From ae6dfea2c9686be1345f5df971f593651308a883 Mon Sep 17 00:00:00 2001 From: jochen Date: Fri, 25 Sep 2026 17:07:58 +0200 Subject: [PATCH] gitea: listens its real internal ssh port (22), not 2222 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit 2222 never meant anything — no container of gitea's publishes it, the software never listens on it, and nobody could say where it came from. The container's real internal sshd is 22 (gitea's own default, unmodified — every other module's listens.port already means the container's real internal port, this one didn't). ports now declares 222:22 directly: 222 is the real, fixed, always-known public git-ssh port, so it needs no per-node setting to reach — unlike an arbitrary auto-assigned port, this one has external consumers who already know the number. --- modules/gitea/module.json | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/modules/gitea/module.json b/modules/gitea/module.json index a5bb2ce..a6ef32f 100644 --- a/modules/gitea/module.json +++ b/modules/gitea/module.json @@ -42,10 +42,10 @@ "why": "the forge, over http" }, { - "port": 2222, + "port": 22, "protocol": "tcp", "from": "mesh", - "why": "git over ssh. Not 22: the machine's own daemon holds that, and a module does not take it" + "why": "git over ssh, gitea's own unmodified sshd. Published on the machine's own side at 222, the mesh's fixed public convention — not 22, which the machine's own daemon holds and a module does not take" } ], "serves": { @@ -118,7 +118,7 @@ ], "ports": [ "3000", - "22" + "222:22" ], "volumes": [ "/services/gitea/gitea:/data" -- 2.54.0