Compare commits
	
		
			45 Commits
		
	
	
		
			2.10.1+1.2
			...
			3.5.2+1.24
		
	
	| Author | SHA1 | Date | |
|---|---|---|---|
| 989294173e | |||
| 4e789bf977 | |||
| 485fa32512 | |||
| 54fd30f38a | |||
| 6d586f6ad3 | |||
| 8c9793ace9 | |||
| 4cfc2ac2e0 | |||
| ca4733a0b0 | |||
| 5a65ef04c5 | |||
| 270ed7bb93 | |||
| b2c9d95e60 | |||
| 88b226f713 | |||
| 94af9cea9e | |||
| 85dcf3a0b1 | |||
| 3840e87f2f | |||
| 777aad5da4 | |||
| 5350ce207f | |||
| 2bfec14654 | |||
| b44e18f063 | |||
| 77624221b4 | |||
| ce632c8e5f | |||
| cac5c8d694 | |||
| cf2298162d | |||
| 0bbac9ed9c | |||
| 8ffd4d33be | |||
| 7364f0b87c | |||
| 1619c333c3 | |||
| 6d681457f8 | |||
| b2087cf373 | |||
| 1418946974 | |||
| 407e587646 | |||
| b4fdbfdbbb | |||
| 544935a5e6 | |||
| e45aee2257 | |||
| e313c82857 | |||
| fb45547f0d | |||
| ace3ff1b4a | |||
| b84edcbe75 | |||
| 25fd554ab7 | |||
| b4273a95e3 | |||
| daf4a26f72 | |||
| 7fec94eaec | |||
| 0bfb666dd0 | |||
| 2554109fab | |||
| bd57d6121b | 
@ -17,6 +17,7 @@ steps:
 | 
			
		||||
    environment:
 | 
			
		||||
      APP_INI_VERSION: v1
 | 
			
		||||
      DOCKER_SETUP_SH_VERSION: v1
 | 
			
		||||
      PG_BACKUP_VERSION: v1
 | 
			
		||||
      DOMAIN: gitea.swarm-test.autonomic.zone
 | 
			
		||||
      GITEA_ALLOW_ONLY_EXTERNAL_REGISTRATION: true
 | 
			
		||||
      GITEA_APP_NAME: Git with solidaritea
 | 
			
		||||
@ -50,7 +51,7 @@ steps:
 | 
			
		||||
        from_secret: drone_abra-bot_token
 | 
			
		||||
      fork: true
 | 
			
		||||
      repositories:
 | 
			
		||||
        - coop-cloud/auto-recipes-catalogue-json
 | 
			
		||||
        - toolshed/auto-recipes-catalogue-json
 | 
			
		||||
 | 
			
		||||
trigger:
 | 
			
		||||
  event: tag
 | 
			
		||||
 | 
			
		||||
							
								
								
									
										15
									
								
								.env.sample
									
									
									
									
									
								
							
							
						
						
									
										15
									
								
								.env.sample
									
									
									
									
									
								
							@ -3,11 +3,14 @@ TYPE=gitea
 | 
			
		||||
DOMAIN=gitea.example.com
 | 
			
		||||
LETS_ENCRYPT_ENV=production
 | 
			
		||||
COMPOSE_FILE="compose.yml"
 | 
			
		||||
ENABLE_BACKUPS=true
 | 
			
		||||
COMPOSE_FILE="$COMPOSE_FILE:compose.mariadb.yml"
 | 
			
		||||
# COMPOSE_FILE="$COMPOSE_FILE:compose.sqlite3.yml"
 | 
			
		||||
# COMPOSE_FILE="$COMPOSE_FILE:compose.postgres.yml"
 | 
			
		||||
 | 
			
		||||
# Enable to use forgejo instead of gitea
 | 
			
		||||
# COMPOSE_FILE="$COMPOSE_FILE:compose.forgejo.yml"
 | 
			
		||||
# SECRET_LFS_JWT_SECRET_VERSION=v1 # length=43
 | 
			
		||||
 | 
			
		||||
GITEA_DOMAIN=git.example.com
 | 
			
		||||
GITEA_ALLOW_ONLY_EXTERNAL_REGISTRATION=true
 | 
			
		||||
@ -29,6 +32,9 @@ GITEA_DEFAULT_USER_VISIBILITY=limited
 | 
			
		||||
GITEA_ALLOWED_USER_VISIBILITY_MODES=limited,private
 | 
			
		||||
GITEA_DEFAULT_ORG_VISIBILITY=limited
 | 
			
		||||
GITEA_REQUIRE_SIGNIN_VIEW=true
 | 
			
		||||
GITEA_ENABLE_PUSH_CREATE_USER=false
 | 
			
		||||
GITEA_ENABLE_PUSH_CREATE_ORG=false
 | 
			
		||||
GITEA_LFS_START_SERVER=false
 | 
			
		||||
 | 
			
		||||
GITEA_REPO_UPLOAD_ENABLED=true
 | 
			
		||||
GITEA_REPO_UPLOAD_ALLOWED_TYPES=*/*
 | 
			
		||||
@ -50,8 +56,10 @@ SECRET_SECRET_KEY_VERSION=v1 # length=64
 | 
			
		||||
# SMTP Mailer
 | 
			
		||||
# COMPOSE_FILE="$COMPOSE_FILE:compose.smtp.yml"
 | 
			
		||||
# GITEA_SMTP_MAILER_ENABLED=1
 | 
			
		||||
# GITEA_MAILER_HOST=mail.gandi.net:465
 | 
			
		||||
# GITEA_MAILER_ADDR=mail.gandi.net
 | 
			
		||||
# GITEA_MAILER_PORT=465
 | 
			
		||||
# SECRET_SMTP_PASSWORD_VERSION=v1
 | 
			
		||||
# GITEA_MAILER_PROTOCOL=smtps
 | 
			
		||||
 | 
			
		||||
# OATH2 Options
 | 
			
		||||
# GITEA_REGISTER_EMAIL_CONFIRM=replace-me
 | 
			
		||||
@ -61,6 +69,11 @@ SECRET_SECRET_KEY_VERSION=v1 # length=64
 | 
			
		||||
# GITEA_ACCOUNT_LINKING=replace-me
 | 
			
		||||
# GITEA_OAUTH2_CLIENT_ENABLED=replace-me
 | 
			
		||||
 | 
			
		||||
# Lifetime of an OAuth2 refresh token in hours, prolly no need to edit. We
 | 
			
		||||
# were hitting issues with infrequently pushed to repos that were not picked
 | 
			
		||||
# up by drone after a month of inactivity, hence the option.
 | 
			
		||||
# GITEA__oauth2__REFRESH_TOKEN_EXPIRATION_TIME=730
 | 
			
		||||
 | 
			
		||||
# Indexer (for issue search)
 | 
			
		||||
# GITEA_REPO_INDEXER_ENABLED=false
 | 
			
		||||
# GITEA_ISSUE_INDEXER_TYPE=db
 | 
			
		||||
 | 
			
		||||
							
								
								
									
										3
									
								
								abra.sh
									
									
									
									
									
								
							
							
						
						
									
										3
									
								
								abra.sh
									
									
									
									
									
								
							@ -1,5 +1,6 @@
 | 
			
		||||
export APP_INI_VERSION=v18
 | 
			
		||||
export APP_INI_VERSION=v21
 | 
			
		||||
export DOCKER_SETUP_SH_VERSION=v1
 | 
			
		||||
export PG_BACKUP_VERSION=v1
 | 
			
		||||
 | 
			
		||||
abra_backup_app() {
 | 
			
		||||
  _abra_backup_dir "app:/var/lib/gitea"
 | 
			
		||||
 | 
			
		||||
							
								
								
									
										16
									
								
								app.ini.tmpl
									
									
									
									
									
								
							
							
						
						
									
										16
									
								
								app.ini.tmpl
									
									
									
									
									
								
							@ -2,10 +2,15 @@ APP_NAME = {{ env "GITEA_APP_NAME" }}
 | 
			
		||||
 | 
			
		||||
[database]
 | 
			
		||||
DB_TYPE = {{ env "GITEA_DB_TYPE" }}
 | 
			
		||||
{{ if ne (env "GITEA_DB_TYPE") "sqlite3" }}
 | 
			
		||||
HOST = {{ env "GITEA_DB_HOST" }}
 | 
			
		||||
NAME = {{ env "GITEA_DB_NAME" }}
 | 
			
		||||
PASSWD = {{ secret "db_password" }}
 | 
			
		||||
USER = {{ env "GITEA_DB_USER" }}
 | 
			
		||||
{{ else }}
 | 
			
		||||
SQLITE_JOURNAL_MODE = {{ env "GITEA_SQLITE_JOURNAL_MODE" }}
 | 
			
		||||
PATH = {{ env "GITEA_PATH" }}
 | 
			
		||||
{{ end }}
 | 
			
		||||
 | 
			
		||||
[picture]
 | 
			
		||||
DISABLE_GRAVATAR = {{ env "GITEA_DISABLE_GRAVATAR" }}
 | 
			
		||||
@ -30,6 +35,8 @@ ENABLE_OPENID_SIGNUP = {{ env "GITEA_ENABLE_OPENID_SIGNUP" }}
 | 
			
		||||
 | 
			
		||||
[repository]
 | 
			
		||||
DEFAULT_BRANCH = main
 | 
			
		||||
ENABLE_PUSH_CREATE_USER = {{ env "GITEA_ENABLE_PUSH_CREATE_USER" }}
 | 
			
		||||
ENABLE_PUSH_CREATE_ORG = {{ env "GITEA_ENABLE_PUSH_CREATE_ORG" }}
 | 
			
		||||
 | 
			
		||||
[repository.upload]
 | 
			
		||||
ENABLED = {{ env "GITEA_REPO_UPLOAD_ENABLED" }}
 | 
			
		||||
@ -53,6 +60,10 @@ SSH_DOMAIN = {{ env "GITEA_DOMAIN" }}
 | 
			
		||||
SSH_LISTEN_PORT = {{ env "GITEA_SSH_PORT" }}
 | 
			
		||||
SSH_PORT = {{ env "GITEA_SSH_PORT" }}
 | 
			
		||||
START_SSH_SERVER = true
 | 
			
		||||
LFS_START_SERVER = {{ env "GITEA_LFS_START_SERVER" }}
 | 
			
		||||
{{ if eq (env "FORGE") "forgejo" }}
 | 
			
		||||
LFS_JWT_SECRET = {{ secret "lfs_jwt_secret" }}
 | 
			
		||||
{{ end }}
 | 
			
		||||
 | 
			
		||||
[security]
 | 
			
		||||
INSTALL_LOCK = true
 | 
			
		||||
@ -71,11 +82,12 @@ JWT_SECRET = {{ secret "jwt_secret" }}
 | 
			
		||||
[mailer]
 | 
			
		||||
ENABLED        = true
 | 
			
		||||
FROM           = {{ env "GITEA_MAILER_FROM" }}
 | 
			
		||||
HOST           = {{ env "GITEA_MAILER_HOST" }}
 | 
			
		||||
PROTOCOL       = {{ env "GITEA_MAILER_PROTOCOL" }}
 | 
			
		||||
SMTP_ADDR      = {{ env "GITEA_MAILER_ADDR" }}
 | 
			
		||||
SMTP_PORT      = {{ env "GITEA_MAILER_PORT" }}
 | 
			
		||||
USER           = {{ env "GITEA_MAILER_USER" }}
 | 
			
		||||
PASSWD         = {{ secret "smtp_password" }}
 | 
			
		||||
MAILER_TYPE    = smtp
 | 
			
		||||
IS_TLS_ENABLED = true
 | 
			
		||||
{{ end }}
 | 
			
		||||
 | 
			
		||||
{{ if eq (env "GITEA_OAUTH2_CLIENT_ENABLED") "1" }}
 | 
			
		||||
 | 
			
		||||
@ -2,4 +2,12 @@ version: '3.8'
 | 
			
		||||
 | 
			
		||||
services:
 | 
			
		||||
  app:
 | 
			
		||||
    image: codeberg.org/forgejo/forgejo:1.21.11-1-rootless
 | 
			
		||||
    image: codeberg.org/forgejo/forgejo:12.0.2-rootless
 | 
			
		||||
    environment:
 | 
			
		||||
    - FORGE=forgejo
 | 
			
		||||
    secrets:
 | 
			
		||||
    - lfs_jwt_secret
 | 
			
		||||
secrets:
 | 
			
		||||
  lfs_jwt_secret:
 | 
			
		||||
    name: ${STACK_NAME}_lfs_jwt_secret_${SECRET_LFS_JWT_SECRET_VERSION}
 | 
			
		||||
    external: true
 | 
			
		||||
 | 
			
		||||
@ -7,14 +7,15 @@ services:
 | 
			
		||||
      - GITEA_DB_HOST="db:3306"
 | 
			
		||||
      - GITEA_DB_NAME=gitea
 | 
			
		||||
      - GITEA_DB_USER=gitea
 | 
			
		||||
    secrets:
 | 
			
		||||
      - db_password
 | 
			
		||||
  db:
 | 
			
		||||
    image: "mariadb:10.11.2"
 | 
			
		||||
    deploy:
 | 
			
		||||
      labels:
 | 
			
		||||
          backupbot.backup: "true"
 | 
			
		||||
          backupbot.backup.pre-hook: 'mysqldump --single-transaction -u root -p"$$(cat /run/secrets/db_root_password)" gitea > /var/lib/mysql/backup.sql'
 | 
			
		||||
          backupbot.backup.post-hook: "rm -rf /var/lib/mysql/backup.sql"
 | 
			
		||||
          backupbot.backup.path: "/var/lib/mysql/backup.sql"
 | 
			
		||||
          backupbot.backup.volumes.mariadb.path: "backup.sql"
 | 
			
		||||
          backupbot.restore.post-hook: "mariadb -u root -p\"$$(cat /run/secrets/db_root_password)\" gitea < /var/lib/mysql/backup.sql"
 | 
			
		||||
    command: |
 | 
			
		||||
      mysqld --character-set-server=utf8mb4 --collation-server=utf8mb4_unicode_ci
 | 
			
		||||
    environment:
 | 
			
		||||
@ -40,4 +41,3 @@ secrets:
 | 
			
		||||
 | 
			
		||||
volumes:
 | 
			
		||||
  mariadb:
 | 
			
		||||
  internal:
 | 
			
		||||
 | 
			
		||||
@ -7,14 +7,15 @@ services:
 | 
			
		||||
      - GITEA_DB_HOST="db:5432"
 | 
			
		||||
      - GITEA_DB_NAME=gitea
 | 
			
		||||
      - GITEA_DB_USER=gitea
 | 
			
		||||
    secrets:
 | 
			
		||||
      - db_password
 | 
			
		||||
  db:
 | 
			
		||||
    image: postgres:15.8
 | 
			
		||||
    image: postgres:15.13
 | 
			
		||||
    deploy:
 | 
			
		||||
      labels:
 | 
			
		||||
          backupbot.backup: "true"
 | 
			
		||||
          backupbot.backup.pre-hook: "PGPASSWORD=$$(cat $${POSTGRES_PASSWORD_FILE}) pg_dump -U $${POSTGRES_USER} $${POSTGRES_DB} > /var/lib/postgresql/data/backup.sql"
 | 
			
		||||
          backupbot.backup.post-hook: "rm -r /var/lib/postgresql/data/backup.sql"
 | 
			
		||||
          backupbot.backup.path: "/var/lib/postgresql/data"
 | 
			
		||||
        backupbot.backup.pre-hook: "/pg_backup.sh backup"
 | 
			
		||||
        backupbot.backup.volumes.db.path: "backup.sql"
 | 
			
		||||
        backupbot.restore.post-hook: '/pg_backup.sh restore'
 | 
			
		||||
    environment: 
 | 
			
		||||
      - POSTGRES_DB=gitea
 | 
			
		||||
      - POSTGRES_USER=gitea
 | 
			
		||||
@ -25,6 +26,10 @@ services:
 | 
			
		||||
      - db:/var/lib/postgresql/data
 | 
			
		||||
    networks:
 | 
			
		||||
      - internal
 | 
			
		||||
    configs:
 | 
			
		||||
        - source: pg_backup
 | 
			
		||||
          target: /pg_backup.sh
 | 
			
		||||
          mode: 0555
 | 
			
		||||
 | 
			
		||||
secrets:
 | 
			
		||||
  db_password:
 | 
			
		||||
@ -33,4 +38,8 @@ secrets:
 | 
			
		||||
 | 
			
		||||
volumes:
 | 
			
		||||
  db:
 | 
			
		||||
  internal:
 | 
			
		||||
 | 
			
		||||
configs:
 | 
			
		||||
  pg_backup:
 | 
			
		||||
    name: ${STACK_NAME}_pg_backup_${PG_BACKUP_VERSION}
 | 
			
		||||
    file: pg_backup.sh
 | 
			
		||||
 | 
			
		||||
@ -5,8 +5,10 @@ services:
 | 
			
		||||
  app:
 | 
			
		||||
    environment:
 | 
			
		||||
      - GITEA_MAILER_FROM
 | 
			
		||||
      - GITEA_MAILER_HOST
 | 
			
		||||
      - GITEA_MAILER_ADDR
 | 
			
		||||
      - GITEA_MAILER_PORT
 | 
			
		||||
      - GITEA_MAILER_USER
 | 
			
		||||
      - "GITEA_MAILER_PROTOCOL=${GITEA_MAILER_PROTOCOL:-smtps}"
 | 
			
		||||
    secrets:
 | 
			
		||||
      - smtp_password
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
							
								
								
									
										8
									
								
								compose.sqlite3.yml
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										8
									
								
								compose.sqlite3.yml
									
									
									
									
									
										Normal file
									
								
							@ -0,0 +1,8 @@
 | 
			
		||||
version: '3.8'
 | 
			
		||||
 | 
			
		||||
services:
 | 
			
		||||
  app:
 | 
			
		||||
    environment:
 | 
			
		||||
      - GITEA_DB_TYPE=sqlite3
 | 
			
		||||
      - GITEA_SQLITE_JOURNAL_MODE=wal
 | 
			
		||||
      - GITEA_PATH=/var/lib/gitea/gitea.db
 | 
			
		||||
							
								
								
									
										10
									
								
								compose.yml
									
									
									
									
									
								
							
							
						
						
									
										10
									
								
								compose.yml
									
									
									
									
									
								
							@ -3,7 +3,7 @@ version: "3.8"
 | 
			
		||||
 | 
			
		||||
services:
 | 
			
		||||
  app:
 | 
			
		||||
    image: "gitea/gitea:1.22.2-rootless"
 | 
			
		||||
    image: "gitea/gitea:1.24.2-rootless"
 | 
			
		||||
    configs:
 | 
			
		||||
      - source: app_ini
 | 
			
		||||
        target: /etc/gitea/app.ini
 | 
			
		||||
@ -11,11 +11,11 @@ services:
 | 
			
		||||
        target: /usr/local/bin/docker-setup.sh
 | 
			
		||||
        mode: 0555
 | 
			
		||||
    secrets:
 | 
			
		||||
      - db_password
 | 
			
		||||
      - internal_token
 | 
			
		||||
      - jwt_secret
 | 
			
		||||
      - secret_key
 | 
			
		||||
    environment:
 | 
			
		||||
      - FORGE=gitea
 | 
			
		||||
      - GITEA_ALLOW_ONLY_EXTERNAL_REGISTRATION
 | 
			
		||||
      - GITEA_APP_NAME
 | 
			
		||||
      - GITEA_AUTO_WATCH_NEW_REPOS
 | 
			
		||||
@ -52,6 +52,8 @@ services:
 | 
			
		||||
      - GITEA_ALLOWED_USER_VISIBILITY_MODES
 | 
			
		||||
      - GITEA_DEFAULT_ORG_VISIBILITY
 | 
			
		||||
      - GITEA_REQUIRE_SIGNIN_VIEW
 | 
			
		||||
      - GITEA__oauth2__REFRESH_TOKEN_EXPIRATION_TIME
 | 
			
		||||
      - GITEA_LFS_START_SERVER=${GITEA_LFS_START_SERVER:-false}
 | 
			
		||||
    volumes:
 | 
			
		||||
      - data:/var/lib/gitea
 | 
			
		||||
      - config:/etc/gitea
 | 
			
		||||
@ -71,7 +73,7 @@ services:
 | 
			
		||||
        failure_action: rollback
 | 
			
		||||
        order: start-first
 | 
			
		||||
      labels:
 | 
			
		||||
        - "backupbot.backup=true"
 | 
			
		||||
        - "backupbot.backup=${ENABLE_BACKUPS:-true}"
 | 
			
		||||
        - "traefik.enable=true"
 | 
			
		||||
        - "traefik.http.routers.${STACK_NAME}.rule=Host(`${DOMAIN}`)"
 | 
			
		||||
        - "traefik.http.routers.${STACK_NAME}.entrypoints=web-secure"
 | 
			
		||||
@ -85,7 +87,7 @@ services:
 | 
			
		||||
        - "traefik.http.middlewares.${STACK_NAME}_cors.headers.accesscontrolalloworiginlist=https://${GITEA_CORS_ALLOW_DOMAIN}"
 | 
			
		||||
        - "traefik.http.middlewares.${STACK_NAME}_cors.headers.accesscontrolmaxage=100"
 | 
			
		||||
        - "traefik.http.middlewares.${STACK_NAME}_cors.headers.addvaryheader=true"
 | 
			
		||||
        - coop-cloud.${STACK_NAME}.version=2.10.1+1.22.2-rootless
 | 
			
		||||
        - coop-cloud.${STACK_NAME}.version=3.5.2+1.24.2-rootless
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
networks:
 | 
			
		||||
 | 
			
		||||
							
								
								
									
										34
									
								
								pg_backup.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										34
									
								
								pg_backup.sh
									
									
									
									
									
										Normal file
									
								
							@ -0,0 +1,34 @@
 | 
			
		||||
#!/bin/bash
 | 
			
		||||
 | 
			
		||||
set -e
 | 
			
		||||
 | 
			
		||||
BACKUP_FILE='/var/lib/postgresql/data/backup.sql'
 | 
			
		||||
 | 
			
		||||
function backup {
 | 
			
		||||
  export PGPASSWORD=$(cat $POSTGRES_PASSWORD_FILE)
 | 
			
		||||
  pg_dump -U ${POSTGRES_USER} ${POSTGRES_DB} > $BACKUP_FILE
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
function restore {
 | 
			
		||||
    cd /var/lib/postgresql/data/
 | 
			
		||||
    restore_config(){
 | 
			
		||||
        # Restore allowed connections
 | 
			
		||||
        cat pg_hba.conf.bak > pg_hba.conf
 | 
			
		||||
        su postgres -c 'pg_ctl reload'
 | 
			
		||||
    }
 | 
			
		||||
    # Don't allow any other connections than local
 | 
			
		||||
    cp pg_hba.conf pg_hba.conf.bak
 | 
			
		||||
    echo "local all all trust" > pg_hba.conf
 | 
			
		||||
    su postgres -c 'pg_ctl reload'
 | 
			
		||||
    trap restore_config EXIT INT TERM
 | 
			
		||||
 | 
			
		||||
    # Recreate Database
 | 
			
		||||
    psql -U ${POSTGRES_USER} -d postgres -c "DROP DATABASE ${POSTGRES_DB} WITH (FORCE);" 
 | 
			
		||||
    createdb -U ${POSTGRES_USER} ${POSTGRES_DB}
 | 
			
		||||
    psql -U ${POSTGRES_USER} -d ${POSTGRES_DB} -1 -f $BACKUP_FILE
 | 
			
		||||
 | 
			
		||||
    trap - EXIT INT TERM
 | 
			
		||||
    restore_config
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
$@
 | 
			
		||||
							
								
								
									
										3
									
								
								release/3.0.0+1.22.2-rootless
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										3
									
								
								release/3.0.0+1.22.2-rootless
									
									
									
									
									
										Normal file
									
								
							@ -0,0 +1,3 @@
 | 
			
		||||
BEWARE! 🚨 This release updates to the newer Gitea SMTP settings format.
 | 
			
		||||
 | 
			
		||||
If you are using SMTP, you will need to split the old GITEA_MAILER_HOST into separate GITEA_MAILER_ADDR (hostname) and GITEA_MAILER_PORT settings.
 | 
			
		||||
		Reference in New Issue
	
	Block a user