# MIGRATION MAP — SecuBox OpenWrt → Debian *Mis à jour : 2026-04-05* Légende : ✅ Terminé · 🔄 En cours · ⬜ À faire · ⏸ Bloqué > **Voir aussi**: [OPENWRT-DEBIAN-COMPARISON.md](../docs/OPENWRT-DEBIAN-COMPARISON.md) pour la comparaison complète des 103 modules OpenWRT vs 52 paquets Debian. --- ## Infrastructure | Composant | Statut | Notes | |-----------|--------|-------| | Repo structure | ✅ | Structure créée | | CLAUDE.md | ✅ | Instructions Claude Code | | secubox_core lib | ✅ | auth, config, logger, system | | nginx template | ✅ | Reverse proxy complet | | rewrite-xhr.py | ✅ | Gère accolades imbriquées | | CI build-image | ✅ | Scaffold créé | | CI build-packages | ✅ | Scaffold créé | | build-image.sh | ✅ | arm64 + amd64 (VirtualBox) | | create-vbox-vm.sh | ✅ | Création VM automatique | | firstboot.sh | ✅ | JWT + SSH + hostname + nftables | | APT repo | ✅ | apt.secubox.in (reprepro + GPG + CI) | | Local cache | ✅ | apt-cacher-ng + repo local | --- ## Boards supportés | Board | SoC | Arch | Profil | Statut | |-------|-----|------|--------|--------| | **mochabin** | Armada 7040 | arm64 | secubox-full | ✅ | | **espressobin-v7** | Armada 3720 | arm64 | secubox-lite | ✅ | | **espressobin-ultra** | Armada 3720 | arm64 | secubox-lite | ✅ | | **vm-x64** | x86_64-generic | amd64 | secubox-full | ✅ | --- ## Paquets Debian — 124 modules (80 UI + 3 backend + 30 tools + 11 infrastructure) | Module | www/ | API | deb/ | Endpoints | Statut | |--------|------|-----|------|-----------|--------| | **secubox-core** | — | ✅ | ✅ | kiosk.py (board detect, kiosk mgmt) v1.1.0 | ✅ | | **secubox-hub** | ✅ (71) | ✅ | ✅ | 50+ endpoints (net mode select) v1.1.0 | ✅ | | **secubox-portal** | ✅ | ✅ | ✅ | login, auth, theme, branding v2.1.0 | ✅ | | **secubox-crowdsec** | ✅ (54) | ✅ | ✅ | 54 endpoints | ✅ | | **secubox-netdata** | ✅ (16) | ✅ | ✅ | 16 endpoints | ✅ | | **secubox-wireguard** | ✅ (28) | ✅ | ✅ | 28+ endpoints | ✅ | | **secubox-vhost** | ✅ | ✅ | ✅ | vhosts, ssl, certs | ✅ | | **secubox-mediaflow** | ✅ (20) | ✅ | ✅ | streams, alerts... | ✅ | | **secubox-dpi** | ✅ | ✅ | ✅ | 40+ endpoints netifyd | ✅ | | **secubox-qos** | ✅ (80) | ✅ | ✅ | 80+ endpoints HTB + VLAN v1.1.0 | ✅ | | **secubox-auth** | ✅ (11) | ✅ | ✅ | 20+ endpoints | ✅ | | **secubox-cdn** | ✅ (36) | ✅ | ✅ | 25+ endpoints | ✅ | | **secubox-system** | ✅ (42) | ✅ | ✅ | 45+ endpoints (board detect, kiosk) v1.2.0 | ✅ | | **secubox-netmodes** | ✅ (34) | ✅ | ✅ | 25+ endpoints + templates | ✅ | | **secubox-nac** | ✅ (32) | ✅ | ✅ | 25+ endpoints | ✅ | | **secubox-haproxy** | ✅ | ✅ | ✅ | stats, backends, acls | ✅ | | **secubox-droplet** | ✅ | ✅ | ✅ | upload, publish | ✅ | | **secubox-streamlit** | ✅ | ✅ | ✅ | apps, deploy | ✅ | | **secubox-streamforge** | ✅ | ✅ | ✅ | apps, templates | ✅ | | **secubox-metablogizer** | ✅ | ✅ | ✅ | sites, tor, publish | ✅ | | **secubox-dns** | ✅ | ✅ | ✅ | zones, records, BIND | ✅ | | **secubox-mail** | ✅ | ✅ | ✅ | Postfix/Dovecot + webmail | ✅ | | **secubox-users** | ✅ | ✅ | ✅ | unified identity v1.1.0 | ✅ | | **secubox-webmail** | ✅ | ✅ | ✅ | Roundcube/SOGo | ✅ | | **secubox-mail-lxc** | — | ✅ | ✅ | LXC backend (no UI) | ✅ | | **secubox-webmail-lxc** | — | ✅ | ✅ | LXC backend (no UI) | ✅ | | **secubox-publish** | ✅ | ✅ | ✅ | Unified publishing | ✅ | | **secubox-waf** | ✅ | ✅ | ✅ | 300+ rules, CrowdSec | ✅ | | **secubox-gitea** | ✅ | ✅ | ✅ | Git server LXC | ✅ | | **secubox-nextcloud** | ✅ | ✅ | ✅ | File sync LXC | ✅ | | **secubox-c3box** | ✅ | ✅ | ✅ | Services portal | ✅ | | **secubox-backup** | ✅ | ✅ | ✅ | config, container backup | ✅ | | **secubox-watchdog** | ✅ | ✅ | ✅ | containers, services, endpoints | ✅ | | **secubox-tor** | ✅ | ✅ | ✅ | circuits, hidden services | ✅ | | **secubox-exposure** | ✅ | ✅ | ✅ | Tor, SSL, DNS, Mesh | ✅ | | **secubox-mitmproxy** | ✅ | ✅ | ✅ | WAF, alerts, bans | ✅ | | **secubox-traffic** | ✅ | ✅ | ✅ | TC/CAKE QoS | ✅ | | **secubox-device-intel** | ✅ | ✅ | ✅ | asset discovery, fingerprinting | ✅ | | **secubox-vortex-dns** | ✅ | ✅ | ✅ | DNS firewall, RPZ, threat feeds | ✅ | | **secubox-vortex-firewall** | ✅ | ✅ | ✅ | nftables threat enforcement | ✅ | | **secubox-meshname** | ✅ | ✅ | ✅ | mesh DNS, mDNS, Avahi | ✅ | | **secubox-soc** | ✅ | ✅ | ✅ | SOC dashboard, clock, map, tickets | ✅ | | **secubox-roadmap** | ✅ | ✅ | ✅ | migration roadmap tracker | ✅ | | **secubox-metrics** | ✅ | ✅ | ✅ | real-time metrics dashboard | ✅ | | **secubox-mesh** | ✅ | ✅ | ✅ | Yggdrasil mesh network | ✅ | | **secubox-p2p** | ✅ | ✅ | ✅ | P2P networking | ✅ | | **secubox-zkp** | ✅ | ✅ | ✅ | ZKP Hamiltonian proofs | ✅ | | **secubox-hardening** | ✅ | ✅ | ✅ | sysctl + module blacklist | ✅ | | **secubox-repo** | ✅ | ✅ | ✅ | APT repository management | ✅ | | **secubox-daemon** | — | Go | ✅ | Mesh daemon (secuboxd, secuboxctl) | ✅ | | **secubox-c3box** | ✅ | Go | ✅ | C3BOX situational awareness dashboard | ✅ | | **secubox-ollama** | ✅ | ✅ | ✅ | models, chat, generate, system | ✅ | | **secubox-jellyfin** | ✅ | ✅ | ✅ | media, config, backup, logs | ✅ | | **secubox-lyrion** | ✅ | ✅ | ✅ | players, library, backup, LMS JSON-RPC | ✅ | | **secubox-console** | — | ✅ | ✅ | Textual TUI dashboard (no www) v1.1.0 | ✅ | | **secubox-soc-agent** | — | ✅ | ✅ | Edge node metrics agent v1.0.0 | ✅ | | **secubox-soc-gateway** | — | ✅ | ✅ | SOC aggregation gateway v1.0.0 | ✅ | | **secubox-soc-web** | ✅ | — | ✅ | React SOC dashboard v1.0.0 | ✅ | | **secubox-hexo** | ✅ | ✅ | ✅ | blogs, posts, themes, deploy | ✅ | | **secubox-webradio** | ✅ | ✅ | ✅ | stations, streaming, recording | ✅ | | **secubox-torrent** | ✅ | ✅ | ✅ | torrents, RSS, categories | ✅ | | **secubox-newsbin** | ✅ | ✅ | ✅ | NZB queue, history, servers | ✅ | | **secubox-domoticz** | ✅ | ✅ | ✅ | devices, rooms, scenes, automation | ✅ | | **secubox-gotosocial** | ✅ | ✅ | ✅ | accounts, federation, moderation | ✅ | | **secubox-simplex** | ✅ | ✅ | ✅ | SMP relay, queues, TLS | ✅ | | **secubox-photoprism** | ✅ | ✅ | ✅ | library, albums, faces, storage | ✅ | | **secubox-homeassistant** | ✅ | ✅ | ✅ | entities, automations, scenes, addons | ✅ | | **secubox-matrix** | ✅ | ✅ | ✅ | users, rooms, federation, media | ✅ | | **secubox-jitsi** | ✅ | ✅ | ✅ | rooms, recordings, auth, prosody | ✅ | | **secubox-peertube** | ✅ | ✅ | ✅ | videos, channels, federation, transcoding | ✅ | | **secubox-voip** | ✅ | ✅ | ✅ | extensions, trunks, routes, IVR, CDR | ✅ | | **secubox-wazuh** | — | ✅ | ✅ | SIEM, agent enrollment | ✅ | | **secubox-ossec** | — | ✅ | ✅ | Host IDS | ✅ | | **secubox-ai-insights** | ✅ | ✅ | ✅ | ML threat detection, anomalies | ✅ | | **secubox-ipblock** | ✅ | ✅ | ✅ | IP blocklist, nftables sets | ✅ | | **secubox-interceptor** | ✅ | ✅ | ✅ | traffic interception, SSL inspect | ✅ | | **secubox-cookies** | ✅ | ✅ | ✅ | cookie tracking, GDPR | ✅ | | **secubox-mac-guard** | ✅ | ✅ | ✅ | MAC whitelist/blacklist | ✅ | | **secubox-dns-provider** | ✅ | ✅ | ✅ | OVH, Gandi, Cloudflare API | ✅ | | **secubox-threats** | ✅ | ✅ | ✅ | unified threat dashboard, IOCs | ✅ | | **secubox-openclaw** | ✅ | ✅ | ✅ | OSINT reconnaissance | ✅ | | **secubox-modem** | ✅ | ✅ | ✅ | LTE/5G modem, SMS, AT terminal | ✅ | ### Phase 9+ — System & Infrastructure Tools (11 new) | Module | www/ | API | deb/ | Endpoints | Statut | |--------|------|-----|------|-----------|--------| | **secubox-nettweak** | ✅ | ✅ | ✅ | sysctl, profiles, TCP/IP tuning | ✅ | | **secubox-ksm** | ✅ | ✅ | ✅ | KSM memory optimization | ✅ | | **secubox-avatar** | ✅ | ✅ | ✅ | identity, avatar upload, service sync | ✅ | | **secubox-admin** | ✅ | ✅ | ✅ | services, logs, disk, processes, reboot | ✅ | | **secubox-metabolizer** | ✅ | ✅ | ✅ | log processing, pattern detection | ✅ | | **secubox-metacatalog** | ✅ | ✅ | ✅ | service registry, health, dependencies | ✅ | | **secubox-cyberfeed** | ✅ | ✅ | ✅ | threat feeds, nftables/hosts export | ✅ | | **secubox-mirror** | ✅ | ✅ | ✅ | APT/NPM/PyPI/Docker cache | ✅ | | **secubox-saas-relay** | ✅ | ✅ | ✅ | API proxy, Fernet, rate limiting | ✅ | | **secubox-rezapp** | ✅ | ✅ | ✅ | Docker/LXC deployment, templates | ✅ | | **secubox-picobrew** | ✅ | ✅ | ✅ | homebrew sensors, fermentation profiles | ✅ | **Total : 125 modules | ~2000+ endpoints API + Go mesh daemon + TUI console + SOC** *Note: mail-lxc and webmail-lxc are backend components integrated into secubox-mail* --- ## Addenda **2026-05-12 — Issue #92 extension:** `secubox-metrics` gains three public live-panel endpoints (`visitor-origin`, `live-hosts`, `cert-status`) consumed by the health banner. --- ## Phases du projet ### Phase 1 — Hardware ✅ - [x] build-image.sh (debootstrap arm64 + amd64) - [x] Board configs (mochabin, espressobin-v7, espressobin-ultra, vm-x64) - [x] create-vbox-vm.sh (VirtualBox) - [x] firstboot.sh (détection board améliorée) - [x] Templates netplan par board - [ ] Kernel 6.6 LTS cross-compile (optionnel — peut utiliser stock Debian) ### Phase 2 — Infrastructure ✅ - [x] secubox_core Python lib - [x] nginx reverse proxy template - [x] rewrite-xhr.py script - [x] CI scaffolds ### Phase 3 — Modules ✅ - [x] Tous les frontends portés (13/13) - [x] Tous les APIs implémentés (14/14) - [x] Packaging debian complet (14/14) - [x] Templates netplan pour netmodes - [x] Frontend secubox-dpi créé ### Phase 4 — APT Repo ✅ - [x] apt.secubox.in (reprepro config) - [x] GPG signing (generate-gpg-key.sh) - [x] CI publish workflow (publish-packages.yml) - [x] repo-manage.sh (add/remove/list/sync) - [x] setup-repo-server.sh (nginx + Let's Encrypt) - [x] Metapackages (secubox-full, secubox-lite) - [x] Local cache build (apt-cacher-ng + repo local) --- ## Commandes de build ```bash # Build image ARM (MOCHAbin) sudo bash image/build-image.sh --board mochabin # Build image x64 pour VirtualBox sudo bash image/build-image.sh --board vm-x64 --vdi # Build image x64 avec cache local (plus rapide) sudo bash image/build-image.sh --board vm-x64 --local-cache --vdi # Créer VM VirtualBox bash image/create-vbox-vm.sh output/secubox-vm-x64-bookworm.vdi # Build un paquet .deb cd packages/secubox-crowdsec && dpkg-buildpackage -us -uc -b # Build et ajouter au repo local bash scripts/build-add-local.sh secubox-crowdsec bookworm ``` --- ## Prochaines étapes 1. ~~Phase 1 : build-image.sh + board configs~~ ✅ Fait 2. ~~Phase 2 : Infrastructure~~ ✅ Fait 3. ~~Phase 3 : Core Modules (52/103)~~ ✅ Fait 4. ~~Phase 4 : APT repo (apt.secubox.in)~~ ✅ Fait 5. ~~Phase 5 : CSPN Hardening~~ ✅ Fait (partiel) 6. ~~Phase 6 : CI/CD~~ ✅ Fait 7. ~~Phase 7 : Documentation + UI Theme~~ ✅ Fait 8. ~~Phase 8 : Applications~~ ✅ **21/21 modules complete** 9. ~~Phase 9 : System Tools~~ ✅ **22/22 modules complete** 10. ~~Phase 10 : Security Extensions~~ ✅ **10/10 modules complete** 11. Tests d'intégration sur VM et hardware réel 12. Déployer apt.secubox.in sur serveur production > **Voir aussi**: [REMAINING-PACKAGES.md](REMAINING-PACKAGES.md) pour l'inventaire détaillé des 53 paquets restants avec classification par complexité --- ## Build avec cache local ```bash # Setup cache local (une fois) sudo bash scripts/setup-local-cache.sh # Builder tous les packages SecuBox bash scripts/build-all-local.sh bookworm amd64 # Construire image avec cache local sudo bash image/build-image.sh --board vm-x64 --local-cache ```