Appliqué en production : 7 écritures, 1 483,23 EUR, compte courant d'associé
porté de -429,75 à -1 912,98. Grand livre auxiliaire intact — 12 tiers, 15
factures fournisseur, inchangés.
La première approche créait un tiers fournisseur « Radureau Gabriel » et lui
adressait 7 factures. C'était faux : le gérant n'est pas un fournisseur de sa
société, et lui ouvrir une fiche l'aurait fait apparaître au grand livre
auxiliaire, dans les balances âgées et les états de dettes fournisseurs —
l'objection exacte déjà opposée à l'URSSAF dans RUNBOOK_charges_sociales.md,
que j'ai reproduite en la contredisant. L'existant le disait pourtant : les 8
dettes déjà portées au compte courant sont toutes des factures de fournisseurs
RÉELS payées personnellement, le tiers n'étant jamais le gérant.
Le modèle correct est direct. Le compte bancaire CCA1 (id 3) porte le numéro
comptable 45511 et son propre journal ; un paiement divers en sens débit, code
613000 Locations, produit
débit 613000 Locations (la charge)
crédit 45511 G. RADUREAU, compte courant (la dette envers l'associé)
Correction au passage : le plan comptable EST chargé (358 comptes, dont un
455110 dédié au compte courant du gérant). adc-009 affirme « module comptabilité
pas déployé » en confondant trois choses — le plan chargé, l'API REST absente,
et le dictionnaire des types de charges sans code comptable.
Deux bugs de ma main, trouvés en répétition :
- l'idempotence comparait les 24 PREMIERS CARACTÈRES du libellé, or
« Indemnité d'occupation — » en fait exactement 24 : mars reconnaissait
février et se déclarait déjà enregistré. Six mois silencieusement sautés.
On compare désormais le libellé entier, avec tolérance à la troncature
« … » de Dolibarr. recordSocialCharge.ts porte le même défaut, latent :
ses libellés diffèrent avant le 24e caractère, aujourd'hui seulement.
- une boucle shell utilisait `set -- $m`, qui ne découpe pas les mots en zsh :
la date devenait « 2026-- ». Le script a correctement refusé d'écrire.
/variouspayments répond « API not found » : le pipeline gated, qui parle REST,
ne peut pas porter cette opération — comme pour les charges sociales. Le script
en garde la discipline (répétition sandbox, relecture par la liste, opt-in
production explicite) sans le juge ni l'artefact de gate.
Le run gated abandonné est conservé sous fleet/harness/runs/ avec ABANDONNE.md :
il documente ce que le harness a vu, et surtout ce qu'il n'a pas vu.
Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
test — Dolibarr UI automation (Deno + Playwright)
A small Deno + Playwright POC that drives the Dolibarr admin UI in the fr-FR
locale. Playwright fills the same forms a human admin would, so the automation
works even where the REST API can't (e.g. generating an API key, which is
encrypted with the instance's own DOLI_INSTANCE_UNIQUE_ID).
Layout
main.ts— original entrypoint (first install, company/display/module setup).provisionSandbox.ts— entrypoint that provisions theerp-sandboxinstance for the AI agent (enable REST API, create a write-scoped user, generate its API key).scripts/login.ts— admin login / logout / whoami helpers.scripts/forms.ts—fillForm,toggleOnOff, CKEditor/ACE helpers.scripts/admin/moduleSetup.ts—configureModule,enableApiModule.scripts/admin/userSetup.ts—createUser,assignRights,generateApiKey.
Configure
Copy .env.example to .env and fill it in. .env, *.key, and
.ai_agent_sandbox.key are gitignored — never commit secrets.
cp .env.example .env
Lock the installer (after a fresh install via main.ts)
Dolibarr keeps its web installer reachable until an install.lock file exists.
After a fresh install (the main.ts flow), create it in the target pod — for the
sandbox:
kubectl -n erp-sandbox exec \
"$(kubectl get pod -n erp-sandbox -l app.kubernetes.io/instance=erp-sandbox -o name)" -- \
/bin/sh -c 'touch /var/www/documents/install.lock && chown www-data:www-data /var/www/documents/install.lock'
The path is the Dolibarr data root (/var/www/documents, a PVC) — that's where
Dolibarr checks, and being on the PVC the lock persists across pod restarts. For
prod, swap to -n erp -l app.kubernetes.io/instance=erp. A sandbox seeded from
prod still needs this: the seed (see ../ops/sandbox/) copies the DB +
documents/mycompany, not install.lock.
Provision the sandbox
Provisions erp-sandbox.arcodange.lab: enables the REST API module, creates the
write-scoped ai_agent_sandbox user, grants it its write rights, and has
Dolibarr generate the user's API key. The key is written to
test/.ai_agent_sandbox.key (gitignored) — it is never printed.
cd test
deno run --allow-all provisionSandbox.ts
Populate .env from the erp-sandbox namespace secrets first. secretkv
carries the app env (including DOLI_ADMIN_PASSWORD); vso-db-credentials
carries the database password:
# Admin password (key DOLI_ADMIN_PASSWORD inside the secretkv secret)
kubectl get secret secretkv -n erp-sandbox \
-o jsonpath='{.data.DOLI_ADMIN_PASSWORD}' | base64 -d
# Database password (key `password` inside vso-db-credentials)
kubectl get secret vso-db-credentials -n erp-sandbox \
-o jsonpath='{.data.password}' | base64 -d
Set in .env:
DOLIBARR_ADDRESS=https://erp-sandbox.arcodange.lab
DOLI_ADMIN_LOGIN=admin
DOLI_ADMIN_PASSWORD="<from secretkv above>"
DOLI_DB_PASSWORD="<from vso-db-credentials above>"
# Optional — otherwise a random password is generated and only the API key emitted:
# AI_AGENT_SANDBOX_PASSWORD="<choose one>"
After it runs
The generated API key lands in test/.ai_agent_sandbox.key. Next step (not
automated by this POC): load it into the dolibarr skill's sandbox config /
Vault at kvv2/erp-sandbox/ai_agent.
Important
The sandbox Dolibarr is not installed/provisioned yet (empty DB, fresh install wizard). Until the install wizard has been completed against the sandbox,
provisionSandbox.tswill not have a UI to drive, and the selectors inmoduleSetup.ts/userSetup.tsare best-effort (Dolibarr 22 conventions, not verified live). Confirm them on the first real run.
Write rights granted
The ai_agent_sandbox user is created non-admin and granted (the authoritative
list is WRITE_IDS in provisionSandbox.ts):
| Module | rights ids |
|---|---|
| facture | lire=11, creer=12 |
| societe | lire=121, creer=122, client voir=262 |
| societe contact | lire=281, creer=282 |
| fournisseur | lire=1181, facture lire=1231, facture creer=1232 |
| produit | lire=31, creer=32 |
| banque | lire=111 |
| user | lire=251 — requis par le probe armé GET /users/info (checkpoint status/relink-env) |