.0.0 | unless-stopped | healthy | Workspace Perso -- TEMP remap 3030->3031 (12/08/2026) : port 3030 orphelin cote host, docker-proxy sans PID visible, non liberable sans sudo -- restaurer 3030 au prochain reboot NAS |
|
||||
| hermes-agent-tt | interne | interne | hermes-tt-net,n8n | interne Docker | unless-stopped | healthy | Agent TT ; DeepSeek V4 Flash |
|
||||
| hermes-agent-nyora | interne | interne | hermes-nyora-net,n8n | interne Docker | unless-stopped | healthy | Agent Nyora ; DeepSeek V4 Flash |
|
||||
| hermes-agent-perso | interne | interne | hermes-perso-net,n8n | interne Docker | unless-stopped | healthy | Agent Perso ; DeepSeek V4 Flash |
|
||||
| hermes-mail-proxy | 3060->8000 | - | n8n | 0.0.0.0 | unless-stopped | **none** | Proxy mail Hermes (3060) |
|
||||
| hermes-workspace-perso | 3031->3000 | hermes-perso.bolbol.tn | hermes-perso-net,n8n | 0.0.0.0 | unless-stopped | healthy | Workspace Perso -- Port 3031 fixe definitivement (19/08/2026) suite a validation Hermes Hub ; 3030 orphelin/abandonne |
|
||||
| hermes-agent-tt | interne | interne | hermes-tt-net,n8n | interne Docker | unless-stopped | healthy | Agent TT ; Mimo V2.5 |
|
||||
| hermes-agent-nyora | interne | interne | hermes-nyora-net,n8n | interne Docker | unless-stopped | healthy | Agent Nyora ; Mimo V2.5 |
|
||||
| hermes-agent-perso | interne | interne | hermes-perso-net,n8n | interne Docker | unless-stopped | healthy | Agent Perso ; Mimo V2.5 |
|
||||
| hermes-mail-browser | 192.168.100.33:3110->8000, 192.168.100.33:8810->6080 | - | n8n | LAN uniquement | unless-stopped | healthy | Navigateur automatise pour sync SharePoint/OneDrive->archive (voir hermes-tt/sharepoint-delta-sync.md) ; remplace hermes-mail-proxy ; ajoute 11/08/2026 |
|
||||
| nyora-doc-api | 3050->8000 | - | n8n | 0.0.0.0 | unless-stopped | healthy | Moteur doc unique (docx/xlsx/pptx/pdf) charte Nyora | MCP ajoute sur /mcp/ (04/08/2026, tool generate_document) |
|
||||
| nyora-convert-api | 3096->8000 | - | n8n | 0.0.0.0 | unless-stopped | (pas de healthcheck) | Conversion universelle document->MD (Mimo V2.5/Bifrost, texte+vision) 04/08/2026 |
|
||||
| redaction-pro | 3092->80 | llm.bolbol.tn | n8n | 0.0.0.0 | always | **none** | Assistant redaction LLM (proxy Bifrost) |
|
||||
| context-hub | 3093->8000 | context.bolbol.tn | n8n | 0.0.0.0 | unless-stopped | healthy | Contexte agents 5 scopes ; MCP SSE |
|
||||
| family-help | 3041->8000 | help.bolbol.tn | n8n | 0.0.0.0 | unless-stopped | **none** | IA familiale FastAPI+SQLite ; PAS de healthcheck |
|
||||
| yesmine-mp1-rag | 3097->8000 | - | n8n | 0.0.0.0 | unless-stopped | healthy | RAG semantique corpus MP1 Yesmine (FastMCP + REST) ; dependance family-help ; ajoute 18/08/2026 |
|
||||
| nyora-notes-mcp | 3098->8000 | - | n8n | 0.0.0.0 | unless-stopped | healthy | Passerelle MCP dediee pour NyoraNotes (StreamableHTTP, scoping strict par token/agent, mapping vault/dsh/) ; ajoute 26/08/2026 |
|
||||
| gsparc-mezzouna-api | 3040->8000 | gsparc-mezzouna.bolbol.tn | n8n | 0.0.0.0 | unless-stopped | healthy | OCR carburant kimi-k2.6 |
|
||||
| rla-api | 3005->3005 | rla.bolbol.tn | n8n | 0.0.0.0 | unless-stopped | healthy | RLA contrats TT (build context: /volume1/docker/rla-api-src) |
|
||||
| reglement-definitif-api | 5099->5055 | - | n8n | 0.0.0.0 | **no** | **none** | Reglement definitif TT ; restart NO (voir alerte) |
|
||||
@@ -65,6 +67,10 @@ Colonne Exposition = binding reel constate. Restart/Health signales quand a risq
|
||||
| qbittorrent-vue | 6881->6881, 6881->6881/udp, 9866->9866 | qb.bolbol.tn | media-stack_default,qbittorrent-vue_default | 0.0.0.0 | unless-stopped | **none** | Torrent (6881) + UI 9866 |
|
||||
| cin-search-tt | 3094->3000 | cin.bolbol.tn (reverse-proxy DSM a creer manuellement) | n8n | 0.0.0.0 | unless-stopped | **none** | Recherche CIN sous-traitants RLA ; migre depuis /volume1/web hors-Docker le 10/07/2026 ; SMTP OVH->Infomaniak, Baserow alias corrige |
|
||||
| formation-consultant | 8801->80 | formation.bolbol.tn (reverse-proxy DSM a creer manuellement) | n8n | 0.0.0.0 | unless-stopped | none | Formation autodidacte perso (nginx+basic auth) ; ajoute 25/07/2026 |
|
||||
| hermes-hub (VPS) | 127.0.0.1:8088->8080 | hub.yesminedor.tn (410), dsh-hub / files-hub .yesminedor.tn | dsh_vps_net, mcp-vps | 127.0.0.1 (Cloudflare Access) | unless-stopped | healthy | Dispatcher minimal Cloudflare Origin (proxy Host-based dsh-hub:3080 et files-hub:8080 uniquement ; UI switcher et DB chat supprimes le 26/08/2026) |
|
||||
| reglement-mcp | 5098->8000 | - | n8n | 0.0.0.0 | unless-stopped | healthy | Serveur MCP pour reglement-definitif-api (Google credentials.json) ; ajoute 23/08/2026, absent du registre jusqu au 30/08 |
|
||||
| gotenberg (gsparc) | interne, pas de port host | - | n8n | interne Docker | unless-stopped | - | Sidecar Chromium/PDF dedie a gsparc-mezzouna-api (export fiches vehicules + tableaux consommation en arabe) ; distinct de l ancien gotenberg 3001 retire le 21/06 ; cable dans gsparc-mezzouna/docker-compose.yml commit 85faef3 (21/06/2026), deploye 25/07/2026 ; jamais documente ici avant le 30/08 |
|
||||
| hermes-watchdog-telegram | interne | - | bridge | interne Docker | unless-stopped | - | Boucle python (relance toutes les 10 min) surveillant les containers via docker.sock, alerte Telegram ; image docker:cli generique (apk install python3 a chaque restart, pas d image dediee -- fragile) ; cree 27/07/2026, jamais documente ici avant le 30/08 |
|
||||
|
||||
---
|
||||
|
||||
@@ -92,6 +98,7 @@ Colonne Exposition = binding reel constate. Restart/Health signales quand a risq
|
||||
## SERVICES RETIRES (ne pas reinstaller, ne pas reutiliser le vhost)
|
||||
| Service | Port libere | Retire | Remplace par |
|
||||
|---------|-------------|--------|--------------|
|
||||
| hermes-mail-proxy | 3060 | ~11/08 (constate le 30/08) | hermes-mail-browser |
|
||||
| gotenberg | 3001 (repris par pihole) | 21/06 | nyora-doc-api |
|
||||
| pandoc | 3002 | 21/06 | nyora-doc-api |
|
||||
| document-factory | 3015 | 21/06 | nyora-doc-api |
|
||||
@@ -99,7 +106,7 @@ Colonne Exposition = binding reel constate. Restart/Health signales quand a risq
|
||||
| document-factory-api | 8002 | 21/06 | nyora-doc-api |
|
||||
| pptx-tt-api | 8015 | 29/06 | nyora-doc-api (vhost pptx.bolbol.tn fantome a purger) |
|
||||
| open-webui | 3091 | 29/06 | redaction-pro |
|
||||
| tika | 9998 | 21/06 | nyora-convert-api (3096) / Mimo V2.5 |
|
||||
| tika | 9998 | — | gemini-3-flash OCR |
|
||||
| paperless | 8021 | — | — |
|
||||
| rayhan-frontend | 3013 | 29/06 | projet clos |
|
||||
| rayhan-mysql | 3306 | 29/06 | projet clos |
|
||||
@@ -145,6 +152,13 @@ Colonne Exposition = binding reel constate. Restart/Health signales quand a risq
|
||||
## Historique des modifications (recentes)
|
||||
| Date | Action | Port | Service |
|
||||
|------|--------|------|---------|
|
||||
| 2026-08-30 | Audit total via Claude : 55 containers reels confirmes (registre en comptait 43/vs derniere resync). Clarifie gotenberg gsparc (sidecar interne distinct de l ancien gotenberg 3001, jamais documente). Corrige hermes-mail-proxy -> retire, remplace par hermes-mail-browser (actif depuis 11/08, jamais documente). Ajoute reglement-mcp (actif depuis 23/08, jamais documente) et hermes-watchdog-telegram (actif depuis 27/07, jamais documente, image fragile a corriger). RAM 41% mais swap 4.1Gi/13Gi utilise -- a surveiller. Disque /volume1 73% (7.6T/11T). linux-mcp-nas signale unhealthy depuis 2j (fonctionnel, healthcheck a verifier). | - | audit-30-08 |
|
||||
| 2026-08-26 | Ajout nyora-notes-mcp (Passerelle MCP dediee NyoraNotes, StreamableHTTP port 3098, scoping strict par token/dossier, connecteur DSH dsh/ valide) | 3098 | nyora-notes-mcp |
|
||||
| 2026-08-26 | Reduction hermes-hub (suppression UI switcher et DB chat, conservation dispatcher pur dsh-hub / files-hub, fix timeout WS /api/events.mux et .host) | 8088 | hermes-hub |
|
||||
| 2026-08-25 | Ajout yesmine-mp1-rag (RAG semantique corpus MP1 Yesmine, REST+FastMCP port 3097, reseau n8n, dependance de family-help) | 3097 | yesmine-mp1-rag |
|
||||
| 2026-08-21 | MAJ Stack : Portainer 2.39.6, n8n 2.36.5 (custom docx/exceljs), Bifrost v1.6.11 (pin image), Gitea 1.27.2-rootless (migration DB OK), Vaultwarden 1.37.1, Tailscale bridge 1.102.3 | — | portainer, n8n, bifrost, gitea, vaultwarden, tailscale |
|
||||
| 2026-08-19 | Deploiement reel Hermes Hub sur VPS Contabo (port 8088 loopback, Cloudflare Access, integration dsh-vps-filebrowser sans auth interne) | 8088 | hermes-hub |
|
||||
| 2026-08-19 | Fixation definitive de hermes-workspace-perso sur le port 3031 (validation Hermes Hub). Port 3030 marque orphelin/abandonne | 3031 | hermes-workspace-perso |
|
||||
| 2026-08-17 | Ajout baserow-schema-mcp (serveur MCP compagnon : create_table/delete_table/create_field/delete_field, proxy JWT vers API REST Baserow -- l'image officielle Baserow n'est pas patchable et son MCP natif ne couvre que les lignes). Reste a faire : reverse-proxy DSM baserow-schema.bolbol.tn -> 3101 (manuel) puis ajout du connecteur cote Claude.ai | 3101 | baserow-schema-mcp, baserow-schema-mcp-oauth-app, baserow-schema-mcp-proxy |
|
||||
| 2026-08-15 | Retrait dsh-test + dsh-filebrowser (test isole NAS termine, migration definitive vers dsh-vps sur VPS hermes-nabil, valide en itinerance) | 8900,8901 | dsh-test, dsh-filebrowser |
|
||||
| 2026-08-14 | Ajout dsh-filebrowser (Filebrowser sur port 8901 pour upload/gestion fichiers workspace dsh-test) | 8901 | dsh-filebrowser |
|
||||
|
||||
Reference in New Issue
Block a user