Compare commits

...
Author SHA1 Message Date
autonomic-bot 478d7a3137 chore: merge upstream main (BREAKING CHANGE: remove forgejo) into upgrade branch
cc-ci/testme cc-ci: success
The upgrade branch was cut before upstream's forgejo removal, so its tree (and the
!testme run that verified it) did not reflect what would actually deploy. Merging
upstream in brings the branch current; the gitea 1.27.1-rootless bump — which fixes
CVE-2026-60004 and CVE-2026-59774 (both CVSS 9.8) — is unchanged.
2026-08-10 16:24:51 +00:00
autonomic-bot 3087f09180 chore: upgrade gitea to 1.27.1-rootless
cc-ci/testme cc-ci: success
2026-08-03 23:48:26 +00:00
autonomic-bot 482e152b23 chore: upgrade gitea to 1.27.0-rootless
cc-ci/testme cc-ci: success
2026-07-24 04:07:59 +00:00
autonomic-bot ade6db5133 chore: upgrade gitea to 1.26.4-rootless
cc-ci/testme cc-ci: success
2026-07-13 20:12:13 +00:00
notplants 37ebd22ba4 Merge pull request 'BREAKING CHANGE: remove forgejo' (#58) from remove-forgejo into master
Reviewed-on: https://git.coopcloud.tech/coop-cloud/gitea/pulls/58
Reviewed-by: 3wordchant <3+3wordchant@noreply.git.coopcloud.tech>
2026-07-07 21:11:52 +00:00
notplants 4c330eb4a4 Merge branch 'master' into remove-forgejo 2026-07-07 21:11:31 +00:00
f 57e224c5b0 doc: release notes 2026-06-25 16:48:12 -03:00
autonomic-bot 7561bed6e1 chore: upgrade gitea to 1.26.4-rootless
cc-ci/testme cc-ci: success
2026-06-22 21:20:16 +00:00
notplants 0ab323d24a Merge pull request 'chore: upgrade gitea to 1.26.2-rootless, postgres to 15.18' (#60) from upgrade-273d214 into master
Reviewed-on: https://git.coopcloud.tech/coop-cloud/gitea/pulls/60
2026-06-22 19:41:31 +00:00
notplants 2f7f1b6bfe chore: upgrade gitea to 1.26.2-rootless, postgres to 15.18
cc-ci/testme cc-ci: success
2026-06-22 19:29:08 +00:00
f 6a0339d3f2 BREAKING CHANGE: remove forgejo 2026-06-16 18:33:21 -03:00
notplants ce4de9e645 Merge pull request 'feat: support Git LFS on plain gitea' (#57) from lfs into master
Reviewed-on: https://git.coopcloud.tech/coop-cloud/gitea/pulls/57
Reviewed-by: ammaratef45 <ammaratef45@proton.me>
2026-06-15 21:08:52 +00:00
notplants 357926f26e feat: support Git LFS on plain gitea
cc-ci/testme cc-ci: success
Add an opt-in compose.lfs.yml that mounts the lfs_jwt_secret secret and
enables GITEA_LFS_START_SERVER for plain gitea (forgejo already bundles
LFS). Emit LFS_JWT_SECRET in app.ini whenever the LFS server is on so the
JWT secret is stable across redeploys instead of being regenerated on
every restart (app.ini is a read-only config mount).

Bump version 3.5.2 -> 3.6.0.
2026-06-15 19:33:03 +00:00
notplants e6a1cc79e9 Merge pull request 'change deploy logic to stop-first instead of start-first' (#53) from stop-first into master
Reviewed-on: https://git.coopcloud.tech/coop-cloud/gitea/pulls/53
2026-06-04 16:47:00 +00:00
notplants 34dd04ac99 Merge branch 'master' into stop-first 2026-06-04 16:46:28 +00:00
ammaratef45 6aa52c1e73 fix abra command in documentation 2026-05-19 03:43:34 +00:00
notplants e7c4999f78 bump version number to 3.5.3 2026-05-18 12:59:07 -04:00
notplants c63e1cdd04 change deploy logic to stop-first instead of start-first 2026-05-18 12:51:20 -04:00
3wc db92e97071 docs: Fix broken README links, appease markdown linter 2026-01-08 21:29:48 -05:00
p4u1 d86d742ed1 Adds missing access controll headers 2025-10-27 18:29:54 +01:00
f 989294173e chore: publish 3.5.2+1.24.2-rootless release 2025-09-01 07:44:54 -03:00
f 4e789bf977 fix: forgejo 12.0.2 2025-09-01 07:38:52 -03:00
f 485fa32512 chore: publish 3.5.1+1.24.2-rootless release 2025-07-26 01:35:54 -03:00
f 54fd30f38a fix: forgejo 12.0.1 2025-07-26 01:33:48 -03:00
f 6d586f6ad3 chore: publish 3.5.0+1.24.2-rootless release 2025-07-19 11:42:35 -03:00
f 8c9793ace9 feat: upgrade to forgejo 12 2025-07-19 11:41:41 -03:00
3wordchant 4cfc2ac2e0 chore: publish 3.4.0+1.24.2-rootless release 2025-06-25 18:34:34 +01:00
f ca4733a0b0 fix: upgrade forgejo to 11.0.2 2025-06-19 10:26:08 -03:00
fauno 5a65ef04c5 Merge pull request 'feat: forgejo 11' (#45) from forgejo into master
Reviewed-on: https://git.coopcloud.tech/coop-cloud/gitea/pulls/45
2025-06-19 13:21:57 +00:00
f 94af9cea9e feat: forgejo 11 2025-05-15 14:36:29 -03:00
8 changed files with 39 additions and 20 deletions
+3 -2
View File
@@ -8,8 +8,9 @@ COMPOSE_FILE="$COMPOSE_FILE:compose.mariadb.yml"
# COMPOSE_FILE="$COMPOSE_FILE:compose.sqlite3.yml" # COMPOSE_FILE="$COMPOSE_FILE:compose.sqlite3.yml"
# COMPOSE_FILE="$COMPOSE_FILE:compose.postgres.yml" # COMPOSE_FILE="$COMPOSE_FILE:compose.postgres.yml"
# Enable to use forgejo instead of gitea # Enable Git LFS on plain gitea (not needed with forgejo, which bundles it).
# COMPOSE_FILE="$COMPOSE_FILE:compose.forgejo.yml" # Mounts the lfs_jwt_secret secret and sets GITEA_LFS_START_SERVER=true.
# COMPOSE_FILE="$COMPOSE_FILE:compose.lfs.yml"
# SECRET_LFS_JWT_SECRET_VERSION=v1 # length=43 # SECRET_LFS_JWT_SECRET_VERSION=v1 # length=43
GITEA_DOMAIN=git.example.com GITEA_DOMAIN=git.example.com
+19 -7
View File
@@ -15,7 +15,7 @@
## Basic usage ## Basic usage
1. Set up Docker Swarm and [`abra`][abra] 1. [Set up Docker Swarm and `abra`][operators-tutorial]
2. Deploy [`coop-cloud/traefik`][cc-traefik] 2. Deploy [`coop-cloud/traefik`][cc-traefik]
3. `abra app new gitea --secrets` (optionally with `--pass` if you'd like 3. `abra app new gitea --secrets` (optionally with `--pass` if you'd like
to save secrets in `pass`) to save secrets in `pass`)
@@ -23,12 +23,15 @@
your Docker swarm box your Docker swarm box
5. `abra app deploy YOURAPPDOMAIN` 5. `abra app deploy YOURAPPDOMAIN`
[operators-tutorial]: https://docs.coopcloud.tech/operators/tutorial/
[cc-traefik]: https://git.coopcloud.tech/coop-cloud/traefik/
## Create first user ## Create first user
Run Run
```bash ```bash
abra app run YOURAPPNAME app gitea -c /etc/gitea/app.ini admin user create --username USERNAME --admin --random-password --email EMAIL abra app run YOURAPPNAME app -- gitea -c /etc/gitea/app.ini admin user create --username USERNAME --admin --random-password --email EMAIL
``` ```
See the [Gitea command-line documentation](https://docs.gitea.io/en-us/command-line/) for more options. Make sure not to forget the `-c /etc/gitea/app.ini`. See the [Gitea command-line documentation](https://docs.gitea.io/en-us/command-line/) for more options. Make sure not to forget the `-c /etc/gitea/app.ini`.
@@ -36,25 +39,34 @@ See the [Gitea command-line documentation](https://docs.gitea.io/en-us/command-l
## Enable SSH ## Enable SSH
You most certainly want to be able to access your repository over SSH. To do so, make sure you uncomment the right lines in the configuration for `traefik`. You most certainly want to be able to access your repository over SSH. To do so, make sure you uncomment the right lines in the configuration for `traefik`.
```
```sh
abra app config YOURTRAEFIKAPP abra app config YOURTRAEFIKAPP
``` ```
There uncomment or add these lines: There uncomment or add these lines:
```
```sh
GITEA_SSH_ENABLED=1 GITEA_SSH_ENABLED=1
COMPOSE_FILE="compose.yml:compose.gitea.yml" COMPOSE_FILE="compose.yml:compose.gitea.yml"
``` ```
Then redeploy traefik: Then redeploy traefik:
```
```sh
abra app undeploy YOURTRAEFIKAPP abra app undeploy YOURTRAEFIKAPP
abra app deploy YOURTRAEFIKAPP abra app deploy YOURTRAEFIKAPP
``` ```
You might need to wait a bit. To check if it worked, you can run You might need to wait a bit. To check if it worked, you can run
```
```sh
telnet my.gitea.example.com 2222 telnet my.gitea.example.com 2222
``` ```
Once you have added a public SSH key, you can check that you can connect to your gitea server with Once you have added a public SSH key, you can check that you can connect to your gitea server with
```
```sh
ssh -T -p 2222 git@my.gitea.example.com ssh -T -p 2222 git@my.gitea.example.com
``` ```
+1 -1
View File
@@ -1,4 +1,4 @@
export APP_INI_VERSION=v21 export APP_INI_VERSION=v22
export DOCKER_SETUP_SH_VERSION=v1 export DOCKER_SETUP_SH_VERSION=v1
export PG_BACKUP_VERSION=v1 export PG_BACKUP_VERSION=v1
+1 -1
View File
@@ -61,7 +61,7 @@ SSH_LISTEN_PORT = {{ env "GITEA_SSH_PORT" }}
SSH_PORT = {{ env "GITEA_SSH_PORT" }} SSH_PORT = {{ env "GITEA_SSH_PORT" }}
START_SSH_SERVER = true START_SSH_SERVER = true
LFS_START_SERVER = {{ env "GITEA_LFS_START_SERVER" }} LFS_START_SERVER = {{ env "GITEA_LFS_START_SERVER" }}
{{ if eq (env "FORGE") "forgejo" }} {{ if (eq (env "GITEA_LFS_START_SERVER") "true") }}
LFS_JWT_SECRET = {{ secret "lfs_jwt_secret" }} LFS_JWT_SECRET = {{ secret "lfs_jwt_secret" }}
{{ end }} {{ end }}
+3 -3
View File
@@ -1,12 +1,12 @@
version: '3.8' version: "3.8"
services: services:
app: app:
image: codeberg.org/forgejo/forgejo:10.0.1-rootless
environment: environment:
- FORGE=forgejo - GITEA_LFS_START_SERVER=true
secrets: secrets:
- lfs_jwt_secret - lfs_jwt_secret
secrets: secrets:
lfs_jwt_secret: lfs_jwt_secret:
name: ${STACK_NAME}_lfs_jwt_secret_${SECRET_LFS_JWT_SECRET_VERSION} name: ${STACK_NAME}_lfs_jwt_secret_${SECRET_LFS_JWT_SECRET_VERSION}
+1 -1
View File
@@ -10,7 +10,7 @@ services:
secrets: secrets:
- db_password - db_password
db: db:
image: postgres:15.10 image: postgres:15.18
deploy: deploy:
labels: labels:
backupbot.backup.pre-hook: "/pg_backup.sh backup" backupbot.backup.pre-hook: "/pg_backup.sh backup"
+4 -4
View File
@@ -3,7 +3,7 @@ version: "3.8"
services: services:
app: app:
image: "gitea/gitea:1.23.8-rootless" image: "gitea/gitea:1.27.1-rootless"
configs: configs:
- source: app_ini - source: app_ini
target: /etc/gitea/app.ini target: /etc/gitea/app.ini
@@ -15,7 +15,6 @@ services:
- jwt_secret - jwt_secret
- secret_key - secret_key
environment: environment:
- FORGE=gitea
- GITEA_ALLOW_ONLY_EXTERNAL_REGISTRATION - GITEA_ALLOW_ONLY_EXTERNAL_REGISTRATION
- GITEA_APP_NAME - GITEA_APP_NAME
- GITEA_AUTO_WATCH_NEW_REPOS - GITEA_AUTO_WATCH_NEW_REPOS
@@ -71,7 +70,7 @@ services:
deploy: deploy:
update_config: update_config:
failure_action: rollback failure_action: rollback
order: start-first order: stop-first
labels: labels:
- "backupbot.backup=${ENABLE_BACKUPS:-true}" - "backupbot.backup=${ENABLE_BACKUPS:-true}"
- "traefik.enable=true" - "traefik.enable=true"
@@ -84,10 +83,11 @@ services:
- "traefik.tcp.services.${STACK_NAME}-ssh.loadbalancer.server.port=${GITEA_SSH_PORT}" - "traefik.tcp.services.${STACK_NAME}-ssh.loadbalancer.server.port=${GITEA_SSH_PORT}"
- "traefik.http.routers.${STACK_NAME}.middlewares=${STACK_NAME}_cors" - "traefik.http.routers.${STACK_NAME}.middlewares=${STACK_NAME}_cors"
- "traefik.http.middlewares.${STACK_NAME}_cors.headers.accesscontrolallowmethods=GET,OPTIONS,PUT" - "traefik.http.middlewares.${STACK_NAME}_cors.headers.accesscontrolallowmethods=GET,OPTIONS,PUT"
- "traefik.http.middlewares.${STACK_NAME}_cors.headers.accesscontrolallowheaders=content-type,authorization"
- "traefik.http.middlewares.${STACK_NAME}_cors.headers.accesscontrolalloworiginlist=https://${GITEA_CORS_ALLOW_DOMAIN}" - "traefik.http.middlewares.${STACK_NAME}_cors.headers.accesscontrolalloworiginlist=https://${GITEA_CORS_ALLOW_DOMAIN}"
- "traefik.http.middlewares.${STACK_NAME}_cors.headers.accesscontrolmaxage=100" - "traefik.http.middlewares.${STACK_NAME}_cors.headers.accesscontrolmaxage=100"
- "traefik.http.middlewares.${STACK_NAME}_cors.headers.addvaryheader=true" - "traefik.http.middlewares.${STACK_NAME}_cors.headers.addvaryheader=true"
- coop-cloud.${STACK_NAME}.version=3.3.1+1.23.8-rootless - coop-cloud.${STACK_NAME}.version=3.6.0+1.24.2-rootless
networks: networks:
+6
View File
@@ -0,0 +1,6 @@
Forgejo support has been moved to its own recipe. Make the move by:
* Getting the recipe locally with `abra recipe fetch forgejo`
* Changing the recipe's TYPE with `abra application config FORGEJO_DOMAIN`
* Redeploy the app with `abra application undeploy` and `abra
application deploy`