Compare commits

...
Author SHA1 Message Date
fauno 91c1f571ce Merge branch 'main' into produccion 2026-09-14 11:19:21 -03:00
fauno 92cd920c08 chore: publish 5.6.2+15.0.8-rootless release 2026-09-11 05:23:19 -03:00
fauno 9497e42181 Merge pull request 'chore(deps): update codeberg.org/forgejo/forgejo docker tag to v15.0.8' (#49) from renovate/codeberg.org-forgejo-forgejo-15.x into main
Reviewed-on: #49
Reviewed-by: fauno <fauno@sutty.coop.ar>
2026-09-11 08:22:26 +00:00
renovate-bot f6f204c974 chore(deps): update codeberg.org/forgejo/forgejo docker tag to v15.0.8 2026-09-10 13:07:28 +00:00
fauno a74d85f4b1 Merge pull request 'chore: p4u1 stepping down as maintainer' (#47) from renove-p4u1-maintainer into main
Reviewed-on: #47
Reviewed-by: fauno <fauno@sutty.coop.ar>
2026-08-25 16:36:31 +00:00
p4u1 2283a6046b Update README.md 2026-08-25 15:28:52 +00:00
fauno 41f5172a42 chore: publish 5.6.1+15.0.7-rootless release 2026-08-20 13:00:31 -03:00
fauno d6e6a8d404 Merge pull request 'chore(deps): update codeberg.org/forgejo/forgejo docker tag to v15.0.7' (#46) from renovate/codeberg.org-forgejo-forgejo-15.x into main
Reviewed-on: #46
Reviewed-by: fauno <fauno@sutty.coop.ar>
2026-08-20 15:58:18 +00:00
renovate-bot 3761b0ab5c chore(deps): update codeberg.org/forgejo/forgejo docker tag to v15.0.7 2026-08-20 09:07:48 +00:00
fauno 12d374997c Merge branch 'main' into produccion 2026-07-30 19:43:24 -03:00
fauno f3fa092011 chore: publish 5.6.0+15.0.6-rootless release 2026-07-30 19:25:59 -03:00
fauno fe308a35bb Merge pull request 'chore(deps): update codeberg.org/forgejo/forgejo docker tag to v15.0.6' (#43) from renovate/codeberg.org-forgejo-forgejo-15.x into main
Reviewed-on: #43
Reviewed-by: fauno <fauno@sutty.coop.ar>
2026-07-30 22:25:30 +00:00
renovate-bot 1b16538e65 chore(deps): update codeberg.org/forgejo/forgejo docker tag to v15.0.6 2026-07-30 21:06:43 +00:00
fauno e49e3034f1 Merge pull request 'feat: sign commits' (#29) from signing into main
Reviewed-on: #29
Reviewed-by: p4u1 <133+p4u1@noreply.git.coopcloud.tech>
2026-07-23 11:13:42 +00:00
fauno 826b116c4b Merge branch 'main' into produccion 2026-07-22 16:42:14 -03:00
fauno 472f53006c Merge branch 'main' of https://git.coopcloud.tech/coop-cloud/forgejo into signing 2026-07-21 11:12:51 -03:00
fauno 18f6d14c3d Merge branch 'ssh-optional' into produccion 2026-06-29 16:12:28 -03:00
fauno 9ac1a5fcd9 fix: disable ssh 2026-06-29 16:11:43 -03:00
fauno 6a10d71402 Merge branch 'ssh-optional' into produccion 2026-06-29 14:33:41 -03:00
fauno 7cfea87d99 feat: ssh server is optional 2026-06-29 14:33:04 -03:00
fauno d39848fcd8 fix: variable not in use 2026-06-29 14:32:46 -03:00
fauno 3577535b62 fix: the port number is hardcoded on traefik 2026-06-29 14:32:09 -03:00
fauno a0eeb57427 doc: forgejo 2026-06-29 14:31:20 -03:00
fauno c884826b0a Merge branch 'metrics' into produccion 2026-06-16 22:58:35 -03:00
fauno 8cec92c042 Merge branch 'metrics' into produccion 2026-06-12 13:23:06 -03:00
fauno 7f44cab6c9 Merge branch 'renovate/codeberg.org-forgejo-forgejo-15.x' into produccion 2026-06-12 13:13:31 -03:00
fauno 461784c151 Merge branch 'metrics' into produccion 2026-06-12 13:04:01 -03:00
fauno c216bba0ab Merge branch 'metrics' into produccion 2026-06-12 13:01:08 -03:00
renovate-bot dbae7db490 chore(deps): update codeberg.org/forgejo/forgejo docker tag to v15.0.3 2026-06-10 07:06:37 +00:00
fauno 44c276220d fix: symlink signing keys 2026-06-08 12:56:39 -03:00
fauno 66ebc75a59 Merge branch 'main' into produccion 2026-06-05 10:55:15 -03:00
fauno f1237cbed8 Merge branch 'main' of https://git.coopcloud.tech/coop-cloud/forgejo into signing 2026-06-05 10:51:55 -03:00
fauno c734a15897 Merge branch 'session' into produccion 2026-05-20 10:29:30 -03:00
fauno c8b1ccf5ba Merge branch 'shutdown' into produccion 2026-05-19 10:44:04 -03:00
fauno 9a741faa0c fix: prevent anubis from redirecting the health check 2026-05-18 10:03:19 -03:00
fauno bd330ed0b5 Merge branch 'signing' into produccion 2026-05-16 20:11:06 -03:00
fauno 000de73bb3 fix: allow key rotation 2026-05-16 13:10:16 -03:00
fauno de61429a3d Merge branch 'caching' into produccion 2026-05-15 17:01:10 -03:00
fauno 5337637cb2 Merge branch 'session' into produccion 2026-05-15 16:39:55 -03:00
fauno b0f52307a5 feat: sign commits 2026-05-14 10:09:39 -03:00
fauno 40dc068a23 Merge branch 'main' into produccion 2026-05-14 10:03:01 -03:00
fauno cbc43eddbc Merge branch 'signing' into produccion 2026-05-13 14:11:45 -03:00
fauno b926ad8111 feat: sign commits 2026-05-13 14:10:35 -03:00
fauno d5a826c87d Merge branch 's3' into gallinero 2026-05-06 14:45:29 -03:00
fauno 9daa7de95a Merge branch 's3' into gallinero 2026-05-06 14:43:18 -03:00
fauno cd6b9a3ca8 Merge branch 's3' into gallinero 2026-05-06 14:39:23 -03:00
fauno 6d62a06408 Merge branch 'renovate/codeberg.org-forgejo-forgejo-15.x' into gallinero 2026-05-06 14:39:19 -03:00
8 changed files with 82 additions and 21 deletions
+9 -2
View File
@@ -51,8 +51,8 @@ GITEA_REPO_UPLOAD_MAX_FILES=5
GITEA_MAILER_FROM=noreply@example.com
GITEA_MAILER_USER=noreply@example.com
GITEA_SSH_PORT=2222
GITEA_SSH_ENABLED=1
# SSH Support
COMPOSE_FILE="$COMPOSE_FILE:compose.ssh.yml"
SECRET_INTERNAL_TOKEN_VERSION=v1 # length=105
SECRET_DB_PASSWORD_VERSION=v1
@@ -72,6 +72,13 @@ GITEA_STORAGE_TYPE=local
# MINIO_CHECKSUM_ALGORITHM=default
# COMPOSE_FILE="$COMPOSE_FILE:compose.s3.yml"
# Instance Commit Signing
# https://forgejo.org/docs/latest/admin/advanced/signing/
# COMPOSE_FILE="$COMPOSE_FILE:compose.signing.yml"
# GITEA_SIGNING_ENABLED=1
# SECRET_SIGNING_PUBLIC_KEY_VERSION=v1
# SECRET_SIGNING_PRIVATE_KEY_VERSION=v1
# SMTP Mailer
# COMPOSE_FILE="$COMPOSE_FILE:compose.smtp.yml"
# GITEA_SMTP_MAILER_ENABLED=1
+17 -6
View File
@@ -3,7 +3,7 @@
[![Build Status](https://build.coopcloud.tech/api/badges/coop-cloud/forgejo/status.svg)](https://build.coopcloud.tech/coop-cloud/forgejo)
<!-- metadata -->
* **Maintainer**: [@p4u1](https://git.coopcloud.tech/p4u1), [@fauno](https://git.coopcloud.tech/fauno)
* **Maintainer**: [@fauno](https://git.coopcloud.tech/fauno)
* **Category**: Development
* **Status**: 5
* **Image**: [`forgejo/forgejo`](https://codeberg.org/forgejo/-/packages/container/forgejo/13-rootless), 4, upstream
@@ -52,17 +52,28 @@ abra app deploy YOURTRAEFIKAPP
```
You might need to wait a bit. To check if it worked, you can run
```
telnet my.gitea.example.com 2222
telnet my.forgejo.example.com 2222
```
Once you have added a public SSH key, you can check that you can connect to your gitea server with
Once you have added a public SSH key, you can check that you can connect to your Forgejo server with
```
ssh -T -p 2222 git@my.gitea.example.com
ssh -T -p 2222 git@my.forgejo.example.com
```
Note that gitea should be configured to listen to port 2222, i.e. `GITEA_SSH_PORT=2222` in the gitea config.
## Protect Forgejo from scrapers with Anubis
Uncomment the Anubis compose file from the `.env` file and re-deploy the
app. Don't forget to actually [enable Anubis on the Traefik app
too](https://recipes.coopcloud.tech/traefik)!
## [Instance Commit Signing](https://forgejo.org/docs/latest/admin/advanced/signing/)
To allow Forgejo to sign commits, uncomment the corresponding
configuration block, and then generate and insert the SSH keys:
```sh
abra app config git.example.coop
ssh-keygen -t ed25519
app app secret insert git.example.coop signing_public_key v1 -f ~/.ssh/id_ed25519.pub
app app secret insert git.example.coop signing_private_key v1 -f ~/.ssh/id_ed25519
app app deploy git.example.coop
```
+2 -2
View File
@@ -1,5 +1,5 @@
export APP_INI_VERSION=v27
export DOCKER_SETUP_SH_VERSION=v1
export APP_INI_VERSION=v30
export DOCKER_SETUP_SH_VERSION=v2
export PG_BACKUP_VERSION=v1
abra_backup_app() {
+16 -3
View File
@@ -62,6 +62,18 @@ ALLOWED_TYPES = {{ env "GITEA_REPO_UPLOAD_ALLOWED_TYPES" }}
FILE_MAX_SIZE = {{ env "GITEA_REPO_UPLOAD_MAX_SIZE" }}
MAX_FILES = {{ env "GITEA_REPO_UPLOAD_MAX_FILES" }}
{{ if eq (env "GITEA_SIGNING_ENABLED") "1" }}
[repository.signing]
FORMAT = ssh
SIGNING_KEY = /var/lib/gitea/signing_key.pub
SIGNING_NAME = {{ env "GITEA_APP_NAME" }}
SIGNING_EMAIL = {{ env "GITEA_MAILER_FROM" }}
INITIAL_COMMIT = always
WIKI = always
CRUD_ACTIONS = always
MERGES = always
{{ end }}
[ui]
SHOW_USER_EMAIL = {{ env "GITEA_SHOW_USER_EMAIL" }}
@@ -75,9 +87,10 @@ DOMAIN = {{ env "GITEA_DOMAIN" }}
LANDING_PAGE = {{ env "GITEA_LANDING_PAGE" }}
ROOT_URL = https://%(DOMAIN)s/
SSH_DOMAIN = {{ env "GITEA_DOMAIN" }}
SSH_LISTEN_PORT = {{ env "GITEA_SSH_PORT" }}
SSH_PORT = {{ env "GITEA_SSH_PORT" }}
START_SSH_SERVER = true
SSH_LISTEN_PORT = 2222
SSH_PORT = 2222
START_SSH_SERVER = {{ env "GITEA_SSH_ENABLED" }}
DISABLE_SSH = {{ if eq (env "GITEA_SSH_ENABLED") "true" }}false{{ else }}true{{ end }}
LFS_START_SERVER = {{ env "GITEA_LFS_START_SERVER" }}
LFS_JWT_SECRET = {{ secret "lfs_jwt_secret" }}
+14
View File
@@ -0,0 +1,14 @@
version: '3.8'
services:
app:
secrets:
- signing_public_key
- signing_private_key
secrets:
signing_public_key:
name: ${STACK_NAME}_signing_public_key_${SECRET_SIGNING_PUBLIC_KEY_VERSION}
external: true
signing_private_key:
name: ${STACK_NAME}_signing_private_key_${SECRET_SIGNING_PRIVATE_KEY_VERSION}
external: true
+11
View File
@@ -0,0 +1,11 @@
---
version: "3.8"
services:
app:
environment:
- GITEA_SSH_ENABLED=true
deploy:
labels:
- "traefik.tcp.routers.${STACK_NAME}-ssh.rule=HostSNI(`*`)"
- "traefik.tcp.routers.${STACK_NAME}-ssh.entrypoints=gitea-ssh"
- "traefik.tcp.services.${STACK_NAME}-ssh.loadbalancer.server.port=${GITEA_SSH_PORT}"
+4 -7
View File
@@ -3,7 +3,7 @@ version: "3.8"
services:
app:
image: codeberg.org/forgejo/forgejo:15.0.5-rootless
image: codeberg.org/forgejo/forgejo:15.0.8-rootless
configs:
- source: app_ini
target: /var/lib/gitea/custom/conf/app.ini
@@ -26,7 +26,7 @@ services:
- GITEA_ENABLE_OPENID_SIGNIN
- GITEA_ENABLE_OPENID_SIGNUP
- GITEA_SMTP_MAILER_ENABLED
- GITEA_SSH_PORT
- GITEA_SSH_ENABLED=false
- GITEA_DISABLE_GRAVATAR
- GITEA_ENABLE_FEDERATED_AVATAR
- GITEA_REGISTER_EMAIL_CONFIRM
@@ -65,7 +65,7 @@ services:
- proxy
- internal
healthcheck:
test: ["CMD", "curl", "-f", "http://localhost:3000/api/healthz"]
test: ["CMD", "curl", "--user-agent=healthcheck", "-f", "http://localhost:3000/api/healthz"]
interval: 30s
timeout: 10s
retries: 10
@@ -81,16 +81,13 @@ services:
- "traefik.http.routers.${STACK_NAME}.entrypoints=web-secure"
- "traefik.http.services.${STACK_NAME}.loadbalancer.server.port=3000"
- "traefik.http.routers.${STACK_NAME}.tls.certresolver=${LETS_ENCRYPT_ENV}"
- "traefik.tcp.routers.${STACK_NAME}-ssh.rule=HostSNI(`*`)"
- "traefik.tcp.routers.${STACK_NAME}-ssh.entrypoints=gitea-ssh"
- "traefik.tcp.services.${STACK_NAME}-ssh.loadbalancer.server.port=${GITEA_SSH_PORT}"
- "traefik.http.routers.${STACK_NAME}.middlewares=${STACK_NAME}_cors"
- "traefik.http.middlewares.${STACK_NAME}_cors.headers.accesscontrolallowmethods=GET,OPTIONS,PUT"
- "traefik.http.middlewares.${STACK_NAME}_cors.headers.accesscontrolallowheaders=content-type,authorization"
- "traefik.http.middlewares.${STACK_NAME}_cors.headers.accesscontrolalloworiginlist=https://${GITEA_CORS_ALLOW_DOMAIN}"
- "traefik.http.middlewares.${STACK_NAME}_cors.headers.accesscontrolmaxage=100"
- "traefik.http.middlewares.${STACK_NAME}_cors.headers.addvaryheader=true"
- coop-cloud.${STACK_NAME}.version=5.5.0+15.0.5-rootless
- coop-cloud.${STACK_NAME}.version=5.6.2+15.0.8-rootless
networks:
+9 -1
View File
@@ -6,10 +6,18 @@
# Prepare git folder
mkdir -p ${HOME} && chmod 0700 ${HOME}
if [ ! -w ${HOME} ]; then echo "${HOME} is not writable"; exit 1; fi
# Prepare custom folder
mkdir -p ${GITEA_CUSTOM} && chmod 0500 ${GITEA_CUSTOM}
# Prepare temp folder
mkdir -p ${GITEA_TEMP} && chmod 0700 ${GITEA_TEMP}
if [ ! -w ${GITEA_TEMP} ]; then echo "${GITEA_TEMP} is not writable"; exit 1; fi
if [ -e /run/secrets/signing_public_key ] ; then
if [ ! -e /var/lib/gitea/signing_key.pub ]; then
ln -s /run/secrets/signing_public_key /var/lib/gitea/signing_key.pub
ln -s /run/secrets/signing_private_key /var/lib/gitea/signing_key
fi
chmod 600 /var/lib/gitea/signing_key*
fi