b6ab518e2a
release: bump minor on the 87 modules converted to Wants=secubox-core (Phase 2)
...
Co-Authored-By: Gerald KERMA <devel@cybermind.fr>
2026-07-19 09:08:22 +02:00
238637e09a
release(webui): bump 127 arch:all packages for hybrid-dark reskin bake-in
2026-07-10 09:07:42 +02:00
f522940509
docs(standalone,lxc): final naming-clarity sweep on 8 placeholder Descriptions ( closes #387 )
...
Final batch of the per-cluster Description-clarity work after #382
(dpi), #383 (dns+threats), #385 (identity+monitoring), and #386
(ai+dpi+mesh+soc). Fixes the last 8 "X Module" placeholder headlines
on master — all standalone utilities or LXC-service apps from the
don't-merge list. No cluster siblings to cross-reference, just
honest headlines + bodies.
Standalone utilities:
- secubox-backup: "Backup Module" → "config + LXC-container
backup manager"
- secubox-config-advisor: "Config-advisor Module" → "security
configuration audit + recommendations"
- secubox-iot-guard: "Iot-guard Module" → "IoT device discovery
+ segmentation"
- secubox-localrecall: "Localrecall Module" → "on-box AI memory
store"
- secubox-tor: "Tor Module" → "Tor relay + hidden-services
manager"
- secubox-vortex-firewall: "Vortex-firewall Module" → "nftables
threat-feed enforcer"
LXC-service apps:
- secubox-gitea: "Gitea Module" → "self-hosted Git server (LXC)"
- secubox-nextcloud: "Nextcloud Module" → "self-hosted file sync +
collaboration (LXC)"
Side fixes:
- Maintainer corrected from "SecuBox <dev@secubox.local>" to
"Gerald KERMA <devel@cybermind.fr>" on config-advisor,
iot-guard, localrecall (3/8 had the placeholder).
Patch-version bump on each so apt sees the metadata change.
16 files, +106/-19. No code/endpoints/services/menu changes. All
changelogs parse cleanly.
After this commit + #383 + #385 + #386 + #382 land, NO secubox-*
package on master ships an "X Module" placeholder headline anymore.
Audit-doc consolidation work complete.
2026-05-27 09:13:36 +02:00
CyberMind
aba60ae356
feat(/data Phase 1): migrate 5 core packages from /srv to /data with postinst auto-mv ( closes #319 Phase 1) ( #320 )
...
Phase 1 — 5 high-impact core packages migrated to the canonical
/data storage convention (charter §Storage). Each package's debian/postinst
gains an idempotent migration block that moves legacy /srv/<dir> → /data/<dir>
on upgrade and leaves a symlink behind for back-compat.
* secubox-mitmproxy v1.0.2: migrates /srv/mitmproxy*, /srv/mitmproxy-waf,
/srv/mitmproxy-in. 8 files in source updated.
* secubox-waf v1.1.1: same dirs (shared with mitmproxy). 5 files updated.
* secubox-mail v2.3.1: migrates /srv/mail. 2 files updated.
* secubox-mail-lxc v2.2.1: migrates /srv/mail. 1 file updated.
* secubox-gitea v1.4.2: migrates /srv/gitea. 4 files updated.
Total: 20 files, 58 substitutions in source. Postinst auto-migration
is service-aware (stop → mv → ln -s → start). Boards previously on
/srv/<pkg> are seamlessly moved; new installs land directly on /data.
Phase 2 (~12 packages) and Phase 3 (3 cosmetic) tracked in #319 .
Co-authored-by: CyberMind-FR <gandalf@Gk2.net>
2026-05-21 16:32:41 +02:00
CyberMind
4f19c604c7
feat(giteactl): forge runner noun verbs — LXC-only CI execution ( closes #190 ) ( #191 )
...
License Headers / check (push) Failing after 5s
Sixth routing verb of SecuBox, parallel to:
haproxyctl vhost add/remove (routing)
mitmproxyctl route add/remove (interception, #173 )
giteactl repo mirror add (replication, #176 )
giteactl user add/remove (identity)
giteactl runner add/remove (CI execution, this — #190 )
Phase B of the gitea-actions migration. Operator decree: LXC only, no
docker on host, no insecure host-mode. Each runner lives in its own LXC
`act-runner-<name>` (matching the modular topology of mail/gitea/
mitmproxy LXCs).
Subcommands:
runner token gen Generate one-shot registration token
runner add NAME --labels L1,L2 [--arch arm64|amd64] [--memory 1G]
lxc-create + apt install + DL gitea-
runner v1.0.3 + register + systemd
runner remove NAME [--keep-data] lxc-stop + lxc-destroy
runner list LXCs locales + /admin/runners JSON
runner logs NAME [--lines N] journalctl -u act_runner (in-LXC)
runner restart NAME
Runner version pinned to 1.0.3 via RUNNER_VERSION env (override-able).
Binary downloaded from https://gitea.com/gitea/runner/releases/ .
Co-authored-by: CyberMind-FR <gandalf@Gk2.net>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-17 11:59:59 +02:00
d7c8cc19e9
Add secubox-repo and secubox-hardening modules, CI/CD workflows
...
New modules (35 total):
- secubox-repo v1.0.0: APT repository management
- repoctl CLI for package management
- GPG key generation and signing
- Multi-distribution support (bookworm, trixie)
- Web dashboard for repository status
- secubox-hardening v1.0.0: Kernel and system hardening
- hardeningctl CLI for security management
- Sysctl hardening (ASLR, kptr_restrict, SYN cookies)
- Module blacklist (uncommon protocols, filesystems)
- Security benchmark with 100% score on VM
CI/CD workflows:
- build-packages.yml: Dynamic matrix for all packages
- build-image.yml: 5 board images with compression
- publish-packages.yml: APT repo publishing
- release.yml: Unified release orchestration
APT repository scripts:
- export-secrets.sh: Export GPG/SSH keys for GitHub Actions
- local-publish.sh: Local test server
- install.sh: User installation script
Security (Phase 5):
- AppArmor profiles for all services
- Audit rules for SecuBox services
- build-all.sh for local builds
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-03-22 22:15:01 +01:00
1868fa2d8c
feat(mail): Debian LXC containers for Postfix/Dovecot/Roundcube
...
Mail Server LXC (mailserverctl v2.1.0):
- Switch from Alpine to Debian bookworm via debootstrap
- Host networking (lxc.net.0.type = none)
- Postfix + Dovecot with virtual mailbox support
- User management via mailctl (add/list/remove)
- DKIM key generation
Roundcube Webmail LXC (roundcubectl v1.4.0):
- Debian bookworm with roundcube package
- SQLite backend, port 8027
- PHP-FPM 8.2 + nginx
- Three-fold commands (components, access)
Also includes:
- Three-fold architecture for 6 modules
- Maintainer update to Gerald KERMA
- Authentication fixes (JWT secret, redirect paths)
- 4 new modules (c3box, gitea, nextcloud, portal)
- WIP.md updated with session progress
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-03-22 10:40:00 +01:00
d3510bf36a
feat: three-fold architecture for streamlit, haproxy, metablogizer
...
Add real backend control scripts and migration support:
- secubox-streamlit: streamlitctl for LXC container management,
app deployment, Gitea integration, OpenWrt migration
- secubox-haproxy: haproxyctl with LXC/Docker/native modes,
vhost/backend/cert management, WAF integration, migration
- secubox-metablogizer: updated UI with three-fold tabs
All modules now follow Components/Status/Access architecture
with tabbed UI and migration modals for importing from OpenWrt.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-03-22 07:28:33 +01:00