alliance-boreale/ansible/devis phases 2.5 et 3.md
Dan Allaire 3e438623c7
Some checks are pending
CI / yaml-lint (push) Waiting to run
CI / ssot-export (push) Waiting to run
CI / tests (push) Waiting to run
CI / docs (push) Waiting to run
Devis des artéfacts à produire
2025-11-01 18:07:06 -04:00

2337 lines
No EOL
61 KiB
Markdown
Raw Blame History

This file contains invisible Unicode characters

This file contains invisible Unicode characters that are indistinguishable to humans but may be processed differently by a computer. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# 📋 DEVIS PHASE 2.5 : PKI PUBLIQUE ALLIANCE BORÉALE
**Version :** 1.0
**Date :** 2025-11-01
**Projet :** Alliance Boréale - Infrastructure PKI
**Membre :** Chezlepro Inc.
**Auteur :** Claude (Profils #4 Architecte Réseau, #10 Auditeur Sécurité)
**Statut :** Devis pour nouveau fil de discussion
---
## 🎯 OBJECTIF
Déployer une **PKI publique** pour l'Alliance Boréale servant de **racine de confiance collective** pour :
- Tous les membres de l'Alliance
- Tous les clients (tenants) des membres
- Signature des artefacts (code, documents, votes)
- Authentification mutuelle (mTLS services)
- Communications sécurisées (S/MIME, Git signing)
**Principe fondamental** : Gouvernance collective via **Shamir Secret Sharing (5/3)** + Transparence totale.
---
## 📦 LIVRABLES
### 1. INFRASTRUCTURE TECHNIQUE
#### 1.1 Serveur PKI (VMID 02003)
**VM** : `ca.infra.chezlepro.ca` (10.0.2.12)
**Specs** :
- RAM : 2GB
- CPU : 2 cores
- Disk : 20GB
- OS : Ubuntu 22.04 LTS
**Logiciel** : **step-ca** (Smallstep Certificate Authority)
**Fonctionnalités** :
- CA Intermédiaire Chezlepro (signée par CA Racine)
- ACME protocol (auto-renewal)
- API REST (intégration FastAPI)
- OCSP responder (vérification révocations)
- Metrics Prometheus
- Backups automatiques
---
#### 1.2 Rôle Ansible : `step-ca`
**Structure complète** :
```
roles/step-ca/
├── tasks/
│ ├── main.yml # Orchestration
│ ├── install.yml # Installation step-ca
│ ├── intermediate-ca.yml # Config CA Intermédiaire
│ ├── provisioners.yml # ACME, JWK, etc.
│ ├── ocsp.yml # OCSP responder
│ ├── nginx.yml # Reverse proxy HTTPS
│ ├── backup.yml # Backups automatiques
│ ├── firewall.yml # nftables
│ └── validate.yml # Tests post-déploiement
├── templates/
│ ├── ca.json.j2 # Config step-ca
│ ├── step-ca.service.j2 # Systemd
│ ├── nginx-ca.conf.j2 # Nginx vhost
│ ├── provisioners/
│ │ ├── acme.json.j2 # Provisioner ACME
│ │ ├── jwk.json.j2 # Provisioner JWK
│ │ └── ansible.json.j2 # Provisioner Ansible
│ └── backup.sh.j2 # Script backup
├── files/
│ ├── intermediate-ca.crt # Certificat CA Intermédiaire (signé offline)
│ ├── intermediate-ca.key # Clé privée CA Intermédiaire (chiffrée)
│ └── root-ca.crt # Certificat CA Racine (public)
├── handlers/
│ └── main.yml # restart step-ca, reload nginx
└── defaults/
└── main.yml # Variables par défaut
```
**Points critiques** :
- ⚠️ `intermediate-ca.crt` et `intermediate-ca.key` doivent être générés **AVANT** déploiement (cérémonie offline)
- ⚠️ Clé privée CA Intermédiaire chiffrée avec passphrase stockée dans Ansible Vault
---
#### 1.3 Rôle Ansible : `pki-client`
**Structure** :
```
roles/pki-client/
├── tasks/
│ ├── main.yml # Installation client
│ ├── install-root-ca.yml # Installation root-ca.crt
│ ├── request-certificate.yml # Demande certificat service
│ ├── auto-renew.yml # Cron renouvellement
│ └── validate.yml # Tests
├── templates/
│ ├── renew-cert.sh.j2 # Script renouvellement
│ └── renew-cert.timer.j2 # Systemd timer
├── files/
│ └── root-ca.crt # CA Racine (distribué partout)
├── handlers/
│ └── main.yml # reload services si cert renouvelé
└── defaults/
└── main.yml
```
**Déployé sur** : TOUS les serveurs (Phase 1, 2, 3+)
---
#### 1.4 Site web PKI : `https://ca.alliance-boreale.ca`
**Contenu** (pages statiques + Jekyll/Hugo) :
```
ca.alliance-boreale.ca/
├── index.html # Page accueil
├── download/
│ ├── root-ca.crt # Téléchargement certificat racine
│ ├── root-ca.crt.sha256 # Hash SHA256
│ └── root-ca.crt.asc # Signature GPG
├── docs/
│ ├── cp.pdf # Certificate Policy
│ ├── cps.pdf # Certification Practice Statement
│ ├── install-guide.pdf # Guide installation
│ └── incident-response.pdf # Plan incidents
├── ceremonies/
│ ├── 2025-11-root-ca-creation.md # PV cérémonie fondatrice
│ ├── 2025-11-root-ca-creation.mp4 # Vidéo (optionnel)
│ └── blockchain-proof.txt # Hash + TxID Bitcoin
├── crl/
│ └── root-ca.crl # Certificate Revocation List
└── ocsp/ # OCSP responder endpoint
```
**Hébergement** : Pages statiques sur `ca.infra.chezlepro.ca` via Nginx
---
### 2. GOUVERNANCE & DOCUMENTATION
#### 2.1 Certificate Policy (CP)
**Document** : `Certificate_Policy_Alliance_Boreale_v1.0.pdf`
**Structure** (RFC 3647 compliant) :
```markdown
# Certificate Policy - Alliance Boréale
Version 1.0 | 2025-11-01
## 1. Introduction
### 1.1 Aperçu Alliance Boréale
### 1.2 Identification du document
- OID: 1.3.6.1.4.1.XXXXX.1 (à obtenir)
- Version: 1.0
- Statut: Production
### 1.3 Portée
- Membres Alliance Boréale
- Clients (tenants) des membres
- Artefacts logiciels Alliance
### 1.4 Parties prenantes
- CA Racine: Gouvernance collective (Shamir 5/3)
- CA Intermédiaires: Membres fédérés
- Sujets: Services, personnes, artefacts
- Utilisateurs: Tous ceux qui font confiance
## 2. Responsabilités
### 2.1 Obligations CA Racine
### 2.2 Obligations CA Intermédiaires
### 2.3 Obligations sujets certificats
### 2.4 Obligations parties utilisatrices
## 3. Identification et authentification
### 3.1 Processus enregistrement
### 3.2 Vérification identité
### 3.3 Authentification renouvellement
### 3.4 Révocation
## 4. Cycle de vie certificats
### 4.1 Demande certificat
### 4.2 Émission
### 4.3 Acceptation
### 4.4 Suspension/Révocation
### 4.5 Renouvellement
### 4.6 Re-keying
## 5. Contrôles opérationnels
### 5.1 Protection clés privées
- CA Racine: Offline, Shamir 5/3, coffres bancaires
- CA Intermédiaires: Online, HSM ou chiffrement fort
### 5.2 Séparation des rôles
### 5.3 Logs et audit
### 5.4 Archivage
### 5.5 Gestion incidents
## 6. Contrôles sécurité physique
### 6.1 CA Racine: Machine airgapped dédiée
### 6.2 CA Intermédiaires: Datacenter sécurisé
## 7. Contrôles sécurité technique
### 7.1 Génération clés
### 7.2 Algorithmes cryptographiques
- RSA 4096 bits (CA Racine/Intermédiaires)
- RSA 2048 ou ECDSA P-256 (certificats finaux)
- SHA-256 minimum
### 7.3 Durées de vie
- CA Racine: 20 ans
- CA Intermédiaires: 2 ans
- Certificats serveurs: 90 jours (auto-renew)
- Code signing: 1 an
## 8. Profils certificats
### 8.1 Certificats serveurs TLS
### 8.2 Certificats code signing
### 8.3 Certificats email (S/MIME)
### 8.4 Certificats clients
## 9. Audit et conformité
### 9.1 Audits internes (peer review annuel)
### 9.2 Rapports publics
### 9.3 Gestion non-conformités
## 10. Dispositions légales
### 10.1 Limitation responsabilité
### 10.2 Garanties
### 10.3 Confidentialité
### 10.4 Propriété intellectuelle
## Annexes
- A. Définitions
- B. OIDs utilisés
- C. Algorithmes approuvés
- D. Contacts
```
**Longueur** : 40-50 pages
**Format** : Markdown + PDF généré
**Publication** :
- Site web PKI
- Repository Git public
- Document 15 dans `/mnt/project/`
---
#### 2.2 Certification Practice Statement (CPS)
**Document** : `Certification_Practice_Statement_Alliance_Boreale_v1.0.pdf`
**Structure** (implémentation concrète de la CP) :
```markdown
# Certification Practice Statement - Alliance Boréale
Version 1.0 | 2025-11-01
## 1. Introduction
### 1.1 Lien avec Certificate Policy
### 1.2 Outils utilisés
- step-ca (Smallstep)
- Shamir Secret Sharing (ssss)
- OpenSSL
- Ansible
## 2. Organisation
### 2.1 Structure gouvernance
- Cercle Opérationnel (gestion CA Racine)
- Membres fédérés (gestion CA Intermédiaires)
### 2.2 Contacts
- security@alliance-boreale.ca
- Incident response: incidents@alliance-boreale.ca
## 3. Processus opérationnels
### 3.1 Génération CA Racine
[Procédure détaillée cérémonie fondatrice]
### 3.2 Génération CA Intermédiaires
[Procédure cérémonie bi-annuelle]
### 3.3 Émission certificats quotidiens
[API step-ca, ACME, etc.]
## 4. Architecture technique
### 4.1 CA Racine (offline)
- Hardware: Raspberry Pi 4 dédié
- Storage: 3x USB chiffrées (AES-256)
- Localisation: 3 coffres bancaires distincts
### 4.2 CA Intermédiaires (online)
- VM Ubuntu 22.04 LTS
- step-ca version X.Y.Z
- PostgreSQL backend
## 5. Procédures cérémonies
### 5.1 Cérémonie fondatrice (CA Racine)
[Checklist complète, étape par étape]
### 5.2 Cérémonies bi-annuelles (signature CA Intermédiaires)
[Checklist, quorum 3/5, enregistrement, publication]
## 6. Gestion révocations
### 6.1 Processus révocation
### 6.2 CRL (Certificate Revocation List)
- Publication: https://ca.alliance-boreale.ca/crl/
- Mise à jour: quotidienne
### 6.3 OCSP (Online Certificate Status Protocol)
- Endpoint: http://ocsp.ca.alliance-boreale.ca
## 7. Sécurité opérationnelle
### 7.1 Backups
- CA Intermédiaire: backup quotidien, rétention 30j
- Logs: rétention 1 an
### 7.2 Monitoring
- Prometheus metrics
- Alerting Icinga2
### 7.3 Gestion incidents
[Procédure, contacts, escalade]
## 8. Conformité
### 8.1 Audits internes
- Fréquence: annuelle
- Auditeurs: pairs (rotation membres)
- Rapport public
### 8.2 Revue CP/CPS
- Fréquence: annuelle ou si changement majeur
## Annexes
- A. Templates certificats (x509v3)
- B. Configuration step-ca
- C. Scripts automatisation
- D. Changelog
```
**Longueur** : 30-40 pages
**Format** : Markdown + PDF
---
#### 2.3 Root CA Distribution Guide
**Document** : `Root_CA_Installation_Guide_v1.0.pdf`
**Structure** :
````markdown
# Guide d'installation - Certificat Racine Alliance Boréale
## Pourquoi installer ce certificat ?
Vous êtes :
- ✅ Membre de l'Alliance Boréale
- ✅ Client (tenant) d'un membre
- ✅ Partenaire de l'Alliance
Installer le certificat racine vous permet de :
- Accéder aux services sans avertissement navigateur
- Vérifier authenticité artefacts signés (code, documents)
- Utiliser authentification mutuelle (certificats clients)
## Téléchargement sécurisé
### Option A : Site web officiel
https://ca.alliance-boreale.ca/download/root-ca.crt
**Vérification** :
```bash
sha256sum root-ca.crt
# Doit afficher: abc123def456...
````
### Option B : Git (recommandé)
```bash
git clone https://git.alliance-boreale.ca/alliance-boreale/pki-public
cd pki-public
gpg --verify root-ca.crt.asc root-ca.crt
```
## Installation par système
### Ubuntu / Debian
```bash
sudo cp root-ca.crt /usr/local/share/ca-certificates/alliance-boreale.crt
sudo update-ca-certificates
```
### RHEL / Fedora
```bash
sudo cp root-ca.crt /etc/pki/ca-trust/source/anchors/
sudo update-ca-trust
```
### macOS
```bash
sudo security add-trusted-cert -d -r trustRoot \
-k /Library/Keychains/System.keychain root-ca.crt
```
### Windows
1. Double-clic sur `root-ca.crt`
2. "Installer le certificat..."
3. "Ordinateur local"
4. "Placer tous les certificats dans le magasin suivant"
5. Sélectionner "Autorités de certification racines de confiance"
6. Terminer
### Firefox (tous OS)
1. Paramètres → Vie privée et sécurité
2. Certificats → Afficher les certificats
3. Autorités → Importer
4. Sélectionner `root-ca.crt`
5. ✅ "Confirmer cette AC pour identifier des sites web"
## Vérification installation
### Linux / macOS
```bash
# Tester avec un service Alliance
curl -v https://sso.infra.chezlepro.ca 2>&1 | grep "SSL certificate verify ok"
```
### Windows / Firefox
Visiter https://sso.infra.chezlepro.ca → Pas d'avertissement = OK
## Révocation (si nécessaire)
Si vous ne faites plus confiance à l'Alliance Boréale :
### Linux
```bash
sudo rm /usr/local/share/ca-certificates/alliance-boreale.crt
sudo update-ca-certificates --fresh
```
### macOS
```bash
sudo security delete-certificate -c "Alliance Boréale Root CA" \
/Library/Keychains/System.keychain
```
### Windows
Panneau de configuration → Certificats → Supprimer
## Support
Questions : support@alliance-boreale.ca Sécurité : security@alliance-boreale.ca
````
**Longueur** : 8-10 pages
**Format** : Markdown + PDF
**Traductions** : FR + EN (minimum)
---
#### 2.4 Key Ceremony Procedures
**Document** : `Key_Ceremony_Procedures_v1.0.pdf`
**Structure** :
```markdown
# Procédures Cérémonies PKI - Alliance Boréale
## 1. Cérémonie Fondatrice (CA Racine) - UNE FOIS
### Prérequis
- [ ] 5 membres fondateurs confirmés
- [ ] 3 membres minimum disponibles (quorum)
- [ ] Machine dédiée (Raspberry Pi 4 neuf)
- [ ] 5 clés USB neuves (chiffrées)
- [ ] 3 coffres bancaires réservés
- [ ] Notaire (optionnel)
### Matériel requis
- Raspberry Pi 4 (4GB RAM, 32GB SD)
- Clavier, souris, écran
- 5x USB 3.0 (16GB minimum)
- Imprimante (backup papier)
- Caméra (enregistrement optionnel)
### Procédure détaillée
#### Étape 1 : Préparation machine (Jour J-7)
```bash
# Installation OS propre
1. Télécharger Raspberry Pi OS Lite (vérifier hash)
2. Flasher SD card
3. Boot, update, install tools
sudo apt update && sudo apt install -y ssss openssl
4. DÉCONNECTER réseau (airgap)
5. Vérifier: ping 8.8.8.8 (doit échouer)
````
#### Étape 2 : Convocation (Jour J-14)
- Email Cercle Opérationnel
- Ordre du jour publié (Forgejo)
- Confirmation présence 3+ membres
#### Étape 3 : Cérémonie (Jour J)
**9h00 - Accueil & vérification identités**
- Appel nominal
- Vérification pièces d'identité
- Signatures feuille présence
- Démarrage enregistrement vidéo (optionnel)
**9h30 - Génération CA Racine**
```bash
# Sur machine airgapped
cd /tmp/ceremony
# Générer clé privée (RSA 4096)
openssl genrsa -out root-ca.key 4096
# Générer certificat auto-signé (20 ans)
openssl req -x509 -new -nodes \
-key root-ca.key \
-sha256 -days 7300 \
-out root-ca.crt \
-subj "/C=CA/ST=Quebec/O=Alliance Boreale/CN=Alliance Boreale Root CA"
# Vérifier
openssl x509 -in root-ca.crt -text -noout
```
**10h30 - Fragmentation Shamir (5/3)**
```bash
# Fragmenter clé privée
ssss-split -t 3 -n 5 -w root-ca < root-ca.key
# Résultat : 5 lignes imprimées
# 1-abc123def456...
# 2-ghi789jkl012...
# 3-mno345pqr678...
# 4-stu901vwx234...
# 5-yza567bcd890...
```
**11h00 - Distribution fragments**
- Chaque fragment → enveloppe scellée
- Signature enveloppe par détenteur
- Remise en main propre
- Accusé réception
**11h30 - Chiffrement USB**
```bash
# Pour chaque USB
sudo cryptsetup luksFormat /dev/sdX
sudo cryptsetup luksOpen /dev/sdX usb-fragment-1
sudo mkfs.ext4 /dev/mapper/usb-fragment-1
sudo mount /dev/mapper/usb-fragment-1 /mnt
# Copier fragment
echo "1-abc123def456..." > /mnt/fragment.txt
# Backup papier (optionnel)
qrencode -o fragment-1-qr.png < /mnt/fragment.txt
lp fragment-1-qr.png # Imprimer
# Unmount & close
sudo umount /mnt
sudo cryptsetup luksClose usb-fragment-1
```
**12h00 - Mise en coffre**
- 3 membres vont en banque (3 banques différentes)
- Déposent USB en coffre
- Reçoivent reçu
**14h00 - Nettoyage & destruction**
```bash
# EFFACEMENT SÉCURISÉ clé privée
shred -vfz -n 10 root-ca.key
# Vérifier disparition
ls -la root-ca.key # Doit échouer
# Garder root-ca.crt (public)
cp root-ca.crt /tmp/root-ca-public.crt
```
**14h30 - Documentation**
- Rédaction PV
- Signatures GPG des 3 participants
- Hash PV → blockchain Bitcoin
- Publication Forgejo
**15h00 - Clôture**
- Arrêt enregistrement vidéo
- Archivage PV
- Publication publique
#### Étape 4 : Post-cérémonie (Jour J+1)
- Publication PV sur site PKI
- Email tous membres (annonce CA Racine créée)
- Distribution root-ca.crt publiquement
---
## 2. Cérémonie Bi-annuelle (Signature CA Intermédiaires)
### Fréquence
Tous les 2 ans (ou si nouveau membre nécessite CA Intermédiaire)
### Quorum
3 membres sur 5 (fragments Shamir)
### Procédure
#### Étape 1 : Préparation (Jour J-14)
- Convocation Cercle Opérationnel
- 3 membres confirment disponibilité + apportent USB
- Réservation lieu (datacenter neutre ou visio)
#### Étape 2 : Génération CA Intermédiaires (Jour J-7)
**Chaque membre génère son CSR (Certificate Signing Request)** :
```bash
# Sur ca.infra.chezlepro.ca
openssl genrsa -out intermediate-ca.key 4096
openssl req -new -key intermediate-ca.key \
-out intermediate-ca.csr \
-subj "/C=CA/ST=Quebec/O=Alliance Boreale/OU=Chezlepro/CN=Chezlepro Intermediate CA"
```
Envoyer `intermediate-ca.csr` à Cercle Op (Forgejo)
#### Étape 3 : Cérémonie signature (Jour J)
**9h00 - Réunion physique (ou vidéo sécurisée)**
**9h30 - Reconstruction clé CA Racine**
```bash
# Machine airgapped (même Raspberry Pi si possible)
cd /tmp/ceremony-2025-11
# 3 membres insèrent USB, entrent passphrase LUKS
# Copient fragments
# Reconstruction
cat fragment-1.txt fragment-3.txt fragment-5.txt | ssss-combine -t 3 > root-ca.key
# Vérifier
openssl rsa -in root-ca.key -check
# OK → clé valide
```
**10h00 - Signature CSR**
```bash
# Pour chaque membre (exemple: Chezlepro)
openssl x509 -req \
-in chezlepro-intermediate-ca.csr \
-CA root-ca.crt \
-CAkey root-ca.key \
-CAcreateserial \
-out chezlepro-intermediate-ca.crt \
-days 730 \ # 2 ans
-sha256 \
-extensions v3_intermediate_ca \
-extfile openssl.cnf
# Vérifier
openssl verify -CAfile root-ca.crt chezlepro-intermediate-ca.crt
# OK
```
**11h00 - Distribution certificats**
- Remettre `*-intermediate-ca.crt` à chaque membre
- Copie sur USB chiffrée (backup)
**11h30 - EFFACEMENT clé CA Racine**
```bash
shred -vfz -n 10 root-ca.key
sync
# Vérifier disparition
```
**12h00 - Remise USB en coffre**
- 3 membres retournent en banque
- Remettent USB en coffre
**14h00 - Documentation**
- PV cérémonie
- Signatures GPG
- Blockchain timestamp
- Publication Forgejo
#### Étape 4 : Déploiement (Jour J+1)
Chaque membre déploie son CA Intermédiaire :
```bash
ansible-playbook playbooks/phase2.5-pki-deploy.yml \
--limit ca.infra.chezlepro.ca \
--ask-vault-pass
```
---
## 3. Cérémonie Extraordinaire (Compromission)
### Déclenchement
Si CA Racine ou fragments compromis
### Procédure d'urgence
1. Révocation immédiate (CRL + OCSP)
2. Notification tous membres + clients (< 24h)
3. Cérémonie extraordinaire génération nouvelle CA Racine
4. Migration tous certificats (< 7 jours)
### Détails
\[À documenter lors de l'incident, chaque cas est unique\]
---
## Annexes
### A. Checklist matériel
- \[ \] Raspberry Pi 4 (4GB)
- \[ \] SD Card 32GB (neuve)
- \[ \] 5x USB 3.0 16GB (neuves)
- \[ \] Clavier + souris + écran
- \[ \] Imprimante (backup papier)
- \[ \] Caméra (enregistrement)
### B. Checklist logiciels
- \[ \] Raspberry Pi OS Lite (vérifié)
- \[ \] ssss (Shamir)
- \[ \] OpenSSL 3.x
- \[ \] qrencode (QR codes)
- \[ \] cryptsetup (LUKS)
### C. Template PV cérémonie
\[Markdown template\]
### D. Configuration OpenSSL
\[openssl.cnf avec extensions v3_intermediate_ca\]
````
**Longueur** : 25-30 pages
**Format** : Markdown + PDF
---
#### 2.5 Incident Response Plan
**Document** : `PKI_Incident_Response_Plan_v1.0.pdf`
**Structure** :
```markdown
# Plan de Réponse aux Incidents PKI - Alliance Boréale
## 1. Classification incidents
### Sévérité P0 (Critique)
- Compromission clé privée CA Racine
- Compromission clé privée CA Intermédiaire
- Révocation CA Racine/Intermédiaire nécessaire
**Délai réponse** : < 4 heures
**Notification** : Immédiate (tous membres + clients)
### Sévérité P1 (Majeure)
- Émission certificat frauduleux détecté
- Perte fragment Shamir
- Compromission serveur PKI (step-ca)
**Délai réponse** : < 24 heures
**Notification** : Cercle Opérationnel + membres affectés
### Sévérité P2 (Modérée)
- Panne serveur PKI (step-ca down)
- Erreur émission certificat (bug)
- CRL/OCSP indisponible
**Délai réponse** : < 72 heures
**Notification** : Cercle Opérationnel
## 2. Contacts urgence
**Équipe réponse incidents PKI** :
- Responsable : president@alliance-boreale.ca
- Technique : security@alliance-boreale.ca
- Backup : Cercle Opérationnel (Matrix #incidents)
**Escalade** :
1. Détection security@
2. P0/P1 Convocation Cercle Op (< 4h)
3. P0 Notification publique (< 24h)
## 3. Procédures par type
### 3.1 Compromission CA Racine (P0)
**Indicateurs** :
- Fragment Shamir divulgué publiquement
- 3+ fragments perdus/volés
- Émission certificat CA Racine non autorisée
**Actions** :
1. **H+0** : Détection, alerte Cercle Op
2. **H+4** : Réunion urgence (quorum 3/5)
- Évaluation gravité
- Décision : révocation ou surveillance
3. **H+24** : Si révocation nécessaire
- Notification publique (site PKI)
- Email tous membres + clients
- Publication médias sociaux
4. **J+3** : Cérémonie extraordinaire
- Génération nouvelle CA Racine
- Signature nouvelles CA Intermédiaires
5. **J+7** : Migration complète
- Tous certificats ré-émis
- Ancienne CA Racine révoquée
### 3.2 Compromission CA Intermédiaire (P1)
**Indicateurs** :
- Clé privée CA Intermédiaire divulguée
- Serveur step-ca piraté
- Émission certificats frauduleux
**Actions** :
1. **H+0** : Détection, arrêt step-ca
2. **H+4** : Investigation (logs, forensics)
3. **H+24** : Révocation CA Intermédiaire
- CRL mis à jour
- OCSP renvoit "revoked"
4. **J+2** : Demande nouvelle CA Intermédiaire
- Génération nouveau CSR
- Cérémonie signature CA Racine
5. **J+7** : Ré-émission certificats affectés
### 3.3 Perte fragment Shamir (P1)
**Indicateurs** :
- Membre perd accès coffre
- USB défectueuse
- Fragment illisible
**Actions** :
1. **H+0** : Notification Cercle Op
2. **J+1** : Évaluation risque
- 1 fragment perdu sur 5 OK (besoin 3)
- 2 fragments perdus Surveillance
- 3+ fragments perdus P0 (re-keying)
3. **Si 2 fragments perdus** :
- Planifier cérémonie re-keying
- Génération nouveaux fragments
- Migration CA Racine (nouvelle clé)
### 3.4 Certificat frauduleux (P1)
**Indicateurs** :
- Certificat émis sans autorisation
- Certificat pour domaine non contrôlé
- Rapport externe (security researcher)
**Actions** :
1. **H+0** : Vérification (est-ce vraiment frauduleux ?)
2. **H+4** : Si confirmé
- Révocation immédiate
- CRL + OCSP mis à jour
3. **H+24** : Investigation
- Comment émis ? (bug, compromission ?)
- Correctif (patch step-ca, audit)
4. **J+3** : Rapport public
- Transparence totale
- Post-mortem publié
## 4. Communication
### Modèles emails
#### Email P0 (Compromission CA Racine)
````
Objet: \[URGENT\] Incident sécurité PKI Alliance Boréale
Chers membres et clients,
Nous vous informons d'un incident de sécurité P0 affectant notre PKI. La CA Racine Alliance Boréale est potentiellement compromise.
ACTIONS IMMÉDIATES REQUISES:
1. Cesser d'utiliser certificats Alliance Boréale
2. Attendre nouvelle CA Racine (ETA: 7 jours)
Détails: https://ca.alliance-boreale.ca/incidents/2025-11-001
Contact urgence: security@alliance-boreale.ca
Alliance Boréale - Cercle Opérationnel
````
#### Page web incidents
```html
<!-- ca.alliance-boreale.ca/incidents/2025-11-001 -->
<h1>Incident PKI 2025-11-001</h1>
<p>Statut: <span class="critical">EN COURS</span></p>
<p>Sévérité: P0 (Critique)</p>
<p>Détecté: 2025-11-01 14:32 UTC</p>
<h2>Description</h2>
<p>[Description incident]</p>
<h2>Impact</h2>
<ul>
<li>Tous certificats émis par CA Racine compromise</li>
<li>Services affectés: [liste]</li>
</ul>
<h2>Actions utilisateurs</h2>
<ol>
<li>Cesser utilisation certificats</li>
<li>Attendre migration (ETA: 7j)</li>
</ol>
<h2>Timeline</h2>
<ul>
<li>2025-11-01 14:32 - Détection</li>
<li>2025-11-01 18:00 - Notification publique</li>
<li>2025-11-04 10:00 - Cérémonie nouvelle CA</li>
<li>2025-11-08 - Migration complète (prévu)</li>
</ul>
<h2>Mises à jour</h2>
<p>Cette page sera mise à jour toutes les 4 heures.</p>
````
## 5. Post-mortem
Après chaque incident P0/P1, rapport public obligatoire :
**Structure post-mortem** :
```markdown
# Post-Mortem Incident PKI 2025-11-001
## Résumé exécutif
[Quoi, quand, impact, résolution]
## Timeline détaillée
[Chronologie exacte]
## Cause racine
[Analyse technique]
## Actions correctives
- [ ] Court terme (< 1 mois)
- [ ] Moyen terme (< 6 mois)
- [ ] Long terme (amélioration process)
## Leçons apprises
[Ce qu'on fera différemment]
## Questions/Réponses
[FAQ pour communauté]
```
**Publication** :
- Site PKI
- Forgejo
- Email tous membres
**Délai** : < 30 jours après résolution
## Annexes
### A. Checklist incidents
\[Checklist par type P0/P1/P2\]
### B. Contacts urgence
\[Liste téléphones, emails, Matrix\]
### C. Templates communication
\[Emails, pages web, posts Matrix\]
````
**Longueur** : 20-25 pages
**Format** : Markdown + PDF
---
### 3. PLAYBOOKS ANSIBLE
#### 3.1 Playbook : `phase2.5-pki-deploy.yml`
**Déploiement infrastructure PKI** :
```yaml
---
# Alliance Boréale - Phase 2.5 : PKI Publique
# Déploiement CA Intermédiaire + distribution racine
- name: "🔐 Phase 2.5 - Déploiement serveur PKI"
hosts: ca.infra.chezlepro.ca
become: true
pre_tasks:
- name: "⚠️ Vérifier présence certificat CA Intermédiaire"
ansible.builtin.stat:
path: "{{ role_path }}/files/intermediate-ca.crt"
register: intermediate_ca_check
failed_when: not intermediate_ca_check.stat.exists
delegate_to: localhost
run_once: true
tags: always
- name: "📋 Afficher avertissement"
ansible.builtin.debug:
msg: |
⚠️ IMPORTANT ⚠️
Ce playbook nécessite que la CÉRÉMONIE FONDATRICE
ait été exécutée et que les fichiers suivants existent:
- roles/step-ca/files/root-ca.crt (public)
- roles/step-ca/files/intermediate-ca.crt (signé offline)
- roles/step-ca/files/intermediate-ca.key (chiffré)
Si ces fichiers n'existent pas, ARRÊTER maintenant
et exécuter la cérémonie fondatrice d'abord.
tags: always
roles:
- common
- step-ca
post_tasks:
- name: "✅ PKI déployée"
ansible.builtin.debug:
msg: |
✅ Serveur PKI déployé avec succès
URL: https://ca.infra.chezlepro.ca
ACME: https://ca.infra.chezlepro.ca/acme/acme/directory
Prochaines étapes:
1. Tester émission certificat:
step ca certificate test.chezlepro.ca test.crt test.key
2. Déployer pki-client sur tous serveurs:
ansible-playbook phase2.5-pki-client.yml
3. Publier site web PKI:
ansible-playbook phase2.5-pki-website.yml
- name: "🌐 Phase 2.5 - Déploiement site web PKI"
hosts: ca.infra.chezlepro.ca
become: true
tasks:
- name: "📦 Installer générateur site statique"
ansible.builtin.apt:
name: jekyll
state: present
- name: "📁 Déployer contenu site PKI"
ansible.builtin.copy:
src: "{{ playbook_dir }}/../pki-website/"
dest: /var/www/pki/
owner: www-data
group: www-data
mode: '0755'
- name: "🔨 Générer site statique"
ansible.builtin.command:
cmd: jekyll build
chdir: /var/www/pki
become_user: www-data
- name: "⚙️ Configurer Nginx vhost"
ansible.builtin.template:
src: nginx-pki-site.conf.j2
dest: /etc/nginx/sites-available/pki-site
notify: reload nginx
- name: "🔗 Activer site"
ansible.builtin.file:
src: /etc/nginx/sites-available/pki-site
dest: /etc/nginx/sites-enabled/pki-site
state: link
notify: reload nginx
- name: "📡 Phase 2.5 - Distribution CA Racine (tous serveurs)"
hosts: all
become: true
roles:
- pki-client
post_tasks:
- name: "✅ Distribution terminée"
ansible.builtin.debug:
msg: "✅ Certificat CA Racine installé sur {{ inventory_hostname }}"
````
---
#### 3.2 Playbook : `phase2.5-pki-migrate.yml`
**Migration certificats auto-signés → PKI** :
```yaml
---
# Migration certificats Phases 1-2 vers PKI
- name: "🔄 Migration certificats DNS (Phase 1)"
hosts: dns_servers
become: true
tasks:
- name: "🔐 Demander nouveaux certificats"
ansible.builtin.command:
cmd: >
step ca certificate
{{ inventory_hostname }}
/etc/ssl/certs/{{ inventory_hostname }}.crt
/etc/ssl/private/{{ inventory_hostname }}.key
--provisioner acme
args:
creates: "/etc/ssl/certs/{{ inventory_hostname }}.crt"
- name: "⚙️ Reconfigurer PowerDNS API"
ansible.builtin.lineinfile:
path: /etc/powerdns/pdns.conf
regexp: '^webserver-port='
line: 'webserver-port=8081'
notify: restart powerdns
- name: "⚙️ Reconfigurer Nginx"
ansible.builtin.template:
src: nginx-dns-pki.conf.j2
dest: /etc/nginx/sites-available/powerdns
notify: reload nginx
- name: "🔄 Migration certificats Keycloak (Phase 2)"
hosts: idp_servers
become: true
tasks:
- name: "🔐 Demander certificat Keycloak"
ansible.builtin.command:
cmd: >
step ca certificate
sso.infra.chezlepro.ca
/etc/ssl/certs/keycloak.crt
/etc/ssl/private/keycloak.key
--provisioner acme
args:
creates: "/etc/ssl/certs/keycloak.crt"
- name: "⚙️ Reconfigurer Nginx"
ansible.builtin.template:
src: nginx-keycloak-pki.conf.j2
dest: /etc/nginx/sites-available/keycloak
notify: reload nginx
- name: "🔄 Migration certificats Forgejo (Phase 2)"
hosts: forge_servers
become: true
tasks:
- name: "🔐 Demander certificat Forgejo"
ansible.builtin.command:
cmd: >
step ca certificate
git.infra.chezlepro.ca
/etc/ssl/certs/forgejo.crt
/etc/ssl/private/forgejo.key
--provisioner acme
args:
creates: "/etc/ssl/certs/forgejo.crt"
- name: "⚙️ Reconfigurer Nginx"
ansible.builtin.template:
src: nginx-forgejo-pki.conf.j2
dest: /etc/nginx/sites-available/forgejo
notify: reload nginx
- name: "🧪 Validation migration"
hosts: localhost
gather_facts: false
tasks:
- name: "🧪 Tester certificats"
ansible.builtin.uri:
url: "https://{{ item }}"
validate_certs: true
loop:
- ns1.infra.chezlepro.ca:8081
- sso.infra.chezlepro.ca
- git.infra.chezlepro.ca
register: cert_tests
- name: "✅ Migration réussie"
ansible.builtin.debug:
msg: "✅ Tous les services utilisent maintenant la PKI Alliance Boréale"
```
---
### 4. VAULT SECRETS
**Mise à jour** `vault/production.yml` :
```yaml
---
# PHASE 2.5 - PKI
# Passphrase pour clé privée CA Intermédiaire (chiffrée au repos)
vault_pki_intermediate_key_passphrase: "changeme-strong-passphrase-here"
# API key step-ca (admin)
vault_step_ca_admin_password: "changeme-step-ca-admin-password"
# Provisioner passwords
vault_step_ca_provisioner_acme_password: "changeme-acme-provisioner-password"
vault_step_ca_provisioner_jwk_password: "changeme-jwk-provisioner-password"
# PostgreSQL pour step-ca (si backend DB au lieu de files)
vault_postgresql_step_ca_password: "changeme-step-ca-db-password"
```
**Génération secrets** :
```bash
# Passphrases (32 chars)
openssl rand -base64 32
# Passwords (24 chars)
openssl rand -base64 24
```
---
### 5. TESTS & VALIDATION
#### 5.1 Tests automatisés
**Script** : `tests/pki-validation.sh`
```bash
#!/bin/bash
# Tests validation PKI Alliance Boréale
set -e
echo "🧪 Tests PKI Alliance Boréale"
echo "=============================="
# Test 1: CA Racine installée
echo "Test 1: CA Racine installée..."
if openssl verify -CAfile /etc/ssl/certs/alliance-boreale-root-ca.crt \
/etc/ssl/certs/alliance-boreale-root-ca.crt; then
echo "✅ CA Racine installée"
else
echo "❌ CA Racine manquante"
exit 1
fi
# Test 2: Serveur PKI accessible
echo "Test 2: Serveur PKI accessible..."
if curl -s https://ca.infra.chezlepro.ca/health | grep -q "ok"; then
echo "✅ Serveur PKI répond"
else
echo "❌ Serveur PKI inaccessible"
exit 1
fi
# Test 3: ACME endpoint
echo "Test 3: ACME endpoint..."
if curl -s https://ca.infra.chezlepro.ca/acme/acme/directory | grep -q "newAccount"; then
echo "✅ ACME fonctionne"
else
echo "❌ ACME non disponible"
exit 1
fi
# Test 4: Émission certificat test
echo "Test 4: Émission certificat test..."
step ca certificate test-$(date +%s).chezlepro.ca test.crt test.key \
--provisioner acme --force
if [ -f test.crt ]; then
echo "✅ Émission certificat OK"
rm -f test.crt test.key
else
echo "❌ Émission certificat échouée"
exit 1
fi
# Test 5: CRL accessible
echo "Test 5: CRL accessible..."
if curl -s https://ca.infra.chezlepro.ca/crl/root-ca.crl > /dev/null; then
echo "✅ CRL disponible"
else
echo "❌ CRL inaccessible"
exit 1
fi
# Test 6: OCSP responder
echo "Test 6: OCSP responder..."
if curl -s http://ocsp.ca.infra.chezlepro.ca/health | grep -q "ok"; then
echo "✅ OCSP répond"
else
echo "⚠️ OCSP non configuré (optionnel Phase 2.5)"
fi
echo ""
echo "=============================="
echo "✅ Tous les tests passent"
echo "PKI Alliance Boréale opérationnelle"
```
---
## 📊 RESSOURCES REQUISES
### VM
| Service | VMID | FQDN | IP | Specs |
|---------|-------|-----------------------|-----------|----------------------|
| step-ca | 02003 | ca.infra.chezlepro.ca | 10.0.2.12 | 2GB RAM, 2 CPU, 20GB |
### Matériel cérémonie
| Item | Quantité | Coût unitaire | Total |
|----------------------|----------|---------------|-------|
| Raspberry Pi 4 (4GB) | 1 | 80$ | 80$ |
| SD Card 32GB | 1 | 15$ | 15$ |
| USB 3.0 16GB | 5 | 10$ | 50$ |
| Câbles/périphériques | \- | \- | 50$ |
| **Sous-total matériel** | | | **195$** |
### Services externes (optionnels)
| Service | Coût annuel |
|--------------------------------------|--------------------|
| 3x Coffres bancaires | 150-300$ |
| Notarisation (si choisi) | 300-500$/cérémonie |
| Assurance RC (si inclusion stores) | 5 000-20 000$ |
| Audit WebTrust (si inclusion stores) | 15 000-50 000$ |
**Total Phase 2.5 (sans notarisation/audit externe)** : \~500$ one-time + 200$/an (coffres)
---
## ⏱️ TIMELINE
### Préparation (Semaine 1-2)
- Rédaction documents gouvernance (CP, CPS, guides)
- Revue par Cercle Opérationnel
- Achat matériel cérémonie
- Réservation coffres bancaires
### Cérémonie Fondatrice (Semaine 3)
- Jour J-7 : Convocation membres
- Jour J : Cérémonie (8h, 3-5 personnes)
- Jour J+1 : Publication PV, distribution root-ca.crt
### Développement Ansible (Semaine 4-5)
- Rôles `step-ca` et `pki-client`
- Playbooks déploiement
- Tests
### Déploiement (Semaine 6)
- Déploiement serveur PKI (VMID 02003)
- Distribution CA Racine (tous serveurs)
- Site web PKI
### Migration (Semaine 7)
- Remplacement certificats auto-signés Phases 1-2
- Tests validation
- Documentation
**Durée totale** : **7 semaines**
---
## 🎯 CRITÈRES DE SUCCÈS
### Techniques
- CA Racine générée offline (Shamir 5/3)
- CA Intermédiaire Chezlepro opérationnelle
- ACME protocol fonctionnel
- Auto-renewal certificats (90j)
- Tous serveurs Phases 1-2 migrés vers PKI
- CRL publié et à jour
- Tests validation 100% passent
### Gouvernance
- CP/CPS publiés et approuvés
- Cérémonie fondatrice documentée (PV, vidéo, blockchain)
- Fragments Shamir en coffres
- Site web PKI public et accessible
- Guide installation distribué à tous membres
### Adoption
- 100% membres ont installé root-ca.crt
- Documentation lue et comprise
- Processus incident response testé (drill)
---
## 📋 DÉPENDANCES
### Prérequis
- Phase 1 (DNS) déployée
- Phase 2 (Keycloak + Forgejo) déployée
- 3+ membres fondateurs disponibles
- Consensus Cercle Opérationnel
### Bloquants potentiels
- Disponibilité 3 membres simultanément (cérémonie)
- Accès coffres bancaires (délai ouverture)
- Complexité technique (formation requise)
---
## 🔄 MAINTENANCE POST-DÉPLOIEMENT
### Quotidien
- Monitoring step-ca (uptime, logs)
- Génération CRL automatique
### Mensuel
- Vérification backups
- Review logs émission certificats
- Test ACME auto-renewal
### Annuel
- Audit interne PKI (peer review)
- Revue CP/CPS
- Test procédure incident response
### Bi-annuel
- Cérémonie signature nouvelles CA Intermédiaires
---
## 📚 RÉFÉRENCES
- RFC 3647: Certificate Policy and Certification Practice Framework
- RFC 5280: X.509 Public Key Infrastructure
- NIST SP 800-57: Recommendation for Key Management
- Smallstep step-ca documentation
- WebTrust Principles (si inclusion stores, futur)
---
**FIN DEVIS PHASE 2.5**
---
# 📋 DEVIS PHASE 3 : ICINGA2 + FASTAPI PIVOT
**Version :** 1.0
**Date :** 2025-11-01
**Projet :** Alliance Boréale - Monitoring & Pivot
**Membre :** Chezlepro Inc.
**Auteur :** Claude (Profils #4 Architecte Réseau, #6 Architecte Logiciel, #10 Auditeur Sécurité)
**Statut :** Devis pour nouveau fil de discussion
**Prérequis** : Phase 2.5 (PKI) déployée
---
## 🎯 OBJECTIF
Déployer la **couche C5 (Pivot)** + **observabilité complète (C3)** avec :
1. **Icinga2** : Monitoring fonctionnel + BPM (modélisation couches C1-C8)
2. **FastAPI Pivot** : API de gestion infrastructure + provisioning tenants
3. **Grafana** : Dashboards + visualisation (consomme Icinga2 + métriques)
**Principe** : Respecter **adjacent-only** via agents Icinga2 + authentification mTLS (PKI Phase 2.5)
---
## 📦 LIVRABLES
### 1. INFRASTRUCTURE MONITORING (ICINGA2)
#### 1.1 Serveur Icinga2 Master (VMID 03011)
**VM** : `icinga.infra.chezlepro.ca` (10.0.3.10)
**Specs** :
- RAM : 4GB
- CPU : 2 cores
- Disk : 50GB
- OS : Ubuntu 22.04 LTS
**Composants** :
- Icinga2 Master
- Icinga2 Director (config as code)
- Icingaweb2 (interface web)
- Icinga2 Business Process Modeling (BPM)
- PostgreSQL (backend)
- Grafana integration
---
#### 1.2 Rôle Ansible : `icinga2-master`
**Structure** :
```
roles/icinga2-master/
├── tasks/
│ ├── main.yml # Orchestration
│ ├── install.yml # Installation Icinga2
│ ├── postgresql.yml # Base données
│ ├── director.yml # Icinga Director
│ ├── icingaweb2.yml # Interface web
│ ├── bpm.yml # Business Process Modeling
│ ├── pki.yml # Certificats (PKI Phase 2.5)
│ ├── checks.yml # Checks de base
│ ├── notifications.yml # Alerting
│ ├── nginx.yml # Reverse proxy
│ ├── firewall.yml # nftables
│ └── validate.yml # Tests
├── templates/
│ ├── icinga2.conf.j2 # Config master
│ ├── zones.conf.j2 # Zones (master + satellites)
│ ├── constants.conf.j2 # Constantes
│ ├── commands/ # Checks commands
│ │ ├── dns-check.conf.j2
│ │ ├── http-check.conf.j2
│ │ ├── postgresql-check.conf.j2
│ │ └── certificate-check.conf.j2
│ ├── services/ # Service definitions
│ │ ├── dns-services.conf.j2
│ │ ├── web-services.conf.j2
│ │ └── db-services.conf.j2
│ ├── notifications/
│ │ ├── email.conf.j2
│ │ └── matrix.conf.j2
│ ├── director/
│ │ ├── director.ini.j2
│ │ └── kickstart.yml.j2
│ ├── icingaweb2/
│ │ ├── config.ini.j2
│ │ ├── resources.ini.j2
│ │ └── authentication.ini.j2
│ ├── bpm/ # Business processes
│ │ ├── infrastructure-c1-c8.conf.j2
│ │ ├── tenant-health.conf.j2
│ │ └── pki-health.conf.j2
│ └── nginx-icinga.conf.j2
├── files/
│ ├── checks/ # Scripts checks custom
│ │ ├── check_powerdns.sh
│ │ ├── check_keycloak.sh
│ │ ├── check_forgejo.sh
│ │ └── check_step_ca.sh
│ └── dashboards/ # Dashboards Grafana (export)
│ ├── infrastructure-overview.json
│ └── icinga2-metrics.json
├── handlers/
│ └── main.yml
└── defaults/
└── main.yml
```
**Fonctionnalités clés** :
- Checks fonctionnels (pas juste métriques)
- BPM : Modélisation dépendances C1C8
- Director : Config Git-backed (IaC)
- SSO Keycloak pour Icingaweb2
- Agents authentifiés par certificats (PKI)
- Notifications Matrix + Email
- API REST complète
---
#### 1.3 Rôle Ansible : `icinga2-agent`
**Déployé sur** : TOUS les serveurs (Phase 1, 2, 2.5, 3)
**Structure** :
```
roles/icinga2-agent/
├── tasks/
│ ├── main.yml # Installation agent
│ ├── pki.yml # Certificat agent (PKI)
│ ├── zones.yml # Configuration zone
│ ├── firewall.yml # Port 5665
│ └── validate.yml # Test connexion master
├── templates/
│ ├── zones.conf.j2 # Zone config
│ └── constants.conf.j2
├── handlers/
│ └── main.yml
└── defaults/
└── main.yml
```
**Principe adjacent-only** :
- Agents C1-C4 remontent directement à Master (C3)
- Agents C6-C8 (tenants) remontent via Satellite Pivot (C5) Master (C3)
---
#### 1.4 Checks Icinga2
**Checks de base** (tous serveurs) :
| Check | Seuil Warning | Seuil Critical |
|-------------------|---------------|----------------|
| CPU Load | \> 80% | \> 95% |
| RAM Usage | \> 80% | \> 90% |
| Disk Usage | \> 80% | \> 90% |
| Swap Usage | \> 50% | \> 80% |
| Processes | custom | custom |
| Network Interface | down | down |
**Checks spécifiques par service** :
**DNS (PowerDNS)** :
- Query resolution time
- AXFR working (master slave)
- DNSSEC validation
- Zone serial up-to-date
- API responding
**Keycloak** :
- HTTP 200 on /health
- Database connections
- Realm availability
- SSO flow test (synthetic)
**Forgejo** :
- HTTP 200 on /
- Git clone test
- SSH port 2222 open
- Database connections
- Webhooks working
**step-ca (PKI)** :
- ACME endpoint responding
- Certificate issuance test
- CRL up-to-date
- OCSP responding
**FastAPI Pivot** :
- API /health endpoint
- Database connections
- Integration tests (PowerDNS, Keycloak APIs)
---
#### 1.5 Business Process Modeling (BPM)
**Process** : Infrastructure Alliance Boréale (C1-C8)
```
Infrastructure Globale (OK si 90%+ OK)
├── Couche C1 : Physique (OK si tous serveurs UP)
│ ├── ns1.infra.chezlepro.ca
│ ├── ns2.infra.chezlepro.ca
│ ├── sso.infra.chezlepro.ca
│ ├── git.infra.chezlepro.ca
│ ├── ca.infra.chezlepro.ca
│ ├── pivot.infra.chezlepro.ca
│ ├── icinga.infra.chezlepro.ca
│ └── grafana.infra.chezlepro.ca
├── Couche C2 : DNS & PKI (OK si 100% OK - critique)
│ ├── PowerDNS Master (ns1) [CRITICAL]
│ ├── PowerDNS Slave (ns2)
│ ├── DNSSEC Validation
│ ├── step-ca API [CRITICAL]
│ └── ACME Renewal Working
├── Couche C3 : Gouvernance & Supervision (OK si 80%+ OK)
│ ├── Keycloak SSO [CRITICAL]
│ ├── Icinga2 Master (self-check)
│ └── Grafana
├── Couche C4 : Forge & Mutualisation (OK si 100% OK)
│ ├── Forgejo Git [CRITICAL]
│ ├── Forgejo SSH
│ └── Forgejo Actions (CI/CD)
├── Couche C5 : Pivot (OK si API répond)
│ ├── FastAPI /health
│ ├── Database Connections
│ └── Integrations APIs
└── Couches C6-C8 : Tenants (OK si 80%+ OK)
├── Tenant 001 (si déployé)
└── [À venir Phase 4]
```
**Visualisation BPM** : Icingaweb2 Business Process
---
### 2. INFRASTRUCTURE PIVOT (FASTAPI)
#### 2.1 Serveur FastAPI Pivot (VMID 05011)
**VM** : `pivot.infra.chezlepro.ca` (10.0.4.10)
**Specs** :
- RAM : 4GB
- CPU : 2 cores
- Disk : 30GB
- OS : Ubuntu 22.04 LTS
---
#### 2.2 Rôle Ansible : `fastapi-pivot`
**Structure complète** :
```
roles/fastapi-pivot/
├── tasks/
│ ├── main.yml # Orchestration
│ ├── install.yml # Python, venv, deps
│ ├── database.yml # PostgreSQL
│ ├── app.yml # Déploiement app
│ ├── nginx.yml # Reverse proxy + mTLS
│ ├── pki.yml # Certificats
│ ├── systemd.yml # Service uvicorn
│ ├── firewall.yml # nftables
│ └── validate.yml # Tests API
├── templates/
│ ├── .env.j2 # Variables d'environnement
│ ├── fastapi-pivot.service.j2 # Systemd
│ ├── nginx-pivot.conf.j2 # Nginx + mTLS
│ ├── alembic.ini.j2 # Migrations DB
│ └── logging.conf.j2 # Logs structurés
├── files/
│ ├── app/
│ │ ├── main.py # FastAPI app principale
│ │ ├── config.py # Configuration
│ │ ├── database.py # SQLAlchemy setup
│ │ ├── auth.py # OAuth2 Keycloak
│ │ ├── dependencies.py # Dépendances FastAPI
│ │ │
│ │ ├── models/ # SQLAlchemy models
│ │ │ ├── __init__.py
│ │ │ ├── tenant.py
│ │ │ ├── service.py
│ │ │ └── audit_log.py
│ │ │
│ │ ├── schemas/ # Pydantic schemas
│ │ │ ├── __init__.py
│ │ │ ├── tenant.py
│ │ │ ├── service.py
│ │ │ └── health.py
│ │ │
│ │ ├── crud/ # CRUD operations
│ │ │ ├── __init__.py
│ │ │ ├── tenant.py
│ │ │ └── service.py
│ │ │
│ │ ├── routers/ # API routes
│ │ │ ├── __init__.py
│ │ │ ├── health.py # /health, /metrics
│ │ │ ├── services.py # /api/v1/services
│ │ │ ├── tenants.py # /api/v1/tenants
│ │ │ ├── dns.py # /api/v1/dns
│ │ │ ├── keycloak_mgmt.py # /api/v1/keycloak
│ │ │ ├── forgejo.py # /api/v1/forgejo
│ │ │ ├── pki.py # /api/v1/pki
│ │ │ └── monitoring.py # /api/v1/monitoring
│ │ │
│ │ ├── integrations/ # Clients API externes
│ │ │ ├── __init__.py
│ │ │ ├── powerdns.py # Client PowerDNS API
│ │ │ ├── keycloak.py # Client Keycloak Admin
│ │ │ ├── forgejo.py # Client Forgejo API
│ │ │ ├── step_ca.py # Client step-ca API
│ │ │ └── icinga2.py # Client Icinga2 API
│ │ │
│ │ └── utils/ # Utilitaires
│ │ ├── __init__.py
│ │ ├── logging.py
│ │ ├── exceptions.py
│ │ └── validators.py
│ │
│ ├── alembic/ # Migrations DB
│ │ ├── env.py
│ │ ├── script.py.mako
│ │ └── versions/
│ │ └── 001_initial.py
│ │
│ ├── tests/ # Tests unitaires
│ │ ├── __init__.py
│ │ ├── test_health.py
│ │ ├── test_tenants.py
│ │ └── test_integrations.py
│ │
│ └── requirements.txt # Dépendances Python
├── handlers/
│ └── main.yml
└── defaults/
└── main.yml
```
---
#### 2.3 API FastAPI Pivot - Endpoints
**Santé & Métriques** :
```
GET /health # Health check
GET /metrics # Prometheus metrics
GET /docs # OpenAPI docs (Swagger)
```
**Services Infrastructure** :
```
GET /api/v1/services # Liste tous services
GET /api/v1/services/{service} # Détails un service
GET /api/v1/services/{service}/health # Health check service
```
**Gestion Tenants** :
```
GET /api/v1/tenants # Liste tenants
POST /api/v1/tenants # Créer tenant
GET /api/v1/tenants/{id} # Détails tenant
PATCH /api/v1/tenants/{id} # Modifier tenant
DELETE /api/v1/tenants/{id} # Supprimer tenant
POST /api/v1/tenants/{id}/deploy # Déployer tenant
```
**DNS (PowerDNS)** :
```
GET /api/v1/dns/zones # Liste zones
POST /api/v1/dns/zones # Créer zone
GET /api/v1/dns/zones/{zone}/records # Liste records
POST /api/v1/dns/zones/{zone}/records # Ajouter record
DELETE /api/v1/dns/zones/{zone}/records/{id} # Supprimer record
```
**Keycloak (Gestion utilisateurs)** :
```
GET /api/v1/keycloak/users # Liste utilisateurs
POST /api/v1/keycloak/users # Créer utilisateur
GET /api/v1/keycloak/realms # Liste realms
GET /api/v1/keycloak/clients # Liste clients
```
**Forgejo (Gestion repos)** :
```
GET /api/v1/forgejo/repos # Liste repos
POST /api/v1/forgejo/repos # Créer repo
GET /api/v1/forgejo/orgs # Liste organisations
GET /api/v1/forgejo/users # Liste utilisateurs
```
**PKI (Certificats)** :
```
GET /api/v1/pki/certificates # Liste certificats émis
POST /api/v1/pki/certificates # Demander certificat
DELETE /api/v1/pki/certificates/{id} # Révoquer certificat
GET /api/v1/pki/ca/status # Status CA
```
**Monitoring (Icinga2)** :
```
GET /api/v1/monitoring/services # État services
GET /api/v1/monitoring/hosts # État hosts
GET /api/v1/monitoring/bpm # Business processes
GET /api/v1/monitoring/alerts # Alertes actives
```
**Authentification** : OAuth2 Keycloak (Bearer token)
**Autorisation** : Rôles Keycloak
- `alliance-admin` : Accès complet
- `alliance-operator` : Lecture + opérations courantes
- `alliance-viewer` : Lecture seule
---
#### 2.4 Intégrations API
**Client PowerDNS** (`integrations/powerdns.py`) :
```python
class PowerDNSClient:
def __init__(self, url: str, api_key: str):
self.url = url
self.api_key = api_key
async def list_zones(self) -> List[Zone]:
# GET /api/v1/servers/localhost/zones
pass
async def create_zone(self, zone: ZoneCreate) -> Zone:
# POST /api/v1/servers/localhost/zones
pass
async def add_record(self, zone: str, record: Record) -> None:
# PATCH /api/v1/servers/localhost/zones/{zone}
pass
```
**Client Keycloak** (`integrations/keycloak.py`) :
```python
class KeycloakAdminClient:
def __init__(self, url: str, admin_user: str, admin_password: str):
self.url = url
self.admin_user = admin_user
self.admin_password = admin_password
async def get_admin_token(self) -> str:
# POST /realms/master/protocol/openid-connect/token
pass
async def list_users(self, realm: str) -> List[User]:
# GET /admin/realms/{realm}/users
pass
async def create_user(self, realm: str, user: UserCreate) -> User:
# POST /admin/realms/{realm}/users
pass
```
**Client Forgejo** (`integrations/forgejo.py`) :
```python
class ForgejoClient:
def __init__(self, url: str, admin_token: str):
self.url = url
self.admin_token = admin_token
async def list_repos(self, org: str) -> List[Repo]:
# GET /api/v1/orgs/{org}/repos
pass
async def create_repo(self, org: str, repo: RepoCreate) -> Repo:
# POST /api/v1/orgs/{org}/repos
pass
```
**Client step-ca** (`integrations/step_ca.py`) :
```python
class StepCAClient:
def __init__(self, url: str, provisioner: str, password: str):
self.url = url
self.provisioner = provisioner
self.password = password
async def request_certificate(self, csr: str) -> Certificate:
# POST /sign
pass
async def revoke_certificate(self, serial: str) -> None:
# POST /revoke
pass
```
**Client Icinga2** (`integrations/icinga2.py`) :
```python
class Icinga2Client:
def __init__(self, url: str, api_user: str, api_password: str):
self.url = url
self.api_user = api_user
self.api_password = api_password
async def get_service_status(self, host: str, service: str) -> ServiceStatus:
# GET /v1/objects/services
pass
async def get_bp_status(self, bp_name: str) -> BPStatus:
# Custom endpoint via Icingaweb2 API
pass
```
---
### 3. VISUALISATION (GRAFANA)
#### 3.1 Serveur Grafana (VMID 03012)
**VM** : `grafana.infra.chezlepro.ca` (10.0.3.11)
**Specs** :
- RAM : 2GB
- CPU : 2 cores
- Disk : 20GB
- OS : Ubuntu 22.04 LTS
---
#### 3.2 Rôle Ansible : `grafana`
**Structure** :
```
roles/grafana/
├── tasks/
│ ├── main.yml
│ ├── install.yml
│ ├── datasources.yml # Icinga2, PostgreSQL
│ ├── dashboards.yml # Import dashboards
│ ├── sso.yml # OAuth Keycloak
│ ├── nginx.yml # Reverse proxy
│ ├── pki.yml # Certificats
│ ├── firewall.yml
│ └── validate.yml
├── templates/
│ ├── grafana.ini.j2
│ ├── datasources/
│ │ ├── icinga2.yml.j2
│ │ └── postgresql.yml.j2
│ └── nginx-grafana.conf.j2
├── files/
│ └── dashboards/
│ ├── infrastructure-overview.json
│ ├── dns-servers.json
│ ├── pki-health.json
│ ├── keycloak-metrics.json
│ ├── forgejo-metrics.json
│ ├── icinga2-status.json
│ └── bpm-processes.json
├── handlers/
│ └── main.yml
└── defaults/
└── main.yml
```
**Datasources** :
- Icinga2 (via plugin ou PostgreSQL IDO)
- PostgreSQL (metrics Icinga2, PowerDNS, etc.)
- FastAPI Pivot (custom metrics)
**Dashboards** :
- Infrastructure Overview (tous services)
- DNS Performance (PowerDNS)
- PKI Health (step-ca, cert expiry)
- Keycloak Metrics (authentications, users)
- Forgejo Activity (commits, repos, CI/CD)
- Icinga2 Status (checks, notifications)
- Business Processes (BPM from Icinga2)
---
## 📊 ARCHITECTURE MONITORING
### Flux de données
```
┌─────────────────────────────────────────────────┐
│ SERVEURS (C1-C8) │
│ ├── Icinga2 Agent (checks passifs + actifs) │
│ └── Certificat PKI (authentification mTLS) │
└──────────────────┬──────────────────────────────┘
│ Port 5665 (mTLS)
┌─────────────────────────────────────────────────┐
│ ICINGA2 MASTER (C3) │
│ ├── Collecte checks │
│ ├── Évaluation BPM │
│ ├── Notifications (Matrix, Email) │
│ └── API REST │
└──────────────────┬──────────────────────────────┘
┌──────────┴──────────┐
│ │
▼ ▼
┌──────────────────┐ ┌──────────────────┐
│ FASTAPI PIVOT │ │ GRAFANA │
│ (C5) │ │ (C3) │
│ │ │ │
│ Consomme API │ │ Dashboards │
│ Icinga2 pour │ │ + alerting │
│ provisioning │ │ │
└──────────────────┘ └──────────────────┘
```
---
## 📋 PLAYBOOKS ANSIBLE
### Playbook : `phase3-deploy.yml`
```yaml
---
# Alliance Boréale - Phase 3 : Monitoring & Pivot
- name: "📊 Phase 3 - Déploiement Icinga2 Master"
hosts: icinga.infra.chezlepro.ca
become: true
roles:
- common
- postgresql
- icinga2-master
post_tasks:
- name: "✅ Icinga2 Master déployé"
ansible.builtin.debug:
msg: |
✅ Icinga2 Master opérationnel
URL: https://icinga.infra.chezlepro.ca/icingaweb2
API: https://icinga.infra.chezlepro.ca:5665/v1
- name: "📡 Phase 3 - Déploiement Agents Icinga2"
hosts: all:!icinga.infra.chezlepro.ca
become: true
roles:
- icinga2-agent
post_tasks:
- name: "✅ Agents déployés"
ansible.builtin.debug:
msg: "✅ Agent Icinga2 installé sur {{ inventory_hostname }}"
- name: "🔧 Phase 3 - Déploiement FastAPI Pivot"
hosts: pivot.infra.chezlepro.ca
become: true
roles:
- common
- postgresql
- fastapi-pivot
post_tasks:
- name: "✅ FastAPI Pivot déployé"
ansible.builtin.debug:
msg: |
✅ FastAPI Pivot opérationnel
URL: https://pivot.infra.chezlepro.ca
API Docs: https://pivot.infra.chezlepro.ca/docs
- name: "📊 Phase 3 - Déploiement Grafana"
hosts: grafana.infra.chezlepro.ca
become: true
roles:
- common
- grafana
post_tasks:
- name: "✅ Grafana déployé"
ansible.builtin.debug:
msg: |
✅ Grafana opérationnel
URL: https://grafana.infra.chezlepro.ca
- name: "🧪 Phase 3 - Validation"
hosts: localhost
gather_facts: false
tasks:
- name: "🧪 Tester endpoints"
ansible.builtin.uri:
url: "{{ item }}"
validate_certs: true
loop:
- https://icinga.infra.chezlepro.ca/icingaweb2
- https://pivot.infra.chezlepro.ca/health
- https://grafana.infra.chezlepro.ca
- name: "✅ Phase 3 terminée"
ansible.builtin.debug:
msg: |
═══════════════════════════════════════
🌲 PHASE 3 TERMINÉE
═══════════════════════════════════════
✅ Icinga2 : https://icinga.infra.chezlepro.ca
✅ FastAPI : https://pivot.infra.chezlepro.ca
✅ Grafana : https://grafana.infra.chezlepro.ca
Infrastructure C1-C5 complète !
Prochaine étape : Déployer premier tenant (C6-C8)
```
---
## ⏱️ TIMELINE
**Durée totale** : **4 semaines**
- Semaine 1 : Icinga2 Master + Agents
- Semaine 2 : FastAPI Pivot (backend)
- Semaine 3 : Grafana + Dashboards
- Semaine 4 : Tests + Documentation
---
## 🎯 CRITÈRES DE SUCCÈS
- Icinga2 supervise 100% serveurs Phases 1-2-2.5
- BPM modélise couches C1-C8
- FastAPI Pivot API complète (tous endpoints)
- Grafana dashboards opérationnels
- SSO Keycloak fonctionne (Icingaweb2 + Grafana)
- Authentification mTLS (PKI Phase 2.5)
- Notifications alertes configurées (Matrix + Email)
---
**FIN DEVIS PHASE 3**
---
**Total pages devis** : Phase 2.5 (\~45 pages) + Phase 3 (\~35 pages) = **\~80 pages**
Prêt pour le prochain fil ! 🚀🔐📊