erplibre/script/todo
Mathieu Benoit 197d19d61e [ADD] vpn : cinq pilotes, secrets en coffre, diagnostic étagé
Le dépôt n'avait aucun moyen de monter un tunnel VPN ni de dire pourquoi il
refuse de monter. Cinq technologies libres, un pilote chacune, derrière un
`vpn.py` qui monte, démonte et diagnostique.

Ce qui n'est pas secret — hôte, utilisateur, routes, MTU — vit dans une
configuration JSON lisible ; clés pré-partagées et mots de passe vivent dans
un coffre KeePassXC. Un profil se montre et se partage sans donner de quoi
monter le tunnel. Les secrets s'écrivent en tmpfs sous 0700, jamais sur un
disque persistant. Le diagnostic part du noyau et remonte, pour que la
première ligne fausse soit la cause et non une conséquence.
Vérifié : 138 tests, dont le rendu de chaque fichier généré.

--- EN ---

The repository had no way to raise a VPN tunnel, nor to say why one refuses
to come up. Five free technologies, one driver each, behind a `vpn.py` that
raises, tears down and diagnoses.

What is not secret — host, user, routes, MTU — lives in readable JSON
configuration; pre-shared keys and passwords live in a KeePassXC vault. A
profile can be shown and shared without handing over the means to raise the
tunnel. Secrets are written to tmpfs at 0700, never to a persistent disk.
Diagnosis starts at the kernel and climbs, so the first false line is the
cause and not a consequence.
Checked: 138 tests, including the rendering of every generated file.

Assisted-by: Claude Opus 5
2026-09-04 03:42:49 +00:00
..
mail [ADD] mail: read and send email from the TODO CLI 2026-08-16 03:56:34 -04:00
auto_ask.py [UPD] invites : 15 secondes pour décider, et le fichier nomme la base 2026-08-29 02:11:04 -04:00
database_manager.py [ADD] database: dupliquer une base, et la neutraliser pour de bon 2026-08-29 02:11:04 -04:00
deploy_form_extras.py [REF] déploiement : la branche, le profil et le type se choisissent par VM 2026-08-25 03:31:12 -04:00
deploy_form_lib.py [ADD] qemu deploy : poser rtk, starship et un agent dans la VM 2026-09-03 05:00:55 -04:00
deploy_form_plan.py [FIX] proxmox : quatre écrans qui parlaient d'une machine locale 2026-08-25 03:28:39 -04:00
dev_tools.py [REF] todo shell : une table unique pour les installateurs amont 2026-09-03 05:00:55 -04:00
kdbx_manager.py [ADD] vpn : cinq pilotes, secrets en coffre, diagnostic étagé 2026-09-04 03:42:49 +00:00
logo_ascii.txt [IMP] bot assistant TODO 2025-04-27 02:40:20 -04:00
longtest_menu.py [ADD] long_test : partir d'un hôte existant, et le menu des deux piles 2026-08-29 01:53:03 -04:00
migration_form.py [ADD] migration: offer « go back to a step » on the resume screen 2026-08-22 07:23:59 -04:00
migration_stats.py [ADD] migration: see and repair the website COW views 2026-08-10 03:10:50 -04:00
migration_status.py [FIX] verdicts de migration : distinguer trouvaille et échec d'outil 2026-08-29 02:11:04 -04:00
migration_status_tui.py [FIX] migration state: open the quality screen in its own process 2026-08-22 07:23:59 -04:00
proxmox_deploy_form.py [REF] déploiement : la branche, le profil et le type se choisissent par VM 2026-08-25 03:31:12 -04:00
proxmox_menu.py [ADD] LongTest : jusqu'à quel étage un Proxmox imbriqué tient-il 2026-08-29 01:53:03 -04:00
qemu_access.py [FIX] qemu menu : passer par le groupe libvirt plutôt que par sudo 2026-09-03 05:00:55 -04:00
qemu_deploy.py [ADD] qemu deploy : poser rtk, starship et un agent dans la VM 2026-09-03 05:00:55 -04:00
qemu_deploy_form.py [ADD] qemu deploy : poser rtk, starship et un agent dans la VM 2026-09-03 05:00:55 -04:00
qemu_hardware.py [FIX] qemu 3D : voir l'ABI figée qui annule l'accélération demandée 2026-09-03 05:00:55 -04:00
qemu_install.py [ADD] qemu deploy : poser rtk, starship et un agent dans la VM 2026-09-03 05:00:55 -04:00
qemu_install_monitor.py [FIX] qemu menu : nommer l'URI libvirt, sinon la liste des VM est vide 2026-09-03 05:00:55 -04:00
qemu_manage.py [ADD] qemu diagnostic : l'état 3D de chaque VM, ABI figée comprise 2026-09-03 05:00:55 -04:00
qemu_menu.py [ADD] qemu diagnostic : un relevé à transmettre, Gérer scindé en trois 2026-09-03 05:00:55 -04:00
qemu_privilege.py [ADD] qemu diagnostic : un relevé à transmettre, Gérer scindé en trois 2026-09-03 05:00:55 -04:00
qemu_recover.py [ADD] qemu diagnostic : un relevé à transmettre, Gérer scindé en trois 2026-09-03 05:00:55 -04:00
README.base.md [ADD] proxmox : un écran pour déployer sur un hôte distant 2026-08-25 03:17:13 -04:00
README.fr.md [ADD] proxmox : un écran pour déployer sur un hôte distant 2026-08-25 03:17:13 -04:00
README.md [ADD] proxmox : un écran pour déployer sur un hôte distant 2026-08-25 03:17:13 -04:00
source_todo.sh [ADD] install: mise as Python provider, pyenv as fallback 2026-08-16 23:33:49 -04:00
textual_setup.py [ADD] todo: install Textual on demand 2026-08-07 03:22:26 -04:00
todo.json [ADD] todo: QEMU/KVM menu 2026-08-07 03:22:26 -04:00
todo.py [REF] todo shell : une table unique pour les installateurs amont 2026-09-03 05:00:55 -04:00
todo_example.json [UPD] TODO: simplify code by reusing method and support same command 2025-04-28 00:35:27 -04:00
todo_file_browser.py [FIX] todo: test menu, file browser and KeePass refusals 2026-08-16 03:56:34 -04:00
todo_i18n.py [ADD] vpn : cinq pilotes, secrets en coffre, diagnostic étagé 2026-09-04 03:42:49 +00:00
todo_install.py [ADD] script todo : installer les outils manquants, les quatre familles 2026-08-31 07:18:13 -04:00
todo_prefs.py [ADD] mail: read and send email from the TODO CLI 2026-08-16 03:56:34 -04:00
todo_telemetry.py [ADD] script todo : installer les outils manquants, les quatre familles 2026-08-31 07:18:13 -04:00
todo_upgrade.py [ADD] commentaires : un relevé non bloquant, sa règle, le code nettoyé 2026-08-30 06:08:30 -04:00
version_manager.py [IMP] script: update copyright year to 2026 2026-03-11 23:16:05 -04:00

TODO is an assistant robot to use ERPLibre Execute it with ./script/todo/todo.py or make todo.

For a new project, copy todo_example.json to private/todo/todo_override.json | private/todo/todo_override_private.json and edit it.

The mail/ package is the mail client reachable from Assistant > Mail: several IMAP/SMTP accounts, a local cache, and a Textual TUI. See ../../doc/EMAIL.md.

Where the code lives

todo.py carries the menus and the general helpers. Everything around a single subject sits in its own file, and the whole thing is assembled by mixins on the TODO class — one file, one subject, its header states its boundary.

File What it owns
todo.py the menus, the configuration, the general helpers
qemu_menu.py the QEMU/KVM menu, the image catalogue, the statistics
qemu_deploy.py deciding then running a deployment
qemu_install.py the recipes run inside a VM
qemu_manage.py lifecycle, disks, hardware, cleanup, addresses
qemu_access.py SSH, tunnels, consoles, Android emulator
proxmox_menu.py the same, on a REMOTE Proxmox VE host

The two deployment forms — libvirt here, Proxmox over there — ask the same questions, so they share a foundation rather than each holding a copy:

File What it owns
deploy_form_lib.py pure logic (sizes, plan, totals, spec), the shared CSS, the resource-row factory, the progress view
deploy_form_plan.py the plan's gestures: overrides, locks, copies, renaming, free values
qemu_deploy_form.py what QEMU/KVM adds: desktops, tools, branches, install profiles
proxmox_deploy_form.py what Proxmox adds: host, storage, bridge, VMID, address

A form inherits PlanMixin and provides three hooks: which presets each resource offers, the name a VM would fall back to, and what a lock freezes. test_todo_deploy_form_lib.py fails if a form redefines a gesture the foundation already carries — that is what keeps the architecture from drifting back into two copies.