fix(config): make app.ini writable so Gitea can persist secrets on (re)deploy

Gitea 1.24+ (re)generates and SAVES the [oauth2] JWT secret to /etc/gitea/app.ini at
LoadCommonSettings. With app.ini mounted directly as a read-only swarm config this fails fatally
(open /etc/gitea/app.ini: read-only file system) on a warm reattach/redeploy, crash-looping the
container before any DB migration. Mount the rendered config at /etc/gitea/app.ini.init (read-only)
and seed it once into the writable config volume via docker-setup.sh, so Gitea owns a writable
/etc/gitea/app.ini. Bumps DOCKER_SETUP_SH_VERSION so the new entrypoint actually deploys.
This commit is contained in:
2026-06-18 01:52:58 +00:00
parent ce4de9e645
commit 1a098452f4
3 changed files with 13 additions and 2 deletions
+1 -1
View File
@@ -1,5 +1,5 @@
export APP_INI_VERSION=v22
export DOCKER_SETUP_SH_VERSION=v1
export DOCKER_SETUP_SH_VERSION=v2
export PG_BACKUP_VERSION=v1
abra_backup_app() {