Commit Graph
14 Commits
Author SHA1 Message Date
bastien 4f8bb61458 feat(cloudpex): site values out of the script, prompted at install into /etc/cloudpex.conf
cloudpex/cloudpex no longer carries the NAS host, share name, SMB user,
mount point or SMB version. It reads /etc/cloudpex.conf (root:root 0600,
KEY=value) line by line, never sources it, and dies with a hint when the
file is missing, incomplete or has a relative mount point.

cloudpex/install.sh prompts for the five values (regex-validated, re-asked
on bad input so the main installer never aborts), shows and keeps an
existing config unless answered n, and skips the config when no terminal
is attached. README (FR) + root README + CLAUDE.md updated.
2026-09-22 17:34:18 +02:00
bastien 872079bafb feat(install): offer /tmp on disk + SSH memory guard, deploy cloudpex helper
/tmp is a RAM-backed tmpfs on Ubuntu (50% of RAM). Agent runs fill it: half
the RAM goes, then every temp-file creation fails with ENOSPC and shells
break. Swap does not lift the cap, so the fix is /tmp on disk.

End-of-install offers (Linux, [y/N], skipped without a terminal, idempotent):
- offer_tmp_on_disk: mask tmp.mount + etc/tmpfiles.d/tmp.conf (wipe at
  boot, 10-day purge, /var/tmp rule kept). Effective at next reboot.
- offer_ssh_memory_guard: the previous server's rules. ssh.service drop-in
  (OOMScoreAdjust=-1000, MemoryMin=256M) + earlyoom with --avoid sshd and
  --prefer node/java. MemoryMin covers sshd only; earlyoom is the real guard.

install_cloudpex deploys the NAS mount helper in the Linux block.
Docs: README steps 12-14 + table, CLAUDE.md layout + lint command.
2026-09-22 16:57:08 +02:00
bastien 9dacef3823 feat(cloudpex): track the on-demand SMB mount helper, add installer + README
cloudpex/cloudpex mounts //192.168.1.111/CloudPex on /mnt/cloudpex on demand
(password prompted, nothing stored, noexec/nosuid/nodev, dir_mode 0750).
cloudpex/install.sh reproduces the live deployment: /usr/local/bin/cloudpex
root:root 0755, /mnt/cloudpex, cifs-utils if mount.cifs is missing.
README (FR) explains why on-demand and not fstab (RECOVERY doc 04).
2026-09-22 16:57:08 +02:00
bastien 3085b86828 test hook fix 2026-05-15 22:16:24 +02:00
bastien 2a56874597 test hook fix 2026-05-15 22:14:04 +02:00
bastien 3509b62187 test hook fix 2026-05-15 22:13:21 +02:00
bastien ac1b733e8a test hook fix 2026-05-15 22:06:07 +02:00
bastien 63e6b61437 test mirror 2026-05-15 21:52:29 +02:00
bastien 5fd27b35f4 added nerdtree to iunstall 2025-12-11 17:03:50 +01:00
bastien 628e6d9aa0 added vim 2025-12-11 16:53:30 +01:00
bastien f3541a6446 delete pipi 2025-12-11 16:51:30 +01:00
bastien ecd845d5ef added install.sh 2025-12-11 16:33:12 +01:00
bastien 741612366a add bash 2025-12-11 16:32:41 +01:00
bastien e7b8acf313 test 2025-12-11 16:30:02 +01:00