Compare commits
19
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
8c27b46cb1 | ||
|
|
25b4861905 | ||
|
|
a35ab05178 | ||
|
|
62092d1370 | ||
|
|
e68cde0b73 | ||
|
|
bdee69c323 | ||
|
|
c0ea6a57ff | ||
|
|
11cd551fb1 | ||
|
|
09c1fc9655 | ||
|
|
050ca1c6c8 | ||
|
|
e043301f4a | ||
|
|
018469e32d | ||
|
|
fd3d2610a0 | ||
|
|
1d03f6172b | ||
|
|
bfe12c03b5 | ||
|
|
2273022c17 | ||
|
|
5bb65a4d1f | ||
|
|
92d99b2346 | ||
|
|
91b789e115 |
+14
-3
@@ -18,13 +18,24 @@ LETS_ENCRYPT_ENV=production
|
|||||||
GITLAB_ROOT_EMAIL="gitlab_admin@example.com"
|
GITLAB_ROOT_EMAIL="gitlab_admin@example.com"
|
||||||
SECRET_INITIAL_ROOT_PASSWORD_VERSION=v1
|
SECRET_INITIAL_ROOT_PASSWORD_VERSION=v1
|
||||||
SECRET_RUNNER_TOKEN_VERSION=v1
|
SECRET_RUNNER_TOKEN_VERSION=v1
|
||||||
SECRET_REGISTRATION_TOKEN_VERSION=v1
|
SECRET_SMTP_PASSWORD_VERSION=v1
|
||||||
|
|
||||||
|
GITLAB_CONF_VERSION=v1
|
||||||
|
ENTRYPOINT_VERSION=v1
|
||||||
|
|
||||||
SSO=false
|
SSO=false
|
||||||
## Authentik Configuration
|
## Authentik Configuration
|
||||||
|
|
||||||
# SSO=true
|
# SSO=true
|
||||||
# ORG_NAME="My Organization"
|
# ORG_NAME="My Organization"
|
||||||
# SSO_PROVIDER_URL="https://authentik.mydomain.com/application/o/gitlab/"
|
# SSO_PROVIDER_URL="https://authentik.mydomain.com/application/o/gitlab/"
|
||||||
# SSO_PROVIDER_ID="your authentik Client ID"
|
# SSO_PROVIDER_ID="your authentik Client ID"
|
||||||
# SECRET_SSO_PROVIDER_SECRET_VERSION=v1
|
# SECRET_SSO_PROVIDER_SECRET_VERSION=v1
|
||||||
|
|
||||||
|
## Enable SMTP sending
|
||||||
|
#SMTP_ENABLE_FLAG=true
|
||||||
|
#SMTP_HOST=smtp.server.com
|
||||||
|
#SMTP_PORT=465
|
||||||
|
#SMTP_USER=your@user.com
|
||||||
|
#SMTP_HOST_FROM_ADDRESS=your@user.com
|
||||||
|
#SMTP_FROM_NAME="Gitlab"
|
||||||
|
#SMTP_STARTTLS_FLAG=true
|
||||||
|
|||||||
@@ -1,8 +1,6 @@
|
|||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
GITLAB_CONF_VERSION=v1
|
export GITLAB_CONF_VERSION=v1
|
||||||
ENTRYPOINT_VERSION=v1
|
export ENTRYPOINT_VERSION=v1
|
||||||
RUNNER_ENTRYPOINT_VERSION=v1
|
|
||||||
RUNNER_CONF_VERSION=v1
|
|
||||||
|
|
||||||
run_rails_command() {
|
run_rails_command() {
|
||||||
su -p root -s /bin/sh -c "gitlab-rails runner '$@'"
|
su -p root -s /bin/sh -c "gitlab-rails runner '$@'"
|
||||||
@@ -30,10 +28,4 @@ disable_signups() {
|
|||||||
enable_signups () {
|
enable_signups () {
|
||||||
run_rails_command 'Gitlab::CurrentSettings.update!(signup_enabled: true)'
|
run_rails_command 'Gitlab::CurrentSettings.update!(signup_enabled: true)'
|
||||||
reconfigure
|
reconfigure
|
||||||
}
|
|
||||||
|
|
||||||
register_runner() {
|
|
||||||
RUNNER_TOKEN="$1"
|
|
||||||
|
|
||||||
gitlab-runner register --non-interactive --url "https://$CI_SERVER_URL" --token "$RUNNER_TOKEN" --executor "docker"
|
|
||||||
}
|
}
|
||||||
@@ -1,83 +0,0 @@
|
|||||||
---
|
|
||||||
version: "3.8"
|
|
||||||
|
|
||||||
services:
|
|
||||||
runner:
|
|
||||||
image: registry.gitlab.com/gitlab-org/gitlab-runner:alpine
|
|
||||||
depends_on:
|
|
||||||
- dind
|
|
||||||
environment:
|
|
||||||
- CI_SERVER_URL=${DOMAIN}
|
|
||||||
- DOCKER_HOST=tcp://socket-proxy:2375
|
|
||||||
- RUNNER_TIMEOUT
|
|
||||||
- RUNNER_CONCURENCY
|
|
||||||
configs:
|
|
||||||
- source: runner_conf
|
|
||||||
target: /etc/gitlab-runner/config.toml
|
|
||||||
- source: entrypoint
|
|
||||||
target: /custom-entrypoint.sh
|
|
||||||
mode: 0555
|
|
||||||
volumes:
|
|
||||||
- "runnner_config:/etc/gitlab-runner"
|
|
||||||
networks:
|
|
||||||
- internal
|
|
||||||
deploy:
|
|
||||||
restart_policy:
|
|
||||||
condition: on-failure
|
|
||||||
entrypoint: /custom-entrypoint.sh
|
|
||||||
|
|
||||||
socket-proxy:
|
|
||||||
image: lscr.io/linuxserver/socket-proxy:3.2.6
|
|
||||||
environment:
|
|
||||||
- PROXY_READ_TIMEOUT=5000
|
|
||||||
- ALLOW_START=1
|
|
||||||
- ALLOW_STOP=1
|
|
||||||
- ALLOW_RESTARTS=1
|
|
||||||
- AUTH=1
|
|
||||||
- BUILD=1
|
|
||||||
- COMMIT=1
|
|
||||||
- CONFIGS=1
|
|
||||||
- CONTAINERS=1
|
|
||||||
- DISABLE_IPV6=0
|
|
||||||
- DISTRIBUTION=0
|
|
||||||
- EVENTS=1
|
|
||||||
- EXEC=1
|
|
||||||
- IMAGES=1
|
|
||||||
- INFO=1
|
|
||||||
- NETWORKS=1
|
|
||||||
- NODES=1
|
|
||||||
- PING=1
|
|
||||||
- POST=1
|
|
||||||
- PLUGINS=1
|
|
||||||
- SECRETS=1
|
|
||||||
- SERVICES=1
|
|
||||||
- SESSION=1
|
|
||||||
- SWARM=1
|
|
||||||
- SYSTEM=1
|
|
||||||
- TASKS=1
|
|
||||||
- VERSION=1
|
|
||||||
- VOLUMES=1
|
|
||||||
volumes:
|
|
||||||
- /var/run/docker.sock:/var/run/docker.sock:ro
|
|
||||||
networks:
|
|
||||||
- internal
|
|
||||||
ports:
|
|
||||||
- "2375:2375"
|
|
||||||
|
|
||||||
volumes:
|
|
||||||
runnner_config:
|
|
||||||
|
|
||||||
secrets:
|
|
||||||
registration_token:
|
|
||||||
name: ${STACK_NAME}_registration_token_${SECRET_REGISTRATION_TOKEN_VERSION}
|
|
||||||
external: true
|
|
||||||
|
|
||||||
configs:
|
|
||||||
runner_conf:
|
|
||||||
name: ${STACK_NAME}_runner_config_${RUNNER_CONF_VERSION}
|
|
||||||
file: runner-config.toml.tmpl
|
|
||||||
template_driver: golang
|
|
||||||
entrypoint:
|
|
||||||
name: ${STACK_NAME}_runner_entrypoint_${RUNNER_ENTRYPOINT_VERSION}
|
|
||||||
file: runner-entrypoint.sh.tmpl
|
|
||||||
template_driver: golang
|
|
||||||
+6
-2
@@ -3,7 +3,7 @@ version: "3.8"
|
|||||||
|
|
||||||
services:
|
services:
|
||||||
app:
|
app:
|
||||||
image: 'gitlab/gitlab-ce:18.3.0-ce.0'
|
image: 'gitlab/gitlab-ce:18.10.4-ce.0'
|
||||||
networks:
|
networks:
|
||||||
- proxy
|
- proxy
|
||||||
- internal
|
- internal
|
||||||
@@ -34,11 +34,12 @@ services:
|
|||||||
- "backupbot.backup=true"
|
- "backupbot.backup=true"
|
||||||
- "backupbot.backup.path=/etc/gitlab/,/var/log/gitlab/,/var/opt/gitlab/"
|
- "backupbot.backup.path=/etc/gitlab/,/var/log/gitlab/,/var/opt/gitlab/"
|
||||||
- "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT:-240}"
|
- "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT:-240}"
|
||||||
- "coop-cloud.${STACK_NAME}.version=0.2.2+18.3.0-ce.0"
|
- "coop-cloud.${STACK_NAME}.version=0.2.3+18.10.4-ce.0"
|
||||||
secrets:
|
secrets:
|
||||||
- initial_root_password
|
- initial_root_password
|
||||||
- runner_token
|
- runner_token
|
||||||
- sso_provider_secret
|
- sso_provider_secret
|
||||||
|
- smtp_password
|
||||||
healthcheck:
|
healthcheck:
|
||||||
test: ["CMD", "bash", "/opt/gitlab/etc/gitlab-healthcheck-rc" ]
|
test: ["CMD", "bash", "/opt/gitlab/etc/gitlab-healthcheck-rc" ]
|
||||||
interval: 30s
|
interval: 30s
|
||||||
@@ -50,6 +51,9 @@ secrets:
|
|||||||
initial_root_password:
|
initial_root_password:
|
||||||
external: true
|
external: true
|
||||||
name: ${STACK_NAME}_initial_root_password_${SECRET_INITIAL_ROOT_PASSWORD_VERSION}
|
name: ${STACK_NAME}_initial_root_password_${SECRET_INITIAL_ROOT_PASSWORD_VERSION}
|
||||||
|
smtp_password:
|
||||||
|
external: true
|
||||||
|
name: ${STACK_NAME}_smtp_password_${SECRET_SMTP_PASSWORD_VERSION}
|
||||||
runner_token:
|
runner_token:
|
||||||
external: true
|
external: true
|
||||||
name: ${STACK_NAME}_runner_token_${SECRET_RUNNER_TOKEN_VERSION}
|
name: ${STACK_NAME}_runner_token_${SECRET_RUNNER_TOKEN_VERSION}
|
||||||
|
|||||||
+19
-19
@@ -82,15 +82,16 @@ external_url 'https://{{ env "DOMAIN" }}'
|
|||||||
###! Docs: https://docs.gitlab.com/omnibus/settings/smtp.html
|
###! Docs: https://docs.gitlab.com/omnibus/settings/smtp.html
|
||||||
###! **Use smtp instead of sendmail/postfix.**
|
###! **Use smtp instead of sendmail/postfix.**
|
||||||
|
|
||||||
# gitlab_rails['smtp_enable'] = true
|
gitlab_rails['smtp_enable'] = {{ env "SMTP_ENABLE_FLAG" }}
|
||||||
# gitlab_rails['smtp_address'] = "smtp.server"
|
gitlab_rails['smtp_address'] = "{{ env "SMTP_HOST" }}"
|
||||||
# gitlab_rails['smtp_port'] = 465
|
gitlab_rails['smtp_port'] = {{ env "SMTP_PORT" }}
|
||||||
# gitlab_rails['smtp_user_name'] = "smtp user"
|
gitlab_rails['smtp_user_name'] = "{{ env "SMTP_USER" }}"
|
||||||
# gitlab_rails['smtp_password'] = "smtp password"
|
gitlab_rails['smtp_password'] = "{{ secret "smtp_password" }}"
|
||||||
# gitlab_rails['smtp_domain'] = "example.com"
|
gitlab_rails['smtp_domain'] = "{{ env "SMTP_DOMAIN" }}"
|
||||||
# gitlab_rails['smtp_authentication'] = "login"
|
gitlab_rails['smtp_authentication'] = "login"
|
||||||
# gitlab_rails['smtp_enable_starttls_auto'] = true
|
gitlab_rails['smtp_enable_starttls_auto'] = true
|
||||||
# gitlab_rails['smtp_tls'] = false
|
gitlab_rails['smtp_tls'] = false
|
||||||
|
|
||||||
# gitlab_rails['smtp_pool'] = false
|
# gitlab_rails['smtp_pool'] = false
|
||||||
|
|
||||||
###! **Can be: 'none', 'peer', 'client_once', 'fail_if_no_peer_cert'**
|
###! **Can be: 'none', 'peer', 'client_once', 'fail_if_no_peer_cert'**
|
||||||
@@ -2291,24 +2292,23 @@ registry_nginx['listen_https'] = false
|
|||||||
# grafana['metrics_basic_auth_password'] = 'please_set_a_unique_password' # default: nil
|
# grafana['metrics_basic_auth_password'] = 'please_set_a_unique_password' # default: nil
|
||||||
# grafana['alerting_enabled'] = false
|
# grafana['alerting_enabled'] = false
|
||||||
|
|
||||||
### SMTP Configuration
|
### SMTP Configuration
|
||||||
#
|
#
|
||||||
# See: http://docs.grafana.org/administration/configuration/#smtp
|
# See: http://docs.grafana.org/administration/configuration/#smtp
|
||||||
#
|
#
|
||||||
# grafana['smtp'] = {
|
# grafana['smtp'] = {
|
||||||
# 'enabled' => true,
|
# 'enabled' => {{ env "SMTP_ENABLE_FLAG" }},
|
||||||
# 'host' => 'localhost:25',
|
# 'host' => '{{ env "SMTP_HOST" }}:{{ env "SMTP_PORT" }}',
|
||||||
# 'user' => nil,
|
# 'user' => {{ env "SMTP_USER" }},
|
||||||
# 'password' => nil,
|
# 'password' => {{ secret "smtp_password" }},
|
||||||
# 'cert_file' => nil,
|
# 'cert_file' => nil,
|
||||||
# 'key_file' => nil,
|
# 'key_file' => nil,
|
||||||
# 'skip_verify' => false,
|
# 'skip_verify' => false,
|
||||||
# 'from_address' => 'admin@grafana.localhost',
|
# 'from_address' => '{{ env "SMTP_FROM_ADDRESS" }}',
|
||||||
# 'from_name' => 'Grafana',
|
# 'from_name' => '{{ env "SMTP_FROM_NAME" }}',
|
||||||
# 'ehlo_identity' => 'dashboard.example.com',
|
# 'ehlo_identity' => '{{ env "SMTP_EHLO" }}',
|
||||||
# 'startTLS_policy' => nil
|
# 'startTLS_policy' => {{ env "SMTP_STARTTLS_FLAG" }}
|
||||||
# }
|
# }
|
||||||
|
|
||||||
# Grafana usage reporting defaults to gitlab_rails['usage_ping_enabled']
|
# Grafana usage reporting defaults to gitlab_rails['usage_ping_enabled']
|
||||||
# grafana['reporting_enabled'] = true
|
# grafana['reporting_enabled'] = true
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,14 @@
|
|||||||
|
{
|
||||||
|
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
|
||||||
|
"extends": [
|
||||||
|
"config:recommended"
|
||||||
|
],
|
||||||
|
"packageRules": [
|
||||||
|
{
|
||||||
|
"matchDatasources": [
|
||||||
|
"docker"
|
||||||
|
],
|
||||||
|
"pinDigests": true
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
@@ -1,10 +0,0 @@
|
|||||||
#!/bin/sh
|
|
||||||
|
|
||||||
set -e
|
|
||||||
|
|
||||||
while [ ! -s /etc/gitlab-runner/config.toml ]
|
|
||||||
do
|
|
||||||
echo "The runner was not registered yet. Next try in 5 seconds."
|
|
||||||
sleep 5
|
|
||||||
done
|
|
||||||
|
|
||||||
Reference in New Issue
Block a user