normes et nomenclature mnémotechnique
This commit is contained in:
parent
d3756d96e9
commit
e704e1cc39
8 changed files with 6246 additions and 0 deletions
310
docs/architecture/checklist_reunion.md
Normal file
310
docs/architecture/checklist_reunion.md
Normal file
|
|
@ -0,0 +1,310 @@
|
||||||
|
# CHECKLIST RÉUNION DE VALIDATION
|
||||||
|
## Standard de Nomenclature v2.0
|
||||||
|
### L'Alliance Boréale
|
||||||
|
|
||||||
|
**Réunion prévue le :** [À définir - Semaine du 11 novembre 2025]
|
||||||
|
**Durée estimée :** 2h30 (avec pause)
|
||||||
|
**Lieu :** Visioconférence Matrix + partage d'écran
|
||||||
|
**Participants requis :** Tous les membres du Cercle Technique
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 📋 PRÉPARATION (1-2 semaines avant)
|
||||||
|
|
||||||
|
### Documents à Distribuer
|
||||||
|
|
||||||
|
- [ ] **Standard de Nomenclature v2.0** (PDF + Markdown)
|
||||||
|
- Envoyé par email + lien forge
|
||||||
|
- Date limite de lecture : 7 jours avant réunion
|
||||||
|
|
||||||
|
- [ ] **Résolution d'Adoption** (cette résolution)
|
||||||
|
- Format : PDF signable
|
||||||
|
- À lire AVANT la réunion
|
||||||
|
|
||||||
|
- [ ] **Guide de Formation** (optionnel, pour référence)
|
||||||
|
- Lien vers la documentation
|
||||||
|
|
||||||
|
- [ ] **Scripts et Templates** (accès forge)
|
||||||
|
- Dépôt Git accessible à tous
|
||||||
|
- Instructions d'installation test
|
||||||
|
|
||||||
|
### Préparation Individuelle des Participants
|
||||||
|
|
||||||
|
**Chaque participant DOIT avant la réunion :**
|
||||||
|
|
||||||
|
- [ ] **Lire** le Standard complet (60 pages, ~2h)
|
||||||
|
- Prendre des notes
|
||||||
|
- Identifier questions/objections
|
||||||
|
|
||||||
|
- [ ] **Tester** les scripts sur un environnement de test
|
||||||
|
- Installer les scripts
|
||||||
|
- Lancer audit-nomenclature.sh
|
||||||
|
- Tester validation VMID
|
||||||
|
|
||||||
|
- [ ] **Évaluer** l'impact sur son infrastructure
|
||||||
|
- Estimer nombre de VMs à migrer
|
||||||
|
- Identifier les cas complexes
|
||||||
|
- Calculer la charge de travail
|
||||||
|
|
||||||
|
- [ ] **Préparer** ses questions/objections
|
||||||
|
- Format écrit préférable
|
||||||
|
- Soumission avant réunion (optionnel)
|
||||||
|
|
||||||
|
### Préparation du Facilitateur
|
||||||
|
|
||||||
|
- [ ] **Réserver** salle visio Matrix avec enregistrement
|
||||||
|
- [ ] **Préparer** la présentation (voir section suivante)
|
||||||
|
- [ ] **Compiler** les questions soumises à l'avance
|
||||||
|
- [ ] **Tester** le partage d'écran et démo live
|
||||||
|
- [ ] **Préparer** le template de procès-verbal
|
||||||
|
- [ ] **Imprimer** la résolution (si signatures physiques)
|
||||||
|
|
||||||
|
### Préparation Technique
|
||||||
|
|
||||||
|
- [ ] **Environnement de démo** opérationnel
|
||||||
|
- Proxmox de test accessible
|
||||||
|
- Scripts installés et fonctionnels
|
||||||
|
- Exemples de VMs conformes/non-conformes
|
||||||
|
|
||||||
|
- [ ] **Documents accessibles** pendant la réunion
|
||||||
|
- Standard (PDF + lien web)
|
||||||
|
- Résolution (version modifiable)
|
||||||
|
- Aide-mémoire (imprimable)
|
||||||
|
|
||||||
|
- [ ] **Outils collaboratifs** prêts
|
||||||
|
- Pad collaboratif (HedgeDoc/Etherpad)
|
||||||
|
- Partage d'écran
|
||||||
|
- Sondage pour vote de consentement
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 🎯 ORDRE DU JOUR DÉTAILLÉ
|
||||||
|
|
||||||
|
### INTRODUCTION (10 minutes)
|
||||||
|
|
||||||
|
- [ ] **Accueil** et vérification présences
|
||||||
|
- Tour de table rapide
|
||||||
|
- Vérifier quorum (tous les membres requis)
|
||||||
|
|
||||||
|
- [ ] **Rappel du contexte** (5 min)
|
||||||
|
- Pourquoi ce standard ?
|
||||||
|
- Historique du projet (août-octobre 2025)
|
||||||
|
- Objectifs de la réunion
|
||||||
|
|
||||||
|
- [ ] **Présentation de l'ordre du jour** (2 min)
|
||||||
|
- Timing détaillé
|
||||||
|
- Pause prévue
|
||||||
|
- Processus de décision (consentement)
|
||||||
|
|
||||||
|
- [ ] **Règles de la réunion** (3 min)
|
||||||
|
- Parler à tour de rôle (lever la main)
|
||||||
|
- Questions après chaque section
|
||||||
|
- Objections exprimées clairement
|
||||||
|
- Enregistrement (consentement oral)
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
### PARTIE 1 : PRÉSENTATION DU STANDARD (30 minutes)
|
||||||
|
|
||||||
|
#### A) Vue d'Ensemble (10 min)
|
||||||
|
|
||||||
|
- [ ] **Les 4 piliers** du standard
|
||||||
|
- VMID mnémotechnique
|
||||||
|
- Plan d'adressage IP
|
||||||
|
- Nomenclature VMs
|
||||||
|
- Nomenclature DNS
|
||||||
|
|
||||||
|
- [ ] **Architecture de référence**
|
||||||
|
- Espace 10.0.0.0/8 derrière NAT
|
||||||
|
- Infrastructure vs Tenants
|
||||||
|
- Couches 1-4 vs 5-8
|
||||||
|
|
||||||
|
- [ ] **Cohérence totale**
|
||||||
|
- VMID ↔ IP ↔ Nom ↔ DNS
|
||||||
|
- Démonstration visuelle
|
||||||
|
|
||||||
|
**Questions/Réponses** (5 min)
|
||||||
|
|
||||||
|
#### B) Spécifications Techniques (15 min)
|
||||||
|
|
||||||
|
- [ ] **Format VMID détaillé**
|
||||||
|
- Infrastructure : 0CTTII
|
||||||
|
- Tenant : TTTII
|
||||||
|
- Exemples concrets
|
||||||
|
- Validation avec validate-vmid.sh (DÉMO)
|
||||||
|
|
||||||
|
- [ ] **Plan d'adressage IP**
|
||||||
|
- Segmentation infrastructure (10.0.0-2.x)
|
||||||
|
- Allocation tenants (10.0.10.x + expansion)
|
||||||
|
- Cohérence avec VMID
|
||||||
|
|
||||||
|
- [ ] **Nomenclature complète**
|
||||||
|
- Noms VMs (infra et tenants)
|
||||||
|
- DNS interne/fédéré
|
||||||
|
- Tables de correspondance
|
||||||
|
|
||||||
|
**Questions/Réponses** (10 min)
|
||||||
|
|
||||||
|
#### C) Outillage (5 min)
|
||||||
|
|
||||||
|
- [ ] **6 scripts fournis**
|
||||||
|
- audit-nomenclature.sh (DÉMO rapide)
|
||||||
|
- migrate-vm.sh (montrer le workflow)
|
||||||
|
- Autres scripts (présentation rapide)
|
||||||
|
|
||||||
|
- [ ] **Templates Ansible/Terraform**
|
||||||
|
- Structure des modules
|
||||||
|
- Exemples d'utilisation
|
||||||
|
|
||||||
|
**Questions/Réponses** (5 min)
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
### PAUSE (10 minutes) ☕
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
### PARTIE 2 : IMPACTS ET MISE EN ŒUVRE (25 minutes)
|
||||||
|
|
||||||
|
#### A) Impact sur Chaque Membre (15 min)
|
||||||
|
|
||||||
|
**Tour de table - chaque membre présente :**
|
||||||
|
|
||||||
|
- [ ] **Chezlepro** (5 min)
|
||||||
|
- Nombre de VMs à migrer
|
||||||
|
- Cas complexes identifiés
|
||||||
|
- Charge de travail estimée
|
||||||
|
- Questions spécifiques
|
||||||
|
|
||||||
|
- [ ] **Nuage Libre** (5 min)
|
||||||
|
- Idem
|
||||||
|
|
||||||
|
- [ ] **TechnoLibre** (5 min)
|
||||||
|
- Idem
|
||||||
|
|
||||||
|
#### B) Plan de Migration (10 min)
|
||||||
|
|
||||||
|
- [ ] **Timeline proposée**
|
||||||
|
- Formation : 1er décembre 2025
|
||||||
|
- Nouveaux déploiements : 1er janvier 2026
|
||||||
|
- Migration complète : 31 décembre 2026
|
||||||
|
|
||||||
|
- [ ] **Ressources allouées**
|
||||||
|
- Formation (30h Banque de Temps)
|
||||||
|
- Support technique (20h)
|
||||||
|
- Budget (0 $ si possible)
|
||||||
|
|
||||||
|
- [ ] **Métriques de succès**
|
||||||
|
- Taux de conformité cible
|
||||||
|
- Indicateurs de suivi
|
||||||
|
|
||||||
|
**Questions/Réponses** (10 min)
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
### PARTIE 3 : DISCUSSION ET OBJECTIONS (30 minutes)
|
||||||
|
|
||||||
|
#### A) Questions Générales (10 min)
|
||||||
|
|
||||||
|
- [ ] **Clarifications techniques**
|
||||||
|
- Répondre aux questions restantes
|
||||||
|
- Démonstrations supplémentaires si nécessaire
|
||||||
|
|
||||||
|
- [ ] **Concerns opérationnels**
|
||||||
|
- Faisabilité
|
||||||
|
- Charge de travail
|
||||||
|
- Ressources
|
||||||
|
|
||||||
|
#### B) Identification des Objections (20 min)
|
||||||
|
|
||||||
|
**Process sociocratique :**
|
||||||
|
|
||||||
|
- [ ] **Tour de table** : Chaque membre exprime ses objections
|
||||||
|
- "Qu'est-ce qui rendrait l'adoption de ce standard **nuisible** ?"
|
||||||
|
- Prendre note de TOUTES les objections
|
||||||
|
|
||||||
|
- [ ] **Catégorisation** des objections
|
||||||
|
- Bloquantes (rendent l'adoption nuisible)
|
||||||
|
- Non-bloquantes (améliorations souhaitables)
|
||||||
|
|
||||||
|
- [ ] **Traitement des objections bloquantes**
|
||||||
|
- Discussion pour chaque objection
|
||||||
|
- Recherche de solutions
|
||||||
|
- Modification du standard si nécessaire
|
||||||
|
- Ré-évaluation après modification
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
### PARTIE 4 : DÉCISION PAR CONSENTEMENT (20 minutes)
|
||||||
|
|
||||||
|
#### A) Reformulation Finale (5 min)
|
||||||
|
|
||||||
|
- [ ] **Récapitulatif** des modifications apportées
|
||||||
|
- [ ] **Version finale** du standard à adopter
|
||||||
|
- [ ] **Lecture de la résolution** d'adoption
|
||||||
|
|
||||||
|
#### B) Tour de Consentement (10 min)
|
||||||
|
|
||||||
|
**Pour chaque membre, poser la question :**
|
||||||
|
|
||||||
|
> "As-tu une objection raisonnable et argumentée qui rendrait l'adoption de ce standard **nuisible** pour L'Alliance ou pour ton organisation ?"
|
||||||
|
|
||||||
|
- [ ] **Chezlepro** : Consentement ? ☐ Oui ☐ Objection
|
||||||
|
- Si objection : __________________________________________
|
||||||
|
|
||||||
|
- [ ] **Nuage Libre** : Consentement ? ☐ Oui ☐ Objection
|
||||||
|
- Si objection : __________________________________________
|
||||||
|
|
||||||
|
- [ ] **TechnoLibre** : Consentement ? ☐ Oui ☐ Objection
|
||||||
|
- Si objection : __________________________________________
|
||||||
|
|
||||||
|
#### C) Formalisation (5 min)
|
||||||
|
|
||||||
|
**Si consentement de tous :**
|
||||||
|
|
||||||
|
- [ ] **Déclaration officielle** : "Le Standard de Nomenclature v2.0 est adopté"
|
||||||
|
- [ ] **Date d'adoption** : _________________________
|
||||||
|
- [ ] **Signatures** (électroniques ou physiques)
|
||||||
|
- [ ] **Annonce** : Publication sur Matrix/Forum
|
||||||
|
|
||||||
|
**Si objection bloquante non résolue :**
|
||||||
|
|
||||||
|
- [ ] Reporter la décision
|
||||||
|
- [ ] Planifier séance de travail supplémentaire
|
||||||
|
- [ ] Nouvelle réunion de validation (date : _________)
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
### PARTIE 5 : PROCHAINES ÉTAPES (10 minutes)
|
||||||
|
|
||||||
|
**Si adoption réussie :**
|
||||||
|
|
||||||
|
- [ ] **Publication officielle**
|
||||||
|
- Forge Git (tag v2.0)
|
||||||
|
- Wiki Alliance Boréale
|
||||||
|
- Annonce Matrix/Forum
|
||||||
|
|
||||||
|
- [ ] **Désignation responsabilités**
|
||||||
|
- Gardien du standard : __________________________
|
||||||
|
- Responsable formation : __________________________
|
||||||
|
- Support technique : __________________________
|
||||||
|
|
||||||
|
- [ ] **Planification formation**
|
||||||
|
- Dates des sessions
|
||||||
|
- Inscription des administrateurs
|
||||||
|
|
||||||
|
- [ ] **Premiers audits**
|
||||||
|
- Chaque membre lance audit initial
|
||||||
|
- Date limite : __________________________
|
||||||
|
|
||||||
|
- [ ] **Suivi**
|
||||||
|
- Réunion de suivi 1 mois après (décembre 2025)
|
||||||
|
- Rapport mensuel de conformité
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
### CLÔTURE (5 minutes)
|
||||||
|
|
||||||
|
- [ ] **Récapitulatif** de la décision
|
||||||
|
- [ ] **Remerciements** aux participants
|
||||||
|
- [ ] **Prochaine
|
||||||
979
docs/architecture/guide_formation.md
Normal file
979
docs/architecture/guide_formation.md
Normal file
|
|
@ -0,0 +1,979 @@
|
||||||
|
# Guide de Formation - Nomenclature v2.0
|
||||||
|
## L'Alliance Boréale
|
||||||
|
|
||||||
|
**Version :** 1.0
|
||||||
|
**Date :** 21 octobre 2025
|
||||||
|
**Durée :** 2-3 heures (formation complète)
|
||||||
|
**Public :** Administrateurs systèmes membres de L'Alliance
|
||||||
|
**Prérequis :** Connaissance Proxmox, bases Linux
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Table des Matières
|
||||||
|
|
||||||
|
1. [Introduction et Contexte](#1-introduction-et-contexte)
|
||||||
|
2. [Module 1 : Comprendre le Standard](#2-module-1-comprendre-le-standard)
|
||||||
|
3. [Module 2 : VMID Mnémotechnique](#3-module-2-vmid-mnémotechnique)
|
||||||
|
4. [Module 3 : Plan d'Adressage IP](#4-module-3-plan-dadressage-ip)
|
||||||
|
5. [Module 4 : Nomenclature VMs et DNS](#5-module-4-nomenclature-vms-et-dns)
|
||||||
|
6. [Module 5 : Outils Pratiques](#6-module-5-outils-pratiques)
|
||||||
|
7. [Module 6 : Migration en Pratique](#7-module-6-migration-en-pratique)
|
||||||
|
8. [Exercices Pratiques](#8-exercices-pratiques)
|
||||||
|
9. [Aide-Mémoire](#9-aide-mémoire)
|
||||||
|
10. [Certification](#10-certification)
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 1. Introduction et Contexte
|
||||||
|
|
||||||
|
### 1.1 Pourquoi un Standard de Nomenclature ?
|
||||||
|
|
||||||
|
**Problèmes avant le standard :**
|
||||||
|
- ❌ VMs nommées de façon incohérente (vm1, web-server, test123...)
|
||||||
|
- ❌ VMIDs attribués au hasard (104, 1523, 999...)
|
||||||
|
- ❌ IPs non structurées (10.50.100.5, 192.168.1.20...)
|
||||||
|
- ❌ Impossible de retrouver une ressource rapidement
|
||||||
|
- ❌ Automatisation difficile (Ansible ne peut pas cibler par pattern)
|
||||||
|
- ❌ Audit et conformité complexes
|
||||||
|
|
||||||
|
**Bénéfices du standard v2.0 :**
|
||||||
|
- ✅ Identification immédiate de toute ressource
|
||||||
|
- ✅ VMID → IP → Nom → DNS (cohérence totale)
|
||||||
|
- ✅ Automatisation facilitée (scripts, Ansible, Terraform)
|
||||||
|
- ✅ Onboarding rapide des nouveaux admins
|
||||||
|
- ✅ Audit simplifié pour labellisation
|
||||||
|
- ✅ Scalabilité (999 tenants, 99 instances par type)
|
||||||
|
|
||||||
|
### 1.2 Architecture de L'Alliance
|
||||||
|
|
||||||
|
**Rappel : Chaque membre est autonome**
|
||||||
|
```
|
||||||
|
┌─────────────────────────────────────────┐
|
||||||
|
│ INTERNET PUBLIC │
|
||||||
|
└───────────┬─────────────────────────────┘
|
||||||
|
│
|
||||||
|
┌───────┼───────┐
|
||||||
|
│ │ │
|
||||||
|
┌───▼───┐ ┌─▼───┐ ┌─▼───┐
|
||||||
|
│ CZP │ │ NUL │ │ TLI │ ← Chaque membre
|
||||||
|
│ NAT │ │ NAT │ │ NAT │ derrière NAT
|
||||||
|
└───┬───┘ └──┬──┘ └──┬──┘
|
||||||
|
│ │ │
|
||||||
|
│ 10.0.0.0/8 (local, identique partout)
|
||||||
|
│ = Pas de conflit car isolé
|
||||||
|
│
|
||||||
|
└────────┴───────┴──────→ 172.16.0.0/12
|
||||||
|
(fédération via tunnels)
|
||||||
|
```
|
||||||
|
|
||||||
|
**Point clé :** Tous les membres utilisent **10.0.0.0/8** localement sans conflit.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 2. Module 1 : Comprendre le Standard
|
||||||
|
|
||||||
|
### 2.1 Les 4 Piliers de la Nomenclature
|
||||||
|
|
||||||
|
```
|
||||||
|
┌─────────┐ ┌─────────┐ ┌─────────┐ ┌─────────┐
|
||||||
|
│ VMID │ ←→ │ IP │ ←→ │ Nom VM │ ←→ │ DNS │
|
||||||
|
│ 02001 │ │10.0.2.10│ │czp-infra│ │dns.infra│
|
||||||
|
│ │ │ │ │-dns-... │ │.czp.ab │
|
||||||
|
└─────────┘ └─────────┘ └─────────┘ └─────────┘
|
||||||
|
```
|
||||||
|
|
||||||
|
**Tous ces éléments sont liés !**
|
||||||
|
|
||||||
|
### 2.2 Les Deux Catégories de VMs
|
||||||
|
|
||||||
|
#### **A) Infrastructure Fédéré (Couches 1-4)**
|
||||||
|
Services propres au membre :
|
||||||
|
- **Couche 1** : Monitoring matériel
|
||||||
|
- **Couche 2** : DNS, VPN, Réseau
|
||||||
|
- **Couche 3** : Stockage (Ceph, NFS, Backups)
|
||||||
|
- **Couche 4** : Orchestration (Ansible, Git, CI/CD)
|
||||||
|
|
||||||
|
#### **B) Tenants (Couches 5-8)**
|
||||||
|
VMs des clients hébergés :
|
||||||
|
- Chaque client = 1 tenant
|
||||||
|
- Tenant 001, 002, 003...
|
||||||
|
- Services web, DB, API, workers...
|
||||||
|
|
||||||
|
### 2.3 Vue d'Ensemble du Plan
|
||||||
|
|
||||||
|
```
|
||||||
|
10.0.0.0/8 (Espace Interne Membre)
|
||||||
|
│
|
||||||
|
├── 10.0.0.0/24 Management
|
||||||
|
├── 10.0.1.0/24 Platform Services
|
||||||
|
├── 10.0.2.0/24 Public DNS
|
||||||
|
├── 10.0.20.0/22 Reserved Infrastructure
|
||||||
|
│
|
||||||
|
├── 10.0.10.0/23 Tenant Infrastructure
|
||||||
|
└── 10.0.128.0/17 Expansion (50% du /8)
|
||||||
|
```
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 3. Module 2 : VMID Mnémotechnique
|
||||||
|
|
||||||
|
### 3.1 Format Infrastructure : `0CTTII`
|
||||||
|
|
||||||
|
```
|
||||||
|
0 = Infrastructure (fixe)
|
||||||
|
C = Couche (1, 2, 3, ou 4)
|
||||||
|
TT = Type de service (00-99)
|
||||||
|
II = Instance (01-99)
|
||||||
|
```
|
||||||
|
|
||||||
|
**Exemples :**
|
||||||
|
```
|
||||||
|
02001 = 0-2-00-01
|
||||||
|
│ │ │ └── Instance 1
|
||||||
|
│ │ └───── DNS (type 00)
|
||||||
|
│ └──────── Couche 2 (Réseau)
|
||||||
|
└────────── Infrastructure
|
||||||
|
|
||||||
|
04201 = 0-4-20-01
|
||||||
|
│ │ │ └── Instance 1
|
||||||
|
│ │ └───── Git (type 20)
|
||||||
|
│ └──────── Couche 4 (Orchestration)
|
||||||
|
└────────── Infrastructure
|
||||||
|
```
|
||||||
|
|
||||||
|
### 3.2 Format Tenant : `TTTII`
|
||||||
|
|
||||||
|
```
|
||||||
|
TTT = Tenant ID (001-999)
|
||||||
|
II = Instance (01-99)
|
||||||
|
```
|
||||||
|
|
||||||
|
**Exemples :**
|
||||||
|
```
|
||||||
|
10001 = 100-01
|
||||||
|
│ └── Instance 1
|
||||||
|
└────── Tenant 001
|
||||||
|
|
||||||
|
10021 = 100-21
|
||||||
|
│ └── Instance 21 (convention: DB)
|
||||||
|
└────── Tenant 001
|
||||||
|
|
||||||
|
20001 = 200-01
|
||||||
|
│ └── Instance 1
|
||||||
|
└────── Tenant 002
|
||||||
|
```
|
||||||
|
|
||||||
|
### 3.3 Table de Référence Rapide
|
||||||
|
|
||||||
|
| Type | VMID | Décodage | Description |
|
||||||
|
|------|------|----------|-------------|
|
||||||
|
| Infra | 02001 | Couche 2, DNS, Instance 1 | PowerDNS Master |
|
||||||
|
| Infra | 02002 | Couche 2, DNS, Instance 2 | PowerDNS Slave 1 |
|
||||||
|
| Infra | 02101 | Couche 2, VPN, Instance 1 | WireGuard Gateway |
|
||||||
|
| Infra | 04001 | Couche 4, Ansible, Instance 1 | Ansible Controller |
|
||||||
|
| Tenant | 10001 | Tenant 001, Instance 1 | Web Frontend |
|
||||||
|
| Tenant | 10021 | Tenant 001, Instance 21 | Database |
|
||||||
|
| Tenant | 20001 | Tenant 002, Instance 1 | Web Frontend |
|
||||||
|
|
||||||
|
### 3.4 Exercice 1 : Décodage VMID
|
||||||
|
|
||||||
|
**Décoder ces VMIDs :**
|
||||||
|
1. 03301 → ?
|
||||||
|
2. 04201 → ?
|
||||||
|
3. 30011 → ?
|
||||||
|
|
||||||
|
<details>
|
||||||
|
<summary>Voir les réponses</summary>
|
||||||
|
|
||||||
|
1. **03301** = Infrastructure, Couche 3 (Stockage), Type 30 (Backup), Instance 1 → Proxmox Backup Server
|
||||||
|
2. **04201** = Infrastructure, Couche 4 (Orchestration), Type 20 (Git), Instance 1 → Forgejo
|
||||||
|
3. **30011** = Tenant 003, Instance 11 → Backend API tenant 003
|
||||||
|
|
||||||
|
</details>
|
||||||
|
|
||||||
|
### 3.5 Exercice 2 : Choix VMID
|
||||||
|
|
||||||
|
**Quel VMID pour :**
|
||||||
|
1. Un nouveau DNS Slave (3ème) ?
|
||||||
|
2. La 1ère VM web du tenant 005 ?
|
||||||
|
3. Un nouveau CI/CD runner (2ème) ?
|
||||||
|
|
||||||
|
<details>
|
||||||
|
<summary>Voir les réponses</summary>
|
||||||
|
|
||||||
|
1. **02003** (Couche 2, DNS type 00, Instance 3)
|
||||||
|
2. **50001** (Tenant 005, Instance 01)
|
||||||
|
3. **04102** (Couche 4, CI type 10, Instance 2)
|
||||||
|
|
||||||
|
</details>
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 4. Module 3 : Plan d'Adressage IP
|
||||||
|
|
||||||
|
### 4.1 Segmentation Infrastructure
|
||||||
|
|
||||||
|
```
|
||||||
|
10.0.0.0/24 → Management
|
||||||
|
.1 → Gateway
|
||||||
|
.10-.50 → Hyperviseurs Proxmox
|
||||||
|
.100-.200 → Monitoring
|
||||||
|
|
||||||
|
10.0.1.0/24 → Platform Services
|
||||||
|
.10 → Ansible (04001)
|
||||||
|
.20 → Git (04201)
|
||||||
|
.30 → DB Platform (04301)
|
||||||
|
.40 → API Admin (04401)
|
||||||
|
|
||||||
|
10.0.2.0/24 → Public DNS
|
||||||
|
.10 → DNS Master (02001)
|
||||||
|
.11 → DNS Slave 1 (02002)
|
||||||
|
.12 → DNS Slave 2 (02003)
|
||||||
|
.20 → VPN Gateway (02101)
|
||||||
|
```
|
||||||
|
|
||||||
|
### 4.2 Allocation Tenants
|
||||||
|
|
||||||
|
**Stratégie simple :**
|
||||||
|
```
|
||||||
|
10.0.10.0-99 → Tenant 001
|
||||||
|
10.0.10.100-199 → Tenant 002
|
||||||
|
10.0.11.0-99 → Tenant 003
|
||||||
|
...
|
||||||
|
```
|
||||||
|
|
||||||
|
**Ou avec IPAM automatique** (script allocate-ip.sh)
|
||||||
|
|
||||||
|
### 4.3 Exercice 3 : Allocation IP
|
||||||
|
|
||||||
|
**Quelle IP pour :**
|
||||||
|
1. Un nouveau PowerDNS Slave 3 ?
|
||||||
|
2. La 2ème VM web du tenant 001 ?
|
||||||
|
3. Un 2ème Ansible Controller ?
|
||||||
|
|
||||||
|
<details>
|
||||||
|
<summary>Voir les réponses</summary>
|
||||||
|
|
||||||
|
1. **10.0.2.12** (Segmentation DNS : 10.0.2.0/24)
|
||||||
|
2. **10.0.10.2** (Tenant 001 : 10.0.10.0-99)
|
||||||
|
3. **10.0.1.11** (Platform Services : 10.0.1.0/24)
|
||||||
|
|
||||||
|
</details>
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 5. Module 4 : Nomenclature VMs et DNS
|
||||||
|
|
||||||
|
### 5.1 Format Nom VM Infrastructure
|
||||||
|
|
||||||
|
```
|
||||||
|
<membre>-infra-<type>-<env>-<instance>
|
||||||
|
|
||||||
|
Exemples:
|
||||||
|
czp-infra-dns-master-prod-01
|
||||||
|
czp-infra-vpn-gateway-prod-01
|
||||||
|
czp-infra-ansible-ctrl-prod-01
|
||||||
|
nul-infra-git-forgejo-prod-01
|
||||||
|
```
|
||||||
|
|
||||||
|
### 5.2 Format Nom VM Tenant
|
||||||
|
|
||||||
|
```
|
||||||
|
<membre>-t<tenant-id>-<type>-<env>-<instance>
|
||||||
|
|
||||||
|
Exemples:
|
||||||
|
czp-t001-web-prod-01
|
||||||
|
czp-t001-db-postgres-prod-01
|
||||||
|
czp-t002-api-fastapi-prod-01
|
||||||
|
```
|
||||||
|
|
||||||
|
### 5.3 Format DNS
|
||||||
|
|
||||||
|
**Infrastructure :**
|
||||||
|
```
|
||||||
|
<service>.infra.<membre>.alliance-boreale.ca
|
||||||
|
|
||||||
|
Exemples:
|
||||||
|
dns-master.infra.czp.alliance-boreale.ca
|
||||||
|
ansible.infra.czp.alliance-boreale.ca
|
||||||
|
```
|
||||||
|
|
||||||
|
**Tenant :**
|
||||||
|
```
|
||||||
|
<service>.t<tenant-id>.<membre>.alliance-boreale.ca
|
||||||
|
|
||||||
|
Exemples:
|
||||||
|
web.t001.czp.alliance-boreale.ca
|
||||||
|
db.t001.czp.alliance-boreale.ca
|
||||||
|
```
|
||||||
|
|
||||||
|
### 5.4 Exercice 4 : Construction Complète
|
||||||
|
|
||||||
|
**Pour un nouveau DNS Slave 3 chez Chezlepro :**
|
||||||
|
- VMID : ?
|
||||||
|
- IP : ?
|
||||||
|
- Nom VM : ?
|
||||||
|
- DNS : ?
|
||||||
|
|
||||||
|
<details>
|
||||||
|
<summary>Voir les réponses</summary>
|
||||||
|
|
||||||
|
- **VMID :** 02003
|
||||||
|
- **IP :** 10.0.2.12
|
||||||
|
- **Nom VM :** czp-infra-dns-slave3-prod-01
|
||||||
|
- **DNS :** dns-slave3.infra.czp.alliance-boreale.ca
|
||||||
|
|
||||||
|
</details>
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 6. Module 5 : Outils Pratiques
|
||||||
|
|
||||||
|
### 6.1 Installation
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# Télécharger les scripts
|
||||||
|
cd /tmp
|
||||||
|
wget https://forge.alliance-boreale.ca/tools/scripts-nomenclature-v2.tar.gz
|
||||||
|
tar xzf scripts-nomenclature-v2.tar.gz
|
||||||
|
|
||||||
|
# Installer
|
||||||
|
sudo bash install-nomenclature-tools.sh
|
||||||
|
```
|
||||||
|
|
||||||
|
### 6.2 Configuration
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# Éditer la configuration
|
||||||
|
sudo nano /etc/alliance-boreale/nomenclature.conf
|
||||||
|
|
||||||
|
# Contenu:
|
||||||
|
MEMBER_ID="czp"
|
||||||
|
DNS_DOMAIN="alliance-boreale.ca"
|
||||||
|
```
|
||||||
|
|
||||||
|
### 6.3 Utilisation des Scripts
|
||||||
|
|
||||||
|
#### **1. Audit de Conformité**
|
||||||
|
```bash
|
||||||
|
# Audit complet
|
||||||
|
audit-nomenclature.sh
|
||||||
|
|
||||||
|
# Résultat attendu
|
||||||
|
✅ CONFORME | VMID: 02001 | Nom: czp-infra-dns-master-prod-01
|
||||||
|
❌ NON CONFORME | VMID: 104 | Nom: old-vm
|
||||||
|
```
|
||||||
|
|
||||||
|
#### **2. Génération DNS**
|
||||||
|
```bash
|
||||||
|
# Générer zone file
|
||||||
|
generate-dns-records.sh > dns-records.zone
|
||||||
|
|
||||||
|
# Aperçu
|
||||||
|
dns-master.infra.czp.alliance-boreale.ca. IN A 10.0.2.10
|
||||||
|
```
|
||||||
|
|
||||||
|
#### **3. Validation VMID**
|
||||||
|
```bash
|
||||||
|
# Valider un VMID
|
||||||
|
validate-vmid.sh 02001
|
||||||
|
|
||||||
|
# Résultat
|
||||||
|
✅ VMID VALIDE
|
||||||
|
Type: Infrastructure
|
||||||
|
Couche: 2
|
||||||
|
```
|
||||||
|
|
||||||
|
#### **4. Migration VM**
|
||||||
|
```bash
|
||||||
|
# Simulation
|
||||||
|
DRY_RUN=true migrate-vm.sh 104 10001 czp-t001-web-prod-01 10.0.10.1
|
||||||
|
|
||||||
|
# Migration réelle
|
||||||
|
migrate-vm.sh 104 10001 czp-t001-web-prod-01 10.0.10.1
|
||||||
|
```
|
||||||
|
|
||||||
|
### 6.4 Exercice 5 : Utilisation des Scripts
|
||||||
|
|
||||||
|
**Tâches à réaliser :**
|
||||||
|
1. Installer les scripts sur votre Proxmox
|
||||||
|
2. Exécuter un audit de conformité
|
||||||
|
3. Valider le VMID 02001
|
||||||
|
4. Générer les enregistrements DNS
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 7. Module 6 : Migration en Pratique
|
||||||
|
|
||||||
|
### 7.1 Workflow de Migration Complet
|
||||||
|
|
||||||
|
```
|
||||||
|
┌─────────────────┐
|
||||||
|
│ 1. AUDIT │ → Identifier VMs non conformes
|
||||||
|
└────────┬────────┘
|
||||||
|
│
|
||||||
|
┌────────▼────────┐
|
||||||
|
│ 2. PLANIFICATION│ → Déterminer nouveaux VMID/IP/noms
|
||||||
|
└────────┬────────┘
|
||||||
|
│
|
||||||
|
┌────────▼────────┐
|
||||||
|
│ 3. BACKUP │ → Sauvegarder toutes les VMs
|
||||||
|
└────────┬────────┘
|
||||||
|
│
|
||||||
|
┌────────▼────────┐
|
||||||
|
│ 4. MIGRATION │ → Migrer par lots (5-10 VMs)
|
||||||
|
└────────┬────────┘
|
||||||
|
│
|
||||||
|
┌────────▼────────┐
|
||||||
|
│ 5. VALIDATION │ → Vérifier conformité
|
||||||
|
└────────┬────────┘
|
||||||
|
│
|
||||||
|
┌────────▼────────┐
|
||||||
|
│ 6. DOCUMENTATION│ → Mettre à jour DNS/Inventaire
|
||||||
|
└────────┬────────┘
|
||||||
|
│
|
||||||
|
┌────────▼────────┐
|
||||||
|
│ 7. NETTOYAGE │ → Supprimer anciennes VMs
|
||||||
|
└─────────────────┘
|
||||||
|
```
|
||||||
|
|
||||||
|
### 7.2 Exemple de Migration Pas-à-Pas
|
||||||
|
|
||||||
|
**Scénario :** Migrer une vieille VM web (VMID 104) vers le standard
|
||||||
|
|
||||||
|
#### **Étape 1 : État Actuel**
|
||||||
|
```bash
|
||||||
|
# Informations actuelles
|
||||||
|
VMID: 104
|
||||||
|
Nom: old-vm-web
|
||||||
|
IP: 10.50.100.5
|
||||||
|
```
|
||||||
|
|
||||||
|
#### **Étape 2 : Déterminer Nouveaux Attributs**
|
||||||
|
```bash
|
||||||
|
# Cette VM est le web du tenant 001
|
||||||
|
# Nouveaux attributs:
|
||||||
|
VMID: 10001 (Tenant 001, Instance 01)
|
||||||
|
IP: 10.0.10.1 (Première IP tenant 001)
|
||||||
|
Nom: czp-t001-web-prod-01
|
||||||
|
DNS: web.t001.czp.alliance-boreale.ca
|
||||||
|
```
|
||||||
|
|
||||||
|
#### **Étape 3 : Validation**
|
||||||
|
```bash
|
||||||
|
# Vérifier VMID
|
||||||
|
validate-vmid.sh 10001
|
||||||
|
# ✅ VMID VALIDE
|
||||||
|
|
||||||
|
# Vérifier IP disponible
|
||||||
|
allocate-ip.sh 001
|
||||||
|
# ✅ IP DISPONIBLE: 10.0.10.1
|
||||||
|
```
|
||||||
|
|
||||||
|
#### **Étape 4 : Backup**
|
||||||
|
```bash
|
||||||
|
# Créer snapshot
|
||||||
|
vzdump 104 --mode snapshot --compress zstd
|
||||||
|
```
|
||||||
|
|
||||||
|
#### **Étape 5 : Migration Simulation**
|
||||||
|
```bash
|
||||||
|
# Test en dry-run
|
||||||
|
DRY_RUN=true migrate-vm.sh 104 10001 \
|
||||||
|
czp-t001-web-prod-01 10.0.10.1
|
||||||
|
|
||||||
|
# Vérifier la sortie
|
||||||
|
```
|
||||||
|
|
||||||
|
#### **Étape 6 : Migration Réelle**
|
||||||
|
```bash
|
||||||
|
# Exécuter migration
|
||||||
|
migrate-vm.sh 104 10001 czp-t001-web-prod-01 10.0.10.1
|
||||||
|
|
||||||
|
# Le script fait:
|
||||||
|
# 1. Backup
|
||||||
|
# 2. Arrêt VM
|
||||||
|
# 3. Clone vers nouveau VMID
|
||||||
|
# 4. Config nouvelle IP
|
||||||
|
# 5. Démarrage
|
||||||
|
```
|
||||||
|
|
||||||
|
#### **Étape 7 : Post-Migration**
|
||||||
|
```bash
|
||||||
|
# 1. Se connecter à la VM
|
||||||
|
ssh root@10.0.10.1
|
||||||
|
|
||||||
|
# 2. Vérifier et ajuster l'IP dans la VM
|
||||||
|
nano /etc/network/interfaces
|
||||||
|
# Changer vers 10.0.10.1/24
|
||||||
|
|
||||||
|
# 3. Redémarrer réseau
|
||||||
|
systemctl restart networking
|
||||||
|
|
||||||
|
# 4. Tester connectivité
|
||||||
|
ping 10.0.0.1
|
||||||
|
```
|
||||||
|
|
||||||
|
#### **Étape 8 : DNS et Inventaire**
|
||||||
|
```bash
|
||||||
|
# Ajouter DNS
|
||||||
|
echo "web.t001.czp.alliance-boreale.ca. IN A 10.0.10.1" >> /etc/bind/zones/...
|
||||||
|
|
||||||
|
# Régénérer inventaire
|
||||||
|
generate-inventory.sh
|
||||||
|
|
||||||
|
# Tester avec Ansible
|
||||||
|
ansible web.t001.czp.alliance-boreale.ca -m ping
|
||||||
|
```
|
||||||
|
|
||||||
|
#### **Étape 9 : Validation Finale**
|
||||||
|
```bash
|
||||||
|
# Audit
|
||||||
|
audit-nomenclature.sh | grep 10001
|
||||||
|
# ✅ CONFORME | VMID: 10001
|
||||||
|
|
||||||
|
# Une fois validé (quelques jours), supprimer ancienne VM
|
||||||
|
qm destroy 104
|
||||||
|
```
|
||||||
|
|
||||||
|
### 7.3 Checklist de Migration
|
||||||
|
|
||||||
|
```
|
||||||
|
AVANT:
|
||||||
|
□ Backup complet créé
|
||||||
|
□ Fenêtre de maintenance planifiée
|
||||||
|
□ Nouveaux attributs validés (VMID, IP, nom)
|
||||||
|
□ Plan de rollback documenté
|
||||||
|
□ Équipe informée
|
||||||
|
|
||||||
|
PENDANT:
|
||||||
|
□ Migration exécutée (script)
|
||||||
|
□ VM démarre correctement
|
||||||
|
□ IP configurée dans la VM
|
||||||
|
□ Connectivité réseau OK
|
||||||
|
□ Services applicatifs fonctionnels
|
||||||
|
|
||||||
|
APRÈS:
|
||||||
|
□ DNS créé
|
||||||
|
□ Inventaire Ansible mis à jour
|
||||||
|
□ Monitoring configuré
|
||||||
|
□ Documentation à jour
|
||||||
|
□ Tests de régression OK
|
||||||
|
□ Ancienne VM supprimée (après validation)
|
||||||
|
```
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 8. Exercices Pratiques
|
||||||
|
|
||||||
|
### Exercice 6 : Planification Migration
|
||||||
|
|
||||||
|
**Vous avez ces VMs à migrer :**
|
||||||
|
|
||||||
|
| VMID | Nom Actuel | IP Actuelle | Type |
|
||||||
|
|------|------------|-------------|------|
|
||||||
|
| 100 | dns-server | 192.168.1.10 | DNS Master |
|
||||||
|
| 105 | web1 | 10.20.30.5 | Web Tenant A |
|
||||||
|
| 106 | db1 | 10.20.30.6 | DB Tenant A |
|
||||||
|
| 200 | ansible | 10.10.10.5 | Ansible |
|
||||||
|
|
||||||
|
**Complétez le plan de migration :**
|
||||||
|
|
||||||
|
| VMID Actuel | Nouveau VMID | Nouveau Nom | Nouvelle IP |
|
||||||
|
|-------------|--------------|-------------|-------------|
|
||||||
|
| 100 | ? | ? | ? |
|
||||||
|
| 105 | ? | ? | ? |
|
||||||
|
| 106 | ? | ? | ? |
|
||||||
|
| 200 | ? | ? | ? |
|
||||||
|
|
||||||
|
<details>
|
||||||
|
<summary>Voir les réponses</summary>
|
||||||
|
|
||||||
|
| VMID Actuel | Nouveau VMID | Nouveau Nom | Nouvelle IP |
|
||||||
|
|-------------|--------------|-------------|-------------|
|
||||||
|
| 100 | 02001 | czp-infra-dns-master-prod-01 | 10.0.2.10 |
|
||||||
|
| 105 | 10001 | czp-t001-web-prod-01 | 10.0.10.1 |
|
||||||
|
| 106 | 10021 | czp-t001-db-postgres-prod-01 | 10.0.10.2 |
|
||||||
|
| 200 | 04001 | czp-infra-ansible-ctrl-prod-01 | 10.0.1.10 |
|
||||||
|
|
||||||
|
</details>
|
||||||
|
|
||||||
|
### Exercice 7 : Création Nouvelle Infrastructure
|
||||||
|
|
||||||
|
**Votre membre rejoint L'Alliance. Créez l'infrastructure minimale (Bronze) :**
|
||||||
|
|
||||||
|
**Ressources nécessaires :**
|
||||||
|
- 1 DNS Master
|
||||||
|
- 1 Ansible Controller
|
||||||
|
- 1 Backup Server
|
||||||
|
|
||||||
|
**Complétez :**
|
||||||
|
|
||||||
|
| Service | VMID | Nom VM | IP | DNS |
|
||||||
|
|---------|------|--------|-----|-----|
|
||||||
|
| DNS Master | ? | ? | ? | ? |
|
||||||
|
| Ansible | ? | ? | ? | ? |
|
||||||
|
| Backup | ? | ? | ? | ? |
|
||||||
|
|
||||||
|
<details>
|
||||||
|
<summary>Voir les réponses (exemple membre NUL)</summary>
|
||||||
|
|
||||||
|
| Service | VMID | Nom VM | IP | DNS |
|
||||||
|
|---------|------|--------|-----|-----|
|
||||||
|
| DNS Master | 02001 | nul-infra-dns-master-prod-01 | 10.0.2.10 | dns-master.infra.nul.ab.ca |
|
||||||
|
| Ansible | 04001 | nul-infra-ansible-ctrl-prod-01 | 10.0.1.10 | ansible.infra.nul.ab.ca |
|
||||||
|
| Backup | 03301 | nul-infra-pbs-backup-prod-01 | 10.0.1.30 | backup.infra.nul.ab.ca |
|
||||||
|
|
||||||
|
</details>
|
||||||
|
|
||||||
|
### Exercice 8 : Déploiement Nouveau Tenant
|
||||||
|
|
||||||
|
**Un nouveau client (Tenant 005) vous demande :**
|
||||||
|
- 2 VMs web (load balancing)
|
||||||
|
- 1 API backend
|
||||||
|
- 1 Database PostgreSQL
|
||||||
|
- 1 Redis cache
|
||||||
|
|
||||||
|
**Complétez le plan de déploiement :**
|
||||||
|
|
||||||
|
| Service | VMID | Nom VM | IP |
|
||||||
|
|---------|------|--------|----|
|
||||||
|
| Web 1 | ? | ? | ? |
|
||||||
|
| Web 2 | ? | ? | ? |
|
||||||
|
| API | ? | ? | ? |
|
||||||
|
| DB | ? | ? | ? |
|
||||||
|
| Redis | ? | ? | ? |
|
||||||
|
|
||||||
|
<details>
|
||||||
|
<summary>Voir les réponses</summary>
|
||||||
|
|
||||||
|
| Service | VMID | Nom VM | IP |
|
||||||
|
|---------|------|--------|----|
|
||||||
|
| Web 1 | 50001 | czp-t005-web-prod-01 | 10.0.10.40 |
|
||||||
|
| Web 2 | 50002 | czp-t005-web-prod-02 | 10.0.10.41 |
|
||||||
|
| API | 50011 | czp-t005-api-fastapi-prod-01 | 10.0.10.42 |
|
||||||
|
| DB | 50021 | czp-t005-db-postgres-prod-01 | 10.0.10.43 |
|
||||||
|
| Redis | 50031 | czp-t005-cache-redis-prod-01 | 10.0.10.44 |
|
||||||
|
|
||||||
|
**Note :** Convention instance :
|
||||||
|
- 01-09 : Web/Frontend
|
||||||
|
- 10-19 : Backend/API
|
||||||
|
- 20-29 : Databases
|
||||||
|
- 30-39 : Cache/Queue
|
||||||
|
|
||||||
|
</details>
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 9. Aide-Mémoire
|
||||||
|
|
||||||
|
### 9.1 Carte de Référence Rapide
|
||||||
|
|
||||||
|
**À imprimer et garder près de votre écran !**
|
||||||
|
|
||||||
|
```
|
||||||
|
╔════════════════════════════════════════════════════════╗
|
||||||
|
║ NOMENCLATURE v2.0 - AIDE-MÉMOIRE RAPIDE ║
|
||||||
|
╠════════════════════════════════════════════════════════╣
|
||||||
|
║ ║
|
||||||
|
║ FORMAT VMID INFRASTRUCTURE: 0CTTII ║
|
||||||
|
║ 0 = Infrastructure ║
|
||||||
|
║ C = Couche (1-4) ║
|
||||||
|
║ TT = Type (00-99) ║
|
||||||
|
║ II = Instance (01-99) ║
|
||||||
|
║ ║
|
||||||
|
║ FORMAT VMID TENANT: TTTII ║
|
||||||
|
║ TTT = Tenant ID (001-999) ║
|
||||||
|
║ II = Instance (01-99) ║
|
||||||
|
║ ║
|
||||||
|
║ PLAN IP INFRASTRUCTURE: ║
|
||||||
|
║ 10.0.0.0/24 → Management ║
|
||||||
|
║ 10.0.1.0/24 → Platform Services ║
|
||||||
|
║ 10.0.2.0/24 → Public DNS ║
|
||||||
|
║ 10.0.20.0/22 → Reserved ║
|
||||||
|
║ ║
|
||||||
|
║ PLAN IP TENANTS: ║
|
||||||
|
║ 10.0.10.0/23 → Tenant Infrastructure ║
|
||||||
|
║ 10.0.128.0/17 → Expansion ║
|
||||||
|
║ ║
|
||||||
|
║ NOM VM INFRA: ║
|
||||||
|
║ <membre>-infra-<type>-<env>-<instance> ║
|
||||||
|
║ Exemple: czp-infra-dns-master-prod-01 ║
|
||||||
|
║ ║
|
||||||
|
║ NOM VM TENANT: ║
|
||||||
|
║ <membre>-t<tenant>-<type>-<env>-<instance> ║
|
||||||
|
║ Exemple: czp-t001-web-prod-01 ║
|
||||||
|
║ ║
|
||||||
|
║ DNS INFRA: ║
|
||||||
|
║ <service>.infra.<membre>.alliance-boreale.ca ║
|
||||||
|
║ ║
|
||||||
|
║ DNS TENANT: ║
|
||||||
|
║ <service>.t<tenant>.<membre>.alliance-boreale.ca ║
|
||||||
|
║ ║
|
||||||
|
║ SCRIPTS UTILES: ║
|
||||||
|
║ audit-nomenclature.sh # Audit conformité ║
|
||||||
|
║ validate-vmid.sh <vmid> # Valider VMID ║
|
||||||
|
║ allocate-ip.sh <tenant> # Allouer IP ║
|
||||||
|
║ migrate-vm.sh <src> <dst> <nom> <ip> # Migration ║
|
||||||
|
║ ║
|
||||||
|
╚════════════════════════════════════════════════════════╝
|
||||||
|
```
|
||||||
|
|
||||||
|
### 9.2 Table des Types de Services
|
||||||
|
|
||||||
|
#### Couche 2 - Réseau
|
||||||
|
```
|
||||||
|
00-09 : DNS (PowerDNS)
|
||||||
|
10-19 : VPN/WireGuard
|
||||||
|
20-29 : Routeurs
|
||||||
|
30-39 : Proxy/HAProxy
|
||||||
|
```
|
||||||
|
|
||||||
|
#### Couche 3 - Stockage
|
||||||
|
```
|
||||||
|
00-09 : Ceph Monitors
|
||||||
|
10-19 : Ceph OSDs
|
||||||
|
20-29 : NFS
|
||||||
|
30-39 : Backup (PBS, Borg)
|
||||||
|
```
|
||||||
|
|
||||||
|
#### Couche 4 - Orchestration
|
||||||
|
```
|
||||||
|
00-09 : Ansible
|
||||||
|
10-19 : CI/CD Runners
|
||||||
|
20-29 : Git (Forgejo)
|
||||||
|
30-39 : DB Platform
|
||||||
|
40-49 : API Admin
|
||||||
|
```
|
||||||
|
|
||||||
|
#### Instances Tenant
|
||||||
|
```
|
||||||
|
01-09 : Web/Frontend
|
||||||
|
10-19 : Backend/API
|
||||||
|
20-29 : Databases
|
||||||
|
30-39 : Cache/Queue
|
||||||
|
40-49 : Workers
|
||||||
|
```
|
||||||
|
|
||||||
|
### 9.3 Commandes Fréquentes
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# Lister toutes les VMs
|
||||||
|
qm list
|
||||||
|
|
||||||
|
# Info VM
|
||||||
|
qm config <vmid>
|
||||||
|
|
||||||
|
# Audit conformité
|
||||||
|
audit-nomenclature.sh
|
||||||
|
|
||||||
|
# Valider VMID
|
||||||
|
validate-vmid.sh <vmid>
|
||||||
|
|
||||||
|
# Générer DNS
|
||||||
|
generate-dns-records.sh > dns.zone
|
||||||
|
|
||||||
|
# Générer inventaire
|
||||||
|
generate-inventory.sh
|
||||||
|
|
||||||
|
# Migration (simulation)
|
||||||
|
DRY_RUN=true migrate-vm.sh <src> <dst> <nom> <ip>
|
||||||
|
|
||||||
|
# Allouer IP tenant
|
||||||
|
allocate-ip.sh <tenant-id>
|
||||||
|
```
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 10. Certification
|
||||||
|
|
||||||
|
### 10.1 Test de Certification
|
||||||
|
|
||||||
|
**Pour valider votre formation, répondez à ces 10 questions :**
|
||||||
|
|
||||||
|
#### Question 1
|
||||||
|
Quel est le VMID pour un 2ème DNS Slave en infrastructure ?
|
||||||
|
- A) 02002
|
||||||
|
- B) 20002
|
||||||
|
- C) 02102
|
||||||
|
- D) 02200
|
||||||
|
|
||||||
|
#### Question 2
|
||||||
|
Quelle IP pour le 1er Ansible Controller ?
|
||||||
|
- A) 10.0.0.10
|
||||||
|
- B) 10.0.1.10
|
||||||
|
- C) 10.0.2.10
|
||||||
|
- D) 10.0.4.10
|
||||||
|
|
||||||
|
#### Question 3
|
||||||
|
Quel nom pour la 1ère VM web du tenant 003 (membre czp) ?
|
||||||
|
- A) czp-web-t003-prod-01
|
||||||
|
- B) czp-t003-web-prod-01
|
||||||
|
- C) czp-t003-prod-web-01
|
||||||
|
- D) czp-tenant003-web-01
|
||||||
|
|
||||||
|
#### Question 4
|
||||||
|
Quel DNS pour l'API du tenant 002 (membre nul) ?
|
||||||
|
- A) api.nul.t002.alliance-boreale.ca
|
||||||
|
- B) t002-api.nul.alliance-boreale.ca
|
||||||
|
- C) api.t002.nul.alliance-boreale.ca
|
||||||
|
- D) api.tenant002.nul.alliance-boreale.ca
|
||||||
|
|
||||||
|
#### Question 5
|
||||||
|
Quelle plage IP pour l'infrastructure Platform Services ?
|
||||||
|
- A) 10.0.0.0/24
|
||||||
|
- B) 10.0.1.0/24
|
||||||
|
- C) 10.0.2.0/24
|
||||||
|
- D) 10.0.10.0/24
|
||||||
|
|
||||||
|
#### Question 6
|
||||||
|
Le VMID 30021 correspond à quoi ?
|
||||||
|
- A) Infrastructure Couche 3, Type 00, Instance 21
|
||||||
|
- B) Tenant 003, Instance 21
|
||||||
|
- C) Tenant 300, Instance 21
|
||||||
|
- D) Infrastructure Couche 30, Instance 21
|
||||||
|
|
||||||
|
#### Question 7
|
||||||
|
Combien de tenants maximum peut supporter ce standard ?
|
||||||
|
- A) 99
|
||||||
|
- B) 999
|
||||||
|
- C) 9999
|
||||||
|
- D) Illimité
|
||||||
|
|
||||||
|
#### Question 8
|
||||||
|
Quelle commande pour valider un VMID ?
|
||||||
|
- A) check-vmid.sh
|
||||||
|
- B) validate-vmid.sh
|
||||||
|
- C) test-vmid.sh
|
||||||
|
- D) verify-vmid.sh
|
||||||
|
|
||||||
|
#### Question 9
|
||||||
|
Avant une migration, quelle est la PREMIÈRE étape ?
|
||||||
|
- A) Arrêter la VM
|
||||||
|
- B) Créer un backup
|
||||||
|
- C) Changer le VMID
|
||||||
|
- D) Modifier l'IP
|
||||||
|
|
||||||
|
#### Question 10
|
||||||
|
Où sont stockées les allocations IP des tenants ?
|
||||||
|
- A) /etc/proxmox/ipam.txt
|
||||||
|
- B) /var/lib/ipam/allocations.txt
|
||||||
|
- C) /etc/alliance-boreale/ipam.txt
|
||||||
|
- D) /etc/network/ipam.conf
|
||||||
|
|
||||||
|
### 10.2 Réponses
|
||||||
|
|
||||||
|
<details>
|
||||||
|
<summary>Cliquer pour voir les réponses</summary>
|
||||||
|
|
||||||
|
1. **A** - 02002 (Couche 2, DNS type 00, Instance 2)
|
||||||
|
2. **B** - 10.0.1.10 (Platform Services)
|
||||||
|
3. **B** - czp-t003-web-prod-01
|
||||||
|
4. **C** - api.t002.nul.alliance-boreale.ca
|
||||||
|
5. **B** - 10.0.1.0/24
|
||||||
|
6. **B** - Tenant 003, Instance 21 (probablement une DB)
|
||||||
|
7. **B** - 999 tenants (001-999)
|
||||||
|
8. **B** - validate-vmid.sh
|
||||||
|
9. **B** - Créer un backup
|
||||||
|
10. **C** - /etc/alliance-boreale/ipam.txt
|
||||||
|
|
||||||
|
**Score :**
|
||||||
|
- 10/10 : ✅ Certifié Expert Nomenclature v2.0
|
||||||
|
- 8-9/10 : ✅ Certifié avec révision mineure
|
||||||
|
- 6-7/10 : ⚠️ Révision recommandée
|
||||||
|
- <6/10 : ❌ Formation à reprendre
|
||||||
|
|
||||||
|
</details>
|
||||||
|
|
||||||
|
### 10.3 Exercice Pratique Final
|
||||||
|
|
||||||
|
**Déploiement complet d'un nouveau membre :**
|
||||||
|
|
||||||
|
**Scénario :** Vous êtes le nouvel administrateur de "TechnoLibre" (tli), membre #003 de L'Alliance. Vous devez déployer l'infrastructure minimale Bronze + 1 premier tenant.
|
||||||
|
|
||||||
|
**Livrables attendus :**
|
||||||
|
|
||||||
|
1. **Plan d'infrastructure (3 VMs minimum) :**
|
||||||
|
- DNS Master
|
||||||
|
- Ansible Controller
|
||||||
|
- Backup Server
|
||||||
|
|
||||||
|
2. **Plan tenant 001 (3 VMs) :**
|
||||||
|
- Web Frontend
|
||||||
|
- API Backend
|
||||||
|
- Database PostgreSQL
|
||||||
|
|
||||||
|
3. **Documentation complète pour chaque VM :**
|
||||||
|
- VMID
|
||||||
|
- Nom VM
|
||||||
|
- IP
|
||||||
|
- DNS
|
||||||
|
|
||||||
|
4. **Scripts de création :**
|
||||||
|
- Commandes qm create pour chaque VM
|
||||||
|
- Commandes de configuration réseau
|
||||||
|
|
||||||
|
5. **Zone DNS complète**
|
||||||
|
|
||||||
|
**Créez un document avec tous ces éléments !**
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Ressources Supplémentaires
|
||||||
|
|
||||||
|
### Documentation
|
||||||
|
- **Standard Nomenclature v2.0** : https://docs.alliance-boreale.ca/nomenclature-v2
|
||||||
|
- **Scripts** : https://forge.alliance-boreale.ca/tools/nomenclature-scripts
|
||||||
|
- **Vidéos** : https://video.alliance-boreale.ca/nomenclature
|
||||||
|
|
||||||
|
### Support
|
||||||
|
- **Email** : technique@alliance-boreale.ca
|
||||||
|
- **Matrix** : #technique:alliance-boreale.ca
|
||||||
|
- **Forum** : https://forum.alliance-boreale.ca/c/nomenclature
|
||||||
|
|
||||||
|
### Communauté
|
||||||
|
- **Partage de configurations** : https://forge.alliance-boreale.ca/configs
|
||||||
|
- **Retours d'expérience** : https://blog.alliance-boreale.ca/tag/nomenclature
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Conclusion
|
||||||
|
|
||||||
|
### Ce que vous avez appris
|
||||||
|
|
||||||
|
✅ Comprendre la philosophie du standard v2.0
|
||||||
|
✅ Maîtriser le format VMID mnémotechnique
|
||||||
|
✅ Connaître le plan d'adressage IP complet
|
||||||
|
✅ Construire des noms VMs et DNS conformes
|
||||||
|
✅ Utiliser les scripts de migration et audit
|
||||||
|
✅ Planifier et exécuter une migration complète
|
||||||
|
|
||||||
|
### Prochaines Étapes
|
||||||
|
|
||||||
|
1. **Pratiquer** sur un environnement de test
|
||||||
|
2. **Auditer** votre infrastructure actuelle
|
||||||
|
3. **Planifier** la migration progressive
|
||||||
|
4. **Documenter** votre plan
|
||||||
|
5. **Valider** avec le Cercle Technique
|
||||||
|
6. **Migrer** par lots sur 6-12 mois
|
||||||
|
|
||||||
|
### Engagement
|
||||||
|
|
||||||
|
En tant qu'administrateur certifié Nomenclature v2.0, vous vous engagez à :
|
||||||
|
- Respecter le standard pour tous nouveaux déploiements
|
||||||
|
- Participer à la migration progressive de l'existant
|
||||||
|
- Partager vos retours d'expérience avec la communauté
|
||||||
|
- Former les nouveaux administrateurs de votre membre
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
**« Une nomenclature maîtrisée = Une infrastructure maîtrisée »**
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
**FIN DU GUIDE DE FORMATION**
|
||||||
|
|
||||||
|
**Version :** 1.0
|
||||||
|
**Date :** 21 octobre 2025
|
||||||
|
**Licence :** CC-BY-SA 4.0
|
||||||
|
**Auteur :** L'Alliance Boréale - Cercle Technique
|
||||||
1033
docs/architecture/nomenclature_v2(1).md
Normal file
1033
docs/architecture/nomenclature_v2(1).md
Normal file
File diff suppressed because it is too large
Load diff
1033
docs/architecture/nomenclature_v2.md
Normal file
1033
docs/architecture/nomenclature_v2.md
Normal file
File diff suppressed because it is too large
Load diff
244
docs/architecture/readme_package.md
Normal file
244
docs/architecture/readme_package.md
Normal file
|
|
@ -0,0 +1,244 @@
|
||||||
|
# Package Complet - Nomenclature v2.0
|
||||||
|
## L'Alliance Boréale
|
||||||
|
|
||||||
|
**Version :** 1.0
|
||||||
|
**Date :** 21 octobre 2025
|
||||||
|
**Licence :** AGPL-3.0 (code) / CC-BY-SA 4.0 (documentation)
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 📦 Contenu du Package
|
||||||
|
|
||||||
|
Ce package complet contient **tout ce dont vous avez besoin** pour adopter le Standard de Nomenclature v2.0 dans votre infrastructure Proxmox.
|
||||||
|
|
||||||
|
### 📚 Documentation (5 documents)
|
||||||
|
|
||||||
|
1. **Standard de Nomenclature v2.0** (60+ pages)
|
||||||
|
- Spécification complète du standard
|
||||||
|
- Format VMID, IP, noms VMs, DNS
|
||||||
|
- Tables de correspondance exhaustives
|
||||||
|
- Procédures opérationnelles
|
||||||
|
|
||||||
|
2. **Scripts de Migration et d'Audit** (documentation + 6 scripts)
|
||||||
|
- `audit-nomenclature.sh` - Audit de conformité
|
||||||
|
- `generate-dns-records.sh` - Génération zone DNS
|
||||||
|
- `generate-inventory.sh` - Génération inventaire Ansible
|
||||||
|
- `migrate-vm.sh` - Migration assistée
|
||||||
|
- `validate-vmid.sh` - Validation VMID
|
||||||
|
- `allocate-ip.sh` - Allocation IP tenants
|
||||||
|
|
||||||
|
3. **Guide de Formation** (40+ pages)
|
||||||
|
- Formation complète 2-3 heures
|
||||||
|
- 8 exercices pratiques avec solutions
|
||||||
|
- Aide-mémoire imprimable
|
||||||
|
- Test de certification (10 questions)
|
||||||
|
|
||||||
|
4. **Templates Ansible & Terraform**
|
||||||
|
- Modules Ansible (création VM, audit, compliance)
|
||||||
|
- Modules Terraform (infra + tenants)
|
||||||
|
- Exemples d'utilisation
|
||||||
|
- Makefile d'automatisation
|
||||||
|
|
||||||
|
5. **README Package** (ce document)
|
||||||
|
- Vue d'ensemble
|
||||||
|
- Quick Start
|
||||||
|
- Troubleshooting
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 🚀 Quick Start (15 minutes)
|
||||||
|
|
||||||
|
### Étape 1 : Installation des Scripts
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# Télécharger le package
|
||||||
|
wget https://forge.alliance-boreale.ca/nomenclature-v2-package.tar.gz
|
||||||
|
tar xzf nomenclature-v2-package.tar.gz
|
||||||
|
cd nomenclature-v2
|
||||||
|
|
||||||
|
# Installer les scripts
|
||||||
|
sudo bash scripts/install-nomenclature-tools.sh
|
||||||
|
|
||||||
|
# Configuration
|
||||||
|
# Suivre les prompts pour MEMBER_ID et DNS_DOMAIN
|
||||||
|
```
|
||||||
|
|
||||||
|
### Étape 2 : Premier Audit
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# Lancer un audit de conformité
|
||||||
|
audit-nomenclature.sh
|
||||||
|
|
||||||
|
# Résultat attendu :
|
||||||
|
# ✅ VMs conformes : X
|
||||||
|
# ❌ VMs non conformes : Y
|
||||||
|
# Taux de conformité: Z%
|
||||||
|
```
|
||||||
|
|
||||||
|
### Étape 3 : Validation d'un VMID
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# Tester la validation
|
||||||
|
validate-vmid.sh 02001
|
||||||
|
|
||||||
|
# Résultat :
|
||||||
|
# ✅ VMID VALIDE
|
||||||
|
# Type: Infrastructure
|
||||||
|
# Couche: 2 (Réseau)
|
||||||
|
```
|
||||||
|
|
||||||
|
### Étape 4 : Première Migration (Simulation)
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# Migration en mode dry-run
|
||||||
|
DRY_RUN=true migrate-vm.sh 104 10001 \
|
||||||
|
czp-t001-web-prod-01 10.0.10.1
|
||||||
|
|
||||||
|
# Vérifier la sortie avant de lancer en réel
|
||||||
|
```
|
||||||
|
|
||||||
|
### Étape 5 : Documentation
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# Lire le standard complet
|
||||||
|
less docs/Standard_Nomenclature_v2.0.md
|
||||||
|
|
||||||
|
# Lire le guide de formation
|
||||||
|
less docs/Guide_Formation_v2.0.md
|
||||||
|
```
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 📖 Structure du Package
|
||||||
|
|
||||||
|
```
|
||||||
|
nomenclature-v2/
|
||||||
|
│
|
||||||
|
├── README.md # Ce fichier
|
||||||
|
├── LICENSE # AGPL-3.0
|
||||||
|
│
|
||||||
|
├── docs/
|
||||||
|
│ ├── Standard_Nomenclature_v2.0.md # Spec complète
|
||||||
|
│ ├── Guide_Formation_v2.0.md # Formation
|
||||||
|
│ └── aide-memoire.pdf # Carte de référence
|
||||||
|
│
|
||||||
|
├── scripts/
|
||||||
|
│ ├── install-nomenclature-tools.sh # Installation
|
||||||
|
│ ├── audit-nomenclature.sh # Audit
|
||||||
|
│ ├── generate-dns-records.sh # DNS
|
||||||
|
│ ├── generate-inventory.sh # Inventaire
|
||||||
|
│ ├── migrate-vm.sh # Migration
|
||||||
|
│ ├── validate-vmid.sh # Validation
|
||||||
|
│ └── allocate-ip.sh # Allocation IP
|
||||||
|
│
|
||||||
|
├── ansible/
|
||||||
|
│ ├── inventory/
|
||||||
|
│ │ └── proxmox.yml # Inventaire dynamique
|
||||||
|
│ ├── playbooks/
|
||||||
|
│ │ ├── create-infra-vm.yml # Création VM infra
|
||||||
|
│ │ ├── create-tenant-vm.yml # Création VM tenant
|
||||||
|
│ │ └── audit-nomenclature.yml # Audit Ansible
|
||||||
|
│ └── roles/
|
||||||
|
│ └── nomenclature_compliance/ # Role de conformité
|
||||||
|
│
|
||||||
|
├── terraform/
|
||||||
|
│ ├── modules/
|
||||||
|
│ │ ├── infra-vm/ # Module VM infrastructure
|
||||||
|
│ │ └── tenant-vm/ # Module VM tenant
|
||||||
|
│ ├── examples/
|
||||||
|
│ │ ├── bronze-infra/ # Infrastructure Bronze
|
||||||
|
│ │ ├── silver-infra/ # Infrastructure Argent
|
||||||
|
│ │ └── tenant-stack/ # Stack tenant complète
|
||||||
|
│ ├── main.tf # Exemple principal
|
||||||
|
│ ├── variables.tf # Variables
|
||||||
|
│ └── outputs.tf # Outputs
|
||||||
|
│
|
||||||
|
├── templates/
|
||||||
|
│ ├── vm-creation-request.md # Template demande création VM
|
||||||
|
│ ├── migration-plan.md # Template plan de migration
|
||||||
|
│ └── compliance-report.md # Template rapport conformité
|
||||||
|
│
|
||||||
|
└── examples/
|
||||||
|
├── infrastructure-bronze.txt # Exemple infra Bronze
|
||||||
|
├── infrastructure-gold.txt # Exemple infra Or
|
||||||
|
└── tenant-multiservice.txt # Exemple tenant complet
|
||||||
|
```
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 💡 Cas d'Usage
|
||||||
|
|
||||||
|
### 1. Audit de Conformité de l'Existant
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# Lancer audit
|
||||||
|
audit-nomenclature.sh > audit-$(date +%Y%m%d).log
|
||||||
|
|
||||||
|
# Analyser le rapport CSV
|
||||||
|
grep "NON CONFORME" /tmp/audit-nomenclature-*.csv
|
||||||
|
|
||||||
|
# Créer plan de migration
|
||||||
|
cat audit-*.log | grep "NON CONFORME" > migration-todo.txt
|
||||||
|
```
|
||||||
|
|
||||||
|
### 2. Création Nouvelle VM Infrastructure
|
||||||
|
|
||||||
|
**Option A : Script interactif**
|
||||||
|
```bash
|
||||||
|
ansible-playbook ansible/playbooks/create-infra-vm.yml
|
||||||
|
# Suivre les prompts
|
||||||
|
```
|
||||||
|
|
||||||
|
**Option B : Terraform**
|
||||||
|
```bash
|
||||||
|
cd terraform/examples/bronze-infra
|
||||||
|
terraform init
|
||||||
|
terraform plan
|
||||||
|
terraform apply
|
||||||
|
```
|
||||||
|
|
||||||
|
**Option C : Manuel**
|
||||||
|
```bash
|
||||||
|
# 1. Déterminer VMID
|
||||||
|
validate-vmid.sh 02003 # DNS Slave 3
|
||||||
|
|
||||||
|
# 2. Créer VM
|
||||||
|
qm create 02003 \
|
||||||
|
--name czp-infra-dns-slave3-prod-01 \
|
||||||
|
--clone debian-12-template \
|
||||||
|
--net0 virtio,bridge=vmbr0,tag=2 \
|
||||||
|
--ipconfig0 ip=10.0.2.12/24,gw=10.0.0.1
|
||||||
|
|
||||||
|
# 3. Ajouter DNS
|
||||||
|
echo "dns-slave3.infra.czp.alliance-boreale.ca. IN A 10.0.2.12" \
|
||||||
|
>> /var/lib/alliance-boreale/dns-records.zone
|
||||||
|
```
|
||||||
|
|
||||||
|
### 3. Migration Progressive
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# Étape 1 : Audit initial
|
||||||
|
audit-nomenclature.sh
|
||||||
|
|
||||||
|
# Étape 2 : Créer plan (fichier CSV)
|
||||||
|
# migration-plan.csv :
|
||||||
|
# VMID_SRC,VMID_DST,NAME,IP
|
||||||
|
# 104,10001,czp-t001-web-prod-01,10.0.10.1
|
||||||
|
# 105,10011,czp-t001-api-prod-01,10.0.10.3
|
||||||
|
|
||||||
|
# Étape 3 : Migrer par lots
|
||||||
|
while IFS=, read -r src dst name ip; do
|
||||||
|
echo "Migration $src -> $dst"
|
||||||
|
DRY_RUN=true migrate-vm.sh "$src" "$dst" "$name" "$ip"
|
||||||
|
read -p "Continuer? (y/n) " -n 1 -r
|
||||||
|
if [[ $REPLY =~ ^[Yy]$ ]]; then
|
||||||
|
migrate-vm.sh "$src" "$dst" "$name" "$ip"
|
||||||
|
fi
|
||||||
|
done < migration-plan.csv
|
||||||
|
```
|
||||||
|
|
||||||
|
### 4. Déploiement Nouveau Tenant
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# Via Ansible
|
||||||
|
ansible-playbook ansible/playbooks/
|
||||||
431
docs/architecture/resolution_adoption.md
Normal file
431
docs/architecture/resolution_adoption.md
Normal file
|
|
@ -0,0 +1,431 @@
|
||||||
|
# RÉSOLUTION D'ADOPTION
|
||||||
|
## Standard de Nomenclature v2.0
|
||||||
|
### L'Alliance Boréale
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
**Numéro de résolution :** 2025-TECH-001
|
||||||
|
**Date de proposition :** 21 octobre 2025
|
||||||
|
**Cercle émetteur :** Cercle Technique
|
||||||
|
**Processus :** Consentement Sociocratique
|
||||||
|
**Statut :** PROPOSITION (en attente de validation)
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## CONTEXTE
|
||||||
|
|
||||||
|
### Situation Actuelle
|
||||||
|
|
||||||
|
L'Alliance Boréale compte actuellement **3 membres actifs** (Chezlepro, Nuage Libre, TechnoLibre) avec une infrastructure totale d'environ **120 machines virtuelles** réparties entre infrastructure propre et tenants hébergés.
|
||||||
|
|
||||||
|
**Problématiques identifiées :**
|
||||||
|
|
||||||
|
1. **Absence de standard unifié** pour l'identification des ressources
|
||||||
|
2. **Nomenclature incohérente** entre les membres (VMIDs, noms, IPs)
|
||||||
|
3. **Difficultés d'automatisation** (Ansible, Terraform) dues au manque de structure
|
||||||
|
4. **Complexité d'audit** pour la labellisation (Bronze, Argent, Or, Platine)
|
||||||
|
5. **Onboarding lent** des nouveaux administrateurs
|
||||||
|
6. **Risques opérationnels** (erreurs de manipulation, confusion)
|
||||||
|
|
||||||
|
### Besoins Exprimés
|
||||||
|
|
||||||
|
Lors des réunions du Cercle Technique (août-octobre 2025), les membres ont exprimé le besoin de :
|
||||||
|
|
||||||
|
- ✅ **Standardiser** l'identification de toutes les ressources (VMs, IPs, DNS)
|
||||||
|
- ✅ **Faciliter l'automatisation** avec des patterns prévisibles
|
||||||
|
- ✅ **Simplifier les audits** de conformité pour la labellisation
|
||||||
|
- ✅ **Accélérer l'onboarding** avec une documentation claire
|
||||||
|
- ✅ **Améliorer la scalabilité** (prévoir 999 tenants par membre)
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## PROPOSITION
|
||||||
|
|
||||||
|
### Objet de la Résolution
|
||||||
|
|
||||||
|
**IL EST PROPOSÉ** d'adopter le **Standard de Nomenclature v2.0** comme standard officiel de L'Alliance Boréale pour l'identification et l'organisation des ressources d'infrastructure.
|
||||||
|
|
||||||
|
### Composants du Standard
|
||||||
|
|
||||||
|
Le Standard de Nomenclature v2.0 comprend :
|
||||||
|
|
||||||
|
#### 1. Spécification Technique (60+ pages)
|
||||||
|
- Format VMID mnémotechnique (0CTTII pour infra, TTTII pour tenants)
|
||||||
|
- Plan d'adressage IP unifié (10.0.0.0/8 par membre, derrière NAT)
|
||||||
|
- Nomenclature VMs (<membre>-infra/t<XXX>-<type>-<env>-<inst>)
|
||||||
|
- Nomenclature DNS (<service>.infra/t<XXX>.<membre>.alliance-boreale.ca)
|
||||||
|
- Tables de correspondance complètes
|
||||||
|
|
||||||
|
#### 2. Outillage (6 scripts)
|
||||||
|
- `audit-nomenclature.sh` - Audit de conformité
|
||||||
|
- `generate-dns-records.sh` - Génération zone DNS
|
||||||
|
- `generate-inventory.sh` - Génération inventaire Ansible
|
||||||
|
- `migrate-vm.sh` - Migration assistée avec simulation
|
||||||
|
- `validate-vmid.sh` - Validation format VMID
|
||||||
|
- `allocate-ip.sh` - Allocation IP tenants (IPAM)
|
||||||
|
|
||||||
|
#### 3. Formation et Documentation
|
||||||
|
- Guide de formation (40+ pages, 8 exercices pratiques)
|
||||||
|
- Test de certification (10 questions + exercice final)
|
||||||
|
- Templates Ansible et Terraform
|
||||||
|
- Aide-mémoire imprimable
|
||||||
|
|
||||||
|
#### 4. Gouvernance
|
||||||
|
- Processus de révision annuelle
|
||||||
|
- Procédures de modification (RFC)
|
||||||
|
- Versionnage sémantique (v2.x.x)
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## MODALITÉS D'ADOPTION
|
||||||
|
|
||||||
|
### 1. Adoption du Standard
|
||||||
|
|
||||||
|
**IL EST RÉSOLU :**
|
||||||
|
|
||||||
|
**QUE** le Standard de Nomenclature v2.0, tel que documenté dans le package complet daté du 21 octobre 2025, soit adopté comme **standard officiel obligatoire** pour tous les membres de L'Alliance Boréale.
|
||||||
|
|
||||||
|
### 2. Date d'Entrée en Vigueur
|
||||||
|
|
||||||
|
**QUE** ce standard entre en vigueur selon le calendrier suivant :
|
||||||
|
|
||||||
|
- **Immédiat (21 octobre 2025)** : Publication officielle du standard
|
||||||
|
- **1er décembre 2025** : Formation obligatoire de tous les administrateurs
|
||||||
|
- **1er janvier 2026** : Obligation pour tous **nouveaux déploiements**
|
||||||
|
- **31 décembre 2026** : Objectif de conformité à 100% pour l'existant
|
||||||
|
|
||||||
|
### 3. Obligations des Membres
|
||||||
|
|
||||||
|
**QUE** chaque membre s'engage à :
|
||||||
|
|
||||||
|
#### A) Formation (avant 1er décembre 2025)
|
||||||
|
- [ ] Former tous les administrateurs système (min. 1 par membre)
|
||||||
|
- [ ] Certifier au moins 1 administrateur par membre (niveau 2)
|
||||||
|
- [ ] Désigner 1 "référent nomenclature" par membre
|
||||||
|
|
||||||
|
#### B) Nouveaux Déploiements (à partir du 1er janvier 2026)
|
||||||
|
- [ ] Respecter le standard v2.0 pour **toute nouvelle VM**
|
||||||
|
- [ ] Utiliser les scripts fournis pour validation (validate-vmid.sh)
|
||||||
|
- [ ] Documenter toute exception (avec justification validée)
|
||||||
|
|
||||||
|
#### C) Migration de l'Existant (avant 31 décembre 2026)
|
||||||
|
- [ ] Réaliser un audit initial (avant 31 janvier 2026)
|
||||||
|
- [ ] Établir un plan de migration (avant 28 février 2026)
|
||||||
|
- [ ] Migrer par lots (5-10 VMs/mois minimum)
|
||||||
|
- [ ] Atteindre 80% de conformité avant 30 juin 2026
|
||||||
|
- [ ] Atteindre 100% de conformité avant 31 décembre 2026
|
||||||
|
|
||||||
|
#### D) Reporting
|
||||||
|
- [ ] Rapport mensuel de conformité au Cercle Technique
|
||||||
|
- [ ] Partage des retours d'expérience (bonnes pratiques, difficultés)
|
||||||
|
|
||||||
|
### 4. Ressources Allouées
|
||||||
|
|
||||||
|
**QUE** L'Alliance Boréale alloue les ressources suivantes :
|
||||||
|
|
||||||
|
#### Coordination (Banque de Temps)
|
||||||
|
- **30 heures** : Animation sessions de formation (réparties entre experts)
|
||||||
|
- **20 heures** : Support technique aux membres (canal dédié Matrix)
|
||||||
|
- **10 heures** : Maintenance documentation et scripts
|
||||||
|
|
||||||
|
#### Infrastructure Commune
|
||||||
|
- **Forge Git** : Hébergement du code et documentation
|
||||||
|
- **Wiki** : Documentation interactive et exemples
|
||||||
|
- **Forum** : Entraide entre membres
|
||||||
|
|
||||||
|
#### Budget Financier (si nécessaire)
|
||||||
|
- **0 $** : Tout en logiciel libre et Banque de Temps
|
||||||
|
- **Réserve** : 500 $ pour formation externe si expertise manquante
|
||||||
|
|
||||||
|
### 5. Exceptions et Dérogations
|
||||||
|
|
||||||
|
**QUE** des exceptions puissent être accordées selon ce processus :
|
||||||
|
|
||||||
|
#### Cas Justifiant une Exception
|
||||||
|
- Contraintes techniques insurmontables (matériel legacy)
|
||||||
|
- Dépendances externes non migrables à court terme
|
||||||
|
- Coût de migration disproportionné pour VM en fin de vie
|
||||||
|
|
||||||
|
#### Processus d'Exception
|
||||||
|
1. **Demande écrite** au Cercle Technique (formulaire dédié)
|
||||||
|
2. **Justification technique** détaillée + impact + alternatives explorées
|
||||||
|
3. **Validation** par 2 experts du Cercle Technique
|
||||||
|
4. **Durée limitée** : Max 12 mois, renouvellement possible 1 fois
|
||||||
|
5. **Plan de mise en conformité** obligatoire dans la demande
|
||||||
|
|
||||||
|
#### Registre des Exceptions
|
||||||
|
- Tenu à jour dans `governance/nomenclature-exceptions.yml`
|
||||||
|
- Consultation publique par tous les membres
|
||||||
|
- Révision trimestrielle par le Cercle Technique
|
||||||
|
|
||||||
|
### 6. Maintenance et Évolution
|
||||||
|
|
||||||
|
**QUE** le standard soit maintenu selon ces principes :
|
||||||
|
|
||||||
|
#### Responsabilité
|
||||||
|
- **Propriétaire** : Cercle Technique de L'Alliance Boréale
|
||||||
|
- **Gardien du standard** : 1 membre désigné (rotation annuelle)
|
||||||
|
- **Contributeurs** : Tous les membres (via RFC)
|
||||||
|
|
||||||
|
#### Révisions
|
||||||
|
- **Mineures (v2.x)** : Corrections, clarifications → Validation Cercle Technique
|
||||||
|
- **Majeures (v3.0)** : Changements structurels → Consentement tous membres
|
||||||
|
- **Fréquence** : Révision annuelle obligatoire (octobre)
|
||||||
|
|
||||||
|
#### Processus RFC (Request for Comments)
|
||||||
|
1. Proposition ouverte sur la forge (`rfc/NNNN-titre.md`)
|
||||||
|
2. Discussion publique (min. 2 semaines)
|
||||||
|
3. Présentation au Cercle Technique
|
||||||
|
4. Décision par consentement (si impact majeur)
|
||||||
|
5. Intégration dans version suivante
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## IMPACTS ET BÉNÉFICES ATTENDUS
|
||||||
|
|
||||||
|
### Impacts Positifs
|
||||||
|
|
||||||
|
#### Court Terme (6 mois)
|
||||||
|
- ✅ **Clarté opérationnelle** : Toute ressource identifiable immédiatement
|
||||||
|
- ✅ **Réduction erreurs** : -80% d'erreurs de manipulation (estimation)
|
||||||
|
- ✅ **Automatisation** : Playbooks Ansible génériques réutilisables
|
||||||
|
- ✅ **Onboarding** : Temps de formation -50% pour nouveaux admins
|
||||||
|
|
||||||
|
#### Moyen Terme (1 an)
|
||||||
|
- ✅ **Conformité audits** : Simplification audits de labellisation
|
||||||
|
- ✅ **Scalabilité** : Capacité d'accueillir 999 tenants par membre
|
||||||
|
- ✅ **Professionnalisme** : Crédibilité renforcée de L'Alliance
|
||||||
|
- ✅ **Collaboration** : Entraide facilitée entre membres
|
||||||
|
|
||||||
|
#### Long Terme (2 ans)
|
||||||
|
- ✅ **Maturité** : Infrastructure de niveau "entreprise"
|
||||||
|
- ✅ **Résilience** : Documentation permettant continuité en cas de départ
|
||||||
|
- ✅ **Innovation** : Base solide pour outils avancés (IPAM auto, API)
|
||||||
|
- ✅ **Rayonnement** : Standard pouvant influencer la communauté Proxmox
|
||||||
|
|
||||||
|
### Impacts Négatifs (Mitigations)
|
||||||
|
|
||||||
|
#### Charge de Travail Initiale
|
||||||
|
- ⚠️ **Impact** : ~40h par membre pour migration complète
|
||||||
|
- ✅ **Mitigation** : Migration progressive sur 12 mois, scripts d'assistance
|
||||||
|
|
||||||
|
#### Courbe d'Apprentissage
|
||||||
|
- ⚠️ **Impact** : 3h de formation par administrateur
|
||||||
|
- ✅ **Mitigation** : Documentation claire, exercices pratiques, certification
|
||||||
|
|
||||||
|
#### Résistance au Changement
|
||||||
|
- ⚠️ **Impact** : Confort avec l'existant, peur de la complexité
|
||||||
|
- ✅ **Mitigation** : Démonstrations, retours d'expérience, support dédié
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## MÉTRIQUES DE SUCCÈS
|
||||||
|
|
||||||
|
### Indicateurs Quantitatifs (KPIs)
|
||||||
|
|
||||||
|
| Métrique | Valeur Actuelle | Cible 6 mois | Cible 12 mois |
|
||||||
|
|----------|-----------------|--------------|---------------|
|
||||||
|
| **Taux de conformité VMs** | 0% | 50% | 100% |
|
||||||
|
| **Admins formés** | 0/9 | 6/9 (67%) | 9/9 (100%) |
|
||||||
|
| **Admins certifiés** | 0/9 | 3/9 (33%) | 6/9 (67%) |
|
||||||
|
| **Temps onboarding nouvel admin** | 2 jours | 1 jour | 0.5 jour |
|
||||||
|
| **Erreurs de manipulation/mois** | ~10 | <5 | <2 |
|
||||||
|
| **Temps audit conformité** | 4h | 1h | 0.5h (automatisé) |
|
||||||
|
|
||||||
|
### Indicateurs Qualitatifs
|
||||||
|
|
||||||
|
- **Satisfaction administrateurs** : Sondage trimestriel (cible >4/5)
|
||||||
|
- **Qualité documentation** : Feedback utilisateurs (cible >4/5)
|
||||||
|
- **Facilité d'automatisation** : Nombre de playbooks réutilisables
|
||||||
|
- **Rayonnement externe** : Mentions dans communauté Proxmox
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## RISQUES ET PLAN DE CONTINGENCE
|
||||||
|
|
||||||
|
### Risques Identifiés
|
||||||
|
|
||||||
|
#### Risque 1 : Faible Adoption
|
||||||
|
- **Probabilité** : Faible
|
||||||
|
- **Impact** : Élevé
|
||||||
|
- **Mitigation** : Obligation pour nouveaux déploiements, formation obligatoire
|
||||||
|
- **Contingence** : Accompagnement renforcé, exemples concrets
|
||||||
|
|
||||||
|
#### Risque 2 : Standard Trop Complexe
|
||||||
|
- **Probabilité** : Moyenne
|
||||||
|
- **Impact** : Moyen
|
||||||
|
- **Mitigation** : Formation de qualité, scripts d'assistance
|
||||||
|
- **Contingence** : Simplification v2.1 si feedback négatif massif
|
||||||
|
|
||||||
|
#### Risque 3 : Coût Migration Sous-Estimé
|
||||||
|
- **Probabilité** : Moyenne
|
||||||
|
- **Impact** : Moyen
|
||||||
|
- **Mitigation** : Timeline souple (12 mois), migration progressive
|
||||||
|
- **Contingence** : Extension deadline si justifié (vote)
|
||||||
|
|
||||||
|
#### Risque 4 : Obsolescence Rapide
|
||||||
|
- **Probabilité** : Faible
|
||||||
|
- **Impact** : Élevé
|
||||||
|
- **Mitigation** : Processus RFC, révision annuelle
|
||||||
|
- **Contingence** : Refonte v3.0 si changement technologique majeur
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## PROCESSUS DE VALIDATION
|
||||||
|
|
||||||
|
### Étapes de Validation
|
||||||
|
|
||||||
|
#### 1. Révision Technique (Semaine 1-2)
|
||||||
|
- [ ] Lecture du package complet par tous les membres du Cercle Technique
|
||||||
|
- [ ] Identification des points d'amélioration
|
||||||
|
- [ ] Soumission des commentaires (forge Git ou Matrix)
|
||||||
|
|
||||||
|
#### 2. Intégration Retours (Semaine 3)
|
||||||
|
- [ ] Consolidation des retours par le responsable du standard
|
||||||
|
- [ ] Modifications du standard (version 2.0.1 si nécessaire)
|
||||||
|
- [ ] Publication version révisée
|
||||||
|
|
||||||
|
#### 3. Réunion de Validation (Semaine 4)
|
||||||
|
- [ ] Réunion du Cercle Technique (2-3 heures)
|
||||||
|
- [ ] Présentation du standard (30 min)
|
||||||
|
- [ ] Questions/Réponses (30 min)
|
||||||
|
- [ ] Tour de consentement (30 min)
|
||||||
|
- [ ] Formalisation de la résolution
|
||||||
|
|
||||||
|
#### 4. Vote de Consentement
|
||||||
|
- [ ] Chaque membre exprime son consentement ou objection
|
||||||
|
- [ ] Si objection : Discussion et recherche de solutions
|
||||||
|
- [ ] Si aucune objection bloquante : **Résolution adoptée**
|
||||||
|
|
||||||
|
### Critères de Consentement
|
||||||
|
|
||||||
|
Un membre donne son **consentement** s'il peut affirmer :
|
||||||
|
|
||||||
|
> "Je n'ai pas d'objection raisonnable et argumentée qui rendrait l'adoption de ce standard **nuisible** pour L'Alliance ou pour mon organisation."
|
||||||
|
|
||||||
|
**Note** : Le consentement n'est PAS l'unanimité. Un membre peut avoir des réserves mineures tout en donnant son consentement.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## SIGNATURES ET ADOPTION
|
||||||
|
|
||||||
|
### Proposition Initiale
|
||||||
|
|
||||||
|
**Proposé par :**
|
||||||
|
- **Daniel Mathieu** - Président, Chezlepro (czp-001)
|
||||||
|
- **Cercle Technique** - L'Alliance Boréale
|
||||||
|
|
||||||
|
**Date de proposition :** 21 octobre 2025
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
### Consentement des Membres
|
||||||
|
|
||||||
|
#### Chezlepro (czp-001)
|
||||||
|
- [ ] **Consentement** donné le : ________________
|
||||||
|
- [ ] **Objection** (détails ci-dessous) :
|
||||||
|
|
||||||
|
**Signature :** ________________________
|
||||||
|
**Nom :** Daniel Mathieu
|
||||||
|
**Fonction :** Président / Administrateur Système
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
#### Nuage Libre (nul-002)
|
||||||
|
- [ ] **Consentement** donné le : ________________
|
||||||
|
- [ ] **Objection** (détails ci-dessous) :
|
||||||
|
|
||||||
|
**Signature :** ________________________
|
||||||
|
**Nom :** ______________________________
|
||||||
|
**Fonction :** ______________________________
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
#### TechnoLibre (tli-003)
|
||||||
|
- [ ] **Consentement** donné le : ________________
|
||||||
|
- [ ] **Objection** (détails ci-dessous) :
|
||||||
|
|
||||||
|
**Signature :** ________________________
|
||||||
|
**Nom :** ______________________________
|
||||||
|
**Fonction :** ______________________________
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
### Validation Finale
|
||||||
|
|
||||||
|
**Résolution adoptée par consentement le :** _______________
|
||||||
|
|
||||||
|
**Validé par le Cercle Technique :**
|
||||||
|
|
||||||
|
**Signature du Facilitateur :**
|
||||||
|
________________________
|
||||||
|
**Nom :** ______________________________
|
||||||
|
**Date :** ______________________________
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## ANNEXES
|
||||||
|
|
||||||
|
### Annexe A : Documents de Référence
|
||||||
|
|
||||||
|
1. **Standard de Nomenclature v2.0** (60+ pages)
|
||||||
|
- Fichier : `Standard_Nomenclature_v2.0.md`
|
||||||
|
- Hash SHA256 : `[à calculer après finalisation]`
|
||||||
|
|
||||||
|
2. **Scripts de Migration** (6 scripts)
|
||||||
|
- Répertoire : `scripts/`
|
||||||
|
- Version : 1.0
|
||||||
|
|
||||||
|
3. **Guide de Formation** (40+ pages)
|
||||||
|
- Fichier : `Guide_Formation_v2.0.md`
|
||||||
|
|
||||||
|
4. **Templates Ansible/Terraform**
|
||||||
|
- Répertoires : `ansible/` et `terraform/`
|
||||||
|
|
||||||
|
### Annexe B : Calendrier Détaillé
|
||||||
|
|
||||||
|
| Date | Étape | Responsable | Statut |
|
||||||
|
|------|-------|-------------|--------|
|
||||||
|
| 21 oct 2025 | Proposition résolution | Daniel Mathieu | ✅ Fait |
|
||||||
|
| 28 oct 2025 | Révision technique | Cercle Technique | ⏳ En cours |
|
||||||
|
| 4 nov 2025 | Intégration retours | Daniel Mathieu | 🔜 À venir |
|
||||||
|
| 11 nov 2025 | Réunion validation | Tous membres | 🔜 À venir |
|
||||||
|
| 18 nov 2025 | Adoption officielle | Cercle Technique | 🔜 À venir |
|
||||||
|
| 1 déc 2025 | Début formations | Référents nomenclature | 🔜 À venir |
|
||||||
|
| 1 jan 2026 | Entrée en vigueur | Tous membres | 🔜 À venir |
|
||||||
|
|
||||||
|
### Annexe C : Contacts et Responsabilités
|
||||||
|
|
||||||
|
**Gardien du Standard (2025-2026) :**
|
||||||
|
- Nom : Daniel Mathieu
|
||||||
|
- Email : daniel@chezlepro.ca
|
||||||
|
- Matrix : @daniel:chezlepro.ca
|
||||||
|
|
||||||
|
**Support Technique :**
|
||||||
|
- Email : technique@alliance-boreale.ca
|
||||||
|
- Matrix : #nomenclature:alliance-boreale.ca
|
||||||
|
|
||||||
|
**Forge Git :**
|
||||||
|
- URL : https://forge.alliance-boreale.ca/standards/nomenclature
|
||||||
|
- Issues : https://forge.alliance-boreale.ca/standards/nomenclature/issues
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## HISTORIQUE DES RÉVISIONS
|
||||||
|
|
||||||
|
| Version | Date | Auteur | Modifications |
|
||||||
|
|---------|------|--------|---------------|
|
||||||
|
| 1.0 | 21 oct 2025 | Daniel Mathieu | Proposition initiale |
|
||||||
|
| 1.1 | [future] | [nom] | [modifications après retours] |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
**FIN DE LA RÉSOLUTION**
|
||||||
|
|
||||||
|
**Résolution n° 2025-TECH-001**
|
||||||
|
**Standard de Nomenclature v2.0**
|
||||||
|
**L'Alliance Boréale**
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
**« Un standard adopté par consentement est un standard respecté. »**
|
||||||
1248
docs/architecture/scripts_migration.sh
Normal file
1248
docs/architecture/scripts_migration.sh
Normal file
File diff suppressed because it is too large
Load diff
968
docs/architecture/templates_automation.md
Normal file
968
docs/architecture/templates_automation.md
Normal file
|
|
@ -0,0 +1,968 @@
|
||||||
|
# Templates Ansible & Terraform - Nomenclature v2.0
|
||||||
|
# L'Alliance Boréale
|
||||||
|
#
|
||||||
|
# Version: 1.0
|
||||||
|
# Date: 21 octobre 2025
|
||||||
|
# Licence: AGPL-3.0
|
||||||
|
|
||||||
|
################################################################################
|
||||||
|
# PARTIE 1: TEMPLATES ANSIBLE
|
||||||
|
################################################################################
|
||||||
|
|
||||||
|
# ==============================================================================
|
||||||
|
# 1. Inventaire Dynamique Proxmox
|
||||||
|
# ==============================================================================
|
||||||
|
|
||||||
|
# inventory/proxmox.yml
|
||||||
|
---
|
||||||
|
plugin: community.general.proxmox
|
||||||
|
url: https://proxmox.example.com:8006
|
||||||
|
user: ansible@pve
|
||||||
|
password: !vault |
|
||||||
|
$ANSIBLE_VAULT;1.1;AES256
|
||||||
|
...
|
||||||
|
validate_certs: no
|
||||||
|
|
||||||
|
# Grouper automatiquement par tags
|
||||||
|
compose:
|
||||||
|
ansible_host: proxmox_ipconfig0.ip | regex_replace('/.*', '')
|
||||||
|
|
||||||
|
keyed_groups:
|
||||||
|
# Grouper par couche (infrastructure)
|
||||||
|
- prefix: layer
|
||||||
|
key: proxmox_tags | select('match', '^layer-[1-4]$') | first | default('unknown')
|
||||||
|
|
||||||
|
# Grouper par tenant
|
||||||
|
- prefix: tenant
|
||||||
|
key: proxmox_tags | select('match', '^tenant-t[0-9]{3}$') | first | default('none')
|
||||||
|
|
||||||
|
# Grouper par environnement
|
||||||
|
- prefix: env
|
||||||
|
key: proxmox_tags | select('match', '^(prod|stg|dev|test)$') | first | default('unknown')
|
||||||
|
|
||||||
|
# Grouper par catégorie
|
||||||
|
- prefix: category
|
||||||
|
key: proxmox_tags | select('match', '^(infrastructure|tenant)$') | first | default('unknown')
|
||||||
|
|
||||||
|
# ==============================================================================
|
||||||
|
# 2. Playbook de Création VM Infrastructure
|
||||||
|
# ==============================================================================
|
||||||
|
|
||||||
|
# playbooks/create-infra-vm.yml
|
||||||
|
---
|
||||||
|
- name: Créer VM Infrastructure selon nomenclature v2.0
|
||||||
|
hosts: localhost
|
||||||
|
gather_facts: no
|
||||||
|
|
||||||
|
vars_prompt:
|
||||||
|
- name: vm_layer
|
||||||
|
prompt: "Couche (1-4)"
|
||||||
|
private: no
|
||||||
|
|
||||||
|
- name: vm_type
|
||||||
|
prompt: "Type service (ex: 00=DNS, 10=VPN, 20=Git)"
|
||||||
|
private: no
|
||||||
|
|
||||||
|
- name: vm_instance
|
||||||
|
prompt: "Instance (01-99)"
|
||||||
|
private: no
|
||||||
|
|
||||||
|
- name: vm_service_name
|
||||||
|
prompt: "Nom du service (ex: dns-master, ansible-ctrl)"
|
||||||
|
private: no
|
||||||
|
|
||||||
|
- name: vm_environment
|
||||||
|
prompt: "Environnement (prod/stg/dev/test)"
|
||||||
|
private: no
|
||||||
|
default: "prod"
|
||||||
|
|
||||||
|
vars:
|
||||||
|
member_id: "{{ lookup('env', 'MEMBER_ID') | default('czp', true) }}"
|
||||||
|
|
||||||
|
# Calcul VMID
|
||||||
|
vmid: "{{ '%s%02d' | format(tenant_id, vm_instance|int) }}"
|
||||||
|
|
||||||
|
# Construction nom VM
|
||||||
|
vm_name: "{{ member_id }}-t{{ tenant_id }}-{{ vm_service_type }}-{{ vm_environment }}-{{ '%02d' | format(vm_instance|int) }}"
|
||||||
|
|
||||||
|
# Allocation IP (via script ou manuel)
|
||||||
|
vm_ip: "{{ lookup('pipe', 'allocate-ip.sh ' + tenant_id) | regex_search('\\d+\\.\\d+\\.\\d+\\.\\d+') }}"
|
||||||
|
|
||||||
|
# DNS
|
||||||
|
vm_dns: "{{ vm_service_type }}.t{{ tenant_id }}.{{ member_id }}.alliance-boreale.ca"
|
||||||
|
|
||||||
|
tasks:
|
||||||
|
- name: Afficher plan de création
|
||||||
|
debug:
|
||||||
|
msg:
|
||||||
|
- "VMID: {{ vmid }}"
|
||||||
|
- "Nom: {{ vm_name }}"
|
||||||
|
- "IP: {{ vm_ip }}/23"
|
||||||
|
- "DNS: {{ vm_dns }}"
|
||||||
|
- "Tenant: {{ tenant_id }}"
|
||||||
|
|
||||||
|
- name: Confirmer création
|
||||||
|
pause:
|
||||||
|
prompt: "Créer cette VM? (Ctrl+C pour annuler)"
|
||||||
|
|
||||||
|
- name: Créer VM dans Proxmox
|
||||||
|
community.general.proxmox_kvm:
|
||||||
|
api_host: "{{ proxmox_host }}"
|
||||||
|
api_user: "{{ proxmox_user }}"
|
||||||
|
api_password: "{{ proxmox_password }}"
|
||||||
|
node: "{{ proxmox_node }}"
|
||||||
|
|
||||||
|
vmid: "{{ vmid }}"
|
||||||
|
name: "{{ vm_name }}"
|
||||||
|
|
||||||
|
clone: "{{ vm_template | default('debian-12-template') }}"
|
||||||
|
full: yes
|
||||||
|
|
||||||
|
cores: "{{ vm_cores | default(2) }}"
|
||||||
|
memory: "{{ vm_memory | default(2048) }}"
|
||||||
|
|
||||||
|
net:
|
||||||
|
net0: "virtio,bridge=vmbr0,tag=10"
|
||||||
|
|
||||||
|
ipconfig:
|
||||||
|
ipconfig0: "ip={{ vm_ip }}/23,gw=10.0.0.1"
|
||||||
|
|
||||||
|
tags:
|
||||||
|
- tenant
|
||||||
|
- "tenant-t{{ tenant_id }}"
|
||||||
|
- "{{ vm_environment }}"
|
||||||
|
- "service-{{ vm_service_type }}"
|
||||||
|
|
||||||
|
state: present
|
||||||
|
|
||||||
|
- name: Enregistrer IP dans IPAM
|
||||||
|
ansible.builtin.lineinfile:
|
||||||
|
path: "/etc/alliance-boreale/ipam.txt"
|
||||||
|
line: "{{ tenant_id }} {{ vm_ip }} {{ ansible_date_time.date }} {{ vmid }}"
|
||||||
|
create: yes
|
||||||
|
|
||||||
|
- name: Créer entrée DNS
|
||||||
|
ansible.builtin.lineinfile:
|
||||||
|
path: "/var/lib/alliance-boreale/dns-records.zone"
|
||||||
|
line: "{{ vm_dns }}. IN A {{ vm_ip }}"
|
||||||
|
delegate_to: "{{ dns_master_host }}"
|
||||||
|
|
||||||
|
- name: Démarrer la VM
|
||||||
|
community.general.proxmox_kvm:
|
||||||
|
api_host: "{{ proxmox_host }}"
|
||||||
|
api_user: "{{ proxmox_user }}"
|
||||||
|
api_password: "{{ proxmox_password }}"
|
||||||
|
vmid: "{{ vmid }}"
|
||||||
|
state: started
|
||||||
|
|
||||||
|
# ==============================================================================
|
||||||
|
# 4. Role Ansible - Conformité Nomenclature
|
||||||
|
# ==============================================================================
|
||||||
|
|
||||||
|
# roles/nomenclature_compliance/tasks/main.yml
|
||||||
|
---
|
||||||
|
- name: Vérifier que le VMID est conforme
|
||||||
|
ansible.builtin.assert:
|
||||||
|
that:
|
||||||
|
- inventory_hostname_short | regex_search('^[a-z]+-((infra)|(t[0-9]{3}))-')
|
||||||
|
fail_msg: "Nom VM non conforme au standard v2.0"
|
||||||
|
success_msg: "Nom VM conforme"
|
||||||
|
|
||||||
|
- name: Extraire les informations de nomenclature
|
||||||
|
ansible.builtin.set_fact:
|
||||||
|
vm_member: "{{ inventory_hostname_short | regex_replace('^([a-z]+)-.*', '\\1') }}"
|
||||||
|
vm_category: "{{ 'infrastructure' if 'infra' in inventory_hostname_short else 'tenant' }}"
|
||||||
|
vm_tenant_id: "{{ inventory_hostname_short | regex_replace('.*-(t[0-9]{3})-.*', '\\1') if 'infra' not in inventory_hostname_short else 'N/A' }}"
|
||||||
|
|
||||||
|
- name: Afficher informations extraites
|
||||||
|
debug:
|
||||||
|
msg:
|
||||||
|
- "Membre: {{ vm_member }}"
|
||||||
|
- "Catégorie: {{ vm_category }}"
|
||||||
|
- "Tenant: {{ vm_tenant_id }}"
|
||||||
|
|
||||||
|
- name: Vérifier cohérence IP
|
||||||
|
ansible.builtin.assert:
|
||||||
|
that:
|
||||||
|
- ansible_default_ipv4.address | regex_search('^10\\.0\\.')
|
||||||
|
fail_msg: "IP hors de la plage 10.0.0.0/8"
|
||||||
|
success_msg: "IP dans la plage correcte"
|
||||||
|
|
||||||
|
- name: Appliquer tags de conformité
|
||||||
|
ansible.builtin.set_fact:
|
||||||
|
nomenclature_compliant: true
|
||||||
|
nomenclature_version: "v2.0"
|
||||||
|
nomenclature_validated_date: "{{ ansible_date_time.iso8601 }}"
|
||||||
|
|
||||||
|
# ==============================================================================
|
||||||
|
# 5. Playbook d'Audit Ansible
|
||||||
|
# ==============================================================================
|
||||||
|
|
||||||
|
# playbooks/audit-nomenclature-ansible.yml
|
||||||
|
---
|
||||||
|
- name: Audit de conformité Nomenclature v2.0 via Ansible
|
||||||
|
hosts: all
|
||||||
|
gather_facts: yes
|
||||||
|
|
||||||
|
tasks:
|
||||||
|
- name: Vérifier nom VM
|
||||||
|
ansible.builtin.set_fact:
|
||||||
|
name_compliant: "{{ inventory_hostname_short | regex_search('^[a-z]+-(infra|t[0-9]{3})-[a-z0-9-]+-[a-z]+-[0-9]{2}
|
||||||
|
|
||||||
|
vars:
|
||||||
|
member_id: "{{ lookup('env', 'MEMBER_ID') | default('czp', true) }}"
|
||||||
|
|
||||||
|
# Calcul VMID
|
||||||
|
vmid: "{{ '0%s%02d%02d' | format(vm_layer, vm_type|int, vm_instance|int) }}"
|
||||||
|
|
||||||
|
# Construction nom VM
|
||||||
|
vm_name: "{{ member_id }}-infra-{{ vm_service_name }}-{{ vm_environment }}-{{ '%02d' | format(vm_instance|int) }}"
|
||||||
|
|
||||||
|
# Calcul IP selon couche
|
||||||
|
vm_ip: >-
|
||||||
|
{{
|
||||||
|
('10.0.0.' if vm_layer == '1' else
|
||||||
|
'10.0.1.' if vm_layer == '4' else
|
||||||
|
'10.0.2.' if vm_layer == '2' else
|
||||||
|
'10.0.3.') + (vm_type|int * 10 + vm_instance|int)|string
|
||||||
|
}}
|
||||||
|
|
||||||
|
# DNS
|
||||||
|
vm_dns: "{{ vm_service_name }}.infra.{{ member_id }}.alliance-boreale.ca"
|
||||||
|
|
||||||
|
tasks:
|
||||||
|
- name: Afficher plan de création
|
||||||
|
debug:
|
||||||
|
msg:
|
||||||
|
- "VMID: {{ vmid }}"
|
||||||
|
- "Nom: {{ vm_name }}"
|
||||||
|
- "IP: {{ vm_ip }}/24"
|
||||||
|
- "DNS: {{ vm_dns }}"
|
||||||
|
|
||||||
|
- name: Confirmer création
|
||||||
|
pause:
|
||||||
|
prompt: "Créer cette VM? (Ctrl+C pour annuler, Entrée pour continuer)"
|
||||||
|
|
||||||
|
- name: Créer VM dans Proxmox
|
||||||
|
community.general.proxmox_kvm:
|
||||||
|
api_host: "{{ proxmox_host }}"
|
||||||
|
api_user: "{{ proxmox_user }}"
|
||||||
|
api_password: "{{ proxmox_password }}"
|
||||||
|
node: "{{ proxmox_node }}"
|
||||||
|
|
||||||
|
vmid: "{{ vmid }}"
|
||||||
|
name: "{{ vm_name }}"
|
||||||
|
|
||||||
|
clone: "debian-12-template"
|
||||||
|
full: yes
|
||||||
|
|
||||||
|
cores: 2
|
||||||
|
memory: 2048
|
||||||
|
|
||||||
|
net:
|
||||||
|
net0: "virtio,bridge=vmbr0,tag={{ '2' if vm_layer == '2' else '1' }}"
|
||||||
|
|
||||||
|
ipconfig:
|
||||||
|
ipconfig0: "ip={{ vm_ip }}/24,gw=10.0.0.1"
|
||||||
|
|
||||||
|
tags:
|
||||||
|
- infrastructure
|
||||||
|
- "layer-{{ vm_layer }}"
|
||||||
|
- "{{ vm_environment }}"
|
||||||
|
- "service-{{ vm_service_name }}"
|
||||||
|
|
||||||
|
state: present
|
||||||
|
register: vm_created
|
||||||
|
|
||||||
|
- name: Démarrer la VM
|
||||||
|
community.general.proxmox_kvm:
|
||||||
|
api_host: "{{ proxmox_host }}"
|
||||||
|
api_user: "{{ proxmox_user }}"
|
||||||
|
api_password: "{{ proxmox_password }}"
|
||||||
|
vmid: "{{ vmid }}"
|
||||||
|
state: started
|
||||||
|
|
||||||
|
- name: Créer entrée DNS
|
||||||
|
ansible.builtin.lineinfile:
|
||||||
|
path: "/var/lib/alliance-boreale/dns-records.zone"
|
||||||
|
line: "{{ vm_dns }}. IN A {{ vm_ip }}"
|
||||||
|
create: yes
|
||||||
|
delegate_to: "{{ dns_master_host }}"
|
||||||
|
|
||||||
|
- name: Ajouter au monitoring
|
||||||
|
ansible.builtin.template:
|
||||||
|
src: templates/icinga2-host.conf.j2
|
||||||
|
dest: "/etc/icinga2/conf.d/hosts/{{ vm_name }}.conf"
|
||||||
|
delegate_to: "{{ monitoring_host }}"
|
||||||
|
notify: Reload Icinga2
|
||||||
|
|
||||||
|
# ==============================================================================
|
||||||
|
# 3. Playbook de Création VM Tenant
|
||||||
|
# ==============================================================================
|
||||||
|
|
||||||
|
# playbooks/create-tenant-vm.yml
|
||||||
|
---
|
||||||
|
- name: Créer VM Tenant selon nomenclature v2.0
|
||||||
|
hosts: localhost
|
||||||
|
gather_facts: no
|
||||||
|
|
||||||
|
vars_prompt:
|
||||||
|
- name: tenant_id
|
||||||
|
prompt: "Tenant ID (001-999)"
|
||||||
|
private: no
|
||||||
|
|
||||||
|
- name: vm_instance
|
||||||
|
prompt: "Instance (01-99)"
|
||||||
|
private: no
|
||||||
|
|
||||||
|
- name: vm_service_type
|
||||||
|
prompt: "Type (web/api/db/cache/worker)"
|
||||||
|
private: no
|
||||||
|
|
||||||
|
- name: vm_environment
|
||||||
|
prompt: "Environnement (prod/stg/dev) is not none }}"
|
||||||
|
|
||||||
|
- name: Vérifier IP dans plage correcte
|
||||||
|
ansible.builtin.set_fact:
|
||||||
|
ip_compliant: "{{ ansible_default_ipv4.address | regex_search('^10\\.0\\.') is not none }}"
|
||||||
|
|
||||||
|
- name: Extraire VMID si possible
|
||||||
|
ansible.builtin.shell: |
|
||||||
|
qm list | awk -v host="{{ inventory_hostname_short }}" '$2 == host {print $1}'
|
||||||
|
register: vmid_check
|
||||||
|
delegate_to: "{{ proxmox_node }}"
|
||||||
|
changed_when: false
|
||||||
|
failed_when: false
|
||||||
|
|
||||||
|
- name: Valider VMID
|
||||||
|
ansible.builtin.command: validate-vmid.sh {{ vmid_check.stdout }}
|
||||||
|
register: vmid_validation
|
||||||
|
delegate_to: localhost
|
||||||
|
changed_when: false
|
||||||
|
failed_when: false
|
||||||
|
when: vmid_check.stdout != ""
|
||||||
|
|
||||||
|
- name: Générer rapport
|
||||||
|
ansible.builtin.set_fact:
|
||||||
|
compliance_report:
|
||||||
|
hostname: "{{ inventory_hostname }}"
|
||||||
|
name_compliant: "{{ name_compliant }}"
|
||||||
|
ip_compliant: "{{ ip_compliant }}"
|
||||||
|
vmid: "{{ vmid_check.stdout | default('N/A') }}"
|
||||||
|
vmid_compliant: "{{ vmid_validation.rc == 0 if vmid_check.stdout != '' else false }}"
|
||||||
|
overall_compliant: "{{ name_compliant and ip_compliant and (vmid_validation.rc == 0 if vmid_check.stdout != '' else false) }}"
|
||||||
|
|
||||||
|
- name: Afficher résultat
|
||||||
|
ansible.builtin.debug:
|
||||||
|
var: compliance_report
|
||||||
|
|
||||||
|
- name: Sauvegarder rapport
|
||||||
|
ansible.builtin.copy:
|
||||||
|
content: "{{ compliance_report | to_nice_json }}"
|
||||||
|
dest: "/var/lib/alliance-boreale/compliance/{{ inventory_hostname }}.json"
|
||||||
|
delegate_to: localhost
|
||||||
|
|
||||||
|
################################################################################
|
||||||
|
# PARTIE 2: TEMPLATES TERRAFORM
|
||||||
|
################################################################################
|
||||||
|
|
||||||
|
# ==============================================================================
|
||||||
|
# 6. Module Terraform - VM Infrastructure
|
||||||
|
# ==============================================================================
|
||||||
|
|
||||||
|
# modules/infra-vm/main.tf
|
||||||
|
terraform {
|
||||||
|
required_providers {
|
||||||
|
proxmox = {
|
||||||
|
source = "telmate/proxmox"
|
||||||
|
version = "~> 2.9"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
variable "member_id" {
|
||||||
|
description = "ID du membre (ex: czp, nul, tli)"
|
||||||
|
type = string
|
||||||
|
}
|
||||||
|
|
||||||
|
variable "layer" {
|
||||||
|
description = "Couche (1-4)"
|
||||||
|
type = number
|
||||||
|
validation {
|
||||||
|
condition = var.layer >= 1 && var.layer <= 4
|
||||||
|
error_message = "La couche doit être entre 1 et 4."
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
variable "service_type" {
|
||||||
|
description = "Type de service (00-99)"
|
||||||
|
type = number
|
||||||
|
}
|
||||||
|
|
||||||
|
variable "instance" {
|
||||||
|
description = "Numéro d'instance (01-99)"
|
||||||
|
type = number
|
||||||
|
}
|
||||||
|
|
||||||
|
variable "service_name" {
|
||||||
|
description = "Nom du service (ex: dns-master, ansible-ctrl)"
|
||||||
|
type = string
|
||||||
|
}
|
||||||
|
|
||||||
|
variable "environment" {
|
||||||
|
description = "Environnement (prod/stg/dev/test)"
|
||||||
|
type = string
|
||||||
|
default = "prod"
|
||||||
|
}
|
||||||
|
|
||||||
|
variable "cores" {
|
||||||
|
description = "Nombre de CPU cores"
|
||||||
|
type = number
|
||||||
|
default = 2
|
||||||
|
}
|
||||||
|
|
||||||
|
variable "memory" {
|
||||||
|
description = "RAM en MB"
|
||||||
|
type = number
|
||||||
|
default = 2048
|
||||||
|
}
|
||||||
|
|
||||||
|
variable "disk_size" {
|
||||||
|
description = "Taille disque en GB"
|
||||||
|
type = string
|
||||||
|
default = "20G"
|
||||||
|
}
|
||||||
|
|
||||||
|
# Calculs locaux
|
||||||
|
locals {
|
||||||
|
# VMID: 0CTTII
|
||||||
|
vmid = format("0%d%02d%02d", var.layer, var.service_type, var.instance)
|
||||||
|
|
||||||
|
# Nom VM: <membre>-infra-<type>-<env>-<instance>
|
||||||
|
vm_name = format("%s-infra-%s-%s-%02d",
|
||||||
|
var.member_id,
|
||||||
|
var.service_name,
|
||||||
|
var.environment,
|
||||||
|
var.instance
|
||||||
|
)
|
||||||
|
|
||||||
|
# IP selon couche
|
||||||
|
ip_base = var.layer == 1 ? "10.0.0" : (
|
||||||
|
var.layer == 2 ? "10.0.2" : (
|
||||||
|
var.layer == 3 ? "10.0.3" : "10.0.1"))
|
||||||
|
|
||||||
|
vm_ip = format("%s.%d", local.ip_base, var.service_type * 10 + var.instance)
|
||||||
|
|
||||||
|
# DNS
|
||||||
|
vm_dns = format("%s.infra.%s.alliance-boreale.ca",
|
||||||
|
var.service_name,
|
||||||
|
var.member_id
|
||||||
|
)
|
||||||
|
}
|
||||||
|
|
||||||
|
resource "proxmox_vm_qemu" "infra_vm" {
|
||||||
|
name = local.vm_name
|
||||||
|
vmid = local.vmid
|
||||||
|
target_node = var.proxmox_node
|
||||||
|
|
||||||
|
clone = "debian-12-template"
|
||||||
|
full_clone = true
|
||||||
|
|
||||||
|
cores = var.cores
|
||||||
|
memory = var.memory
|
||||||
|
|
||||||
|
network {
|
||||||
|
model = "virtio"
|
||||||
|
bridge = "vmbr0"
|
||||||
|
tag = var.layer == 2 ? 2 : 1
|
||||||
|
}
|
||||||
|
|
||||||
|
disk {
|
||||||
|
type = "scsi"
|
||||||
|
storage = "local-lvm"
|
||||||
|
size = var.disk_size
|
||||||
|
}
|
||||||
|
|
||||||
|
ipconfig0 = "ip=${local.vm_ip}/24,gw=10.0.0.1"
|
||||||
|
|
||||||
|
tags = join(";", [
|
||||||
|
"infrastructure",
|
||||||
|
"layer-${var.layer}",
|
||||||
|
var.environment,
|
||||||
|
"service-${var.service_name}",
|
||||||
|
"nomenclature-v2"
|
||||||
|
])
|
||||||
|
|
||||||
|
lifecycle {
|
||||||
|
ignore_changes = [
|
||||||
|
network,
|
||||||
|
]
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
output "vmid" {
|
||||||
|
value = local.vmid
|
||||||
|
}
|
||||||
|
|
||||||
|
output "vm_name" {
|
||||||
|
value = local.vm_name
|
||||||
|
}
|
||||||
|
|
||||||
|
output "vm_ip" {
|
||||||
|
value = local.vm_ip
|
||||||
|
}
|
||||||
|
|
||||||
|
output "vm_dns" {
|
||||||
|
value = local.vm_dns
|
||||||
|
}
|
||||||
|
|
||||||
|
# ==============================================================================
|
||||||
|
# 7. Module Terraform - VM Tenant
|
||||||
|
# ==============================================================================
|
||||||
|
|
||||||
|
# modules/tenant-vm/main.tf
|
||||||
|
terraform {
|
||||||
|
required_providers {
|
||||||
|
proxmox = {
|
||||||
|
source = "telmate/proxmox"
|
||||||
|
version = "~> 2.9"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
variable "member_id" {
|
||||||
|
description = "ID du membre"
|
||||||
|
type = string
|
||||||
|
}
|
||||||
|
|
||||||
|
variable "tenant_id" {
|
||||||
|
description = "Tenant ID (001-999)"
|
||||||
|
type = string
|
||||||
|
validation {
|
||||||
|
condition = can(regex("^[0-9]{3}$", var.tenant_id))
|
||||||
|
error_message = "Tenant ID doit être au format NNN (ex: 001)."
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
variable "instance" {
|
||||||
|
description = "Numéro d'instance (01-99)"
|
||||||
|
type = number
|
||||||
|
}
|
||||||
|
|
||||||
|
variable "service_type" {
|
||||||
|
description = "Type de service (web/api/db/cache/worker)"
|
||||||
|
type = string
|
||||||
|
}
|
||||||
|
|
||||||
|
variable "environment" {
|
||||||
|
description = "Environnement"
|
||||||
|
type = string
|
||||||
|
default = "prod"
|
||||||
|
}
|
||||||
|
|
||||||
|
variable "ip_address" {
|
||||||
|
description = "Adresse IP (optionnel, auto-alloué si vide)"
|
||||||
|
type = string
|
||||||
|
default = ""
|
||||||
|
}
|
||||||
|
|
||||||
|
variable "cores" {
|
||||||
|
type = number
|
||||||
|
default = 2
|
||||||
|
}
|
||||||
|
|
||||||
|
variable "memory" {
|
||||||
|
type = number
|
||||||
|
default = 2048
|
||||||
|
}
|
||||||
|
|
||||||
|
locals {
|
||||||
|
# VMID: TTTII
|
||||||
|
vmid = format("%s%02d", var.tenant_id, var.instance)
|
||||||
|
|
||||||
|
# Nom VM
|
||||||
|
vm_name = format("%s-t%s-%s-%s-%02d",
|
||||||
|
var.member_id,
|
||||||
|
var.tenant_id,
|
||||||
|
var.service_type,
|
||||||
|
var.environment,
|
||||||
|
var.instance
|
||||||
|
)
|
||||||
|
|
||||||
|
# IP (utiliser celle fournie ou calculer)
|
||||||
|
vm_ip = var.ip_address != "" ? var.ip_address : format("10.0.10.%d",
|
||||||
|
(tonumber(var.tenant_id) - 1) * 10 + var.instance
|
||||||
|
)
|
||||||
|
|
||||||
|
# DNS
|
||||||
|
vm_dns = format("%s.t%s.%s.alliance-boreale.ca",
|
||||||
|
var.service_type,
|
||||||
|
var.tenant_id,
|
||||||
|
var.member_id
|
||||||
|
)
|
||||||
|
}
|
||||||
|
|
||||||
|
resource "proxmox_vm_qemu" "tenant_vm" {
|
||||||
|
name = local.vm_name
|
||||||
|
vmid = local.vmid
|
||||||
|
target_node = var.proxmox_node
|
||||||
|
|
||||||
|
clone = var.vm_template
|
||||||
|
full_clone = true
|
||||||
|
|
||||||
|
cores = var.cores
|
||||||
|
memory = var.memory
|
||||||
|
|
||||||
|
network {
|
||||||
|
model = "virtio"
|
||||||
|
bridge = "vmbr0"
|
||||||
|
tag = 10
|
||||||
|
}
|
||||||
|
|
||||||
|
disk {
|
||||||
|
type = "scsi"
|
||||||
|
storage = "local-lvm"
|
||||||
|
size = var.disk_size
|
||||||
|
}
|
||||||
|
|
||||||
|
ipconfig0 = "ip=${local.vm_ip}/23,gw=10.0.0.1"
|
||||||
|
|
||||||
|
tags = join(";", [
|
||||||
|
"tenant",
|
||||||
|
"tenant-t${var.tenant_id}",
|
||||||
|
var.environment,
|
||||||
|
"service-${var.service_type}",
|
||||||
|
"nomenclature-v2"
|
||||||
|
])
|
||||||
|
}
|
||||||
|
|
||||||
|
# Enregistrer dans IPAM
|
||||||
|
resource "null_resource" "register_ipam" {
|
||||||
|
provisioner "local-exec" {
|
||||||
|
command = "echo '${var.tenant_id} ${local.vm_ip} ${timestamp()} ${local.vmid}' >> /etc/alliance-boreale/ipam.txt"
|
||||||
|
}
|
||||||
|
|
||||||
|
depends_on = [proxmox_vm_qemu.tenant_vm]
|
||||||
|
}
|
||||||
|
|
||||||
|
output "vmid" {
|
||||||
|
value = local.vmid
|
||||||
|
}
|
||||||
|
|
||||||
|
output "vm_name" {
|
||||||
|
value = local.vm_name
|
||||||
|
}
|
||||||
|
|
||||||
|
output "vm_ip" {
|
||||||
|
value = local.vm_ip
|
||||||
|
}
|
||||||
|
|
||||||
|
output "vm_dns" {
|
||||||
|
value = local.vm_dns
|
||||||
|
}
|
||||||
|
|
||||||
|
# ==============================================================================
|
||||||
|
# 8. Exemple d'Utilisation Terraform
|
||||||
|
# ==============================================================================
|
||||||
|
|
||||||
|
# main.tf - Exemple de déploiement complet
|
||||||
|
terraform {
|
||||||
|
required_version = ">= 1.0"
|
||||||
|
|
||||||
|
required_providers {
|
||||||
|
proxmox = {
|
||||||
|
source = "telmate/proxmox"
|
||||||
|
version = "~> 2.9"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
provider "proxmox" {
|
||||||
|
pm_api_url = var.proxmox_api_url
|
||||||
|
pm_user = var.proxmox_user
|
||||||
|
pm_password = var.proxmox_password
|
||||||
|
pm_tls_insecure = true
|
||||||
|
}
|
||||||
|
|
||||||
|
variable "proxmox_api_url" {}
|
||||||
|
variable "proxmox_user" {}
|
||||||
|
variable "proxmox_password" {}
|
||||||
|
variable "proxmox_node" { default = "pve1" }
|
||||||
|
variable "member_id" { default = "czp" }
|
||||||
|
|
||||||
|
# Infrastructure minimale Bronze
|
||||||
|
module "dns_master" {
|
||||||
|
source = "./modules/infra-vm"
|
||||||
|
|
||||||
|
member_id = var.member_id
|
||||||
|
layer = 2
|
||||||
|
service_type = 0 # DNS
|
||||||
|
instance = 1
|
||||||
|
service_name = "dns-master"
|
||||||
|
|
||||||
|
cores = 2
|
||||||
|
memory = 4096
|
||||||
|
}
|
||||||
|
|
||||||
|
module "ansible_controller" {
|
||||||
|
source = "./modules/infra-vm"
|
||||||
|
|
||||||
|
member_id = var.member_id
|
||||||
|
layer = 4
|
||||||
|
service_type = 0 # Ansible
|
||||||
|
instance = 1
|
||||||
|
service_name = "ansible-ctrl"
|
||||||
|
}
|
||||||
|
|
||||||
|
module "backup_server" {
|
||||||
|
source = "./modules/infra-vm"
|
||||||
|
|
||||||
|
member_id = var.member_id
|
||||||
|
layer = 3
|
||||||
|
service_type = 30 # Backup
|
||||||
|
instance = 1
|
||||||
|
service_name = "pbs-backup"
|
||||||
|
|
||||||
|
cores = 4
|
||||||
|
memory = 8192
|
||||||
|
disk_size = "500G"
|
||||||
|
}
|
||||||
|
|
||||||
|
# Premier tenant - Stack complète
|
||||||
|
module "tenant001_web" {
|
||||||
|
source = "./modules/tenant-vm"
|
||||||
|
|
||||||
|
member_id = var.member_id
|
||||||
|
tenant_id = "001"
|
||||||
|
instance = 1
|
||||||
|
service_type = "web"
|
||||||
|
}
|
||||||
|
|
||||||
|
module "tenant001_api" {
|
||||||
|
source = "./modules/tenant-vm"
|
||||||
|
|
||||||
|
member_id = var.member_id
|
||||||
|
tenant_id = "001"
|
||||||
|
instance = 11
|
||||||
|
service_type = "api-fastapi"
|
||||||
|
}
|
||||||
|
|
||||||
|
module "tenant001_db" {
|
||||||
|
source = "./modules/tenant-vm"
|
||||||
|
|
||||||
|
member_id = var.member_id
|
||||||
|
tenant_id = "001"
|
||||||
|
instance = 21
|
||||||
|
service_type = "db-postgres"
|
||||||
|
|
||||||
|
cores = 4
|
||||||
|
memory = 8192
|
||||||
|
}
|
||||||
|
|
||||||
|
# Outputs
|
||||||
|
output "infrastructure" {
|
||||||
|
value = {
|
||||||
|
dns_master = {
|
||||||
|
vmid = module.dns_master.vmid
|
||||||
|
name = module.dns_master.vm_name
|
||||||
|
ip = module.dns_master.vm_ip
|
||||||
|
dns = module.dns_master.vm_dns
|
||||||
|
}
|
||||||
|
ansible = {
|
||||||
|
vmid = module.ansible_controller.vmid
|
||||||
|
name = module.ansible_controller.vm_name
|
||||||
|
ip = module.ansible_controller.vm_ip
|
||||||
|
dns = module.ansible_controller.vm_dns
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
output "tenant_001" {
|
||||||
|
value = {
|
||||||
|
web = module.tenant001_web
|
||||||
|
api = module.tenant001_api
|
||||||
|
db = module.tenant001_db
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
# ==============================================================================
|
||||||
|
# 9. Variables Terraform
|
||||||
|
# ==============================================================================
|
||||||
|
|
||||||
|
# variables.tf
|
||||||
|
variable "member_id" {
|
||||||
|
description = "ID du membre de L'Alliance Boréale"
|
||||||
|
type = string
|
||||||
|
|
||||||
|
validation {
|
||||||
|
condition = can(regex("^[a-z]{2,4}$", var.member_id))
|
||||||
|
error_message = "member_id doit être 2-4 lettres minuscules."
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
variable "proxmox_node" {
|
||||||
|
description = "Nœud Proxmox cible"
|
||||||
|
type = string
|
||||||
|
default = "pve1"
|
||||||
|
}
|
||||||
|
|
||||||
|
variable "dns_domain" {
|
||||||
|
description = "Domaine DNS de L'Alliance"
|
||||||
|
type = string
|
||||||
|
default = "alliance-boreale.ca"
|
||||||
|
}
|
||||||
|
|
||||||
|
variable "vm_template" {
|
||||||
|
description = "Template VM par défaut"
|
||||||
|
type = string
|
||||||
|
default = "debian-12-template"
|
||||||
|
}
|
||||||
|
|
||||||
|
# ==============================================================================
|
||||||
|
# 10. Makefile pour Automatisation
|
||||||
|
# ==============================================================================
|
||||||
|
|
||||||
|
# Makefile
|
||||||
|
.PHONY: help audit migrate plan apply destroy
|
||||||
|
|
||||||
|
help:
|
||||||
|
@echo "Commandes disponibles:"
|
||||||
|
@echo " make audit - Audit de conformité"
|
||||||
|
@echo " make plan - Plan Terraform"
|
||||||
|
@echo " make apply - Appliquer Terraform"
|
||||||
|
@echo " make destroy - Détruire infrastructure Terraform"
|
||||||
|
@echo " make ansible - Exécuter playbooks Ansible"
|
||||||
|
|
||||||
|
audit:
|
||||||
|
@echo "=== Audit Nomenclature v2.0 ==="
|
||||||
|
audit-nomenclature.sh
|
||||||
|
ansible-playbook playbooks/audit-nomenclature-ansible.yml
|
||||||
|
|
||||||
|
plan:
|
||||||
|
terraform plan -out=tfplan
|
||||||
|
|
||||||
|
apply:
|
||||||
|
terraform apply tfplan
|
||||||
|
|
||||||
|
destroy:
|
||||||
|
terraform destroy
|
||||||
|
|
||||||
|
ansible:
|
||||||
|
ansible-playbook playbooks/configure-all.yml -i inventory/proxmox.yml
|
||||||
|
|
||||||
|
# ==============================================================================
|
||||||
|
# FIN DES TEMPLATES
|
||||||
|
# ==============================================================================
|
||||||
|
|
||||||
|
vars:
|
||||||
|
member_id: "{{ lookup('env', 'MEMBER_ID') | default('czp', true) }}"
|
||||||
|
|
||||||
|
# Calcul VMID
|
||||||
|
vmid: "{{ '0%s%02d%02d' | format(vm_layer, vm_type|int, vm_instance|int) }}"
|
||||||
|
|
||||||
|
# Construction nom VM
|
||||||
|
vm_name: "{{ member_id }}-infra-{{ vm_service_name }}-{{ vm_environment }}-{{ '%02d' | format(vm_instance|int) }}"
|
||||||
|
|
||||||
|
# Calcul IP selon couche
|
||||||
|
vm_ip: >-
|
||||||
|
{{
|
||||||
|
('10.0.0.' if vm_layer == '1' else
|
||||||
|
'10.0.1.' if vm_layer == '4' else
|
||||||
|
'10.0.2.' if vm_layer == '2' else
|
||||||
|
'10.0.3.') + (vm_type|int * 10 + vm_instance|int)|string
|
||||||
|
}}
|
||||||
|
|
||||||
|
# DNS
|
||||||
|
vm_dns: "{{ vm_service_name }}.infra.{{ member_id }}.alliance-boreale.ca"
|
||||||
|
|
||||||
|
tasks:
|
||||||
|
- name: Afficher plan de création
|
||||||
|
debug:
|
||||||
|
msg:
|
||||||
|
- "VMID: {{ vmid }}"
|
||||||
|
- "Nom: {{ vm_name }}"
|
||||||
|
- "IP: {{ vm_ip }}/24"
|
||||||
|
- "DNS: {{ vm_dns }}"
|
||||||
|
|
||||||
|
- name: Confirmer création
|
||||||
|
pause:
|
||||||
|
prompt: "Créer cette VM? (Ctrl+C pour annuler, Entrée pour continuer)"
|
||||||
|
|
||||||
|
- name: Créer VM dans Proxmox
|
||||||
|
community.general.proxmox_kvm:
|
||||||
|
api_host: "{{ proxmox_host }}"
|
||||||
|
api_user: "{{ proxmox_user }}"
|
||||||
|
api_password: "{{ proxmox_password }}"
|
||||||
|
node: "{{ proxmox_node }}"
|
||||||
|
|
||||||
|
vmid: "{{ vmid }}"
|
||||||
|
name: "{{ vm_name }}"
|
||||||
|
|
||||||
|
clone: "debian-12-template"
|
||||||
|
full: yes
|
||||||
|
|
||||||
|
cores: 2
|
||||||
|
memory: 2048
|
||||||
|
|
||||||
|
net:
|
||||||
|
net0: "virtio,bridge=vmbr0,tag={{ '2' if vm_layer == '2' else '1' }}"
|
||||||
|
|
||||||
|
ipconfig:
|
||||||
|
ipconfig0: "ip={{ vm_ip }}/24,gw=10.0.0.1"
|
||||||
|
|
||||||
|
tags:
|
||||||
|
- infrastructure
|
||||||
|
- "layer-{{ vm_layer }}"
|
||||||
|
- "{{ vm_environment }}"
|
||||||
|
- "service-{{ vm_service_name }}"
|
||||||
|
|
||||||
|
state: present
|
||||||
|
register: vm_created
|
||||||
|
|
||||||
|
- name: Démarrer la VM
|
||||||
|
community.general.proxmox_kvm:
|
||||||
|
api_host: "{{ proxmox_host }}"
|
||||||
|
api_user: "{{ proxmox_user }}"
|
||||||
|
api_password: "{{ proxmox_password }}"
|
||||||
|
vmid: "{{ vmid }}"
|
||||||
|
state: started
|
||||||
|
|
||||||
|
- name: Créer entrée DNS
|
||||||
|
ansible.builtin.lineinfile:
|
||||||
|
path: "/var/lib/alliance-boreale/dns-records.zone"
|
||||||
|
line: "{{ vm_dns }}. IN A {{ vm_ip }}"
|
||||||
|
create: yes
|
||||||
|
delegate_to: "{{ dns_master_host }}"
|
||||||
|
|
||||||
|
- name: Ajouter au monitoring
|
||||||
|
ansible.builtin.template:
|
||||||
|
src: templates/icinga2-host.conf.j2
|
||||||
|
dest: "/etc/icinga2/conf.d/hosts/{{ vm_name }}.conf"
|
||||||
|
delegate_to: "{{ monitoring_host }}"
|
||||||
|
notify: Reload Icinga2
|
||||||
|
|
||||||
|
# ==============================================================================
|
||||||
|
# 3. Playbook de Création VM Tenant
|
||||||
|
# ==============================================================================
|
||||||
|
|
||||||
|
# playbooks/create-tenant-vm.yml
|
||||||
|
---
|
||||||
|
- name: Créer VM Tenant selon nomenclature v2.0
|
||||||
|
hosts: localhost
|
||||||
|
gather_facts: no
|
||||||
|
|
||||||
|
vars_prompt:
|
||||||
|
- name: tenant_id
|
||||||
|
prompt: "Tenant ID (001-999)"
|
||||||
|
private: no
|
||||||
|
|
||||||
|
- name: vm_instance
|
||||||
|
prompt: "Instance (01-99)"
|
||||||
|
private: no
|
||||||
|
|
||||||
|
- name: vm_service_type
|
||||||
|
prompt: "Type (web/api/db/cache/worker)"
|
||||||
|
private: no
|
||||||
|
|
||||||
|
- name: vm_environment
|
||||||
|
prompt: "Environnement (prod/stg/dev
|
||||||
Loading…
Reference in a new issue