Compare commits

..
5 changed files with 20 additions and 23 deletions
+5 -2
View File
@@ -51,8 +51,8 @@ GITEA_REPO_UPLOAD_MAX_FILES=5
GITEA_MAILER_FROM=noreply@example.com GITEA_MAILER_FROM=noreply@example.com
GITEA_MAILER_USER=noreply@example.com GITEA_MAILER_USER=noreply@example.com
# SSH Support GITEA_SSH_PORT=2222
COMPOSE_FILE="$COMPOSE_FILE:compose.ssh.yml" GITEA_SSH_ENABLED=1
SECRET_INTERNAL_TOKEN_VERSION=v1 # length=105 SECRET_INTERNAL_TOKEN_VERSION=v1 # length=105
SECRET_DB_PASSWORD_VERSION=v1 SECRET_DB_PASSWORD_VERSION=v1
@@ -111,3 +111,6 @@ GITEA_STORAGE_TYPE=local
# FORGEJO_METRICS_ENABLED_ISSUE_BY_REPOSITORY=false # FORGEJO_METRICS_ENABLED_ISSUE_BY_REPOSITORY=false
# SECRET_FORGEJO_METRICS_TOKEN_VERSION=v1 # SECRET_FORGEJO_METRICS_TOKEN_VERSION=v1
# COMPOSE_FILE="$COMPOSE_FILE:compose.metrics.yml" # COMPOSE_FILE="$COMPOSE_FILE:compose.metrics.yml"
# Enable access logs. See Access logs on Traefik.
#ACCESS_LOGS=true
+5 -3
View File
@@ -52,13 +52,15 @@ abra app deploy YOURTRAEFIKAPP
``` ```
You might need to wait a bit. To check if it worked, you can run You might need to wait a bit. To check if it worked, you can run
``` ```
telnet my.forgejo.example.com 2222 telnet my.gitea.example.com 2222
``` ```
Once you have added a public SSH key, you can check that you can connect to your Forgejo server with Once you have added a public SSH key, you can check that you can connect to your gitea server with
``` ```
ssh -T -p 2222 git@my.forgejo.example.com ssh -T -p 2222 git@my.gitea.example.com
``` ```
Note that gitea should be configured to listen to port 2222, i.e. `GITEA_SSH_PORT=2222` in the gitea config.
## Protect Forgejo from scrapers with Anubis ## Protect Forgejo from scrapers with Anubis
Uncomment the Anubis compose file from the `.env` file and re-deploy the Uncomment the Anubis compose file from the `.env` file and re-deploy the
+3 -4
View File
@@ -87,10 +87,9 @@ DOMAIN = {{ env "GITEA_DOMAIN" }}
LANDING_PAGE = {{ env "GITEA_LANDING_PAGE" }} LANDING_PAGE = {{ env "GITEA_LANDING_PAGE" }}
ROOT_URL = https://%(DOMAIN)s/ ROOT_URL = https://%(DOMAIN)s/
SSH_DOMAIN = {{ env "GITEA_DOMAIN" }} SSH_DOMAIN = {{ env "GITEA_DOMAIN" }}
SSH_LISTEN_PORT = 2222 SSH_LISTEN_PORT = {{ env "GITEA_SSH_PORT" }}
SSH_PORT = 2222 SSH_PORT = {{ env "GITEA_SSH_PORT" }}
START_SSH_SERVER = {{ env "GITEA_SSH_ENABLED" }} START_SSH_SERVER = true
DISABLE_SSH = {{ if eq (env "GITEA_SSH_ENABLED") "true" }}false{{ else }}true{{ end }}
LFS_START_SERVER = {{ env "GITEA_LFS_START_SERVER" }} LFS_START_SERVER = {{ env "GITEA_LFS_START_SERVER" }}
LFS_JWT_SECRET = {{ secret "lfs_jwt_secret" }} LFS_JWT_SECRET = {{ secret "lfs_jwt_secret" }}
-11
View File
@@ -1,11 +0,0 @@
---
version: "3.8"
services:
app:
environment:
- GITEA_SSH_ENABLED=true
deploy:
labels:
- "traefik.tcp.routers.${STACK_NAME}-ssh.rule=HostSNI(`*`)"
- "traefik.tcp.routers.${STACK_NAME}-ssh.entrypoints=gitea-ssh"
- "traefik.tcp.services.${STACK_NAME}-ssh.loadbalancer.server.port=${GITEA_SSH_PORT}"
+7 -3
View File
@@ -3,7 +3,7 @@ version: "3.8"
services: services:
app: app:
image: codeberg.org/forgejo/forgejo:15.0.7-rootless image: codeberg.org/forgejo/forgejo:15.0.9-rootless
configs: configs:
- source: app_ini - source: app_ini
target: /var/lib/gitea/custom/conf/app.ini target: /var/lib/gitea/custom/conf/app.ini
@@ -26,7 +26,7 @@ services:
- GITEA_ENABLE_OPENID_SIGNIN - GITEA_ENABLE_OPENID_SIGNIN
- GITEA_ENABLE_OPENID_SIGNUP - GITEA_ENABLE_OPENID_SIGNUP
- GITEA_SMTP_MAILER_ENABLED - GITEA_SMTP_MAILER_ENABLED
- GITEA_SSH_ENABLED=false - GITEA_SSH_PORT
- GITEA_DISABLE_GRAVATAR - GITEA_DISABLE_GRAVATAR
- GITEA_ENABLE_FEDERATED_AVATAR - GITEA_ENABLE_FEDERATED_AVATAR
- GITEA_REGISTER_EMAIL_CONFIRM - GITEA_REGISTER_EMAIL_CONFIRM
@@ -81,13 +81,17 @@ services:
- "traefik.http.routers.${STACK_NAME}.entrypoints=web-secure" - "traefik.http.routers.${STACK_NAME}.entrypoints=web-secure"
- "traefik.http.services.${STACK_NAME}.loadbalancer.server.port=3000" - "traefik.http.services.${STACK_NAME}.loadbalancer.server.port=3000"
- "traefik.http.routers.${STACK_NAME}.tls.certresolver=${LETS_ENCRYPT_ENV}" - "traefik.http.routers.${STACK_NAME}.tls.certresolver=${LETS_ENCRYPT_ENV}"
- "traefik.tcp.routers.${STACK_NAME}-ssh.rule=HostSNI(`*`)"
- "traefik.tcp.routers.${STACK_NAME}-ssh.entrypoints=gitea-ssh"
- "traefik.tcp.services.${STACK_NAME}-ssh.loadbalancer.server.port=${GITEA_SSH_PORT}"
- "traefik.http.routers.${STACK_NAME}.middlewares=${STACK_NAME}_cors" - "traefik.http.routers.${STACK_NAME}.middlewares=${STACK_NAME}_cors"
- "traefik.http.routers.${STACK_NAME}.observability.accesslogs=${ACCESS_LOGS:-false}"
- "traefik.http.middlewares.${STACK_NAME}_cors.headers.accesscontrolallowmethods=GET,OPTIONS,PUT" - "traefik.http.middlewares.${STACK_NAME}_cors.headers.accesscontrolallowmethods=GET,OPTIONS,PUT"
- "traefik.http.middlewares.${STACK_NAME}_cors.headers.accesscontrolallowheaders=content-type,authorization" - "traefik.http.middlewares.${STACK_NAME}_cors.headers.accesscontrolallowheaders=content-type,authorization"
- "traefik.http.middlewares.${STACK_NAME}_cors.headers.accesscontrolalloworiginlist=https://${GITEA_CORS_ALLOW_DOMAIN}" - "traefik.http.middlewares.${STACK_NAME}_cors.headers.accesscontrolalloworiginlist=https://${GITEA_CORS_ALLOW_DOMAIN}"
- "traefik.http.middlewares.${STACK_NAME}_cors.headers.accesscontrolmaxage=100" - "traefik.http.middlewares.${STACK_NAME}_cors.headers.accesscontrolmaxage=100"
- "traefik.http.middlewares.${STACK_NAME}_cors.headers.addvaryheader=true" - "traefik.http.middlewares.${STACK_NAME}_cors.headers.addvaryheader=true"
- coop-cloud.${STACK_NAME}.version=5.6.1+15.0.7-rootless - coop-cloud.${STACK_NAME}.version=5.6.3+15.0.9-rootless
networks: networks: