Compare commits

..
3 changed files with 13 additions and 3 deletions
+1 -1
View File
@@ -1,5 +1,5 @@
export APP_INI_VERSION=v22 export APP_INI_VERSION=v22
export DOCKER_SETUP_SH_VERSION=v1 export DOCKER_SETUP_SH_VERSION=v3
export PG_BACKUP_VERSION=v1 export PG_BACKUP_VERSION=v1
abra_backup_app() { abra_backup_app() {
+2 -2
View File
@@ -6,7 +6,7 @@ services:
image: "gitea/gitea:1.26.2-rootless" image: "gitea/gitea:1.26.2-rootless"
configs: configs:
- source: app_ini - source: app_ini
target: /etc/gitea/app.ini target: /etc/gitea/app.ini.init
- source: docker_setup_sh - source: docker_setup_sh
target: /usr/local/bin/docker-setup.sh target: /usr/local/bin/docker-setup.sh
mode: 0555 mode: 0555
@@ -88,7 +88,7 @@ services:
- "traefik.http.middlewares.${STACK_NAME}_cors.headers.accesscontrolalloworiginlist=https://${GITEA_CORS_ALLOW_DOMAIN}" - "traefik.http.middlewares.${STACK_NAME}_cors.headers.accesscontrolalloworiginlist=https://${GITEA_CORS_ALLOW_DOMAIN}"
- "traefik.http.middlewares.${STACK_NAME}_cors.headers.accesscontrolmaxage=100" - "traefik.http.middlewares.${STACK_NAME}_cors.headers.accesscontrolmaxage=100"
- "traefik.http.middlewares.${STACK_NAME}_cors.headers.addvaryheader=true" - "traefik.http.middlewares.${STACK_NAME}_cors.headers.addvaryheader=true"
- coop-cloud.${STACK_NAME}.version=3.6.1+1.26.2-rootless - coop-cloud.${STACK_NAME}.version=3.6.0+1.24.2-rootless
networks: networks:
+10
View File
@@ -13,3 +13,13 @@ mkdir -p ${GITEA_CUSTOM} && chmod 0500 ${GITEA_CUSTOM}
# Prepare temp folder # Prepare temp folder
mkdir -p ${GITEA_TEMP} && chmod 0700 ${GITEA_TEMP} mkdir -p ${GITEA_TEMP} && chmod 0700 ${GITEA_TEMP}
if [ ! -w ${GITEA_TEMP} ]; then echo "${GITEA_TEMP} is not writable"; exit 1; fi if [ ! -w ${GITEA_TEMP} ]; then echo "${GITEA_TEMP} is not writable"; exit 1; fi
# Seed app.ini into the writable config volume (/etc/gitea) from the read-only swarm config
# (mounted at app.ini.init). Gitea persists settings back to app.ini — e.g. it saves the
# [oauth2] JWT_SECRET on boot since 1.24 — which crashes if app.ini is the read-only mount itself.
# Test `! -s` (empty), not `! -f` (missing): upgrades from the old direct-mount layout leave a
# 0-byte app.ini placeholder that still needs seeding. A non-empty app.ini is left untouched.
if [ ! -s /etc/gitea/app.ini ]; then
cp /etc/gitea/app.ini.init /etc/gitea/app.ini
fi
chmod 0600 /etc/gitea/app.ini 2>/dev/null || true