fix(config): make app.ini writable so Gitea can persist secrets on (re)deploy
Gitea 1.24+ (re)generates and SAVES the [oauth2] JWT secret to /etc/gitea/app.ini at LoadCommonSettings. With app.ini mounted directly as a read-only swarm config this fails fatally (open /etc/gitea/app.ini: read-only file system) on a warm reattach/redeploy, crash-looping the container before any DB migration. Mount the rendered config at /etc/gitea/app.ini.init (read-only) and seed it once into the writable config volume via docker-setup.sh, so Gitea owns a writable /etc/gitea/app.ini. Bumps DOCKER_SETUP_SH_VERSION so the new entrypoint actually deploys.
This commit is contained in:
+1
-1
@@ -6,7 +6,7 @@ services:
|
||||
image: "gitea/gitea:1.24.2-rootless"
|
||||
configs:
|
||||
- source: app_ini
|
||||
target: /etc/gitea/app.ini
|
||||
target: /etc/gitea/app.ini.init
|
||||
- source: docker_setup_sh
|
||||
target: /usr/local/bin/docker-setup.sh
|
||||
mode: 0555
|
||||
|
||||
Reference in New Issue
Block a user