gitea: listens its real internal ssh port (22), not 2222
2222 never meant anything — no container of gitea's publishes it, the software never listens on it, and nobody could say where it came from. The container's real internal sshd is 22 (gitea's own default, unmodified — every other module's listens.port already means the container's real internal port, this one didn't). ports now declares 222:22 directly: 222 is the real, fixed, always-known public git-ssh port, so it needs no per-node setting to reach — unlike an arbitrary auto-assigned port, this one has external consumers who already know the number.
This commit is contained in:
@@ -42,10 +42,10 @@
|
|||||||
"why": "the forge, over http"
|
"why": "the forge, over http"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"port": 2222,
|
"port": 22,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
"why": "git over ssh. Not 22: the machine's own daemon holds that, and a module does not take it"
|
"why": "git over ssh, gitea's own unmodified sshd. Published on the machine's own side at 222, the mesh's fixed public convention — not 22, which the machine's own daemon holds and a module does not take"
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"serves": {
|
"serves": {
|
||||||
@@ -118,7 +118,7 @@
|
|||||||
],
|
],
|
||||||
"ports": [
|
"ports": [
|
||||||
"3000",
|
"3000",
|
||||||
"22"
|
"222:22"
|
||||||
],
|
],
|
||||||
"volumes": [
|
"volumes": [
|
||||||
"/services/gitea/gitea:/data"
|
"/services/gitea/gitea:/data"
|
||||||
|
|||||||
Reference in New Issue
Block a user