Compare commits
7
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
84702e4819
|
||
|
|
c6d152bff7 | ||
|
|
f5b581a487 | ||
|
|
010c852dc2 | ||
|
|
92cd920c08 | ||
|
|
9497e42181 | ||
|
|
f6f204c974 |
+5
-2
@@ -51,8 +51,8 @@ GITEA_REPO_UPLOAD_MAX_FILES=5
|
|||||||
GITEA_MAILER_FROM=noreply@example.com
|
GITEA_MAILER_FROM=noreply@example.com
|
||||||
GITEA_MAILER_USER=noreply@example.com
|
GITEA_MAILER_USER=noreply@example.com
|
||||||
|
|
||||||
# SSH Support
|
GITEA_SSH_PORT=2222
|
||||||
COMPOSE_FILE="$COMPOSE_FILE:compose.ssh.yml"
|
GITEA_SSH_ENABLED=1
|
||||||
|
|
||||||
SECRET_INTERNAL_TOKEN_VERSION=v1 # length=105
|
SECRET_INTERNAL_TOKEN_VERSION=v1 # length=105
|
||||||
SECRET_DB_PASSWORD_VERSION=v1
|
SECRET_DB_PASSWORD_VERSION=v1
|
||||||
@@ -111,3 +111,6 @@ GITEA_STORAGE_TYPE=local
|
|||||||
# FORGEJO_METRICS_ENABLED_ISSUE_BY_REPOSITORY=false
|
# FORGEJO_METRICS_ENABLED_ISSUE_BY_REPOSITORY=false
|
||||||
# SECRET_FORGEJO_METRICS_TOKEN_VERSION=v1
|
# SECRET_FORGEJO_METRICS_TOKEN_VERSION=v1
|
||||||
# COMPOSE_FILE="$COMPOSE_FILE:compose.metrics.yml"
|
# COMPOSE_FILE="$COMPOSE_FILE:compose.metrics.yml"
|
||||||
|
|
||||||
|
# Enable access logs. See Access logs on Traefik.
|
||||||
|
#ACCESS_LOGS=true
|
||||||
|
|||||||
@@ -52,13 +52,15 @@ abra app deploy YOURTRAEFIKAPP
|
|||||||
```
|
```
|
||||||
You might need to wait a bit. To check if it worked, you can run
|
You might need to wait a bit. To check if it worked, you can run
|
||||||
```
|
```
|
||||||
telnet my.forgejo.example.com 2222
|
telnet my.gitea.example.com 2222
|
||||||
```
|
```
|
||||||
Once you have added a public SSH key, you can check that you can connect to your Forgejo server with
|
Once you have added a public SSH key, you can check that you can connect to your gitea server with
|
||||||
```
|
```
|
||||||
ssh -T -p 2222 git@my.forgejo.example.com
|
ssh -T -p 2222 git@my.gitea.example.com
|
||||||
```
|
```
|
||||||
|
|
||||||
|
Note that gitea should be configured to listen to port 2222, i.e. `GITEA_SSH_PORT=2222` in the gitea config.
|
||||||
|
|
||||||
## Protect Forgejo from scrapers with Anubis
|
## Protect Forgejo from scrapers with Anubis
|
||||||
|
|
||||||
Uncomment the Anubis compose file from the `.env` file and re-deploy the
|
Uncomment the Anubis compose file from the `.env` file and re-deploy the
|
||||||
|
|||||||
+3
-4
@@ -87,10 +87,9 @@ DOMAIN = {{ env "GITEA_DOMAIN" }}
|
|||||||
LANDING_PAGE = {{ env "GITEA_LANDING_PAGE" }}
|
LANDING_PAGE = {{ env "GITEA_LANDING_PAGE" }}
|
||||||
ROOT_URL = https://%(DOMAIN)s/
|
ROOT_URL = https://%(DOMAIN)s/
|
||||||
SSH_DOMAIN = {{ env "GITEA_DOMAIN" }}
|
SSH_DOMAIN = {{ env "GITEA_DOMAIN" }}
|
||||||
SSH_LISTEN_PORT = 2222
|
SSH_LISTEN_PORT = {{ env "GITEA_SSH_PORT" }}
|
||||||
SSH_PORT = 2222
|
SSH_PORT = {{ env "GITEA_SSH_PORT" }}
|
||||||
START_SSH_SERVER = {{ env "GITEA_SSH_ENABLED" }}
|
START_SSH_SERVER = true
|
||||||
DISABLE_SSH = {{ if eq (env "GITEA_SSH_ENABLED") "true" }}false{{ else }}true{{ end }}
|
|
||||||
LFS_START_SERVER = {{ env "GITEA_LFS_START_SERVER" }}
|
LFS_START_SERVER = {{ env "GITEA_LFS_START_SERVER" }}
|
||||||
LFS_JWT_SECRET = {{ secret "lfs_jwt_secret" }}
|
LFS_JWT_SECRET = {{ secret "lfs_jwt_secret" }}
|
||||||
|
|
||||||
|
|||||||
@@ -1,11 +0,0 @@
|
|||||||
---
|
|
||||||
version: "3.8"
|
|
||||||
services:
|
|
||||||
app:
|
|
||||||
environment:
|
|
||||||
- GITEA_SSH_ENABLED=true
|
|
||||||
deploy:
|
|
||||||
labels:
|
|
||||||
- "traefik.tcp.routers.${STACK_NAME}-ssh.rule=HostSNI(`*`)"
|
|
||||||
- "traefik.tcp.routers.${STACK_NAME}-ssh.entrypoints=gitea-ssh"
|
|
||||||
- "traefik.tcp.services.${STACK_NAME}-ssh.loadbalancer.server.port=${GITEA_SSH_PORT}"
|
|
||||||
+7
-3
@@ -3,7 +3,7 @@ version: "3.8"
|
|||||||
|
|
||||||
services:
|
services:
|
||||||
app:
|
app:
|
||||||
image: codeberg.org/forgejo/forgejo:15.0.7-rootless
|
image: codeberg.org/forgejo/forgejo:15.0.9-rootless
|
||||||
configs:
|
configs:
|
||||||
- source: app_ini
|
- source: app_ini
|
||||||
target: /var/lib/gitea/custom/conf/app.ini
|
target: /var/lib/gitea/custom/conf/app.ini
|
||||||
@@ -26,7 +26,7 @@ services:
|
|||||||
- GITEA_ENABLE_OPENID_SIGNIN
|
- GITEA_ENABLE_OPENID_SIGNIN
|
||||||
- GITEA_ENABLE_OPENID_SIGNUP
|
- GITEA_ENABLE_OPENID_SIGNUP
|
||||||
- GITEA_SMTP_MAILER_ENABLED
|
- GITEA_SMTP_MAILER_ENABLED
|
||||||
- GITEA_SSH_ENABLED=false
|
- GITEA_SSH_PORT
|
||||||
- GITEA_DISABLE_GRAVATAR
|
- GITEA_DISABLE_GRAVATAR
|
||||||
- GITEA_ENABLE_FEDERATED_AVATAR
|
- GITEA_ENABLE_FEDERATED_AVATAR
|
||||||
- GITEA_REGISTER_EMAIL_CONFIRM
|
- GITEA_REGISTER_EMAIL_CONFIRM
|
||||||
@@ -81,13 +81,17 @@ services:
|
|||||||
- "traefik.http.routers.${STACK_NAME}.entrypoints=web-secure"
|
- "traefik.http.routers.${STACK_NAME}.entrypoints=web-secure"
|
||||||
- "traefik.http.services.${STACK_NAME}.loadbalancer.server.port=3000"
|
- "traefik.http.services.${STACK_NAME}.loadbalancer.server.port=3000"
|
||||||
- "traefik.http.routers.${STACK_NAME}.tls.certresolver=${LETS_ENCRYPT_ENV}"
|
- "traefik.http.routers.${STACK_NAME}.tls.certresolver=${LETS_ENCRYPT_ENV}"
|
||||||
|
- "traefik.tcp.routers.${STACK_NAME}-ssh.rule=HostSNI(`*`)"
|
||||||
|
- "traefik.tcp.routers.${STACK_NAME}-ssh.entrypoints=gitea-ssh"
|
||||||
|
- "traefik.tcp.services.${STACK_NAME}-ssh.loadbalancer.server.port=${GITEA_SSH_PORT}"
|
||||||
- "traefik.http.routers.${STACK_NAME}.middlewares=${STACK_NAME}_cors"
|
- "traefik.http.routers.${STACK_NAME}.middlewares=${STACK_NAME}_cors"
|
||||||
|
- "traefik.http.routers.${STACK_NAME}.observability.accesslogs=${ACCESS_LOGS:-false}"
|
||||||
- "traefik.http.middlewares.${STACK_NAME}_cors.headers.accesscontrolallowmethods=GET,OPTIONS,PUT"
|
- "traefik.http.middlewares.${STACK_NAME}_cors.headers.accesscontrolallowmethods=GET,OPTIONS,PUT"
|
||||||
- "traefik.http.middlewares.${STACK_NAME}_cors.headers.accesscontrolallowheaders=content-type,authorization"
|
- "traefik.http.middlewares.${STACK_NAME}_cors.headers.accesscontrolallowheaders=content-type,authorization"
|
||||||
- "traefik.http.middlewares.${STACK_NAME}_cors.headers.accesscontrolalloworiginlist=https://${GITEA_CORS_ALLOW_DOMAIN}"
|
- "traefik.http.middlewares.${STACK_NAME}_cors.headers.accesscontrolalloworiginlist=https://${GITEA_CORS_ALLOW_DOMAIN}"
|
||||||
- "traefik.http.middlewares.${STACK_NAME}_cors.headers.accesscontrolmaxage=100"
|
- "traefik.http.middlewares.${STACK_NAME}_cors.headers.accesscontrolmaxage=100"
|
||||||
- "traefik.http.middlewares.${STACK_NAME}_cors.headers.addvaryheader=true"
|
- "traefik.http.middlewares.${STACK_NAME}_cors.headers.addvaryheader=true"
|
||||||
- coop-cloud.${STACK_NAME}.version=5.6.1+15.0.7-rootless
|
- coop-cloud.${STACK_NAME}.version=5.6.3+15.0.9-rootless
|
||||||
|
|
||||||
|
|
||||||
networks:
|
networks:
|
||||||
|
|||||||
Reference in New Issue
Block a user