diff options
Diffstat (limited to 'CLAUDE.md')
| -rw-r--r-- | CLAUDE.md | 39 |
1 files changed, 31 insertions, 8 deletions
@@ -14,9 +14,18 @@ meshbay/ │ ├── meshbay-hub/ # Hub server (FastAPI + PostgreSQL) — meshbay-hub RPM │ └── meshbay-node/ # Node daemon + local UI — meshbay-node RPM ├── poc/ # POC spike scripts (reference, not production) -└── docs/ # Architecture drafts and POC plans +├── docs/ # Architecture drafts and POC plans +├── packaging/ # RPM spec files, DEB control files, systemd units +└── QE/ # NOT versioned (.gitignore) — test artefacts, credentials, demos + ├── demo-v1/ # Scripts démo opérationnels (setup_demo.py, run_node.py, download.py) + ├── spikes/ # Expérimentations futures (remplace ~/draft/) + └── server-state/ # Inventaire de ce qui tourne sur meshbay.org ``` +**Règle QE/** : tout test sur meshbay.org doit ouvrir le port UFW, tester, et +fermer le port + tuer les processus dans le MÊME bloc de commandes. +Jamais de processus orphelins ni de ports ouverts après un test. + ## Python environment - **Minimum Python:** 3.12 @@ -75,20 +84,34 @@ Scope: `hub`, `node`, `common`, or omitted for cross-cutting ## Security rules - **Never commit private keys** (hub_private.pem, *.key, unlock.key, keystore.enc) -- **Never commit node_state.json or bob_state.json** (contain private key material) +- **Never commit QE/** — credentials, test keys, demo data go there - **Never log GEK, private keys, or plaintext passwords** — even at DEBUG level -- **meshbay.org is internet-facing** — kill all test processes after spikes, close test UFW ports +- **meshbay.org is internet-facing** — open port → test → close port + kill processes in same block ## Known calibration TODOs - Argon2id `memory_cost`: currently 65536 (64 MB, 78ms) — increase to 262144 (256 MB) before prod to target ~500ms on typical home server hardware. Implement a `calibrate` CLI command. -## meshbay.org server +## Key modules — où trouver quoi + +| Besoin | Module | Fichier | +|---|---|---| +| Chiffrement chunks (prod) | `meshbay_common.crypto` | `crypto.py` | +| Dérivation clés depuis password | `meshbay_common.keyderive` | `keyderive.py` | +| Bundle clés (web) | `meshbay_common.keyderive` | `keyderive.py` + `static/keyderive.js` | +| GEK wrap/unwrap (ECIES) | `meshbay_common.crypto` | `crypto.py` | +| Double Ratchet (chat) | `meshbay_common.ratchet` | `ratchet.py` | +| AES-GCM (navigateur) | `meshbay_common.webcrypto` | `webcrypto.py` + `static/crypto.js` | +| Keystore node | `meshbay_node.keystore` | `keystore.py` | +| Scripts de démo opérationnels | — | `QE/demo-v1/*.py` (non versionné) | + +## meshbay.org server (état cible) - OS: Ubuntu 26.04 LTS, Python 3.14.4 - SSH: `ssh cbesson@meshbay.org` -- Web proxy: Caddy (to be installed) behind ports 80/443 -- UFW rules: only 22/tcp, 80/tcp, 443/tcp -- **Always close test ports after spikes** (`sudo ufw delete allow <port>/<proto>`) -- Hub POC files: `~/meshbay-poc/` (reference only, not production) +- Caddy : reverse proxy HTTPS sur 80/443 +- UFW rules: **22/tcp, 80/tcp, 443/tcp uniquement** +- Services légitimes : `meshbay-hub.service`, Caddy, PostgreSQL (local) +- Inventaire détaillé : `QE/server-state/meshbay.org.md` +- Deploy hub : voir `QE/server-state/meshbay.org.md` |