# Guide de déploiement — Imago sur serveur Docker > Cible : serveur Docker du lab (dev.lab.home / Proxmox) > Registry : `docker-registry.dev.home:5000` > Prérequis : Docker 24+, Docker Compose v2, accès SSH --- ## Étape 1 — Builder et pousser l'image vers le registry Depuis le poste de développement (Windows + WSL Debian) : ```powershell cd C:\dev\git\python\imago\docker # Builder l'image .\build-img.ps1 # Pousser vers le registry (version semver auto-incrémentée) .\deploy-img.ps1 ``` L'image est disponible à : - `docker-registry.dev.home:5000/imago-backend:latest` - `docker-registry.dev.home:5000/imago-backend:2.0.0` --- ## Étape 2 — Préparer les secrets de production ```bash # Générer des secrets forts (à faire UNE SEULE fois) openssl rand -hex 32 # SECRET_KEY openssl rand -hex 32 # ADMIN_API_KEY → note-la, c'est ta clé admin openssl rand -hex 32 # JWT_SECRET_KEY openssl rand -hex 32 # SIGNED_URL_SECRET openssl rand -hex 16 # MINIO_ROOT_PASSWORD openssl rand -hex 16 # POSTGRES_PASSWORD ``` Créer `.env.production` (remplacer les `<...>`) : ```bash # ── Application ── APP_NAME=Imago APP_VERSION=2.0.0 DEBUG=false SECRET_KEY= # ── Base de données ── DATABASE_URL=postgresql+asyncpg://imago:@db:5432/imago # ── Stockage MinIO ── STORAGE_BACKEND=s3 S3_BUCKET=imago S3_ENDPOINT_URL=http://minio:9000 S3_ACCESS_KEY=minioadmin S3_SECRET_KEY= S3_REGION=us-east-1 SIGNED_URL_SECRET= # ── Redis ── REDIS_URL=redis://redis:***@ADMIN_API_KEY= JWT_SECRET_KEY= JWT_ALGORITHM=HS256 # ── AI ── AI_ENABLED=true AI_PROVIDER=openrouter OPENROUTER_API_KEY= OPENROUTER_MODEL=qwen/qwen2.5-vl-72b-instruct AI_TAGS_MIN=5 AI_TAGS_MAX=10 AI_DESCRIPTION_LANGUAGE=francais AI_REQUEST_TIMEOUT=60 AI_MAX_RETRIES=2 # ── OCR ── OCR_ENABLED=true OCR_LANGUAGES=fra+eng # ── CORS ── CORS_ORIGINS=["http://localhost:3000", "http://localhost:8000"] # ── Pipeline ── PIPELINE_TIMEOUT=300 PIPELINE_MAX_RETRIES=3 # ── Rate Limiting (Redis persistence) ── RATE_LIMIT_STORAGE_URL=redis://redis:***@#!/bin/bash # Backup PostgreSQL — tous les jours à 2h 0 2 * * * docker exec imago-db-1 pg_dump -U imago imago > /opt/imago/backups/imago_$(date +\%Y\%m\%d).sql # Nettoyer les backups de plus de 30 jours 0 3 * * * find /opt/imago/backups -name "*.sql" -mtime +30 -delete ``` --- ## Étape 5 — Vérifications post-déploiement ```bash # Vérifier que tous les conteneurs tournent docker compose -f /opt/imago/docker-compose.production.yml ps # Santé de l'API curl http://localhost:8000/health # Santé détaillée (tous les services) curl http://localhost:8000/health/detailed # Accéder au panneau admin curl http://localhost:3000 ``` Checklist : - [ ] `http://localhost:8000/health` → `{"status":"healthy"}` - [ ] `http://localhost:8000/health/detailed` → tous les checks OK - [ ] `http://localhost:3000` → page de login accessible - [ ] Connexion admin avec `ADMIN_API_KEY` - [ ] Upload d'une image test → pipeline OK - [ ] Métriques Prometheus `/metrics` → données présentes