{ "module": "gitea", "version": "1", "requires": [ "postgres-database", "route", "secret" ], "contributes": { "postgres-database": { "name": "gitea" }, "route": { "web": { "label": "git", "endpoint": "web" }, "internal-api-refused": { "label": "git", "path": "/api/internal", "deny": true, "priority": 100000 } } }, "binds": { "postgres-database": "${dir:state}/database.json", "route": "${dir:state}/route.json" }, "secrets": { "postgres-database": "${dir:state}/database.secret", "secret": { "internal-token": "${dir:state}/internal-token.secret", "admin": "${dir:state}/admin.secret" } }, "capabilities": [ "container-runtime" ], "emits": [ "repo.created", "issue.opened", "pull.merged" ], "listens": [ { "name": "web", "port": 3000, "protocol": "tcp", "from": "mesh", "why": "the forge, over http" }, { "name": "ssh", "port": 22, "protocol": "tcp", "from": "mesh", "why": "git over ssh, gitea's own unmodified sshd. Published on the machine's own side at 222, the mesh's fixed public convention \u2014 not 22, which the machine's own daemon holds and a module does not take" } ], "serves": { "npm-package-registry": { "scheme": "http", "port": 3000, "npm-path": "/api/packages/novox/npm/" }, "git": { "scheme": "http", "port": 3000 } }, "receives": { "npm-package-registry": "${dir:grants}/npm.json" }, "grants": { "npm-package-registry": "${dir:grants}" }, "claims": [ { "name": "npm-package-registry", "scope": "mesh" }, { "name": "git", "scope": "mesh" } ], "resources": [ { "id": "mesh-state", "type": "directory", "mode": "0700", "place": "mesh" }, { "id": "runtime-state", "type": "directory", "path": "${dir:mesh-state}/state", "mode": "0700" }, { "id": "state", "type": "directory", "mode": "0700", "place": "." }, { "id": "grants", "type": "directory", "mode": "0700" }, { "id": "server-env", "type": "file", "path": "${dir:state}/server.env", "mode": "0600", "content": "GITEA__security__INTERNAL_TOKEN=${secret:internal-token}\nGITEA__database__DB_TYPE=postgres\nGITEA__database__HOST=${bound:postgres-database:at}:${bound:postgres-database:port}\nGITEA__database__NAME=${bound:postgres-database:as}\nGITEA__database__USER=${bound:postgres-database:as}\nGITEA__database__PASSWD=${secret:postgres-database}\n" }, { "id": "data", "type": "directory", "mode": "0700", "owner": "1000:1000" }, { "id": "server", "type": "container", "name": "gitea", "image": "gitea/gitea@sha256:87a67ee09d3ae0d1df5fda5dcda3e2a1f9236a45b0a59025d6e00e46adc43bef", "env": { "DB_TYPE": "postgres", "USER_UID": "1000", "USER_GID": "1000" }, "env-file": [ "${dir:state}/server.env" ], "ports": [ "3000", "222:22" ], "volumes": [ "${dir:data}:/data" ], "secrets-in-environment": "gitea honours GITEA__database__PASSWD__FILE and GITEA__security__INTERNAL_TOKEN__FILE; convertible, awaiting a bed that proves it", "logging": "journald" }, { "id": "admin-bootstrap", "type": "container", "name": "mesh-gitea-admin", "image": "gitea/gitea@sha256:87a67ee09d3ae0d1df5fda5dcda3e2a1f9236a45b0a59025d6e00e46adc43bef", "run-once": true, "env": { "USER_UID": "1000", "USER_GID": "1000", "MESH_GITEA_ADMIN_USER": "mesh-admin" }, "env-file": [ "${dir:state}/server.env" ], "volumes": [ "${dir:data}:/data", "${dir:state}/admin.secret:/run/secrets/admin:ro" ], "args": [ "/bin/sh", "-c", "su-exec git gitea admin user create --admin --username \"$MESH_GITEA_ADMIN_USER\" --email mesh-admin@localhost --password \"$(cat /run/secrets/admin)\" --must-change-password=false || true" ], "secrets-in-environment": "gitea honours GITEA__database__PASSWD__FILE and GITEA__security__INTERNAL_TOKEN__FILE; convertible, awaiting a bed that proves it" }, { "id": "runtime-config", "type": "file", "path": "${dir:mesh-state}/config.json", "mode": "0600", "content": "{}\n", "merge": "json" } ], "provides": [ { "name": "npm-package-registry", "scope": "mesh" }, { "name": "git", "scope": "mesh" } ], "build": { "artifacts": [ { "name": "code", "kind": "bundle", "language": "typescript", "entrypoints": [ "index.js", "tools/index.js", "provisioner/index.js" ], "loads": [ "index.js", "tools/index.js", "provisioner/index.js" ], "env": { "MESH_GITEA_URL": "http://127.0.0.1:${port:3000}", "MESH_GITEA_CONFIG_FILE": "${dir:mesh-state}/config.json", "MESH_GITEA_ADMIN_USER": "mesh-admin", "MESH_GITEA_ADMIN_PASSWORD_FILE": "${dir:state}/admin.secret", "MESH_GITEA_STATE_DIR": "${dir:runtime-state}", "MESH_RECEIVES": "${dir:grants}/npm.json" } } ] }, "jails": [ { "name": "gitea", "failregex": "^.*Failed authentication attempt for .* from (?::\\d+)?\\s*$\n ^.*Invalid user .* from port \\d+\\s*$\n ^.*User \\S+ from not allowed because .*$", "jail": "backend = systemd\njournalmatch = CONTAINER_NAME=gitea\nport = http,https,222\nmaxretry = 3\nfindtime = 1d\nbantime = 1d" } ] }