feat(packaging) : package YunoHost veille-ia_ynh (packaging v2, helpers 2.1)

- manifest.toml validé contre le schéma officiel manifest.v2.schema.json
  (sources par tag forge avec placeholder sha256 assumé, nodejs 24, ports,
  system_user, install_dir, data_dir, permission privée all_users, SSO)
- Scripts install/remove/upgrade/backup/restore/change_url (bash -n OK) :
  build au fil de l'eau avec BASE_PATH, ALERTS_TOKEN généré à l'install,
  .env chmod 400, logs journald
- conf/nginx.conf : proxy_params_with_auth (header Ynh-User), conf/systemd.service :
  node via __NODEJS_DIR__, sandboxing modéré, conf/env : DATA_DIR/OLLAMA_URL/ALERTS_TOKEN
- tests.toml minimal, doc DESCRIPTION/ADMIN fr+en
- README racine : dev local, variables d'env, procédure de release, Ollama
This commit is contained in:
cyber-mawonaj
2026-08-01 09:25:39 -04:00
parent ff26136dfb
commit b3ff529cfa
17 changed files with 559 additions and 39 deletions
+41
View File
@@ -0,0 +1,41 @@
[Unit]
Description=Veille IA — observatoire de veille sur les modèles IA (SvelteKit)
After=network.target
[Service]
Type=simple
User=__APP__
Group=__APP__
WorkingDirectory=__INSTALL_DIR__/app
Environment="PATH=__PATH_WITH_NODEJS__"
Environment="NODE_ENV=production"
Environment="HOST=127.0.0.1"
Environment="PORT=__PORT__"
Environment="ORIGIN=https://__DOMAIN____PATH__"
# DATA_DIR, OLLAMA_URL, ALERTS_TOKEN (fichier posé à l'install, chmod 400)
EnvironmentFile=__INSTALL_DIR__/app/.env
ExecStart=__NODEJS_DIR__/node build/index.js
# Logs vers journald : yunohost service log __APP__
StandardOutput=journal
StandardError=journal
SyslogIdentifier=__APP__
# Sandboxing (niveau modéré : le service doit pouvoir lancer git dans le data_dir,
# phase 1 — simple-git — et joindre Ollama en HTTP sortant).
NoNewPrivileges=yes
PrivateTmp=yes
ProtectSystem=full
ProtectKernelModules=yes
ProtectKernelTunables=yes
ProtectControlGroups=yes
RestrictRealtime=yes
RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6 AF_NETLINK
LockPersonality=yes
SystemCallArchitectures=native
CapabilityBoundingSet=
[Install]
WantedBy=multi-user.target