diff --git a/_INDEX.md b/_INDEX.md index aceeafc..3f58f93 100644 --- a/_INDEX.md +++ b/_INDEX.md @@ -10,6 +10,7 @@ | Runbook | Date | Tags | |---------|------|------| +| [Relocalisation de bifrost-proxy sur VPS (port 3086), découplage total de Sfax pour hermes-nabil et dsh-vps, relais socat NAS et retrait du stub bifrost 3085 (tickets infra-2026-09-030 et 031)](common/ports-registry.md) | 2026-09-09 | infra, bifrost, bifrost-proxy, vps, tailscale, socat, hermes-nabil, dsh | | [Correctif routage Bifrost -> OpenCode Go (base_url casse sur un residu de sidecar abandonne, chemin /zen/go sans /v1) + raccordement hermes-tt/hermes-nabil/DSH au pattern bifrost-proxy (creation vk-hermes-nabil, cloture volet routage du ticket infra-2026-09-023)](common/bifrost-opencode-routing-fix-20260907.md) | 2026-09-07 | infra, bifrost, opencode-go, hermes-tt, hermes-nabil, dsh, virtual-key, routing | | [Piège clé virtuelle Nabil-Key (bfk-0cd1fb...) vs clés dédiées Hermes : fuite budgétaire 8 $/mois, audit exhaustif (perso/tt/nyora), correction chirurgicale vision perso, et tests d'inférence réels (ticket infra-2026-09-014)](common/piege-virtual-key-nabil-key-bifrost-hermes-20260904.md) | 2026-09-04 | infra, bifrost, virtual-key, nabil-key, budget, hermes, audit, gemini | | [Architecture stub forwarder Bifrost (NAS -> VPS via socat/SOCKS5 tailscale-nyora-bridge:1055), procédure de rollback immédiat (<5s), piège allow_all_keys / config.json au boot, et injection session x-bf-eh-x-opencode-session sur bifrost-proxy (tickets infra-2026-09-010 et 008)](common/migration-vps-bifrost-stub-forwarder-20260904.md) | 2026-09-04 | infra, bifrost, vps, tailscale, socat, rollback, allow-all-keys, opencode-go | diff --git a/common/ports-registry.md b/common/ports-registry.md index 53aec62..3f1a9c4 100644 --- a/common/ports-registry.md +++ b/common/ports-registry.md @@ -1,5 +1,5 @@ # Ports Registry — NAS Synology DS920+ -# Derniere mise a jour : 30/08/2026 (Audit total : 55 containers confirmes, gotenberg gsparc clarifie, hermes-mail-browser, reglement-mcp, hermes-watchdog-telegram documentes) +# Derniere mise a jour : 06/09/2026 (openclaw-perso documenté sur le port 8910 pour le ticket perso-2026-09-022) # LIRE CE FICHIER AVANT TOUT NOUVEAU DEPLOIEMENT # Mettre a jour apres chaque ajout/suppression de service @@ -32,8 +32,8 @@ Colonne Exposition = binding reel constate. Restart/Health signales quand a risq | portainer | 9000->9000, 9443->9443 | portainer.bolbol.tn | bridge | 0.0.0.0 | unless-stopped | **none** | Gestion containers ; reseau bridge | | nyora-notes | 8787->8787 | - | n8n | 0.0.0.0 | unless-stopped | healthy | Memoire inter-sessions Hermes (8787) | | linux-mcp-nas | 127.0.0.1:3042->8000 | mcp-nas.nd.i234.me | n8n | 127.0.0.1 | always | healthy | MCP shell NAS ; bind 127.0.0.1 (via reverse-proxy) | -| bifrost | 3085->8080 | - (retire du WAN 03/07) | n8n | 0.0.0.0 | unless-stopped | healthy | Gateway LLM ; piege allow_all_keys DB | -| bifrost-proxy | 3086->80 | - | n8n | 0.0.0.0 | unless-stopped | **none** | Auth rewrite + cap 16384 tokens ; PAS de healthcheck | +| bifrost | 3085 (décommissionné) | - | - | - | - | decommissioned | Ancien stub forwarder socat 3085 retiré (Ticket infra-2026-09-031). Port libéré. | +| bifrost-proxy | 3086->80 | - | n8n | 0.0.0.0 | unless-stopped | - | Relais socat SOCKS5 vers bifrost-proxy VPS (100.94.90.119:3086). bifrost-proxy OpenResty migré sur VPS (Ticket infra-2026-09-030) | | hermes-workspace-tt | 3010->3000 | hermes-tt.bolbol.tn | hermes-tt-net,n8n | 0.0.0.0 | unless-stopped | healthy | Workspace TT (agent=8650 interne) | | hermes-workspace-nyora | 3020->3000 | hermes-nyora.bolbol.tn | hermes-nyora-net,n8n | 0.0.0.0 | unless-stopped | healthy | Workspace Nyora (agent=8660 interne) | | hermes-workspace-perso | 3031->3000 | hermes-perso.bolbol.tn | hermes-perso-net,n8n | 0.0.0.0 | unless-stopped | healthy | Workspace Perso -- Port 3031 fixe definitivement (19/08/2026) suite a validation Hermes Hub ; 3030 orphelin/abandonne | @@ -41,8 +41,8 @@ Colonne Exposition = binding reel constate. Restart/Health signales quand a risq | hermes-agent-nyora | interne | interne | hermes-nyora-net,n8n | interne Docker | unless-stopped | healthy | Agent Nyora ; Mimo V2.5 | | hermes-agent-perso | interne | interne | hermes-perso-net,n8n | interne Docker | unless-stopped | healthy | Agent Perso ; Mimo V2.5 | | hermes-mail-browser | 192.168.100.33:3110->8000, 192.168.100.33:8810->6080 | - | n8n | LAN uniquement | unless-stopped | healthy | Navigateur automatise pour sync SharePoint/OneDrive->archive (voir hermes-tt/sharepoint-delta-sync.md) ; remplace hermes-mail-proxy ; ajoute 11/08/2026 | -| nyora-doc-api | 3050->8000 | - | n8n | 0.0.0.0 | unless-stopped | healthy | Moteur doc unique (docx/xlsx/pptx/pdf) charte Nyora | MCP ajoute sur /mcp/ (04/08/2026, tool generate_document) | -| nyora-convert-api | 3096->8000 | - | n8n | 0.0.0.0 | unless-stopped | (pas de healthcheck) | Conversion universelle document->MD (Mimo V2.5/Bifrost, texte+vision) 04/08/2026 | +| nyora-doc-api | 3050->8000 | - | n8n | 0.0.0.0 | unless-stopped | healthy | Moteur doc unique (docx/xlsx/pptx/pdf) charte Nyora | Migre sur VPS Contabo (100.94.90.119:3050) (04/09/2026) | +| nyora-convert-api | 3096->8000 | - | n8n | 0.0.0.0 | unless-stopped | healthy | Actif sur NAS pour corpus pack-mp1 ; miroir deploye et valide sur VPS (100.94.90.119:3096) (04/09/2026) | | redaction-pro | 3092->80 | llm.bolbol.tn | n8n | 0.0.0.0 | always | **none** | Assistant redaction LLM (proxy Bifrost) | | context-hub | 3093->8000 | context.bolbol.tn | n8n | 0.0.0.0 | unless-stopped | healthy | Contexte agents 5 scopes ; MCP SSE | | family-help | 3041->8000 | help.bolbol.tn | n8n | 0.0.0.0 | unless-stopped | **none** | IA familiale FastAPI+SQLite ; PAS de healthcheck | @@ -51,8 +51,6 @@ Colonne Exposition = binding reel constate. Restart/Health signales quand a risq | gsparc-mezzouna-api | 3040->8000 | gsparc-mezzouna.bolbol.tn | n8n | 0.0.0.0 | unless-stopped | healthy | OCR carburant kimi-k2.6 | | rla-api | 3005->3005 | rla.bolbol.tn | n8n | 0.0.0.0 | unless-stopped | healthy | RLA contrats TT (build context: /volume1/docker/rla-api-src) | | reglement-definitif-api | 5099->5055 | - | n8n | 0.0.0.0 | **no** | **none** | Reglement definitif TT ; restart NO (voir alerte) | -| veille-frontend | 3055->3000 | veille.bolbol.tn | n8n | 0.0.0.0 | unless-stopped | **none** | Veille IA ; depends veille-backend | -| veille-backend | interne | interne | n8n | interne Docker | unless-stopped | **none** | Backend veille FastAPI | | dashboard-terrain | 8085->8080 | dashboard-terrain.bolbol.tn | n8n | 0.0.0.0 | unless-stopped | **none** | Dashboard terrain | | panda-dashboard | 3021->80 | panda.bolbol.tn | n8n_default | 0.0.0.0 | always | **none** | Dashboard Fiat Panda ; reseau n8n_default | | Trilium | 4292->8080 | trilium.bolbol.tn | n8n,trilium_default | 0.0.0.0 | **no** | healthy | Notes ; restart NO (voir alerte) | @@ -71,6 +69,7 @@ Colonne Exposition = binding reel constate. Restart/Health signales quand a risq | reglement-mcp | 5098->8000 | - | n8n | 0.0.0.0 | unless-stopped | healthy | Serveur MCP pour reglement-definitif-api (Google credentials.json) ; ajoute 23/08/2026, absent du registre jusqu au 30/08 | | gotenberg (gsparc) | interne, pas de port host | - | n8n | interne Docker | unless-stopped | - | Sidecar Chromium/PDF dedie a gsparc-mezzouna-api (export fiches vehicules + tableaux consommation en arabe) ; distinct de l ancien gotenberg 3001 retire le 21/06 ; cable dans gsparc-mezzouna/docker-compose.yml commit 85faef3 (21/06/2026), deploye 25/07/2026 ; jamais documente ici avant le 30/08 | | hermes-watchdog-telegram | interne | - | bridge | interne Docker | unless-stopped | - | Boucle python (relance toutes les 10 min) surveillant les containers via docker.sock, alerte Telegram ; image docker:cli generique (apk install python3 a chaque restart, pas d image dediee -- fragile) ; cree 27/07/2026, jamais documente ici avant le 30/08 | +| openclaw-perso | 127.0.0.1:8910->18789 | - | n8n | 127.0.0.1 | unless-stopped | healthy | Agent OpenClaw autonome perso en test parallèle (ticket perso-2026-09-022) ; Control UI bind loopback 127.0.0.1 (accès via tunnel SSH local pour fonction Talk/Microphone WebCrypto) ; bot Telegram @Perso_OC_bot configuré et actif ; ajouté 06/09/2026 | --- @@ -152,6 +151,10 @@ Colonne Exposition = binding reel constate. Restart/Health signales quand a risq ## Historique des modifications (recentes) | Date | Action | Port | Service | |------|--------|------|---------| +| 2026-09-09 | Décommissionnement stub bifrost NAS 3085 (Ticket infra-2026-09-031) : stub socat retiré (docker-compose down), port 3085 libéré sur NAS. Relocalisation bifrost-proxy VPS 100% finalisée. | 3085 | bifrost | +| 2026-09-08 | Relocalisation bifrost-proxy vers VPS (Ticket infra-2026-09-030) : bifrost-proxy OpenResty déployé sur VPS (port 3086, bifrost-net). hermes-nabil et dsh-vps repointés localement sur VPS (découplage total Sfax). bifrost-proxy NAS converti en relais socat SOCKS5 vers VPS 3086. | 3086 | bifrost-proxy | +| 2026-09-04 | Migration VPS (Tickets infra-2026-09-010 et infra-2026-09-008) : Bifrost (3085) et nyora-doc-api (3050) migres sur VPS Contabo (100.94.90.119), nyora-convert-api (3096) deploye en miroir sur VPS (tests 13/13 OK, conteneur NAS non touche pour pack-mp1). Côté NAS : conteneur bifrost renomme bifrost-nas-backup (arrete, secours immediat), stub forwarder socat SOCKS5 deploye sur 3085 vers VPS. bifrost-proxy (3086) patche pour injection x-bf-eh-x-opencode-session=$resolved_vk. Inferences reelles Gemini et OpenCode Go testees et validees avec succes. | 3085, 3086, 3050, 3096 | bifrost, bifrost-proxy, nyora-doc-api, nyora-convert-api | +| 2026-09-04 | Decommission veille-backend (FastAPI) et veille-frontend, remplaces par page HTML statique (localStorage, tags, recherche, filtre lu/non lu) servie sur bolbol.tn/veille. Containers et images supprimes, code archive dans _archived/nyora-veille-DECOM-20260904, entree reverse proxy veille.bolbol.tn retiree par Nabil, workflow n8n Ingest Opportunites desactive (backend cible supprime). | - | decom-veille-04-09 | | 2026-08-30 | Audit total via Claude : 55 containers reels confirmes (registre en comptait 43/vs derniere resync). Clarifie gotenberg gsparc (sidecar interne distinct de l ancien gotenberg 3001, jamais documente). Corrige hermes-mail-proxy -> retire, remplace par hermes-mail-browser (actif depuis 11/08, jamais documente). Ajoute reglement-mcp (actif depuis 23/08, jamais documente) et hermes-watchdog-telegram (actif depuis 27/07, jamais documente, image fragile a corriger). RAM 41% mais swap 4.1Gi/13Gi utilise -- a surveiller. Disque /volume1 73% (7.6T/11T). linux-mcp-nas signale unhealthy depuis 2j (fonctionnel, healthcheck a verifier). | - | audit-30-08 | | 2026-08-26 | Ajout nyora-notes-mcp (Passerelle MCP dediee NyoraNotes, StreamableHTTP port 3098, scoping strict par token/dossier, connecteur DSH dsh/ valide) | 3098 | nyora-notes-mcp | | 2026-08-26 | Reduction hermes-hub (suppression UI switcher et DB chat, conservation dispatcher pur dsh-hub / files-hub, fix timeout WS /api/events.mux et .host) | 8088 | hermes-hub |