2026-09-16 00:41:43 -04:00
|
|
|
#!/usr/bin/env bash
|
|
|
|
|
# © 2026 TechnoLibre (http://www.technolibre.ca)
|
|
|
|
|
# License AGPL-3.0 or later (http://www.gnu.org/licenses/agpl)
|
|
|
|
|
#
|
|
|
|
|
# Dépendances système ERPLibre pour NixOS.
|
|
|
|
|
#
|
|
|
|
|
# Les quatre autres scripts de distribution POSENT des paquets. Celui-ci n'en
|
|
|
|
|
# pose aucun : il dépose une déclaration et demande au système de s'y
|
|
|
|
|
# conformer. C'est la seule façon dont une dépendance dure sur NixOS — ce qui
|
|
|
|
|
# est installé à la main vit hors de la configuration et disparaît à la
|
|
|
|
|
# reconstruction suivante.
|
|
|
|
|
#
|
|
|
|
|
# Idempotent : relancé, il réécrit le module, n'ajoute pas deux fois l'import,
|
|
|
|
|
# et « nixos-rebuild switch » ne fait rien s'il n'y a rien à changer.
|
|
|
|
|
set -e
|
|
|
|
|
|
|
|
|
|
. ./env_var.sh
|
|
|
|
|
|
|
|
|
|
EL_USER=${USER}
|
[FIX] nixos : le service ERPLibre déclaré, démarré quand Odoo est là
Trois obstacles enchaînés, aucun visible sans une vraie machine. /etc est
généré depuis le store : le « tee » d'une unité y rend « Read-only file
system », et l'installation échouait à sa DERNIÈRE étape, après que le
clone, le venv et un démarrage d'Odoo avaient réussi. ExecStart=/bin/bash
rendait 203/EXEC, /bin étant un montage FUSE que systemd ne voit pas ; et
le PATH d'une unité n'a pas bash, que réclament les shebangs de run.sh.
Déclarée, l'unité est démarrée par la reconstruction — qui a lieu pendant
« make install_os », quand la source d'Odoo n'arrive qu'après : une
condition la fait sauter plutôt qu'échouer 21 fois de suite. Mesuré :
service actif, 8069 servi par lui, login en 303.
--- EN ---
Three chained obstacles, none visible without a real machine. /etc is
generated from the store: « tee » of a unit there returns « Read-only file
system », and the install failed at its LAST step, after the clone, the
venv and an Odoo start had all succeeded. ExecStart=/bin/bash returned
203/EXEC, /bin being a FUSE mount systemd does not see; and a unit's PATH
carries no bash, which run.sh's shebangs ask for.
Declared, the unit is started by the rebuild — which happens during
« make install_os », while Odoo's source lands later: a condition makes it
skip rather than fail 21 times over. Measured: service active, 8069 served
by it, login in 303.
Assisted-by: Claude Opus 5
2026-09-16 21:31:50 -04:00
|
|
|
# Le répertoire du service, pris du checkout QUI POSE le module : « make
|
|
|
|
|
# install_os » tourne à la racine du dépôt, et c'est ce dépôt-là que le
|
|
|
|
|
# service doit lancer. Deviner « /home/$USER/git/erplibre » se tromperait sur
|
|
|
|
|
# une installation de production, qui vit sous /opt.
|
|
|
|
|
EL_DIR=${EL_DIR:-${PWD}}
|
[FIX] nixos : afficher le guide de connexion, appliquer la locale
Le déploiement écrit /etc/motd partout et compte sur pam_motd pour le
montrer — vrai des quatre images cloud, faux ici : sshd rend « printmotd
no » et le PAM n'en contient aucun. Le guide était écrit, complet, et
personne ne le lisait. Il gagne un bloc propre à NixOS, dont le piège
qu'il existe pour dire — /etc/nixos/erplibre.nix est réécrit par
« make install_os », et ce qu'on y ajoute disparaît sans un mot.
La locale demandée ne s'appliquait pas : cloud-init passe par locale-gen
et update-locale, absents ici. Mesuré — fr_CA demandé, en_US obtenu. Rien
n'est imposé à une NixOS qu'on avait déjà.
--- EN ---
Deployment writes /etc/motd everywhere and relies on pam_motd to show it —
true of the four cloud images, false here: sshd returns "printmotd no" and
the PAM stack holds none. The guide was written, complete, and nobody read
it. It gains a NixOS block, including the trap it exists to name —
/etc/nixos/erplibre.nix is rewritten by "make install_os", and what you
add there vanishes without a word.
The requested locale did not apply: cloud-init goes through locale-gen and
update-locale, absent here. Measured — fr_CA asked, en_US obtained.
Nothing is imposed on a NixOS one already had.
Assisted-by: Claude Opus 5
2026-09-16 00:44:00 -04:00
|
|
|
# Les réglages régionaux que le DÉPLOIEMENT a demandés, lus là où cloud-init
|
|
|
|
|
# garde ce qu'il a reçu. Vides quand rien ne les a demandés — une NixOS que
|
|
|
|
|
# l'on avait déjà —, et le module laisse alors les réglages en place.
|
|
|
|
|
EL_CLOUD_CFG=/var/lib/cloud/instance/cloud-config.txt
|
|
|
|
|
lire_seed() {
|
|
|
|
|
sudo grep -m1 -E "^${1}: " "${EL_CLOUD_CFG}" 2>/dev/null |
|
|
|
|
|
cut -d" " -f2- | tr -d "\r" || true
|
|
|
|
|
}
|
[ADD] cache qemu : NixOS apprend l'autorité, et le hors ligne s'ouvre
NixOS était SOUSTRAIT du cache faute d'ancre de confiance par fichier, ce
qui lui fermait le hors ligne : le magasin est alors la seule source, et
l'exception ne laisse rien. Une déclaration arriverait trop tard, la
première reconstruction étant le premier téléchargement.
L'autorité est donc POINTÉE, consommateur par consommateur, et
l'environnement se perd à trois frontières : nix-daemon, activé par
socket, qu'un fragment sous /run/systemd/system atteint ; sudo, que
« env_keep » traverse — le nix de root parle droit au magasin local et
télécharge lui-même ; et la session ssh, ouverte une seconde avant que
cloud-init n'écrive le faisceau. Vérifié : installation complète, 0 refus.
--- EN ---
NixOS was EXEMPTED from the cache for want of a per-file trust anchor,
which closed offline deployment to it: the store is then the only source,
and an exemption leaves nothing. A declaration would come too late, the
first rebuild being the first download.
The authority is therefore POINTED AT, consumer by consumer, and the
environment is lost at three boundaries: nix-daemon, socket-activated,
reached by a drop-in under /run/systemd/system; sudo, crossed by
« env_keep » — root's nix talks straight to the local store and downloads
itself; and the ssh session, opened one second before cloud-init writes
the bundle. Checked: a complete install, 0 refusals.
Assisted-by: Claude Opus 5
2026-09-16 21:33:10 -04:00
|
|
|
# Le faisceau que cloud-init a bâti, s'il l'a fait : vide sur une machine
|
|
|
|
|
# sans cache, et le module n'y déclare alors aucune variable — y pointer
|
|
|
|
|
# couperait TLS partout.
|
|
|
|
|
EL_CA_BUNDLE=/var/lib/erplibre/ca-bundle.crt
|
|
|
|
|
[ -r "${EL_CA_BUNDLE}" ] || EL_CA_BUNDLE=""
|
[FIX] nixos : afficher le guide de connexion, appliquer la locale
Le déploiement écrit /etc/motd partout et compte sur pam_motd pour le
montrer — vrai des quatre images cloud, faux ici : sshd rend « printmotd
no » et le PAM n'en contient aucun. Le guide était écrit, complet, et
personne ne le lisait. Il gagne un bloc propre à NixOS, dont le piège
qu'il existe pour dire — /etc/nixos/erplibre.nix est réécrit par
« make install_os », et ce qu'on y ajoute disparaît sans un mot.
La locale demandée ne s'appliquait pas : cloud-init passe par locale-gen
et update-locale, absents ici. Mesuré — fr_CA demandé, en_US obtenu. Rien
n'est imposé à une NixOS qu'on avait déjà.
--- EN ---
Deployment writes /etc/motd everywhere and relies on pam_motd to show it —
true of the four cloud images, false here: sshd returns "printmotd no" and
the PAM stack holds none. The guide was written, complete, and nobody read
it. It gains a NixOS block, including the trap it exists to name —
/etc/nixos/erplibre.nix is rewritten by "make install_os", and what you
add there vanishes without a word.
The requested locale did not apply: cloud-init goes through locale-gen and
update-locale, absent here. Measured — fr_CA asked, en_US obtained.
Nothing is imposed on a NixOS one already had.
Assisted-by: Claude Opus 5
2026-09-16 00:44:00 -04:00
|
|
|
EL_LOCALE=${EL_LOCALE:-$(lire_seed locale)}
|
|
|
|
|
EL_TZ=${EL_TZ:-$(lire_seed timezone)}
|
[UPD] install : le venv d'outillage passe en Python 3.14.7
install_erplibre.sh bâtissait .venv.erplibre avec le python3 du système, quelle
que soit sa version : un 3.10 y donnait un venv que l'outillage ne sait pas
charger. Il délègue à install_venv.sh, qui obtient la version par mise, pyenv
ou la distribution, et rebâtit un venv hors service. Le PATCH ne borne que le
venv d'Odoo, dont le pyproject exige « >=3.12.10,<3.13 » : l'exiger ailleurs
écartait un Python de distribution d'un cran en retard — NixOS 25.11 livre
3.14.2 — et faisait compiler CPython pour rien. Le module NixOS déclare
désormais les DEUX Python, substitués depuis les fichiers de version.
Vérifié : 15 tests sur des venvs factices, conservés, rebâtis ou refusés selon
leur état, et un chemin sans pyvenv.cfg garde son contenu.
--- EN ---
install_erplibre.sh built .venv.erplibre with the system python3, whatever its
version: a 3.10 gave a venv the tooling cannot load. It delegates to
install_venv.sh, which obtains the version through mise, pyenv or the
distribution, and rebuilds a venv out of service. The PATCH bounds only Odoo's
venv, whose pyproject requires ">=3.12.10,<3.13": requiring it elsewhere turned
away a distribution Python one step behind — NixOS 25.11 ships 3.14.2 — and
compiled CPython for nothing. The NixOS module now declares BOTH Pythons,
substituted from the version files.
Checked: 15 tests on stub venvs, kept, rebuilt or refused by their state, and a
path without pyvenv.cfg keeps its content.
Assisted-by: Claude Opus 5
2026-09-24 13:31:32 -04:00
|
|
|
# « 3.12.10 » donne « python312 », le nom du paquet nixpkgs. Les deux versions
|
|
|
|
|
# du dépôt sont déclarées : celle d'Odoo et celle de l'outillage. Le second est
|
|
|
|
|
# VIDE quand elles coïncident, un même paquet nommé deux fois entrant en
|
|
|
|
|
# collision dans le profil.
|
|
|
|
|
el_nix_python_pkg() {
|
|
|
|
|
local v
|
|
|
|
|
v="$(xargs < "$1" 2> /dev/null)"
|
|
|
|
|
[ -n "${v}" ] || return 0
|
|
|
|
|
echo "python$(echo "${v}" | cut -d. -f1)$(echo "${v}" | cut -d. -f2)"
|
|
|
|
|
}
|
|
|
|
|
EL_PY_ODOO_PKG="$(el_nix_python_pkg .python-odoo-version)"
|
|
|
|
|
EL_PY_ODOO_PKG="${EL_PY_ODOO_PKG:-python312}"
|
|
|
|
|
EL_PY_TOOLS_PKG="$(el_nix_python_pkg conf/python-erplibre-version)"
|
|
|
|
|
[ "${EL_PY_TOOLS_PKG}" = "${EL_PY_ODOO_PKG}" ] && EL_PY_TOOLS_PKG=""
|
|
|
|
|
|
2026-09-16 00:41:43 -04:00
|
|
|
MODULE_SRC="conf/nixos/erplibre.nix"
|
|
|
|
|
MODULE_DST="/etc/nixos/erplibre.nix"
|
|
|
|
|
CONFIG="/etc/nixos/configuration.nix"
|
|
|
|
|
|
|
|
|
|
if [ ! -f /etc/os-release ] || ! grep -q '^ID=nixos' /etc/os-release; then
|
|
|
|
|
echo "Ce script ne vaut que pour NixOS."
|
|
|
|
|
exit 1
|
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
if [ ! -f "${MODULE_SRC}" ]; then
|
|
|
|
|
echo "Module absent : ${MODULE_SRC} (lancer depuis la racine du dépôt)."
|
|
|
|
|
exit 1
|
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
echo -e "\n---- Module ERPLibre pour NixOS ----"
|
|
|
|
|
# Le nom du compte est substitué comme le user-data cloud-init l'est : le
|
|
|
|
|
# module déclare un rôle PostgreSQL, et un rôle porte un nom.
|
[FIX] nixos : le service ERPLibre déclaré, démarré quand Odoo est là
Trois obstacles enchaînés, aucun visible sans une vraie machine. /etc est
généré depuis le store : le « tee » d'une unité y rend « Read-only file
system », et l'installation échouait à sa DERNIÈRE étape, après que le
clone, le venv et un démarrage d'Odoo avaient réussi. ExecStart=/bin/bash
rendait 203/EXEC, /bin étant un montage FUSE que systemd ne voit pas ; et
le PATH d'une unité n'a pas bash, que réclament les shebangs de run.sh.
Déclarée, l'unité est démarrée par la reconstruction — qui a lieu pendant
« make install_os », quand la source d'Odoo n'arrive qu'après : une
condition la fait sauter plutôt qu'échouer 21 fois de suite. Mesuré :
service actif, 8069 servi par lui, login en 303.
--- EN ---
Three chained obstacles, none visible without a real machine. /etc is
generated from the store: « tee » of a unit there returns « Read-only file
system », and the install failed at its LAST step, after the clone, the
venv and an Odoo start had all succeeded. ExecStart=/bin/bash returned
203/EXEC, /bin being a FUSE mount systemd does not see; and a unit's PATH
carries no bash, which run.sh's shebangs ask for.
Declared, the unit is started by the rebuild — which happens during
« make install_os », while Odoo's source lands later: a condition makes it
skip rather than fail 21 times over. Measured: service active, 8069 served
by it, login in 303.
Assisted-by: Claude Opus 5
2026-09-16 21:31:50 -04:00
|
|
|
sed -e "s/@EL_USER@/${EL_USER}/g" -e "s#@EL_DIR@#${EL_DIR}#g" \
|
[FIX] nixos : afficher le guide de connexion, appliquer la locale
Le déploiement écrit /etc/motd partout et compte sur pam_motd pour le
montrer — vrai des quatre images cloud, faux ici : sshd rend « printmotd
no » et le PAM n'en contient aucun. Le guide était écrit, complet, et
personne ne le lisait. Il gagne un bloc propre à NixOS, dont le piège
qu'il existe pour dire — /etc/nixos/erplibre.nix est réécrit par
« make install_os », et ce qu'on y ajoute disparaît sans un mot.
La locale demandée ne s'appliquait pas : cloud-init passe par locale-gen
et update-locale, absents ici. Mesuré — fr_CA demandé, en_US obtenu. Rien
n'est imposé à une NixOS qu'on avait déjà.
--- EN ---
Deployment writes /etc/motd everywhere and relies on pam_motd to show it —
true of the four cloud images, false here: sshd returns "printmotd no" and
the PAM stack holds none. The guide was written, complete, and nobody read
it. It gains a NixOS block, including the trap it exists to name —
/etc/nixos/erplibre.nix is rewritten by "make install_os", and what you
add there vanishes without a word.
The requested locale did not apply: cloud-init goes through locale-gen and
update-locale, absent here. Measured — fr_CA asked, en_US obtained.
Nothing is imposed on a NixOS one already had.
Assisted-by: Claude Opus 5
2026-09-16 00:44:00 -04:00
|
|
|
-e "s/@EL_LOCALE@/${EL_LOCALE}/g" -e "s#@EL_TZ@#${EL_TZ}#g" \
|
[ADD] cache qemu : NixOS apprend l'autorité, et le hors ligne s'ouvre
NixOS était SOUSTRAIT du cache faute d'ancre de confiance par fichier, ce
qui lui fermait le hors ligne : le magasin est alors la seule source, et
l'exception ne laisse rien. Une déclaration arriverait trop tard, la
première reconstruction étant le premier téléchargement.
L'autorité est donc POINTÉE, consommateur par consommateur, et
l'environnement se perd à trois frontières : nix-daemon, activé par
socket, qu'un fragment sous /run/systemd/system atteint ; sudo, que
« env_keep » traverse — le nix de root parle droit au magasin local et
télécharge lui-même ; et la session ssh, ouverte une seconde avant que
cloud-init n'écrive le faisceau. Vérifié : installation complète, 0 refus.
--- EN ---
NixOS was EXEMPTED from the cache for want of a per-file trust anchor,
which closed offline deployment to it: the store is then the only source,
and an exemption leaves nothing. A declaration would come too late, the
first rebuild being the first download.
The authority is therefore POINTED AT, consumer by consumer, and the
environment is lost at three boundaries: nix-daemon, socket-activated,
reached by a drop-in under /run/systemd/system; sudo, crossed by
« env_keep » — root's nix talks straight to the local store and downloads
itself; and the ssh session, opened one second before cloud-init writes
the bundle. Checked: a complete install, 0 refusals.
Assisted-by: Claude Opus 5
2026-09-16 21:33:10 -04:00
|
|
|
-e "s#@EL_CA_BUNDLE@#${EL_CA_BUNDLE}#g" \
|
[UPD] install : le venv d'outillage passe en Python 3.14.7
install_erplibre.sh bâtissait .venv.erplibre avec le python3 du système, quelle
que soit sa version : un 3.10 y donnait un venv que l'outillage ne sait pas
charger. Il délègue à install_venv.sh, qui obtient la version par mise, pyenv
ou la distribution, et rebâtit un venv hors service. Le PATCH ne borne que le
venv d'Odoo, dont le pyproject exige « >=3.12.10,<3.13 » : l'exiger ailleurs
écartait un Python de distribution d'un cran en retard — NixOS 25.11 livre
3.14.2 — et faisait compiler CPython pour rien. Le module NixOS déclare
désormais les DEUX Python, substitués depuis les fichiers de version.
Vérifié : 15 tests sur des venvs factices, conservés, rebâtis ou refusés selon
leur état, et un chemin sans pyvenv.cfg garde son contenu.
--- EN ---
install_erplibre.sh built .venv.erplibre with the system python3, whatever its
version: a 3.10 gave a venv the tooling cannot load. It delegates to
install_venv.sh, which obtains the version through mise, pyenv or the
distribution, and rebuilds a venv out of service. The PATCH bounds only Odoo's
venv, whose pyproject requires ">=3.12.10,<3.13": requiring it elsewhere turned
away a distribution Python one step behind — NixOS 25.11 ships 3.14.2 — and
compiled CPython for nothing. The NixOS module now declares BOTH Pythons,
substituted from the version files.
Checked: 15 tests on stub venvs, kept, rebuilt or refused by their state, and a
path without pyvenv.cfg keeps its content.
Assisted-by: Claude Opus 5
2026-09-24 13:31:32 -04:00
|
|
|
-e "s/@EL_PY_ODOO_PKG@/${EL_PY_ODOO_PKG}/g" \
|
|
|
|
|
-e "s/@EL_PY_TOOLS_PKG@/${EL_PY_TOOLS_PKG}/g" \
|
[FIX] nixos : le service ERPLibre déclaré, démarré quand Odoo est là
Trois obstacles enchaînés, aucun visible sans une vraie machine. /etc est
généré depuis le store : le « tee » d'une unité y rend « Read-only file
system », et l'installation échouait à sa DERNIÈRE étape, après que le
clone, le venv et un démarrage d'Odoo avaient réussi. ExecStart=/bin/bash
rendait 203/EXEC, /bin étant un montage FUSE que systemd ne voit pas ; et
le PATH d'une unité n'a pas bash, que réclament les shebangs de run.sh.
Déclarée, l'unité est démarrée par la reconstruction — qui a lieu pendant
« make install_os », quand la source d'Odoo n'arrive qu'après : une
condition la fait sauter plutôt qu'échouer 21 fois de suite. Mesuré :
service actif, 8069 servi par lui, login en 303.
--- EN ---
Three chained obstacles, none visible without a real machine. /etc is
generated from the store: « tee » of a unit there returns « Read-only file
system », and the install failed at its LAST step, after the clone, the
venv and an Odoo start had all succeeded. ExecStart=/bin/bash returned
203/EXEC, /bin being a FUSE mount systemd does not see; and a unit's PATH
carries no bash, which run.sh's shebangs ask for.
Declared, the unit is started by the rebuild — which happens during
« make install_os », while Odoo's source lands later: a condition makes it
skip rather than fail 21 times over. Measured: service active, 8069 served
by it, login in 303.
Assisted-by: Claude Opus 5
2026-09-16 21:31:50 -04:00
|
|
|
"${MODULE_SRC}" | sudo tee "${MODULE_DST}" > /dev/null
|
|
|
|
|
echo " posé : ${MODULE_DST} (compte ${EL_USER}, dépôt ${EL_DIR})"
|
[ADD] cache qemu : NixOS apprend l'autorité, et le hors ligne s'ouvre
NixOS était SOUSTRAIT du cache faute d'ancre de confiance par fichier, ce
qui lui fermait le hors ligne : le magasin est alors la seule source, et
l'exception ne laisse rien. Une déclaration arriverait trop tard, la
première reconstruction étant le premier téléchargement.
L'autorité est donc POINTÉE, consommateur par consommateur, et
l'environnement se perd à trois frontières : nix-daemon, activé par
socket, qu'un fragment sous /run/systemd/system atteint ; sudo, que
« env_keep » traverse — le nix de root parle droit au magasin local et
télécharge lui-même ; et la session ssh, ouverte une seconde avant que
cloud-init n'écrive le faisceau. Vérifié : installation complète, 0 refus.
--- EN ---
NixOS was EXEMPTED from the cache for want of a per-file trust anchor,
which closed offline deployment to it: the store is then the only source,
and an exemption leaves nothing. A declaration would come too late, the
first rebuild being the first download.
The authority is therefore POINTED AT, consumer by consumer, and the
environment is lost at three boundaries: nix-daemon, socket-activated,
reached by a drop-in under /run/systemd/system; sudo, crossed by
« env_keep » — root's nix talks straight to the local store and downloads
itself; and the ssh session, opened one second before cloud-init writes
the bundle. Checked: a complete install, 0 refusals.
Assisted-by: Claude Opus 5
2026-09-16 21:33:10 -04:00
|
|
|
echo " autorité du cache : ${EL_CA_BUNDLE:-aucune}"
|
[UPD] install : le venv d'outillage passe en Python 3.14.7
install_erplibre.sh bâtissait .venv.erplibre avec le python3 du système, quelle
que soit sa version : un 3.10 y donnait un venv que l'outillage ne sait pas
charger. Il délègue à install_venv.sh, qui obtient la version par mise, pyenv
ou la distribution, et rebâtit un venv hors service. Le PATCH ne borne que le
venv d'Odoo, dont le pyproject exige « >=3.12.10,<3.13 » : l'exiger ailleurs
écartait un Python de distribution d'un cran en retard — NixOS 25.11 livre
3.14.2 — et faisait compiler CPython pour rien. Le module NixOS déclare
désormais les DEUX Python, substitués depuis les fichiers de version.
Vérifié : 15 tests sur des venvs factices, conservés, rebâtis ou refusés selon
leur état, et un chemin sans pyvenv.cfg garde son contenu.
--- EN ---
install_erplibre.sh built .venv.erplibre with the system python3, whatever its
version: a 3.10 gave a venv the tooling cannot load. It delegates to
install_venv.sh, which obtains the version through mise, pyenv or the
distribution, and rebuilds a venv out of service. The PATCH bounds only Odoo's
venv, whose pyproject requires ">=3.12.10,<3.13": requiring it elsewhere turned
away a distribution Python one step behind — NixOS 25.11 ships 3.14.2 — and
compiled CPython for nothing. The NixOS module now declares BOTH Pythons,
substituted from the version files.
Checked: 15 tests on stub venvs, kept, rebuilt or refused by their state, and a
path without pyvenv.cfg keeps its content.
Assisted-by: Claude Opus 5
2026-09-24 13:31:32 -04:00
|
|
|
echo " Python : ${EL_PY_ODOO_PKG} (Odoo)${EL_PY_TOOLS_PKG:+, ${EL_PY_TOOLS_PKG} (outillage)}"
|
[FIX] nixos : afficher le guide de connexion, appliquer la locale
Le déploiement écrit /etc/motd partout et compte sur pam_motd pour le
montrer — vrai des quatre images cloud, faux ici : sshd rend « printmotd
no » et le PAM n'en contient aucun. Le guide était écrit, complet, et
personne ne le lisait. Il gagne un bloc propre à NixOS, dont le piège
qu'il existe pour dire — /etc/nixos/erplibre.nix est réécrit par
« make install_os », et ce qu'on y ajoute disparaît sans un mot.
La locale demandée ne s'appliquait pas : cloud-init passe par locale-gen
et update-locale, absents ici. Mesuré — fr_CA demandé, en_US obtenu. Rien
n'est imposé à une NixOS qu'on avait déjà.
--- EN ---
Deployment writes /etc/motd everywhere and relies on pam_motd to show it —
true of the four cloud images, false here: sshd returns "printmotd no" and
the PAM stack holds none. The guide was written, complete, and nobody read
it. It gains a NixOS block, including the trap it exists to name —
/etc/nixos/erplibre.nix is rewritten by "make install_os", and what you
add there vanishes without a word.
The requested locale did not apply: cloud-init goes through locale-gen and
update-locale, absent here. Measured — fr_CA asked, en_US obtained.
Nothing is imposed on a NixOS one already had.
Assisted-by: Claude Opus 5
2026-09-16 00:44:00 -04:00
|
|
|
echo " régional : locale « ${EL_LOCALE:-non demandée} »," \
|
|
|
|
|
"fuseau « ${EL_TZ:-non demandé} »"
|
2026-09-16 00:41:43 -04:00
|
|
|
|
|
|
|
|
if [ ! -f "${CONFIG}" ]; then
|
|
|
|
|
echo "Configuration introuvable : ${CONFIG}"
|
|
|
|
|
exit 1
|
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
# L'import, une fois. Sans lui le module est un fichier mort : NixOS ne lit
|
|
|
|
|
# que ce que la configuration importe.
|
|
|
|
|
if grep -q "erplibre.nix" "${CONFIG}"; then
|
|
|
|
|
echo " import déjà présent dans ${CONFIG}"
|
|
|
|
|
else
|
|
|
|
|
sudo sed -i '0,/imports *= *\[/s//imports = [\n .\/erplibre.nix/' "${CONFIG}"
|
|
|
|
|
if grep -q "erplibre.nix" "${CONFIG}"; then
|
|
|
|
|
echo " import ajouté à ${CONFIG}"
|
|
|
|
|
else
|
|
|
|
|
echo "Aucun bloc « imports = [ » dans ${CONFIG} : ajoutez-y"
|
|
|
|
|
echo " ./erplibre.nix"
|
|
|
|
|
exit 1
|
|
|
|
|
fi
|
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
echo -e "\n---- nixos-rebuild switch ----"
|
|
|
|
|
# La reconstruction télécharge et bâtit : elle est LONGUE au premier passage,
|
|
|
|
|
# et c'est elle qui pose PostgreSQL, node, le compilateur, nix-ld et envfs.
|
|
|
|
|
#
|
|
|
|
|
# Son code de retour n'est PAS le verdict. « switch-to-configuration » rend 4
|
|
|
|
|
# quand une unité n'a pas pu redémarrer, alors que le système est bel et bien
|
|
|
|
|
# activé : sur une VM cloud-init, cloud-config est un service à un coup, et
|
|
|
|
|
# toute reconstruction ultérieure le trouve mort. Prendre ce 4 pour un échec
|
|
|
|
|
# ferait échouer chaque redéploiement d'une machine déjà installée. C'est la
|
|
|
|
|
# vérification ci-dessous qui tranche, sur l'état du système.
|
|
|
|
|
if sudo nixos-rebuild switch; then
|
|
|
|
|
echo " reconstruction appliquée"
|
|
|
|
|
else
|
|
|
|
|
echo " ⚠ nixos-rebuild rend $? : une unité n'a pas redémarré."
|
|
|
|
|
echo " Le système peut être activé quand même — vérification ci-dessous."
|
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
echo -e "\n---- Vérification ----"
|
|
|
|
|
manque=0
|
|
|
|
|
# La version voulue vient du dépôt, pas d'une valeur écrite ici : le module
|
|
|
|
|
# déclare python312 parce que .python-odoo-version dit 3.12.x, et les deux
|
|
|
|
|
# doivent se répondre. « 3.12.10 » -> « 3.12 », qui est ce que
|
|
|
|
|
# lib_python_provider.sh cherche en /usr/bin.
|
|
|
|
|
PY_WANT="$(cat .python-odoo-version 2> /dev/null | xargs)"
|
|
|
|
|
PY_MM="${PY_WANT%.*}"
|
|
|
|
|
for chemin in /bin/bash /usr/bin/env "/usr/bin/python${PY_MM}"; do
|
|
|
|
|
if [ -e "${chemin}" ]; then
|
|
|
|
|
echo " ${chemin}"
|
|
|
|
|
else
|
|
|
|
|
echo " MANQUE : ${chemin}"
|
|
|
|
|
manque=1
|
|
|
|
|
fi
|
|
|
|
|
done
|
|
|
|
|
if ! command -v psql > /dev/null 2>&1; then
|
|
|
|
|
echo " MANQUE : psql"
|
|
|
|
|
manque=1
|
|
|
|
|
fi
|
|
|
|
|
if [ "${manque}" -ne 0 ]; then
|
|
|
|
|
# Sans /bin/bash, la moindre cible make échoue avant sa première ligne :
|
|
|
|
|
# continuer ferait échouer l'installation une heure plus tard, ailleurs.
|
|
|
|
|
echo "Le système n'est pas conforme au module : voir services.envfs.enable."
|
|
|
|
|
exit 1
|
|
|
|
|
fi
|
|
|
|
|
echo " système conforme au module ERPLibre."
|