diff --git a/docker-setup.sh.tmpl b/docker-setup.sh.tmpl index a3a626c..54f4d5e 100644 --- a/docker-setup.sh.tmpl +++ b/docker-setup.sh.tmpl @@ -14,15 +14,11 @@ mkdir -p ${GITEA_CUSTOM} && chmod 0500 ${GITEA_CUSTOM} mkdir -p ${GITEA_TEMP} && chmod 0700 ${GITEA_TEMP} if [ ! -w ${GITEA_TEMP} ]; then echo "${GITEA_TEMP} is not writable"; exit 1; fi -# Seed app.ini into the WRITABLE config volume (/etc/gitea) from the read-only swarm config -# (mounted at /etc/gitea/app.ini.init). Gitea must be able to PERSIST settings to app.ini — e.g. -# Gitea 1.24+ (re)generates and SAVES the [oauth2] JWT_SECRET at LoadCommonSettings; with app.ini -# mounted directly as a read-only swarm config this fails fatally ("open /etc/gitea/app.ini: -# read-only file system") on (re)deploy. Seed when MISSING OR EMPTY (`! -s`, not `! -f`): upgrading -# from a release that mounted app.ini directly as a swarm config leaves a 0-byte placeholder at -# /etc/gitea/app.ini in the reattached config volume — `! -f` would treat that as "present" and skip, -# leaving Gitea to boot the install wizard on an empty config. A non-empty app.ini (Gitea's persisted -# state) is preserved across restarts; truncate/delete it to force a re-seed from the rendered config. +# Seed app.ini into the writable config volume (/etc/gitea) from the read-only swarm config +# (mounted at app.ini.init). Gitea persists settings back to app.ini — e.g. it saves the +# [oauth2] JWT_SECRET on boot since 1.24 — which crashes if app.ini is the read-only mount itself. +# Test `! -s` (empty), not `! -f` (missing): upgrades from the old direct-mount layout leave a +# 0-byte app.ini placeholder that still needs seeding. A non-empty app.ini is left untouched. if [ ! -s /etc/gitea/app.ini ]; then cp /etc/gitea/app.ini.init /etc/gitea/app.ini fi