fix(config): make app.ini writable so Gitea can persist secrets on (re)deploy

Gitea 1.24+ (re)generates and SAVES the [oauth2] JWT secret to /etc/gitea/app.ini at
LoadCommonSettings. With app.ini mounted directly as a read-only swarm config this fails fatally
(open /etc/gitea/app.ini: read-only file system) on a warm reattach/redeploy, crash-looping the
container before any DB migration. Mount the rendered config at /etc/gitea/app.ini.init (read-only)
and seed it once into the writable config volume via docker-setup.sh, so Gitea owns a writable
/etc/gitea/app.ini. Bumps DOCKER_SETUP_SH_VERSION so the new entrypoint actually deploys.
This commit is contained in:
2026-06-18 01:52:58 +00:00
parent ce4de9e645
commit 1a098452f4
3 changed files with 13 additions and 2 deletions
+1 -1
View File
@@ -1,5 +1,5 @@
export APP_INI_VERSION=v22 export APP_INI_VERSION=v22
export DOCKER_SETUP_SH_VERSION=v1 export DOCKER_SETUP_SH_VERSION=v2
export PG_BACKUP_VERSION=v1 export PG_BACKUP_VERSION=v1
abra_backup_app() { abra_backup_app() {
+1 -1
View File
@@ -6,7 +6,7 @@ services:
image: "gitea/gitea:1.24.2-rootless" image: "gitea/gitea:1.24.2-rootless"
configs: configs:
- source: app_ini - source: app_ini
target: /etc/gitea/app.ini target: /etc/gitea/app.ini.init
- source: docker_setup_sh - source: docker_setup_sh
target: /usr/local/bin/docker-setup.sh target: /usr/local/bin/docker-setup.sh
mode: 0555 mode: 0555
+11
View File
@@ -13,3 +13,14 @@ mkdir -p ${GITEA_CUSTOM} && chmod 0500 ${GITEA_CUSTOM}
# Prepare temp folder # Prepare temp folder
mkdir -p ${GITEA_TEMP} && chmod 0700 ${GITEA_TEMP} mkdir -p ${GITEA_TEMP} && chmod 0700 ${GITEA_TEMP}
if [ ! -w ${GITEA_TEMP} ]; then echo "${GITEA_TEMP} is not writable"; exit 1; fi if [ ! -w ${GITEA_TEMP} ]; then echo "${GITEA_TEMP} is not writable"; exit 1; fi
# Seed app.ini into the WRITABLE config volume (/etc/gitea) from the read-only swarm config
# (mounted at /etc/gitea/app.ini.init). Gitea must be able to PERSIST settings to app.ini — e.g.
# Gitea 1.24+ (re)generates and SAVES the [oauth2] JWT_SECRET at LoadCommonSettings; with app.ini
# mounted directly as a read-only swarm config this fails fatally ("open /etc/gitea/app.ini:
# read-only file system") on (re)deploy. Seed-once preserves any runtime-persisted state across
# restarts/upgrades; delete /etc/gitea/app.ini to re-seed from the recipe's rendered config.
if [ ! -f /etc/gitea/app.ini ]; then
cp /etc/gitea/app.ini.init /etc/gitea/app.ini
fi
chmod 0600 /etc/gitea/app.ini 2>/dev/null || true