Commit Graph
35 Commits
Author SHA1 Message Date
Bastien Chanot 30b0e44a45 chore(clean): remove dead CSS + normalize whitespace (tour CLN)
index.html: drop unused .reveal.d6 rule (markup uses d1-d5 only).

CV_Bastien_Chanot.html:
- remove dead `position: running(siteFooter)` — no `element()` consumer,
  and .footer-bar is `display:none` in @media print (the @page
  auto-numbered footer replaces it); on screen running() is an invalid
  position value, ignored.
- remove no-op `box-shadow: none` on .page (weasyprint ignores box-shadow;
  .page sets a shadow nowhere).
- remove dead `.skills-grid { font-size: 8.4pt }` (every direct child is a
  .skill-label/.skill-values div that sets its own size; no bare text).
- normalize stray blank lines.

Behavior-preserving: PDF regenerated from the edited HTML is byte-identical
to the pre-edit baseline (text sha256 + per-page PNG render hash match),
so CV_Bastien_Chanot.pdf is unchanged and the PDF=HTML invariant holds.
2026-07-05 20:47:51 +02:00
Bastien Chanot d7256ffe0e chore(deploy): mark 2026-07-05-2 @ b24c58b 2026-07-05 20:25:07 +02:00
Bastien Chanot b24c58b8a4 Merge chore/tour-residuals into develop 2026-07-05 20:06:12 +02:00
Bastien Chanot ef7e2312c6 docs: legalize functional neutrals (CLN-4) + CSP-hash invariant + TOUR follow-up
CLAUDE.md palette now two enforceable lists (6 brand + 8 documented
neutrals — anything else is a violation); workflow gains the recompute-
CSP-hash-after-JS-edit invariant with the exact command. README points to
the neutrals list. TOUR.md follow-up: CLN-3/CLN-4/SEC-7 closed, INF-2
corrected (false positive — .gitignore exists).
2026-07-05 19:59:45 +02:00
Bastien Chanot c0632aefa8 fix(security): pin script-src to the inline script's sha256 hash (SEC-7)
unsafe-inline dropped for scripts (index has zero style/script attributes;
the single inline script is hash-pinned). style-src keeps unsafe-inline
(CV carries 2 style attributes + single-file convention). Verified in
hardened container: served-script hash == policy hash, JS executes.
2026-07-05 19:59:45 +02:00
Bastien Chanot d63a52ec50 chore(clean): dedup card CSS via grouped selectors (CLN-3)
Shared chrome/hover/head/title/tag blocks for stack/project/theme cards +
methode items; per-class blocks keep only specifics. Zero HTML change,
cascade-order verified (no interfering rules between shared and specific
blocks). Net -60 lines; the audit's ~421 estimate was overstated.
2026-07-05 19:59:45 +02:00
Bastien Chanot bd7f6e4984 docs(deploy): runbook style — one command per line, session style 2026-07-05 15:31:10 +02:00
Bastien Chanot 395c77b597 chore(deploy): mark 2026-07-05 @ 5fe8b41 2026-07-05 15:23:46 +02:00
Bastien Chanot 5fe8b4119b feat(deploy): bootstrap runbook 2026-07-05 15:17:00 +02:00
Bastien Chanot 7b2d033761 Merge chore/tour-2026-07-05 into develop 2026-07-05 15:07:30 +02:00
Bastien Chanot c335769e1a docs(tour): auto run 2026-07-05 — converged in 2 iterations, 10 fixed, 3 open 2026-07-05 14:19:44 +02:00
Bastien Chanot 840632a6f8 docs: .githooks + hooksPath clone note; deploy section synced (native-nginx prod, hardened container path, headers snippet) 2026-07-05 14:12:43 +02:00
Bastien Chanot 7e7bd66384 chore(clean): enforce palette + reduced-motion, drop dead CSS
- 5x background:#fff -> var(--page) (stack/project/theme/methode cards +
  CV body) per CLAUDE.md 'no pure white background' (user-approved strict
  conformity; visual change: cards now blend with parchment, border-kept)
- prefers-reduced-motion now also kills transitions (universal rule)
- dead .screen-label rule removed (no matching element)
- PDF regenerated via weasyprint (must match HTML invariant)
2026-07-05 14:12:01 +02:00
Bastien Chanot ba13d697a5 fix(security): unprivileged nginx + security headers on every location
- base image -> nginxinc/nginx-unprivileged:1.28-alpine, digest-pinned
  (BREAKING for the docker path: container port 80 -> 8080; compose
  mapping/healthcheck updated in the same change, cap_add dropped)
- nginx add_header inheritance fix: shared snippets file re-included in
  every location that sets Cache-Control -- previously ALL security
  headers were dropped on real responses (verified live before/after)
- server_tokens off; set_real_ip_from restricted to 127.0.0.1
- expires directives removed (duplicated Cache-Control); gzip_types
  text/html redundancy removed (nginx -t warn)
2026-07-05 14:10:55 +02:00
Bastien Chanot 5a813df015 docs(tour): report-only audit 2026-07-05 — 7 security, 5 clean, 2 doc findings; reconcile zero-drift 2026-07-05 13:09:42 +02:00
Bastien Chanot f8b32d0797 Merge feature/doc-sync into develop 2026-07-01 14:31:37 +02:00
Bastien ChanotandClaude Opus 4.8 ce5c0481df docs: Docker deploy + contents table
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RNaYKPEkjH1jbgoX1TwKMX
2026-07-01 14:31:37 +02:00
Bastien Chanot b5e127489b Merge chore/reconcile-memory into develop 2026-07-01 14:27:48 +02:00
Bastien ChanotandClaude Opus 4.8 dd186c9dac chore(memory): reconcile TODO with shipped extended-vitrine (1369d27)
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RNaYKPEkjH1jbgoX1TwKMX
2026-07-01 00:20:23 +02:00
Bastien Chanot 195188f518 chore: adopt gitflow socle + pre-commit hook 2026-06-29 02:37:20 +02:00
Bastien Chanot 1ae73e0534 cv definitif 2026-05-17 04:26:29 +02:00
Bastien ChanotandClaude Opus 4.7 aa52153b2c docs(memory): BLK-001 favicon 404 in prod — Dockerfile COPY whitelist
Root cause + fix logged. New repo assets must be added to Dockerfile
COPY whitelist explicitly; future option = glob pattern if asset count
grows. Journal updated.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-17 04:08:18 +02:00
Bastien ChanotandClaude Opus 4.7 f1e4392c65 fix(docker): COPY favicon assets into image + cache header
Dockerfile selectively COPYs files into /usr/share/nginx/html. Favicon
assets (favicon.svg, favicon-32.png, favicon.ico, apple-touch-icon.png)
were added to the repo in ef31fb3 but never wired into the Dockerfile,
so a rebuilt container served 404 for /favicon.svg and friends — broken
favicon in prod even after `docker compose up -d --build`.

nginx.conf gets a matching long-cache rule for icon/image assets
(30 days, immutable, access_log off) — they rarely change and the file
name is the cache key anyway.

Deploy: on the VPS, `docker compose up -d --build`.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-17 04:07:32 +02:00
Bastien Chanot 1f9416edf0 added pdf and html cv version 2026-05-17 03:54:39 +02:00
Bastien ChanotandClaude Opus 4.7 86d4c729ed docs(memory): capitalize BDR-005 favicon strategy + LRN-002 PIL icon recipe
- BDR-005: SVG primary + PIL-generated PNG/ICO fallback for favicon set;
  alternatives (rsvg-convert/inkscape, SVG-only, online generator) rejected
  with reasons; CV mirror deferred to user finalization.
- LRN-002: PIL supersample x8 + Lanczos downscale produces clean
  small-format icon antialiasing without rsvg-convert/inkscape/ImageMagick.
- journal: 2026-05-17 entry — extended-vitrine refactor (1369d27) +
  favicon set (ef31fb3); CV files left untouched (user WIP).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-17 03:53:42 +02:00
Bastien ChanotandClaude Opus 4.7 ef31fb3059 feat(landing): add favicon set — SVG primary + PNG/ICO fallback
Brand pulse-dot translated to favicon: dark rounded square (#0d1b12) +
inner green dot (#6ab98a) + faint outer ring (#2d7a4f @60%). Identical
visual language to .brand::before in the nav.

Assets:
- favicon.svg          — vector primary (modern browsers, scales)
- favicon-32.png       — PNG hint
- favicon.ico          — legacy multi-size (16/24/32/48)
- apple-touch-icon.png — iOS home-screen 180x180

PIL-generated PNG/ICO at 8x supersample + Lanczos downscale for clean
antialiasing. No external dependency added (PIL already on system).

index.html: 4 <link> tags wired in <head> (SVG, PNG 32, ICO alternate,
apple-touch). CV HTML left untouched; browser auto-fetches /favicon.ico
from root as fallback — TODO logged to mirror the link block when the
user finalizes CV edits.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-17 03:51:14 +02:00
Bastien ChanotandClaude Opus 4.7 1369d27b5b feat(landing): extended-vitrine refactor — CV-aligned, +Projets, +Méthode
Landing now says more than the CV instead of duplicating it.

- meta/title: synced with new positioning (kernel, AOSP, cloud gaming, GPU)
- nav: added #projets and #methode anchors
- hero: subtitle "Développeur Systèmes · Embarqué · Backend",
  tech banner Backend·Cloud
- about: senior wording + 3 new paragraphs (philosophy, target context,
  what I'm not chasing)
- stack: 6 → 8 cards
  - dropped VMware, Gitflow, Agile
  - added cgroups, namespaces, SELinux, GitHub Actions
  - new Cloud/Infra card (AWS EC2, g4dn bare-metal, IAM, S3, CloudWatch,
    Scaleway VPS, OVH/Hetzner, Nginx, Apache, Let's Encrypt)
  - new IA/Outils card (Claude Code agents/skills, N8N, automation)
  - Familier avec: C++ sub-row in Langages
- parcours: removed lone-wolf wording (seul / responsable unique);
  CareGame / ZenQuality / Deewee rewritten as intro + technical bullets +
  per-experience stack pills; Deewee dates corrected to fév.-nov. 2017
  with Stage 42 + CDD contract line
- new Projets section between Parcours and Formation: Git auto-hébergé
  (git.bchanot.fr) and Homelab
- new Méthode section between Formation and Contact: 5 habits
- contact email: chanot.bastien@gmail.com → bastien@bchanot.fr
- CSS: extensions only (.timeline-bullets, .timeline-stack,
  .timeline-intro, .timeline-contract, .projects-grid, .project-card*,
  .methode-list, .methode-item, .methode-num, .stack-note, .pill-context),
  all reusing existing design tokens

TODO.md tracks the refactor milestone.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-17 03:50:41 +02:00
bastien 54e9145bd7 mirror test 2026-05-15 22:19:04 +02:00
bastienandClaude 08220bd024 docs(memory): journal entry for formation copy fix
Co-Authored-By: Claude <noreply@anthropic.com>
2026-05-15 20:48:37 +02:00
bastienandClaude e1d75d8b1e fix(formation): correct copy and remove inaccurate CareGame line
- Section title now anchors the "bas niveau" thread across both schools.
- Section intro: drop <em> for consistency with other section-intro blocks.
- École 42 description rewritten to surface kernel/memory/shell/security focus.
- TSRIT: remove false claim about stage transformed into CDI at CareGame
  (CareGame internship dates from 2018-2019 during 42, not 2015 TSRIT).

Co-Authored-By: Claude <noreply@anthropic.com>
2026-05-15 20:48:12 +02:00
bastienandClaude c2e1dd30a8 docs(memory): backfill registries for docker, certbot, formation
decisions.md  — log BDR-004 (containerize site with nginx:alpine behind reverse
                proxy): rationale, hardening flags (read_only, cap_drop,
                no-new-privileges, tmpfs), alternatives rejected (bare nginx,
                Caddy/Traefik). Reference commits: 7957b04.

learnings.md  — log LRN-001 (certbot --nginx matches `server_name`, not
                filename): root cause was leftover `server_name autreprojet.fr`
                in `sites-available/bchanot.fr`. Future check:
                `grep -n "server_name" /etc/nginx/sites-enabled/*` before any
                certbot install on a multi-site VPS.

journal.md    — 5 lines covering docker setup, git init + remote + push,
                certbot diagnose + fix, prior commit batch, and today's
                feat(formation) section work (commit 1d5fbfa).

Co-Authored-By: Claude <noreply@anthropic.com>
2026-05-15 20:37:28 +02:00
bastienandClaude 1d5fbfa148 feat(formation): add dedicated Formation section + nav link, remove Formation aside from Contact
- New <section id="formation"> between Parcours and Contact, reusing timeline
  + card visual components from the existing system (palette, typos, animations).
- École 42 (2015–2019): 3 theme cards (Systèmes & Kernel · Bas niveau & Outils
  système · Sécurité & Algorithmie) with project list + concise technical proof
  for each entry (no scolarisms).
- TSRIT — Next Formation (2013–2015): BTS + "Félicitations du jury" badge,
  réseau/TCP-IP/admin Linux fundamentals, stage transformed into CareGame CDI.
- Nav: "Formation" link inserted between Parcours and Contact.
- Contact: removed the old <aside class="contact-side"> Formation block and
  the now-unused .contact-side / .education / 2-col contact-grid CSS;
  .contact-list becomes 2-col on >=768px to fill the freed space.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-05-15 20:20:04 +02:00
bastien 414bce1ce9 final version of cv html and pdf 2026-05-15 20:08:50 +02:00
bastienandClaude Opus 4.7 7957b04de0 feat(docker): containerize site with configurable host port
Add Dockerfile (nginx:1.27-alpine), nginx.conf (gzip, cache, CSP and
security headers, no HSTS — left to outer proxy), and docker-compose
service `bchanot-web`. Host port is configurable via PORT env var
(default 8080) and bound to 127.0.0.1 so the container sits behind a
reverse proxy. Container hardened with read_only fs, cap_drop ALL,
no-new-privileges, and tmpfs for nginx runtime dirs. Healthcheck via
wget on /. Also adds .dockerignore and .env.example, and ignores .env.

Usage:
  cp .env.example .env
  docker compose up -d --build

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-15 16:53:20 +02:00
bastienandClaude Opus 4.7 54e830016c chore: initial commit — landing page + CV + Claude config
Single-page static site at bchanot.fr: landing (index.html) and CV
(HTML + PDF), pure HTML/CSS/JS, no build step. Includes project
conventions (CLAUDE.md), README, and .claude/ memory/tasks/audits
scaffolding.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-15 16:53:06 +02:00