Compare commits

..
Author SHA1 Message Date
sixsmith 8c27b46cb1 Update renovate.json
Support digest pinning
2026-08-24 23:18:53 +00:00
javielico 25b4861905 Typo on SECRET_SMTP_PASSWORD_VERSION 2026-06-30 12:48:21 +00:00
javielico a35ab05178 I removed the surrounding quotes ("{{ ... }}") assuming your templating engine renders true booleans 2026-06-30 12:44:49 +00:00
javielico 62092d1370 Replacing mistake from smtp grafana to gitlab smtp 2026-06-30 12:40:04 +00:00
javielico e68cde0b73 Fixed issue with rb validation and variables issues 2026-06-30 12:29:46 +00:00
javielico bdee69c323 Uncommenting SMTP details 2026-06-30 12:21:33 +00:00
javielico c0ea6a57ff Change tag for version 18.4.0-ce 2026-06-30 13:10:37 +01:00
javielico 11cd551fb1 chore: update image tags 2026-06-30 13:05:03 +01:00
javielico 09c1fc9655 Push to new version 18.10.3-ce.0 2026-06-30 12:00:02 +00:00
javielico 050ca1c6c8 Handling smtp password for gitlab 2026-06-30 11:55:40 +00:00
javielico e043301f4a Handling of smtp_password secrets 2026-06-30 11:53:00 +00:00
javielico 018469e32d Add variables for handling smtp access 2026-06-30 11:51:08 +00:00
javielico fd3d2610a0 Added variables for smtp values 2026-06-30 11:49:02 +00:00
javielico 1d03f6172b Adding GITLAB_CONF_VERSION=v1 ENTRYPOINT_VERSION=v1 to the .env.sample as it's missing 2026-06-30 10:51:09 +00:00
javielico bfe12c03b5 Update abra.sh to export variables 2026-06-30 10:47:09 +00:00
marlon 2273022c17 Merge pull request 'chore(deps): update gitlab/gitlab-ce docker tag to v18.10.1' (#6) from renovate/gitlab-gitlab-ce-18.x into master
Reviewed-on: #6
2026-04-17 19:10:55 +00:00
renovate-bot 5bb65a4d1f chore(deps): update gitlab/gitlab-ce docker tag to v18.10.1 2026-03-25 13:10:12 +00:00
marlon 92d99b2346 Merge pull request 'chore: Configure Renovate' (#5) from renovate/configure into master
Reviewed-on: #5
2026-03-10 20:13:02 +00:00
renovate-bot 91b789e115 Add renovate.json 2026-03-10 17:41:58 +00:00
marlon b47095b29b chore: publish 0.2.2+18.3.0-ce.0 release 2025-08-24 16:32:42 -04:00
marlon ec06738768 chore: publish 0.2.1+18.2.4-ce.0 release 2025-08-24 16:19:48 -04:00
marlon 7d902ef71d chore: publish 0.2.0+18.2.4-ce.0 release 2025-08-24 16:11:47 -04:00
marlon bc66403532 chore: publish 0.1.5+17.11.7-ce.0 release 2025-08-24 15:45:01 -04:00
marlon 81afcc2d47 chore: publish 0.1.4+17.8.7-ce.0 release 2025-08-24 15:31:08 -04:00
marlon a8a94ca4d2 chore: publish 0.1.3+17.7.3-ce.0 release 2025-05-21 14:39:47 -04:00
marlon 7c8ac5a72a Merge pull request 'set-ssh-port' (#4) from set-ssh-port into master
Reviewed-on: #4
2025-05-21 18:35:06 +00:00
marlon 454f23dfa3 fix quotes typo 2025-05-21 14:33:06 -04:00
marlon 177679f02c set ssh listen port based on env 2025-05-21 14:15:12 -04:00
marlon bb7c789ac1 chore: publish 0.1.2+17.7.3-ce.0 release 2025-01-24 16:35:10 -05:00
marlon 742dbafd07 chore: publish 0.1.2+17.7.3-ce.0 release 2025-01-24 16:25:14 -05:00
marlon 88de802669 Merge pull request 'use traefik for SSH forwarding, move config version variables to abra.sh, update documentation' (#3) from traefik-port-routing into master
Reviewed-on: #3
2025-01-24 21:17:51 +00:00
marlon a59a49a296 Merge branch 'master' into traefik-port-routing 2025-01-24 20:59:13 +00:00
marlon 3900518035 use traefik for SSH forwarding, move config version variables to abra.sh, update documentation 2025-01-24 15:17:10 -05:00
cas abd69b3467 Update .drone.yml 2025-01-08 10:09:12 -08:00
10 changed files with 92 additions and 36 deletions
+1 -1
View File
@@ -32,7 +32,7 @@ steps:
from_secret: drone_abra-bot_token
fork: true
repositories:
- coop-cloud/auto-recipes-catalogue-json
- toolshed/auto-recipes-catalogue-json
trigger:
event: tag
+16 -5
View File
@@ -3,7 +3,7 @@ TYPE=gitlab
DOMAIN=gitlab.example.com
REGISTRY_DOMAIN=registry.gitlab.example.com
# The Gitlab Pages domain must not be a subdomain of the main Gitlab domain
# The GitLab Pages domain must not be a subdomain of the main GitLab domain
PAGES_DOMAIN=pages.example.com
# Prevent public signups
@@ -12,14 +12,16 @@ POST_DEPLOY_CMDS=disable_signups
## Domain aliases
EXTRA_DOMAINS=", `$REGISTRY_DOMAIN`, `$PAGES_DOMAIN`"
GITLAB_SSH_PORT=2222
LETS_ENCRYPT_ENV=production
GITLAB_CONF_VERSION=v1
ENTRYPOINT_VERSION=v1
GITLAB_ROOT_EMAIL="gitlab_admin@example.com"
SECRET_INITIAL_ROOT_PASSWORD_VERSION=v1
SECRET_RUNNER_TOKEN_VERSION=v1
SECRET_SMTP_PASSWORD_VERSION=v1
GITLAB_CONF_VERSION=v1
ENTRYPOINT_VERSION=v1
SSO=false
## Authentik Configuration
@@ -27,4 +29,13 @@ SSO=false
# ORG_NAME="My Organization"
# SSO_PROVIDER_URL="https://authentik.mydomain.com/application/o/gitlab/"
# SSO_PROVIDER_ID="your authentik Client ID"
# SECRET_SSO_PROVIDER_SECRET_VERSION=v1
# SECRET_SSO_PROVIDER_SECRET_VERSION=v1
## Enable SMTP sending
#SMTP_ENABLE_FLAG=true
#SMTP_HOST=smtp.server.com
#SMTP_PORT=465
#SMTP_USER=your@user.com
#SMTP_HOST_FROM_ADDRESS=your@user.com
#SMTP_FROM_NAME="Gitlab"
#SMTP_STARTTLS_FLAG=true
+27 -1
View File
@@ -1,6 +1,6 @@
# gitlab
> GitLab server, using GitLab omnibus
> A git, CI/CD, and project management platform using GitLab omnibus
<!-- metadata -->
@@ -28,6 +28,17 @@
GitLab is configured to accept ssh:// git connections on the non-standard port 2222. This is because by default the Coop Cloud host server also must accept SSH connections for server management, so port 22 is already occupied and can't be used by GitLab.
To allow Traefik to accept connections on port 2222, edit the configuration of your Traefik app:
`abra app config traefik.yourserver.com`
Uncomment the following section:
```
COMPOSE_FILE="$COMPOSE_FILE:compose.gitea.yml"
GITEA_SSH_ENABLED=1
```
Redeploy Traefik
`abra app undeploy traefik.yourserver.com`
`abra app deploy traefik.yourserver.com`
To configure your local git client to use the non-standard port by default, modify your local client's ~/.ssh/config file to include the following:
```
Host: git.yourserver.org
@@ -35,6 +46,21 @@ Host: git.yourserver.org
Port 2222
```
## Management Commands
The following commands for managing GitLab are available by running `abra app command <your gitlab app> app <command>`
`disable_basic_login` - Disables standard email/password based login to the server (for example, to allow only SSO login)
`enable_basic_login` - Re-enables standard email/password based login (enabled by default)
`disable_signups` - Prevents public signups to create accounts on the server
`enable_signups` - Re-enables public signups (signups are enabled by default)
`run_rails_command` - Run a command on GitLab's rails console. For more information: https://docs.gitlab.com/ee/administration/operations/rails_console.html
`reconfigure` - Reload the GitLab configuration (usually necessary after using `run_rails_command`)
## SSO Configuration
- Create a Provider and Application in Authentik: https://docs.goauthentik.io/integrations/services/gitlab/#openid-connect-auth
+2
View File
@@ -1,4 +1,6 @@
#!/bin/bash
export GITLAB_CONF_VERSION=v1
export ENTRYPOINT_VERSION=v1
run_rails_command() {
su -p root -s /bin/sh -c "gitlab-rails runner '$@'"
+9 -8
View File
@@ -3,7 +3,7 @@ version: "3.8"
services:
app:
image: 'gitlab/gitlab-ce:17.7.0-ce.0'
image: 'gitlab/gitlab-ce:18.10.4-ce.0'
networks:
- proxy
- internal
@@ -13,8 +13,6 @@ services:
- source: entrypoint
target: /entrypoint.sh
mode: 0555
ports:
- '0.0.0.0:2222:2222'
entrypoint:
/entrypoint.sh
volumes:
@@ -30,18 +28,18 @@ services:
- "traefik.http.routers.${STACK_NAME}.rule=Host(`${DOMAIN}`${EXTRA_DOMAINS})"
- "traefik.http.routers.${STACK_NAME}.entrypoints=web-secure"
- "traefik.http.routers.${STACK_NAME}.tls.certresolver=${LETS_ENCRYPT_ENV}"
## Redirect from EXTRA_DOMAINS to DOMAIN
#- "traefik.http.routers.${STACK_NAME}.middlewares=${STACK_NAME}-redirect"
#- "traefik.http.middlewares.${STACK_NAME}-redirect.headers.SSLForceHost=true"
#- "traefik.http.middlewares.${STACK_NAME}-redirect.headers.SSLHost=${DOMAIN}"
- "traefik.tcp.routers.${STACK_NAME}-ssh.rule=HostSNI(`*`)"
- "traefik.tcp.routers.${STACK_NAME}-ssh.entrypoints=gitea-ssh"
- "traefik.tcp.services.${STACK_NAME}-ssh.loadbalancer.server.port=${GITLAB_SSH_PORT}"
- "backupbot.backup=true"
- "backupbot.backup.path=/etc/gitlab/,/var/log/gitlab/,/var/opt/gitlab/"
- "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT:-240}"
- "coop-cloud.${STACK_NAME}.version=0.1.1+17.7.0-ce.0"
- "coop-cloud.${STACK_NAME}.version=0.2.3+18.10.4-ce.0"
secrets:
- initial_root_password
- runner_token
- sso_provider_secret
- smtp_password
healthcheck:
test: ["CMD", "bash", "/opt/gitlab/etc/gitlab-healthcheck-rc" ]
interval: 30s
@@ -53,6 +51,9 @@ secrets:
initial_root_password:
external: true
name: ${STACK_NAME}_initial_root_password_${SECRET_INITIAL_ROOT_PASSWORD_VERSION}
smtp_password:
external: true
name: ${STACK_NAME}_smtp_password_${SECRET_SMTP_PASSWORD_VERSION}
runner_token:
external: true
name: ${STACK_NAME}_runner_token_${SECRET_RUNNER_TOKEN_VERSION}
+1 -1
View File
@@ -6,4 +6,4 @@ echo "Copying custom Gitlab config to /etc/gitlab/"
cp /gitlab.rb /etc/gitlab/gitlab.rb
echo "Entrypoint finished, launching Gitlab"
exec "/assets/wrapper"
exec "/assets/init-container"
+20 -20
View File
@@ -82,15 +82,16 @@ external_url 'https://{{ env "DOMAIN" }}'
###! Docs: https://docs.gitlab.com/omnibus/settings/smtp.html
###! **Use smtp instead of sendmail/postfix.**
# gitlab_rails['smtp_enable'] = true
# gitlab_rails['smtp_address'] = "smtp.server"
# gitlab_rails['smtp_port'] = 465
# gitlab_rails['smtp_user_name'] = "smtp user"
# gitlab_rails['smtp_password'] = "smtp password"
# gitlab_rails['smtp_domain'] = "example.com"
# gitlab_rails['smtp_authentication'] = "login"
# gitlab_rails['smtp_enable_starttls_auto'] = true
# gitlab_rails['smtp_tls'] = false
gitlab_rails['smtp_enable'] = {{ env "SMTP_ENABLE_FLAG" }}
gitlab_rails['smtp_address'] = "{{ env "SMTP_HOST" }}"
gitlab_rails['smtp_port'] = {{ env "SMTP_PORT" }}
gitlab_rails['smtp_user_name'] = "{{ env "SMTP_USER" }}"
gitlab_rails['smtp_password'] = "{{ secret "smtp_password" }}"
gitlab_rails['smtp_domain'] = "{{ env "SMTP_DOMAIN" }}"
gitlab_rails['smtp_authentication'] = "login"
gitlab_rails['smtp_enable_starttls_auto'] = true
gitlab_rails['smtp_tls'] = false
# gitlab_rails['smtp_pool'] = false
###! **Can be: 'none', 'peer', 'client_once', 'fail_if_no_peer_cert'**
@@ -678,7 +679,7 @@ gitlab_rails['omniauth_providers'] = [
# high_availability['mountpoint'] = ["/var/opt/gitlab/git-data", "/var/opt/gitlab/gitlab-rails/shared"]
### GitLab Shell settings for GitLab
# gitlab_rails['gitlab_shell_ssh_port'] = 22
gitlab_rails['gitlab_shell_ssh_port'] = {{ env "GITLAB_SSH_PORT" }}
# gitlab_rails['gitlab_shell_git_timeout'] = 800
### Enable gitlab-sshd on a different port than OpenSSH
@@ -2291,24 +2292,23 @@ registry_nginx['listen_https'] = false
# grafana['metrics_basic_auth_password'] = 'please_set_a_unique_password' # default: nil
# grafana['alerting_enabled'] = false
### SMTP Configuration
### SMTP Configuration
#
# See: http://docs.grafana.org/administration/configuration/#smtp
#
# grafana['smtp'] = {
# 'enabled' => true,
# 'host' => 'localhost:25',
# 'user' => nil,
# 'password' => nil,
# 'enabled' => {{ env "SMTP_ENABLE_FLAG" }},
# 'host' => '{{ env "SMTP_HOST" }}:{{ env "SMTP_PORT" }}',
# 'user' => {{ env "SMTP_USER" }},
# 'password' => {{ secret "smtp_password" }},
# 'cert_file' => nil,
# 'key_file' => nil,
# 'skip_verify' => false,
# 'from_address' => 'admin@grafana.localhost',
# 'from_name' => 'Grafana',
# 'ehlo_identity' => 'dashboard.example.com',
# 'startTLS_policy' => nil
# 'from_address' => '{{ env "SMTP_FROM_ADDRESS" }}',
# 'from_name' => '{{ env "SMTP_FROM_NAME" }}',
# 'ehlo_identity' => '{{ env "SMTP_EHLO" }}',
# 'startTLS_policy' => {{ env "SMTP_STARTTLS_FLAG" }}
# }
# Grafana usage reporting defaults to gitlab_rails['usage_ping_enabled']
# grafana['reporting_enabled'] = true
+1
View File
@@ -0,0 +1 @@
Fixes bug where GITLAB_SSH_PORT was not set in the Gitlab config
+1
View File
@@ -0,0 +1 @@
Starting with 18.0, GitLab will collect event-level product usage data from Self-Managed and Dedicated instances — while ensuring privacy, transparency, and customer control. GitLab administrators can turn off the data collection toggle before any data is collected in version 18.0. For more information about this change and how you can opt out, see the documentation: https://docs.gitlab.com/17.11/administration/settings/event_data/
+14
View File
@@ -0,0 +1,14 @@
{
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
"extends": [
"config:recommended"
],
"packageRules": [
{
"matchDatasources": [
"docker"
],
"pinDigests": true
}
]
}