Projets Techniques

Technical Projects

Architectures, déploiements et cas d'usage réels.

Architectures, deployments, and real-world use cases.

Moomoo Café (moomoocafe.fr)

2026
Hébergement, Déploiement & Sécurisation (Archivé)
Hosting, Deployment & Security (Archived)
Moomoo Café
Docker Traefik MariaDB VPS Linux

Contexte : Mise en production et infogérance complète de l'application Moomoo Café. L'enjeu était de proposer une architecture robuste, capable de cloisonner les données sensibles (espaces entreprises et employés) tout en garantissant un accès chiffré via Internet.

Architecture Conteneurisée (3 Conteneurs)

  • Conteneur 1 (Reverse Proxy Traefik) : Point d'entrée unique exposé sur les ports 80/443. Il intercepte les requêtes web, gère automatiquement le renouvellement des certificats SSL (Let's Encrypt), et route le trafic de manière sécurisée vers le frontend.
  • Conteneur 2 (Application Web) : Héberge la logique de l'application (Frontend/Backend). Il est isolé d'Internet et n'est accessible que par Traefik via un réseau Docker privé.
  • Conteneur 3 (Base de données MariaDB) : Stocke les identifiants, les données des employés et les configurations des entreprises. Ce conteneur n'a aucune exposition externe (pas de port binding 3306 sur l'hôte). Il communique exclusivement avec le conteneur applicatif via le réseau interne Docker, garantissant une sécurité "Zero Trust" depuis l'extérieur.

Context: Full production deployment and infrastructure management for the Moomoo Café application. The challenge was to provide a robust architecture capable of isolating sensitive data (employee and company dashboards) while ensuring encrypted access from the web.

Containerized Architecture (3 Containers)

  • Container 1 (Traefik Reverse Proxy): Single entry point exposed on ports 80/443. Intercepts web requests, automatically handles SSL certificates renewal (Let's Encrypt), and routes traffic securely to the frontend.
  • Container 2 (Web Application): Hosts the application logic (Frontend/Backend). It is isolated from the Internet and only accessible by Traefik through a private Docker network.
  • Container 3 (MariaDB Database): Stores credentials, employee data, and company settings. This container has no external exposure (no 3306 port binding on the host). It communicates exclusively with the app container via the internal Docker network, ensuring external "Zero Trust" security.

Schéma des flux de l'infrastructure Docker

Docker Infrastructure Flow Schema

graph LR Client([Web Client]) -->|HTTPS :443| Traefik[Traefik
Reverse Proxy] subgraph "Host VPS (Private Docker Network)" Traefik -->|Internal Routing| App[Web Container
Moomoo App] App -->|SQL Queries| DB[(Database Container
MariaDB)] end classDef proxy fill:#2e1065,stroke:#9b51e0,stroke-width:2px,color:#fff; classDef app fill:#0f172a,stroke:#3b82f6,stroke-width:2px,color:#fff; classDef db fill:#0f172a,stroke:#10b981,stroke-width:2px,color:#fff; classDef client fill:#f1f5f9,stroke:#64748b,stroke-width:2px,color:#000; class Traefik proxy; class App app; class DB db; class Client client;

Aperçu de l'application (Cliquez pour agrandir)

Application Overview (Click to enlarge)

Accueil Moomoo Café
Page d'accueil Homepage
Portail Connexion B2B
Portail Connexion B2B B2B Login Portal
Prise de commandes B2B
Interface de commandes Ordering Interface
Suivi des commandes B2B
Suivi des commandes Order Tracking
Portail Employés
Portail Employés Staff Login Portal
Gestion des commandes en cuisine
Dashboard de Gestion (Cuisine) Kitchen Management Dashboard

Sécurisation des accès administrateurs & Hardening AD

2024
Mitsubishi Electric R&D Centre Europe
Mitsubishi Electric
Active Directory PingCastle Admin By Request PowerShell Fortinet VMware vSphere

Contexte : Le S.I. présentait des vulnérabilités critiques avec un score PingCastle de 100/100 sur les comptes à privilèges, dû à une utilisation généralisée des droits administrateurs locaux. L'objectif était de mettre l'infrastructure en conformité avec les guidelines de sécurité du groupe (Zero Trust, Modèle de Tiering).

Réalisations Techniques :

  • Gestion des Privilèges (PAM) : Révocation totale des droits administrateurs locaux sur l'ensemble des postes. Déploiement par GPO et MDT de la solution Admin By Request pour permettre une élévation de privilèges temporaire, soumise à validation et entièrement journalisée.
  • Hardening Active Directory : Implémentation de l'architecture de Tiering (Tier 1-0 pour les serveurs/AD, Tier 2 pour la bureautique). Nettoyage en masse des attributs SIDHistory obsolètes via scripting PowerShell (188 objets traités). Le score PingCastle a été drastiquement réduit de 100 à 5.
  • Station Blanche d'Administration : Déploiement d'une VM d'administration dédiée. Isolation réseau stricte via FortiGate (blocage total de l'accès à Internet). Sécurisation du flux entrant via GPO : activation du RDP sur un port personnalisé et blocage du port standard.
  • LAPS : Préparation du déploiement de Microsoft LAPS pour la rotation automatisée des mots de passe des comptes administrateurs locaux.

Context: The IT system had critical vulnerabilities, including a PingCastle score of 100/100 for privileged accounts due to the widespread use of local admin rights. The goal was to align the infrastructure with corporate security guidelines (Zero Trust, AD Tiering Model).

Technical Achievements:

  • Privileged Access Management (PAM): Full revocation of local administrator rights across workstations. Deployment of Admin By Request via GPO and MDT to enable temporary, workflow-approved, and fully audited privilege elevation.
  • Active Directory Hardening: Implementation of the Tiering model (Tier 1-0 for Servers/AD, Tier 2 for workstations). Mass cleanup of obsolete SIDHistory attributes via PowerShell scripting (188 objects processed). The PingCastle vulnerability score was drastically reduced from 100 to 5.
  • Dedicated Admin Workstation: Deployment of a dedicated administration VM. Strict network isolation via FortiGate (total outbound internet block). Inbound traffic secured via GPO: custom RDP port activation and default port blocking.
  • LAPS: Preparation and deployment planning of Microsoft LAPS for automated local administrator password rotation.

Flux de la station d'administration isolée

Isolated Admin Workstation Flow

graph LR IT([IT Team
USERS VLAN]) -->|Secure RDP| VM[Admin Workstation
Clean Room VM] Internet((Internet)) -.->|Blocked by FortiGate| VM subgraph "SERVERS VLAN (Tier 1-0 Secure Zone)" VM -->|RSAT / RDP| AD[(Active Directory)] VM -->|Console / RDP| SRV[Infrastructure Servers] end classDef secure fill:#2e1065,stroke:#9b51e0,stroke-width:2px,color:#fff; classDef ad fill:#0f172a,stroke:#10b981,stroke-width:2px,color:#fff; classDef srv fill:#0f172a,stroke:#3b82f6,stroke-width:2px,color:#fff; classDef user fill:#f1f5f9,stroke:#64748b,stroke-width:2px,color:#000; classDef net fill:#ef4444,stroke:#b91c1c,stroke-width:2px,color:#fff; class VM secure; class AD ad; class SRV srv; class IT user; class Internet net;

Migration Réseau MPLS vers SD-WAN & Tenant M365

MPLS to SD-WAN Network Migration & M365 Tenant

2024
Mitsubishi Electric R&D Centre Europe
Mitsubishi Electric
SD-WAN Réseau M365 RGPD
  • Migration de l'interconnexion réseau européen des branches du groupe d'une technologie MPLS vers des liens SD-WAN sécurisés dans un but d'optimisation et d'uniformité.
  • Amélioration de la résilience réseau et réduction globale des coûts d'infrastructure télécom.
  • Migration préalable des outils bureautiques Office 365 depuis le tenant global vers le tenant européen pour assurer la conformité RGPD.
  • Migration of the corporate European branch network interconnection from MPLS technology to secure SD-WAN links for optimization and uniformity.
  • Improvement of network resilience and overall reduction of telecom infrastructure costs.
  • Prior migration of Office 365 productivity tools from the global tenant to the European tenant to ensure GDPR compliance.

Virtualisation & Isolation du Serveur de Badgeage

Badge Server Virtualization & Isolation

2024
Mitsubishi Electric R&D Centre Europe
Mitsubishi Electric
VMware vSphere VLAN Python
  • Remplacement en urgence d'un serveur physique vieillissant gérant le système de badgeage.
  • Externalisation de la sauvegarde existante, création d'une nouvelle Machine Virtuelle et restauration complète de l'environnement de production.
  • Création et implémentation d'un VLAN isolé spécifiquement dédié pour assurer l'étanchéité du réseau.
  • Développement et adaptation d'un script Python permettant l'export régulier (chaque minute) d'un fichier de présence vers des tablettes distantes situées sur le même réseau isolé.
  • Emergency replacement of an aging physical server managing the badging system.
  • Externalization of the existing backup, creation of a new Virtual Machine, and full restoration of the production environment.
  • Creation and implementation of a specifically dedicated isolated VLAN to ensure network segmentation.
  • Development and adaptation of a Python script enabling the regular export (every minute) of an attendance file to remote tablets located on the same isolated network.

Déploiement EDR Trend Micro & Serveur WSUS

Trend Micro EDR & WSUS Server Deployment

2024
Mitsubishi Electric R&D Centre Europe
Mitsubishi Electric
Cybersécurité EDR WSUS GPO
  • Migration de l'ensemble du parc bureautique, serveurs (Windows et Linux) et contrôleurs de domaine vers la solution EDR Trend Micro Deep Security pour répondre aux exigences de défense proactive.
  • Installation, configuration et mise en production d'un serveur Microsoft WSUS (rôles, groupes d'ordinateurs).
  • Création de stratégies de groupe (GPO) granulaires pour centraliser et automatiser le déploiement des correctifs de sécurité (séparation des politiques postes clients / serveurs).
  • Migration of the entire workstation fleet, servers (Windows and Linux), and domain controllers to the Trend Micro Deep Security EDR solution to meet proactive defense requirements.
  • Installation, configuration, and production deployment of a Microsoft WSUS server (roles, computer groups).
  • Creation of granular Group Policy Objects (GPOs) to centralize and automate the deployment of security patches (separation of workstation and server policies).

Refonte de l'Arborescence du Serveur de Fichiers (AGDLP)

File Server Structure Redesign (AGDLP)

2024
Mitsubishi Electric R&D Centre Europe
Mitsubishi Electric
Windows Server Active Directory AGDLP
  • Pilotage d'une réunion COPIL pour définir et expliquer l'implémentation de la méthode de sécurité Microsoft AGDLP.
  • Communication avec l'ensemble des managers de chaque service pour repenser et concevoir l'arborescence des données.
  • Création des répertoires, des groupes globaux et des groupes de domaine local, et attribution sécurisée des droits d'accès sur les dossiers partagés.
  • Led a steering committee (COPIL) meeting to define and explain the implementation of the Microsoft AGDLP security method.
  • Communication with all department managers to redesign and structure the data tree.
  • Creation of directories, global groups, and domain local groups, followed by secure assignment of access rights to shared folders.

Réorganisation Baie Serveur & Continuité Electrique

Server Rack Reorganization & Electrical Continuity

2024
Mitsubishi Electric R&D Centre Europe
Mitsubishi Electric
Infrastructure Datacenter Réseau
  • Nettoyage complet et repérage systématique des branchements et identification des ports sur les commutateurs réseau.
  • Implémentation d'une nouvelle organisation physique : gestion stricte des câbles, codes couleurs et étiquetage réseau standardisé.
  • Mise en place d'un ATS (Automatic Transfer Switch) et de 2 ePDUs pour garantir la continuité de l'alimentation électrique.
  • Repositionnement des équipements critiques basé sur une analyse stricte de gestion des risques physiques.
  • Complete cleanup and systematic mapping of connections and port identification on network switches.
  • Implementation of a new physical organization: strict cable management, color coding, and standardized network labeling.
  • Installation of an ATS (Automatic Transfer Switch) and 2 ePDUs to ensure electrical power continuity.
  • Repositioning of critical equipment based on strict physical risk management analysis.

Refonte ITSM (GLPI) & Catalogue de Services

ITSM Redesign (GLPI) & Service Catalog

2024
Mitsubishi Electric R&D Centre Europe
Mitsubishi Electric
GLPI ITSM Support IT
  • Revue et reconfiguration de l'outil ITSM GLPI incluant la refonte des entités, la création de SLA (Service Level Agreements) et la définition de gabarits de tickets récurrents.
  • Mise en place des procédures de "Changements", refonte de la base de connaissances et ouverture officielle du portail GLPI en libre-service pour les utilisateurs.
  • Élaboration d'un catalogue de services complet en collaboration avec le DSI de transition, incluant la documentation des opérations de niveau 1 et 2.
  • Augmentation de l'indicateur de taux de couverture de la documentation de 35% à 75%.
  • Review and reconfiguration of the GLPI ITSM tool including entity redesign, creation of SLAs (Service Level Agreements), and definition of recurring ticket templates.
  • Implementation of "Change" management procedures, knowledge base redesign, and official opening of the self-service GLPI portal for users.
  • Development of a comprehensive service catalog in collaboration with the interim CIO, including documentation for Level 1 and 2 operations.
  • Increased the documentation coverage rate indicator from 35% to 75%.