From 1a098452f43e2df8776b5d530921378fcfb6658c Mon Sep 17 00:00:00 2001 From: autonomic-bot Date: Thu, 18 Jun 2026 01:52:58 +0000 Subject: [PATCH] fix(config): make app.ini writable so Gitea can persist secrets on (re)deploy Gitea 1.24+ (re)generates and SAVES the [oauth2] JWT secret to /etc/gitea/app.ini at LoadCommonSettings. With app.ini mounted directly as a read-only swarm config this fails fatally (open /etc/gitea/app.ini: read-only file system) on a warm reattach/redeploy, crash-looping the container before any DB migration. Mount the rendered config at /etc/gitea/app.ini.init (read-only) and seed it once into the writable config volume via docker-setup.sh, so Gitea owns a writable /etc/gitea/app.ini. Bumps DOCKER_SETUP_SH_VERSION so the new entrypoint actually deploys. --- abra.sh | 2 +- compose.yml | 2 +- docker-setup.sh.tmpl | 11 +++++++++++ 3 files changed, 13 insertions(+), 2 deletions(-) diff --git a/abra.sh b/abra.sh index 54bf0f3..4b0cbbe 100644 --- a/abra.sh +++ b/abra.sh @@ -1,5 +1,5 @@ export APP_INI_VERSION=v22 -export DOCKER_SETUP_SH_VERSION=v1 +export DOCKER_SETUP_SH_VERSION=v2 export PG_BACKUP_VERSION=v1 abra_backup_app() { diff --git a/compose.yml b/compose.yml index 88265c2..47fa295 100644 --- a/compose.yml +++ b/compose.yml @@ -6,7 +6,7 @@ services: image: "gitea/gitea:1.24.2-rootless" configs: - source: app_ini - target: /etc/gitea/app.ini + target: /etc/gitea/app.ini.init - source: docker_setup_sh target: /usr/local/bin/docker-setup.sh mode: 0555 diff --git a/docker-setup.sh.tmpl b/docker-setup.sh.tmpl index 310e8f7..206b73f 100644 --- a/docker-setup.sh.tmpl +++ b/docker-setup.sh.tmpl @@ -13,3 +13,14 @@ mkdir -p ${GITEA_CUSTOM} && chmod 0500 ${GITEA_CUSTOM} # Prepare temp folder mkdir -p ${GITEA_TEMP} && chmod 0700 ${GITEA_TEMP} if [ ! -w ${GITEA_TEMP} ]; then echo "${GITEA_TEMP} is not writable"; exit 1; fi + +# Seed app.ini into the WRITABLE config volume (/etc/gitea) from the read-only swarm config +# (mounted at /etc/gitea/app.ini.init). Gitea must be able to PERSIST settings to app.ini — e.g. +# Gitea 1.24+ (re)generates and SAVES the [oauth2] JWT_SECRET at LoadCommonSettings; with app.ini +# mounted directly as a read-only swarm config this fails fatally ("open /etc/gitea/app.ini: +# read-only file system") on (re)deploy. Seed-once preserves any runtime-persisted state across +# restarts/upgrades; delete /etc/gitea/app.ini to re-seed from the recipe's rendered config. +if [ ! -f /etc/gitea/app.ini ]; then + cp /etc/gitea/app.ini.init /etc/gitea/app.ini +fi +chmod 0600 /etc/gitea/app.ini 2>/dev/null || true