Files
Imago/docs/DEPLOYMENT.md
T
bruno 0050ace888
CI / Lint & Format (push) Failing after 9s
CI / Tests (push) Has been skipped
CI / Security Scan (push) Failing after 7s
CI / Docker Build (push) Has been skipped
Update deploy doc to use docker-registry.dev.home:5000 + production compose
2026-06-22 20:30:22 -04:00

3.2 KiB

Guide de déploiement — Imago sur serveur Docker

Cible : serveur Docker du lab (dev.lab.home / Proxmox) Registry : docker-registry.dev.home:5000 Prérequis : Docker 24+, Docker Compose v2, accès SSH


Étape 1 — Builder et pousser l'image vers le registry

Depuis le poste de développement (Windows + WSL Debian) :

cd C:\dev\git\python\imago\docker

# Builder l'image
.\build-img.ps1

# Pousser vers le registry (version semver auto-incrémentée)
.\deploy-img.ps1

L'image est disponible à :

  • docker-registry.dev.home:5000/imago-backend:latest
  • docker-registry.dev.home:5000/imago-backend:2.0.0

Étape 2 — Préparer les secrets de production

# Générer des secrets forts (à faire UNE SEULE fois)
openssl rand -hex 32  # SECRET_KEY
openssl rand -hex 32  # ADMIN_API_KEY  → note-la, c'est ta clé admin
openssl rand -hex 32  # JWT_SECRET_KEY
openssl rand -hex 32  # SIGNED_URL_SECRET
openssl rand -hex 16  # MINIO_ROOT_PASSWORD
openssl rand -hex 16  # POSTGRES_PASSWORD

Créer .env.production (remplacer les <...>) :

# ── Application ──
APP_NAME=Imago
APP_VERSION=2.0.0
DEBUG=false
SECRET_KEY=<valeur générée>

# ── Base de données ──
DATABASE_URL=postgresql+asyncpg://imago:<POSTGRES_PASSWORD>@db:5432/imago

# ── Stockage MinIO ──
STORAGE_BACKEND=s3
S3_BUCKET=imago
S3_ENDPOINT_URL=http://minio:9000
S3_ACCESS_KEY=minioadmin
S3_SECRET_KEY=<S3_SECRET_KEY généré>
S3_REGION=us-east-1
SIGNED_URL_SECRET=<valeur générée>

# ── Redis ──
REDIS_URL=redis://redis:***@ADMIN_API_KEY=<valeur générée>
JWT_SECRET_KEY=<valeur générée>
JWT_ALGORITHM=HS256

# ── AI ──
AI_ENABLED=true
AI_PROVIDER=openrouter
OPENROUTER_API_KEY=<clé OpenRouter>
OPENROUTER_MODEL=qwen/qwen2.5-vl-72b-instruct
AI_TAGS_MIN=5
AI_TAGS_MAX=10
AI_DESCRIPTION_LANGUAGE=francais
AI_REQUEST_TIMEOUT=60
AI_MAX_RETRIES=2

# ── OCR ──
OCR_ENABLED=true
OCR_LANGUAGES=fra+eng

# ── CORS ──
CORS_ORIGINS=["http://localhost:3000", "http://localhost:8000"]

# ── Pipeline ──
PIPELINE_TIMEOUT=300
PIPELINE_MAX_RETRIES=3

# ── Rate Limiting (Redis persistence) ──
RATE_LIMIT_STORAGE_URL=redis://redis:***@#!/bin/bash
# Backup PostgreSQL — tous les jours à 2h
0 2 * * * docker exec imago-db-1 pg_dump -U imago imago > /opt/imago/backups/imago_$(date +\%Y\%m\%d).sql

# Nettoyer les backups de plus de 30 jours
0 3 * * * find /opt/imago/backups -name "*.sql" -mtime +30 -delete

Étape 5 — Vérifications post-déploiement

# Vérifier que tous les conteneurs tournent
docker compose -f /opt/imago/docker-compose.production.yml ps

# Santé de l'API
curl http://localhost:8000/health

# Santé détaillée (tous les services)
curl http://localhost:8000/health/detailed

# Accéder au panneau admin
curl http://localhost:3000

Checklist :

  • http://localhost:8000/health → {"status":"healthy"}
  • http://localhost:8000/health/detailed → tous les checks OK
  • http://localhost:3000 → page de login accessible
  • Connexion admin avec ADMIN_API_KEY
  • Upload d'une image test → pipeline OK
  • Métriques Prometheus /metrics → données présentes