New modules created (8): - secubox-ai-insights: ML threat detection and anomaly analysis - secubox-ipblock: IP blocklist manager with nftables integration - secubox-interceptor: Traffic interception and SSL inspection - secubox-cookies: Cookie tracking and GDPR compliance - secubox-mac-guard: MAC address whitelist/blacklist control - secubox-dns-provider: Multi-provider DNS API (OVH, Gandi, Cloudflare) - secubox-threats: Unified threat dashboard with IOC management - secubox-openclaw: OSINT reconnaissance tool Previously built: - secubox-wazuh: SIEM integration - secubox-ossec: Host IDS All modules include: - FastAPI backend with JWT authentication - P31 Phosphor light theme frontend - Debian packaging with systemd integration - nginx reverse proxy config - Menu integration Total packages: 93 (was 85) All migration phases complete (8, 9, 10) Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
10 KiB
MIGRATION MAP — SecuBox OpenWrt → Debian
Mis à jour : 2026-04-04
Légende : ✅ Terminé · 🔄 En cours · ⬜ À faire · ⏸ Bloqué
Voir aussi: OPENWRT-DEBIAN-COMPARISON.md pour la comparaison complète des 103 modules OpenWRT vs 52 paquets Debian.
Infrastructure
| Composant | Statut | Notes |
|---|---|---|
| Repo structure | ✅ | Structure créée |
| CLAUDE.md | ✅ | Instructions Claude Code |
| secubox_core lib | ✅ | auth, config, logger, system |
| nginx template | ✅ | Reverse proxy complet |
| rewrite-xhr.py | ✅ | Gère accolades imbriquées |
| CI build-image | ✅ | Scaffold créé |
| CI build-packages | ✅ | Scaffold créé |
| build-image.sh | ✅ | arm64 + amd64 (VirtualBox) |
| create-vbox-vm.sh | ✅ | Création VM automatique |
| firstboot.sh | ✅ | JWT + SSH + hostname + nftables |
| APT repo | ✅ | apt.secubox.in (reprepro + GPG + CI) |
| Local cache | ✅ | apt-cacher-ng + repo local |
Boards supportés
| Board | SoC | Arch | Profil | Statut |
|---|---|---|---|---|
| mochabin | Armada 7040 | arm64 | secubox-full | ✅ |
| espressobin-v7 | Armada 3720 | arm64 | secubox-lite | ✅ |
| espressobin-ultra | Armada 3720 | arm64 | secubox-lite | ✅ |
| vm-x64 | x86_64-generic | amd64 | secubox-full | ✅ |
Paquets Debian — 93 modules (80 UI + 3 backend + 10 tools)
| Module | www/ | API | deb/ | Endpoints | Statut |
|---|---|---|---|---|---|
| secubox-core | — | ✅ | ✅ | kiosk.py (board detect, kiosk mgmt) v1.1.0 | ✅ |
| secubox-hub | ✅ (71) | ✅ | ✅ | 50+ endpoints (net mode select) v1.1.0 | ✅ |
| secubox-portal | ✅ | ✅ | ✅ | login, auth, theme, branding v2.1.0 | ✅ |
| secubox-crowdsec | ✅ (54) | ✅ | ✅ | 54 endpoints | ✅ |
| secubox-netdata | ✅ (16) | ✅ | ✅ | 16 endpoints | ✅ |
| secubox-wireguard | ✅ (28) | ✅ | ✅ | 28+ endpoints | ✅ |
| secubox-vhost | ✅ | ✅ | ✅ | vhosts, ssl, certs | ✅ |
| secubox-mediaflow | ✅ (20) | ✅ | ✅ | streams, alerts... | ✅ |
| secubox-dpi | ✅ | ✅ | ✅ | 40+ endpoints netifyd | ✅ |
| secubox-qos | ✅ (80) | ✅ | ✅ | 80+ endpoints HTB + VLAN v1.1.0 | ✅ |
| secubox-auth | ✅ (11) | ✅ | ✅ | 20+ endpoints | ✅ |
| secubox-cdn | ✅ (36) | ✅ | ✅ | 25+ endpoints | ✅ |
| secubox-system | ✅ (42) | ✅ | ✅ | 45+ endpoints (board detect, kiosk) v1.2.0 | ✅ |
| secubox-netmodes | ✅ (34) | ✅ | ✅ | 25+ endpoints + templates | ✅ |
| secubox-nac | ✅ (32) | ✅ | ✅ | 25+ endpoints | ✅ |
| secubox-haproxy | ✅ | ✅ | ✅ | stats, backends, acls | ✅ |
| secubox-droplet | ✅ | ✅ | ✅ | upload, publish | ✅ |
| secubox-streamlit | ✅ | ✅ | ✅ | apps, deploy | ✅ |
| secubox-streamforge | ✅ | ✅ | ✅ | apps, templates | ✅ |
| secubox-metablogizer | ✅ | ✅ | ✅ | sites, tor, publish | ✅ |
| secubox-dns | ✅ | ✅ | ✅ | zones, records, BIND | ✅ |
| secubox-mail | ✅ | ✅ | ✅ | Postfix/Dovecot + webmail | ✅ |
| secubox-users | ✅ | ✅ | ✅ | unified identity v1.1.0 | ✅ |
| secubox-webmail | ✅ | ✅ | ✅ | Roundcube/SOGo | ✅ |
| secubox-mail-lxc | — | ✅ | ✅ | LXC backend (no UI) | ✅ |
| secubox-webmail-lxc | — | ✅ | ✅ | LXC backend (no UI) | ✅ |
| secubox-publish | ✅ | ✅ | ✅ | Unified publishing | ✅ |
| secubox-waf | ✅ | ✅ | ✅ | 300+ rules, CrowdSec | ✅ |
| secubox-gitea | ✅ | ✅ | ✅ | Git server LXC | ✅ |
| secubox-nextcloud | ✅ | ✅ | ✅ | File sync LXC | ✅ |
| secubox-c3box | ✅ | ✅ | ✅ | Services portal | ✅ |
| secubox-backup | ✅ | ✅ | ✅ | config, container backup | ✅ |
| secubox-watchdog | ✅ | ✅ | ✅ | containers, services, endpoints | ✅ |
| secubox-tor | ✅ | ✅ | ✅ | circuits, hidden services | ✅ |
| secubox-exposure | ✅ | ✅ | ✅ | Tor, SSL, DNS, Mesh | ✅ |
| secubox-mitmproxy | ✅ | ✅ | ✅ | WAF, alerts, bans | ✅ |
| secubox-traffic | ✅ | ✅ | ✅ | TC/CAKE QoS | ✅ |
| secubox-device-intel | ✅ | ✅ | ✅ | asset discovery, fingerprinting | ✅ |
| secubox-vortex-dns | ✅ | ✅ | ✅ | DNS firewall, RPZ, threat feeds | ✅ |
| secubox-vortex-firewall | ✅ | ✅ | ✅ | nftables threat enforcement | ✅ |
| secubox-meshname | ✅ | ✅ | ✅ | mesh DNS, mDNS, Avahi | ✅ |
| secubox-soc | ✅ | ✅ | ✅ | SOC dashboard, clock, map, tickets | ✅ |
| secubox-roadmap | ✅ | ✅ | ✅ | migration roadmap tracker | ✅ |
| secubox-metrics | ✅ | ✅ | ✅ | real-time metrics dashboard | ✅ |
| secubox-mesh | ✅ | ✅ | ✅ | Yggdrasil mesh network | ✅ |
| secubox-p2p | ✅ | ✅ | ✅ | P2P networking | ✅ |
| secubox-zkp | ✅ | ✅ | ✅ | ZKP Hamiltonian proofs | ✅ |
| secubox-hardening | ✅ | ✅ | ✅ | sysctl + module blacklist | ✅ |
| secubox-repo | ✅ | ✅ | ✅ | APT repository management | ✅ |
| secubox-daemon | — | Go | ✅ | Mesh daemon (secuboxd, secuboxctl) | ✅ |
| secubox-c3box | ✅ | Go | ✅ | C3BOX situational awareness dashboard | ✅ |
| secubox-ollama | ✅ | ✅ | ✅ | models, chat, generate, system | ✅ | | secubox-jellyfin | ✅ | ✅ | ✅ | media, config, backup, logs | ✅ | | secubox-lyrion | ✅ | ✅ | ✅ | players, library, backup, LMS JSON-RPC | ✅ | | secubox-console | — | ✅ | ✅ | Textual TUI dashboard (no www) v1.1.0 | ✅ | | secubox-soc-agent | — | ✅ | ✅ | Edge node metrics agent v1.0.0 | ✅ | | secubox-soc-gateway | — | ✅ | ✅ | SOC aggregation gateway v1.0.0 | ✅ | | secubox-soc-web | ✅ | — | ✅ | React SOC dashboard v1.0.0 | ✅ |
| secubox-hexo | ✅ | ✅ | ✅ | blogs, posts, themes, deploy | ✅ | | secubox-webradio | ✅ | ✅ | ✅ | stations, streaming, recording | ✅ | | secubox-torrent | ✅ | ✅ | ✅ | torrents, RSS, categories | ✅ | | secubox-newsbin | ✅ | ✅ | ✅ | NZB queue, history, servers | ✅ | | secubox-domoticz | ✅ | ✅ | ✅ | devices, rooms, scenes, automation | ✅ | | secubox-gotosocial | ✅ | ✅ | ✅ | accounts, federation, moderation | ✅ | | secubox-simplex | ✅ | ✅ | ✅ | SMP relay, queues, TLS | ✅ | | secubox-photoprism | ✅ | ✅ | ✅ | library, albums, faces, storage | ✅ | | secubox-homeassistant | ✅ | ✅ | ✅ | entities, automations, scenes, addons | ✅ | | secubox-matrix | ✅ | ✅ | ✅ | users, rooms, federation, media | ✅ | | secubox-jitsi | ✅ | ✅ | ✅ | rooms, recordings, auth, prosody | ✅ | | secubox-peertube | ✅ | ✅ | ✅ | videos, channels, federation, transcoding | ✅ | | secubox-voip | ✅ | ✅ | ✅ | extensions, trunks, routes, IVR, CDR | ✅ |
| secubox-wazuh | — | ✅ | ✅ | SIEM, agent enrollment | ✅ | | secubox-ossec | — | ✅ | ✅ | Host IDS | ✅ | | secubox-ai-insights | ✅ | ✅ | ✅ | ML threat detection, anomalies | ✅ | | secubox-ipblock | ✅ | ✅ | ✅ | IP blocklist, nftables sets | ✅ | | secubox-interceptor | ✅ | ✅ | ✅ | traffic interception, SSL inspect | ✅ | | secubox-cookies | ✅ | ✅ | ✅ | cookie tracking, GDPR | ✅ | | secubox-mac-guard | ✅ | ✅ | ✅ | MAC whitelist/blacklist | ✅ | | secubox-dns-provider | ✅ | ✅ | ✅ | OVH, Gandi, Cloudflare API | ✅ | | secubox-threats | ✅ | ✅ | ✅ | unified threat dashboard, IOCs | ✅ | | secubox-openclaw | ✅ | ✅ | ✅ | OSINT reconnaissance | ✅ |
Total : 93 modules | ~2000+ endpoints API + Go mesh daemon + TUI console + SOC
Note: mail-lxc and webmail-lxc are backend components integrated into secubox-mail
Phases du projet
Phase 1 — Hardware ✅
- build-image.sh (debootstrap arm64 + amd64)
- Board configs (mochabin, espressobin-v7, espressobin-ultra, vm-x64)
- create-vbox-vm.sh (VirtualBox)
- firstboot.sh (détection board améliorée)
- Templates netplan par board
- Kernel 6.6 LTS cross-compile (optionnel — peut utiliser stock Debian)
Phase 2 — Infrastructure ✅
- secubox_core Python lib
- nginx reverse proxy template
- rewrite-xhr.py script
- CI scaffolds
Phase 3 — Modules ✅
- Tous les frontends portés (13/13)
- Tous les APIs implémentés (14/14)
- Packaging debian complet (14/14)
- Templates netplan pour netmodes
- Frontend secubox-dpi créé
Phase 4 — APT Repo ✅
- apt.secubox.in (reprepro config)
- GPG signing (generate-gpg-key.sh)
- CI publish workflow (publish-packages.yml)
- repo-manage.sh (add/remove/list/sync)
- setup-repo-server.sh (nginx + Let's Encrypt)
- Metapackages (secubox-full, secubox-lite)
- Local cache build (apt-cacher-ng + repo local)
Commandes de build
# Build image ARM (MOCHAbin)
sudo bash image/build-image.sh --board mochabin
# Build image x64 pour VirtualBox
sudo bash image/build-image.sh --board vm-x64 --vdi
# Build image x64 avec cache local (plus rapide)
sudo bash image/build-image.sh --board vm-x64 --local-cache --vdi
# Créer VM VirtualBox
bash image/create-vbox-vm.sh output/secubox-vm-x64-bookworm.vdi
# Build un paquet .deb
cd packages/secubox-crowdsec && dpkg-buildpackage -us -uc -b
# Build et ajouter au repo local
bash scripts/build-add-local.sh secubox-crowdsec bookworm
Prochaines étapes
Phase 1 : build-image.sh + board configs✅ FaitPhase 2 : Infrastructure✅ FaitPhase 3 : Core Modules (52/103)✅ FaitPhase 4 : APT repo (apt.secubox.in)✅ FaitPhase 5 : CSPN Hardening✅ Fait (partiel)Phase 6 : CI/CD✅ FaitPhase 7 : Documentation + UI Theme✅ FaitPhase 8 : Applications✅ 21/21 modules completePhase 9 : System Tools✅ 22/22 modules completePhase 10 : Security Extensions✅ 10/10 modules complete- Tests d'intégration sur VM et hardware réel
- Déployer apt.secubox.in sur serveur production
Voir aussi: REMAINING-PACKAGES.md pour l'inventaire détaillé des 53 paquets restants avec classification par complexité
Build avec cache local
# Setup cache local (une fois)
sudo bash scripts/setup-local-cache.sh
# Builder tous les packages SecuBox
bash scripts/build-all-local.sh bookworm amd64
# Construire image avec cache local
sudo bash image/build-image.sh --board vm-x64 --local-cache