erplibre/doc/PRODUCTION.md
Mathieu Benoit f39b2e9451 [UPD] support: drop Ubuntu 20.04/22.04, add AlmaLinux and Rocky
Ubuntu 20.04 and 22.04 leave EVERY architecture, not just s390x. pikepdf
needs qpdf 12.2, whose build requires C++20, while focal ships GCC 9 and
publishes no g++-10 for s390x at all. Python 3.8, node 10, cargo 0.67 and
OpenSSL 1.1.1 each had a workaround; the pile of them did not. 18.04
follows, already off the lists. The refusal lands before any apt, this
script also serving existing machines.

AlmaLinux 9 and 10, Rocky 9 and 10 join the catalog on all four
architectures: the twelve "latest" URLs were opened, with no index to
parse unlike Fedora. They would have booted unreachable though -- the
cloud-config forced "groups: users, sudo", but the RHEL family has no
sudo group, only wheel, and an unknown group makes useradd fail, hence no
password and no key. The very trap already known for Debian, repeated
elsewhere. Host side, EPEL and CRB are enabled: without them most -devel
packages are missing, silently.

The server / graphical choice gains Cinnamon, the Linux Mint desktop,
from the distribution's own repositories. Mint's repository is set aside:
plain HTTP, and i386/amd64 only, which would rule out arm64 and s390x.
Along the way, dnf now installs an ENVIRONMENT rather than a group --
"gnome-desktop" brings gdm and gnome-shell but not base-x, hence no X
server.

--- FR ---

Ubuntu 20.04 et 22.04 partent de TOUTES les architectures, pas seulement
de s390x. pikepdf réclame qpdf 12.2, dont la compilation exige C++20,
quand focal livre GCC 9 et ne publie même pas de g++-10 pour s390x.
Python 3.8, node 10, cargo 0.67 et OpenSSL 1.1.1 avaient chacun leur
contournement ; leur accumulation, non. 18.04 suit, déjà hors des
listes. Le refus tombe avant tout apt, ce script servant aussi les
machines existantes.

AlmaLinux 9 et 10, Rocky 9 et 10 entrent au catalogue, sur les quatre
architectures : les douze URL « latest » ont été ouvertes, aucun index à
analyser contrairement à Fedora. Elles auraient pourtant démarré
inaccessibles — le cloud-config imposait « groups: users, sudo », or la
famille RHEL n'a pas de groupe sudo mais wheel, et un groupe inconnu fait
échouer useradd, donc ni mot de passe ni clé. C'est le piège déjà connu
pour Debian, reproduit ailleurs. Côté hôte, EPEL et CRB sont activés :
sans eux la plupart des -devel manquent, en silence.

Le choix serveur / graphique gagne Cinnamon, le bureau de Linux Mint,
depuis les dépôts de la distribution. Le dépôt de Mint lui-même est
écarté : il est en HTTP nu et ne publie que i386 et amd64, ce qui
exclurait arm64 et s390x. Au passage, dnf installe désormais un
ENVIRONNEMENT et non un groupe — « gnome-desktop » apporte gdm et
gnome-shell mais pas base-x, donc pas de serveur X.

Assisted-by: Claude Opus 5
2026-08-16 23:33:49 -04:00

5.7 KiB

ERPLibre production guide

Requirement

  • 5Go of disk space

Production installation procedure

1. Clone the project:

git clone https://github.com/ERPLibre/ERPLibre.git
cd ERPLibre

2. Modify the parameters

Modify the file env_var.sh for production installation. Enable nginx if you need a proxy with EL_INSTALL_NGINX at True. Redirect your DNS to the proxy's ip and add your A and AAAA into EL_WEBSITE_NAME with space between.

3. Execute the scripts:

With proxy nginx production, install certbot before for SSL

# Snap installation
# https://snapcraft.io/docs/installing-snap-on-debian
sudo apt install -y snapd
sudo snap install core
sudo snap refresh core

# https://certbot.eff.org/lets-encrypt/debianbuster-nginx
# Certbot
sudo snap install --classic certbot
sudo ln -s /snap/bin/certbot /usr/bin/certbot

Ubuntu 18.04 server

./script/install/install_dev.sh
./script/install/install_production.sh

A service is running by SystemD. You can access it with the DNS name found in env_var.sh

Ubuntu 24.04 server

Apply fix libpng12-0: https://www.linuxuprising.com/2018/05/fix-libpng12-0-missing-in-ubuntu-1804.html

./script/install/install_dev.sh
./script/install/install_production.sh

A service is running by SystemD, you can access it with the DNS name found in env_var.sh

4. SSL:

Generate a ssl certificate

sudo certbot --nginx

Watch log

sudo systemctl -feu [EL_USER]

Run by address ip

Comment the following line in /[EL_USER]/erplibre/config.conf

xmlrpc_interface = 0.0.0.0
proxy_mode = True

Add your address ip server_name in nginx config /etc/nginx/sites-available/[EL_WEBSITE_NAME]

Restart daemon:

sudo systemctl restart nginx
sudo systemctl restart [EL_USER]

Production execution

cd /[EL_USER]/erplibre
./run.sh -d [DATABASE] --no-database-list

Move prod database to dev

When moving prod database to your dev environment, you want to remove email servers and install user test to test the database. WARNING, this is not safe for production, you will expose all data.

  1. Copy your database image to directory image_db, exemple the image name is my_db.zip
  2. Run
./script/database/db_restore.py --clean_cache --database test_my_db --image my_db
./script/addons/update_prod_to_dev.sh test_my_db

Update production

Update all features.

./run.sh --limit-time-real 99999 --no-http --stop-after-init -u all -d DATABASE

Postgresql

To show config files:

psql -U postgres -c 'SHOW config_file'

Edit this file to accept interface from all networks:

/var/lib/postgres/data/postgresql.conf

Delete an instance in production

CAUTION, this will delete user's home, it's irrevocable.

./script/database/delete_production.sh

Update ip when public ip change with CloudFlare and crontab

First you need a valid python3 interpreter running with cloudflare module installed: (make sure your pip3 pointing the right python3)

pip3 install cloudflare==2.20.0

Then you need to create the cfg files with credentials for your cloudflare account.

mkdir ~/.cloudflare

Edit ~/.cloudflare/cloudflare.cfg

[PROFILE_NAME]
email=EMAIL
token=TOKEN (Use the global API key so that it works)

Add your cron and specify the python3 you want to use with it.

  • USER is the local user with permissions to execute the script
  • PATH is path to inside of ERPLibre/deployment/ folder
  • PROFILE_NAME must match the PROFILE_NAME in cloudflare.cfg
  • CLOUDFLARE_ZONE_NAME is the name of the website zone on cloudflare
  • DNS_NAME is the name of one DNS A record name available on that zone

Notes:

  • Only one crontab is required because the script will automatically research all available zones with outdated ip and update them on all A records.
  • For each crontab run, if public IP did not change compared to what is on cloudflare, the script will not do unnecessary changes and let everything as is.
vim /etc/crontab
# Add
*/5 * * * * USER cd PATH && python3 script/deployment/update_dns_cloudflare.py --profile PROFILE_NAME --zone_name CLOUDFLARE_ZONE_NAME --dns_name DNS_NAME --auto_sync

Check log with

sudo journalctl -feu cron

If you want to log what is happening and when the script is run, like logging when ip changes, you can add a logging part to your cron

vim /etc/crontab
# Add
*/5 * * * * USER cd PATH && python3 script/deployment/update_dns_cloudflare.py --profile PROFILE_NAME --zone_name CLOUDFLARE_ZONE_NAME --dns_name DNS_NAME --auto_sync > /home/USER/logs/update_dns_ZONE_NAME.log 2>&1

You can then read all logs with this command (Need to have ts installed: sudo apt install moreutils)

tail -f /home/USER/logs/update_dns_ZONE_NAME.log | ts

Docker

Update

When update a docker, you need to update the list of module.

Run script to update configuration :

./script/docker/docker_gen_config.sh

Edit the docker-compose.yml and update the command line (change DATABASE) to :

    command: odoo --workers 2 -u erplibre_info -d DATABASE

Note, the goal is to call env['ir.module.module'].update_list().

Restart the docker :

docker compose down
docker compose up -d

Revert the command in docker-compose.yml.

You can validate in log the update, you need to find odoo.modules.loading: updating modules list, check

docker compose logs -f

Update all

Do a backup on url https://HOST/web/database/manager

Edit the docker-compose.yml and update the command line (change DATABASE) to :

    command: odoo --workers 2 -u all -d DATABASE

Watch log to see error, if you got error, you need to do some code to migrate your data, depend the case.

make docker_show_logs_live