{ "module": "gitea", "version": "1", "requires": [ "postgres-database", "route" ], "contributes": { "postgres-database": { "name": "gitea" }, "route": { "label": "git", "port": 3000 } }, "binds": { "postgres-database": "/var/lib/gitea/database.json", "route": "/var/lib/gitea/route.json" }, "secrets": { "postgres-database": "/var/lib/gitea/database.secret" }, "capabilities": [ "container-runtime" ], "emits": [ "module.gitea.repo.created", "module.gitea.issue.opened", "module.gitea.pull.merged" ], "listens": [ { "port": 3000, "protocol": "tcp", "from": "mesh", "why": "the forge, over http" }, { "port": 2222, "protocol": "tcp", "from": "mesh", "why": "git over ssh. Not 22: the machine's own daemon holds that, and a module does not take it" } ], "serves": { "package-registry": { "scheme": "http", "port": 3000, "npm-path": "/api/packages/novox/npm/" } }, "receives": { "package-registry": "/var/lib/gitea/grants/mesh.json" }, "grants": { "package-registry": "/var/lib/gitea/grants" }, "own-secrets": { "internal-token": "/var/lib/gitea/internal-token.secret", "admin": "/var/lib/gitea/admin.secret", "broker": "/var/lib/mesh/gitea/broker" }, "resources": [ { "id": "mesh-state", "type": "directory", "path": "/var/lib/mesh/gitea", "mode": "0700" }, { "id": "state", "type": "directory", "path": "/var/lib/gitea", "mode": "0700" }, { "id": "grants", "type": "directory", "path": "/var/lib/gitea/grants", "mode": "0700" }, { "id": "server-env", "type": "file", "path": "/var/lib/gitea/server.env", "mode": "0600", "content": "GITEA__security__INTERNAL_TOKEN=${secret:internal-token}\nGITEA__database__DB_TYPE=postgres\nGITEA__database__HOST=${bound:postgres-database:at}:${bound:postgres-database:port}\nGITEA__database__NAME=${bound:postgres-database:as}\nGITEA__database__USER=${bound:postgres-database:as}\nGITEA__database__PASSWD=${secret:postgres-database}\n" }, { "id": "data", "type": "directory", "path": "/services/gitea/gitea", "mode": "0700", "owner": "1000:1000" }, { "id": "server", "type": "container", "name": "gitea", "image": "gitea/gitea@sha256:dfc61e347c8b582df918f4556401bf2cecdfbdb56c5282ae9488dd76fca3e41c", "env": { "DB_TYPE": "postgres", "USER_UID": "1000", "USER_GID": "1000" }, "env-file": [ "/var/lib/gitea/server.env" ], "ports": [ "3000", "2222:22" ], "volumes": [ "/services/gitea/gitea:/data" ], "secrets-in-environment": "gitea honours GITEA__database__PASSWD__FILE and GITEA__security__INTERNAL_TOKEN__FILE; convertible, awaiting a bed that proves it" }, { "id": "admin-bootstrap", "type": "container", "name": "mesh-gitea-admin", "image": "gitea/gitea@sha256:dfc61e347c8b582df918f4556401bf2cecdfbdb56c5282ae9488dd76fca3e41c", "run-once": true, "env": { "USER_UID": "1000", "USER_GID": "1000", "MESH_GITEA_ADMIN_USER": "mesh-admin" }, "env-file": [ "/var/lib/gitea/server.env" ], "volumes": [ "/services/gitea/gitea:/data", "/var/lib/gitea/admin.secret:/run/secrets/admin:ro" ], "args": [ "/bin/sh", "-c", "su-exec git gitea admin user create --admin --username \"$MESH_GITEA_ADMIN_USER\" --email mesh-admin@localhost --password \"$(cat /run/secrets/admin)\" --must-change-password=false || true" ], "secrets-in-environment": "gitea honours GITEA__database__PASSWD__FILE and GITEA__security__INTERNAL_TOKEN__FILE; convertible, awaiting a bed that proves it" }, { "id": "runtime-config", "type": "file", "path": "/var/lib/mesh/gitea/config.json", "mode": "0600", "content": "{}\n", "merge": "json" }, { "id": "runtime", "type": "container", "name": "mesh-gitea", "network": "host", "volumes": [ "/var/lib/mesh/gitea/broker:/run/secrets/broker:ro", "/var/lib/mesh/gitea/config.json:/run/config/config.json:ro", "/var/lib/gitea/grants:/var/lib/gitea/grants:ro", "/var/lib/gitea/admin.secret:/run/secrets/admin:ro" ], "env": { "MESH_BROKER_FILE": "/run/secrets/broker", "MESH_GITEA_URL": "http://127.0.0.1:3000", "MESH_GITEA_CONFIG_FILE": "/run/config/config.json", "MESH_GITEA_ADMIN_USER": "mesh-admin", "MESH_GITEA_ADMIN_PASSWORD_FILE": "/run/secrets/admin", "MESH_RECEIVES": "/var/lib/gitea/grants/mesh.json" }, "artifact": "runtime", "restart-on": [ "runtime-config" ] } ], "provides": [ { "name": "package-registry", "scope": "mesh" } ], "build": { "on": [ { "arg": "BUILD_BASE", "module": "mesh-tools", "artifact": "build" }, { "arg": "RUNTIME_BASE", "module": "mesh-tools", "artifact": "runtime" } ], "artifacts": [ { "name": "runtime", "kind": "image", "from": "Dockerfile" } ] } }