secubox-deb/scripts
CyberMind-FR b77a49fc2f docs(scripts): document agent-worktree in scripts/README (ref #83)
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-12 10:05:48 +02:00
..
bench feat(bench): Add performance benchmark suite for ARM64 optimization 2026-04-30 09:12:00 +02:00
lib feat(scripts): implement agent-worktree start sub-command (ref #83) 2026-05-12 09:54:12 +02:00
tests feat(scripts): implement agent-worktree clean sub-command (ref #83) 2026-05-12 10:03:47 +02:00
add-health-endpoints.py feat(api): Add /health endpoint to 53 modules 2026-05-09 10:40:05 +02:00
agent-worktree.sh feat(scripts): implement agent-worktree clean sub-command (ref #83) 2026-05-12 10:03:47 +02:00
apply-crt-theme.py Apply CRT P31 Phosphor theme to all 38 module UIs 2026-03-23 18:56:11 +01:00
apply-light-theme.py Add CRT light theme across all UI modules 2026-03-25 08:55:45 +01:00
apt-publish.sh feat(secubox): complete meta-script generator Tasks 14-17 2026-05-11 05:32:29 +02:00
apt-sync.sh feat(secubox): complete meta-script generator Tasks 14-17 2026-05-11 05:32:29 +02:00
build-add-local.sh Initial commit: SecuBox-DEB migration from OpenWrt to Debian 2026-03-21 09:41:06 +01:00
build-all-local.sh feat(build): Slipstream ALL packages, AZERTY, no-compress option 2026-03-30 06:37:35 +02:00
build-all.sh fix(build): Add timeouts to prevent build script hangs 2026-04-26 19:04:20 +02:00
build-packages.sh feat(scripts): Add --filter and --dry-run to build-packages.sh (ref #80) 2026-05-12 09:11:14 +02:00
capture-module-screenshots.sh feat(kiosk): Add VirtualBox debug logging for X11 troubleshooting 2026-04-13 08:26:06 +02:00
capture-screenshots.py feat(docs): Add screenshot capture system and multilingual wiki generator 2026-05-09 10:09:21 +02:00
create-secubox-vm.sh docs: Add VirtualBox quick start guide and VM creation script 2026-04-04 10:31:21 +02:00
deploy.sh fix(deploy): Remove --delete from www rsync to prevent module conflicts 2026-05-02 18:13:16 +02:00
diag-leds.sh feat(led-heartbeat): Add bash heartbeat script and diagnostic tool (ref #39) 2026-05-07 07:13:59 +02:00
export-preseed.sh Add preseed system for configuration persistence 2026-03-24 19:41:08 +01:00
fix-emoji-fonts.sh feat(kiosk): Add VirtualBox debug logging for X11 troubleshooting 2026-04-13 08:26:06 +02:00
fix-namespace-errors.sh fix(kiosk): Skip X11 config on bare metal, disable service sandboxing 2026-04-15 09:52:20 +02:00
fix-navbar.sh Fix p2p/zkp/mesh navbar and add fix-navbar.sh script 2026-03-26 07:19:29 +01:00
flash-multiboot.sh feat(scripts): Add flash-multiboot.sh download/flash tool 2026-04-27 19:12:23 +02:00
generate-docs.py feat(docs): Add screenshot capture system and multilingual wiki generator 2026-05-09 10:09:21 +02:00
generate-secubox-yaml.py feat(secubox): complete meta-script generator Tasks 14-17 2026-05-11 05:32:29 +02:00
haproxy-workflow.sh fix(health): VHost health prober placeholder categorization + Eye Remote metrics 2026-05-06 16:44:49 +02:00
install-apparmor.sh Add secubox-repo and secubox-hardening modules, CI/CD workflows 2026-03-22 22:15:01 +01:00
install-audit.sh Add secubox-repo and secubox-hardening modules, CI/CD workflows 2026-03-22 22:15:01 +01:00
local-repo-add.sh Initial commit: SecuBox-DEB migration from OpenWrt to Debian 2026-03-21 09:41:06 +01:00
migration-export.sh feat(migration): Add --exclude-services option to export script 2026-04-29 15:34:35 +02:00
migration-import.sh feat(migration): Extend migration tools v2.1.0 with 19 modules 2026-04-29 14:17:30 +02:00
migration-transform.py feat(migration): Add OpenWrt → SecuBox-DEB migration tools 2026-04-29 12:45:47 +02:00
new-module.sh feat: modular nginx config + hub roadmap + new modules 2026-03-21 20:34:01 +01:00
new-package.sh feat: modular nginx config + hub roadmap + new modules 2026-03-21 20:34:01 +01:00
patch-multiboot-efi.sh feat(live-boot): Complete live RAM boot implementation v2.2.4-live 2026-04-27 13:30:50 +02:00
port-frontend.sh Initial commit: SecuBox-DEB migration from OpenWrt to Debian 2026-03-21 09:41:06 +01:00
qemu-screenshot.sh feat(kiosk): Add VirtualBox debug logging for X11 troubleshooting 2026-04-13 08:26:06 +02:00
README.md docs(scripts): document agent-worktree in scripts/README (ref #83) 2026-05-12 10:05:48 +02:00
render-deploy-artifacts.sh feat(scripts): Render nginx vhost + DEPLOY.md + license artifacts (ref #80) 2026-05-12 09:32:01 +02:00
requirements-screenshot.txt Add screenshot tool and wiki documentation 2026-03-24 12:36:19 +01:00
retrofit-nginx-modular.sh feat: modular nginx config + hub roadmap + new modules 2026-03-21 20:34:01 +01:00
rewrite-xhr.py Initial commit: SecuBox-DEB migration from OpenWrt to Debian 2026-03-21 09:41:06 +01:00
run-qemu.sh feat: Add QEMU/VBox launcher scripts + fix kiosk log bug 2026-04-10 12:02:25 +02:00
run-vbox.sh feat: Add QEMU/VBox launcher scripts + fix kiosk log bug 2026-04-10 12:02:25 +02:00
screenshot-tool.py Fix screenshot tool login with aiohttp 2026-03-24 13:24:30 +01:00
secubox-healthbump feat(ui): Add dice icons, scribe trace, and LED pulse improvements 2026-05-08 22:33:23 +02:00
secubox-nginx-sync.sh feat(ui): Sidebar v2.30.0 with hardware LED health bumper integration 2026-05-08 17:56:18 +02:00
secubox-screenshots.sh feat(network): Smart auto-IP with ARP collision detection (v1.7.0.2) 2026-04-14 16:28:02 +02:00
setup-local-cache.sh Initial commit: SecuBox-DEB migration from OpenWrt to Debian 2026-03-21 09:41:06 +01:00
stage-apt-repo.sh feat(scripts): Add stage-apt-repo.sh orchestrator (ref #80) 2026-05-12 09:31:16 +02:00
stage-gpg-bootstrap.sh feat(scripts): Add GPG bootstrap wrapper for staged repo (ref #80) 2026-05-12 09:27:22 +02:00
sync-all-routes.sh fix(infra): mitmproxy route sync stability — restore metablogizer sites 2026-05-12 09:54:52 +02:00
sync-mitmproxy-routes.sh fix(infra): mitmproxy route sync stability — restore metablogizer sites 2026-05-12 09:54:52 +02:00
sync-wiki.sh feat(live-boot): Complete live RAM boot implementation v2.2.4-live 2026-04-27 13:30:50 +02:00
ui-fix-checker.sh fix(ui): Add sidebar navigation to 11 modules 2026-04-10 13:20:24 +02:00
ui-screenshot-capture.py fix(ui): Add sidebar navigation to 11 modules 2026-04-10 13:20:24 +02:00
update-css-design-tokens.py feat: Implement 6-Module Design System across all UI components 2026-04-08 18:29:36 +02:00
update-debian-nginx.sh feat: modular nginx config + hub roadmap + new modules 2026-03-21 20:34:01 +01:00
update-nginx-modular.sh feat: modular nginx config + hub roadmap + new modules 2026-03-21 20:34:01 +01:00
validate-staged-repo.sh fix(scripts): Decouple chroot apt-update grep from pipefail (ref #80) 2026-05-12 09:39:14 +02:00
vbox-setup.sh feat(build): Add kiosk mode + VirtualBox setup + Profile Generator architecture 2026-04-29 09:16:36 +02:00
vhost-matrix-sync.sh fix(infra): Fix vhost-matrix-sync stderr logging for clean JSON output 2026-05-06 17:32:27 +02:00

SecuBox-DEB — Scripts

Outils de build, déploiement et maintenance pour SecuBox-DEB.


Build Scripts

Script Description
build-packages.sh Build tous les packages .deb
build-all.sh Build complet + deploy
build-all-local.sh Build avec cache local
build-add-local.sh Ajouter package au repo local

Usage

# Build tous les packages
bash build-packages.sh

# Build un package spécifique
bash build-packages.sh --package secubox-hub

# Build avec cache local (plus rapide)
bash build-all-local.sh

Deploy Scripts

Script Description
deploy.sh Déployer sur cible via SSH

Usage

# Déployer un package
bash deploy.sh secubox-hub root@192.168.1.1

# Déployer tous les packages
bash deploy.sh all root@192.168.1.1

Package Scaffolding

Script Description
new-package.sh Créer structure package Debian
new-module.sh Créer module avec API FastAPI
port-frontend.sh Porter frontend depuis OpenWrt

Usage

# Nouveau package
bash new-package.sh secubox-mymodule

# Nouveau module avec API
bash new-module.sh mymodule

# Porter frontend LuCI
bash port-frontend.sh crowdsec-dashboard

Multi-Agent Worktrees

Script Description
agent-worktree.sh Lifecycle helper for one-branch-per-issue work in isolated git worktrees

Usage

# Create a worktree bound to GitHub issue #83
bash scripts/agent-worktree.sh start --issue 83
cd ~/CyberMindStudio/secubox-deb-worktrees/83-multi-agent-worktree-workflow

# List active worktrees + ahead/behind/dirty status
bash scripts/agent-worktree.sh list

# Rebase the current worktree on origin/master
bash scripts/agent-worktree.sh sync

# Push and open the PR (`Closes #83` in body)
bash scripts/agent-worktree.sh finish

# After merge, remove the worktree and local branch
bash scripts/agent-worktree.sh clean 83

See scripts/agent-worktree.sh --help for the full reference and docs/superpowers/specs/2026-05-12-multi-agent-worktree-workflow-design.md for the design rationale.


Local Cache Setup

Script Description
setup-local-cache.sh Configurer apt-cacher-ng
local-repo-add.sh Ajouter .deb au repo local

Usage

# Setup initial
sudo bash setup-local-cache.sh

# Ajouter un package
bash local-repo-add.sh ../output/debs/secubox-core_1.0.0.deb

Flash & Download

Script Description
flash-multiboot.sh Download & flash multiboot USB

Usage

# List available releases
bash flash-multiboot.sh --list

# Flash latest multiboot to USB
sudo bash flash-multiboot.sh /dev/sdb

# Download specific release without flashing
bash flash-multiboot.sh --release multiboot-v2.2.4-live --download

# Flash with force (no confirmation)
sudo bash flash-multiboot.sh --force /dev/sdb

VM & Testing

Script Description
run-qemu.sh Lancer image dans QEMU
run-vbox.sh Lancer VM VirtualBox
create-secubox-vm.sh Créer VM SecuBox
qemu-screenshot.sh Screenshot VM QEMU

Usage

# Test dans QEMU
bash run-qemu.sh ../output/secubox-vm-x64.img

# Screenshot automatique
bash qemu-screenshot.sh

Fix & Maintenance

Script Description
fix-navbar.sh Corriger navbar modules
fix-emoji-fonts.sh Installer fonts emoji
fix-namespace-errors.sh Fix namespace Python
ui-fix-checker.sh Vérifier UI modules
update-nginx-modular.sh Update config nginx
retrofit-nginx-modular.sh Migrer config nginx
update-debian-nginx.sh Update nginx Debian

Security Scripts

Script Description
install-apparmor.sh Installer profils AppArmor
install-audit.sh Configurer auditd

Usage

sudo bash install-apparmor.sh
sudo bash install-audit.sh

Screenshot & Documentation

Script Description
capture-module-screenshots.sh Screenshots tous modules
secubox-screenshots.sh Screenshots automatiques

Export Scripts

Script Description
export-preseed.sh Exporter config preseed

Performance Benchmarks

Script Description
bench/api-latency.py API endpoint latency testing (P50/P95/P99)
bench/memory-baseline.sh Per-service memory tracking (RSS/PSS/USS)
bench/startup-time.sh Service cold-start measurement
bench/cpu-profile.sh Flame graph generation with py-spy
bench/locustfile.py Locust load test scenarios

See bench/README.md for detailed usage.

Quick Usage

# API latency
./bench/api-latency.py --host 192.168.255.250 --requests 50

# Memory baseline
./bench/memory-baseline.sh

# Load test
locust -f bench/locustfile.py --host https://192.168.255.250

Migration Scripts

Script Description
migration-export.sh Export SecuBox-OpenWrt configs via SSH
migration-import.sh Import migration archive to SecuBox-DEB
migration-transform.py UCI → TOML/netplan/nftables converter

Overview

Migration Data Saver exports services and content from SecuBox-OpenWrt and restores them to SecuBox-DEB targets (VirtualBox/amd64, ESPRESSObin/ARM64).

┌─────────────────────────────────┐
│  SecuBox-OpenWrt (source)       │
│  ├─ /etc/config/* (UCI)         │
│  ├─ /etc/wireguard/*.conf       │
│  ├─ /etc/crowdsec/*             │
│  └─ /srv/www/* (content)        │
└──────────────┬──────────────────┘
               │ SSH + tar
               ▼
┌─────────────────────────────────┐
│  Migration Archive (.tar.gz)    │
│  ├─ manifest.json               │
│  ├─ configs/ (UCI → TOML)       │
│  ├─ secrets/ (encrypted)        │
│  └─ content/ (web/media)        │
└──────────────┬──────────────────┘
               │ transform + import
               ▼
┌─────────────────────────────────┐
│  SecuBox-DEB (target)           │
│  ├─ /etc/secubox/*.toml         │
│  ├─ /etc/netplan/*.yaml         │
│  ├─ /etc/nftables.conf          │
│  └─ /srv/www/*                  │
└─────────────────────────────────┘

Usage

# 1. Setup SSH key access to OpenWrt source
ssh-copy-id -i ~/.ssh/secubox-openwrt root@192.168.255.1

# 2. Export from OpenWrt
bash scripts/migration-export.sh -h 192.168.255.1 -i ~/.ssh/secubox-openwrt -o /tmp/migration.tar.gz

# 3. Preview import on target (dry-run)
bash scripts/migration-import.sh -f /tmp/migration.tar.gz --dry-run

# 4. Apply migration
bash scripts/migration-import.sh -f /tmp/migration.tar.gz

# Export with encryption
bash scripts/migration-export.sh -h 192.168.255.1 -e -o /tmp/migration.tar.gz.enc

# Import encrypted archive
bash scripts/migration-import.sh -f /tmp/migration.tar.gz.enc --passphrase "secret"

# Export/import specific modules only
bash scripts/migration-export.sh -h 192.168.255.1 -m wireguard,crowdsec,certs -o /tmp/partial.tar.gz
bash scripts/migration-import.sh -f /tmp/partial.tar.gz -m wireguard,crowdsec

Exported Modules

Module OpenWrt Source Debian Destination
network /etc/config/network (UCI) /etc/netplan/00-secubox.yaml
firewall /etc/config/firewall (UCI) /etc/nftables.conf
wireguard /etc/wireguard/*.conf /etc/wireguard/*.conf
crowdsec /etc/crowdsec/* /etc/crowdsec/*
dhcp /etc/config/dhcp (UCI) /etc/dnsmasq.d/secubox.conf
haproxy /etc/haproxy/* /etc/haproxy/*
nginx /etc/nginx/* /etc/nginx/*
certs /etc/letsencrypt/* /etc/letsencrypt/*
content /srv/www/* /srv/www/*
vhosts /etc/config/vhost (UCI) /etc/secubox/vhosts/*.toml
users /etc/secubox/auth.toml /etc/secubox/auth.toml
state /var/lib/secubox/* /var/lib/secubox/*

Rollback

Pre-import snapshots are created automatically at /var/lib/secubox/rollback/pre-migration-TIMESTAMP/. To rollback:

# Restore from snapshot
cp -a /var/lib/secubox/rollback/pre-migration-20260429-143022/* /etc/

Environment Variables

Variable Description
SECUBOX_TARGET Cible SSH (user@host)
SECUBOX_PORT Port SSH (défaut: 22)

See Also


Author

Gerald KERMA devel@cybermind.fr