diff --git a/docs/guides/guide-netbox b/docs/guides/guide-netbox new file mode 100644 index 0000000..5799893 --- /dev/null +++ b/docs/guides/guide-netbox @@ -0,0 +1,203 @@ +# **MANUEL DE L’OPÉRATEUR – NETBOX PRODUCTION** +**Version : 1.0 – 31/10/2025** +**Infrastructure : Debian 12 – sans Docker – Ansible + Forgejo + nftables** + +--- + +## OBJECTIF +Ce manuel te permet de **créer, maintenir, dépanner et détruire** un serveur **NetBox** de **production** en **5 minutes**, **de façon reproductible**, **sécurisée**, et **sans boîte noire**. + +--- + +## PRÉREQUIS (avant de commencer) + +| Élément | Détail | +|--------|-------| +| **VM** | Debian 12 Bookworm (genericcloud) | +| **Compte** | `ansible` avec **clé SSH publique** dans `~/.ssh/authorized_keys` | +| **Sudo** | `ansible ALL=(ALL) NOPASSWD: ALL` dans `/etc/sudoers.d/ansible` | +| **Réseau** | IP fixe + DNS A record → `netbox.tondomaine.com` | +| **Forgejo** | Repo `netbox-deploy` cloné localement ou via SSH | +| **Ansible** | `ansible >= 2.14` installé sur ton poste ou runner Forgejo | +| **Vault** | Mot de passe Ansible Vault stocké dans **Forgejo Secrets** → `ANSIBLE_VAULT_PASS` | + +--- + +## 1. CRÉER UN NOUVEAU SERVEUR NETBOX (5 min) + +### Étapes + +```bash +# 1. Cloner le repo (si pas déjà fait) +git clone ssh://git@forgejo.tondomaine.com/tonuser/netbox-deploy.git +cd netbox-deploy + +# 2. Ajouter la nouvelle VM dans l’inventaire +nano inventories/production/hosts +``` +```ini +[netbox] +netbox-prod2 ansible_host=203.0.113.42 ansible_user=ansible +``` + +```bash +# 3. (Optionnel) Personnaliser les variables +cp inventories/production/group_vars/all.yml inventories/production/host_vars/netbox-prod2.yml +nano inventories/production/host_vars/netbox-prod2.yml +``` +→ Modifie : +```yaml +netbox_domain: netbox2.tondomaine.com +letsencrypt_email: admin@tondomaine.com +``` + +```bash +# 4. Lancer le déploiement +ansible-playbook -i inventories/production/hosts site.yml \ + --limit netbox-prod2 \ + --vault-password-file <(echo $ANSIBLE_VAULT_PASS) +``` + +> **Résultat** : NetBox accessible sur `https://netbox2.tondomaine.com` en **moins de 5 min** + +--- + +## 2. OPÉRATIONS COURANTES + +| Action | Commande | +|--------|----------| +| **Vérifier le service** | `sudo systemctl status netbox` | +| **Redémarrer NetBox** | `sudo systemctl restart netbox` | +| **Voir les logs** | `journalctl -u netbox -f` | +| **Accéder à la DB** | `sudo -u postgres psql -d netbox` | +| **Backup manuel** | `sudo -u postgres pg_dump netbox > /opt/netbox/backups/netbox-$(date +%F).sql` | +| **Vérifier nftables** | `sudo nft list ruleset` | +| **Renouveler SSL** | `sudo certbot renew` | +| **Mettre à jour NetBox** | Voir §3 | + +--- + +## 3. MISE À JOUR NETBOX (sécurisée) + +### Playbook dédié : `upgrade.yml` + +```yaml +# upgrade.yml +- name: Mettre à jour NetBox + hosts: netbox + become: yes + tasks: + - name: Stopper NetBox + systemd: name=netbox state=stopped + + - name: Pull dernière version + git: + repo: https://github.com/netbox-community/netbox.git + dest: /opt/netbox/src + version: "v4.1.0" # ← change ici + become_user: netbox + + - name: Mettre à jour dépendances + pip: + requirements: /opt/netbox/src/requirements.txt + virtualenv: /opt/netbox/venv + become_user: netbox + + - name: Migrer DB + command: /opt/netbox/venv/bin/python manage.py migrate + args: { chdir: /opt/netbox/src/netbox } + become_user: netbox + + - name: Collect static + command: /opt/netbox/venv/bin/python manage.py collectstatic --no-input + args: { chdir: /opt/netbox/src/netbox } + become_user: netbox + + - name: Démarrer NetBox + systemd: name=netbox state=started +``` + +```bash +ansible-playbook -i inventories/production/hosts upgrade.yml \ + --vault-password-file <(echo $ANSIBLE_VAULT_PASS) +``` + +--- + +## 4. DÉPANNAGE RAPIDE + +| Symptôme | Diagnostic | Solution | +|--------|----------|----------| +| **502 Bad Gateway** | Nginx → Gunicorn down | `sudo systemctl status netbox` → `restart netbox` | +| **Login refusé** | Mauvais mot de passe | Réinitialiser : `python manage.py shell` → `User.objects.filter(username='admin').first().set_password('nouveau')` | +| **DB erreur** | PostgreSQL down | `sudo systemctl status postgresql` | +| **SSL expiré** | Certbot échoue | `sudo certbot renew --dry-run` → corrige DNS | +| **IP bloquée** | nftables | `sudo nft list ruleset` → ajoute règle temporaire | + +--- + +## 5. SAUVEGARDE & RESTAURATION + +### Backup automatique (cron) + +```bash +# /etc/cron.daily/netbox-backup +#!/bin/bash +BACKUP_DIR="/opt/netbox/backups" +DATE=$(date +%F) +sudo -u postgres pg_dump netbox > $BACKUP_DIR/netbox-$DATE.sql +find $BACKUP_DIR -name "*.sql" -mtime +30 -delete +``` + +```bash +chmod +x /etc/cron.daily/netbox-backup +``` + +### Restauration + +```bash +sudo -u postgres psql -d netbox < /opt/netbox/backups/netbox-2025-10-31.sql +``` + +--- + +## 6. DÉSACTIVATION / SUPPRESSION + +```bash +# 1. Supprimer du DNS +# 2. Arrêter services +sudo systemctl stop netbox nginx + +# 3. Supprimer données (irréversible) +sudo rm -rf /opt/netbox +sudo -u postgres dropdb netbox +sudo -u postgres dropuser netbox + +# 4. Nettoyer nftables (optionnel) +sudo nft flush ruleset +sudo systemctl disable nftables +``` + +--- + +## 7. SÉCURITÉ – CHECKLIST OPÉRATEUR + +| Vérification | Fréquence | +|-------------|----------| +| `certbot renew --dry-run` | Hebdo | +| `nft list ruleset` | Mensuel | +| `fail2ban-client status` | Mensuel | +| `ansible-playbook site.yml --check` | Avant mise à jour | +| Rotation logs (`journalctl --vacuum-time=30d`) | Trimestriel | + +--- + +## 8. RÉFÉRENCES + +| Lien | Usage | +|-----|------| +| `https://netbox.tondomaine.com` | Interface web | +| Forgejo → `netbox-deploy` | Code source | +| `/opt/netbox/src/netbox` | Code NetBox | +| `/etc/nftables.conf` | Firewall | +| `journalctl -u netbox` | Logs |