The forge's announcer announces each new head of an open pull request as pull.updated, once, and marks the head pending; the controller asks the build seat to check it against every machine of the mesh's facts, and says the verdict as checked, which the forge's holder sets as the head commit's status mesh/merge-gate - an error never as a success - with the check's own account as a comment when it is not a pass. merge-check.sh is the catalogue's check: every manifest through the running controller's module check and merge gate, and the Go tests of each module the change touches, a module whose dependencies cannot be fetched said as not tested.
252 lines
6.4 KiB
JSON
252 lines
6.4 KiB
JSON
{
|
|
"module": "gitea",
|
|
"version": "1",
|
|
"requires": [
|
|
"postgres-database",
|
|
"route",
|
|
"secret"
|
|
],
|
|
"contributes": {
|
|
"postgres-database": {
|
|
"name": "gitea"
|
|
},
|
|
"route": {
|
|
"web": {
|
|
"label": "git",
|
|
"endpoint": "web"
|
|
},
|
|
"internal-api-refused": {
|
|
"label": "git",
|
|
"path": "/api/internal",
|
|
"deny": true,
|
|
"priority": 100000
|
|
}
|
|
}
|
|
},
|
|
"binds": {
|
|
"postgres-database": "${dir:state}/database.json",
|
|
"route": "${dir:state}/route.json"
|
|
},
|
|
"secrets": {
|
|
"postgres-database": "${dir:state}/database.secret",
|
|
"secret": {
|
|
"internal-token": "${dir:state}/internal-token.secret",
|
|
"admin": "${dir:state}/admin.secret"
|
|
}
|
|
},
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"emits": [
|
|
"repo.created",
|
|
"issue.opened",
|
|
"pull.merged",
|
|
"pull.updated"
|
|
],
|
|
"consumes": [
|
|
"mesh-controller.checked"
|
|
],
|
|
"listens": [
|
|
{
|
|
"name": "web",
|
|
"port": 3000,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "the forge, over http"
|
|
},
|
|
{
|
|
"name": "ssh",
|
|
"port": 22,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "git over ssh, gitea's own unmodified sshd. Published on the machine's own side at 222, the mesh's fixed public convention \u2014 not 22, which the machine's own daemon holds and a module does not take"
|
|
}
|
|
],
|
|
"serves": {
|
|
"npm-package-registry": {
|
|
"scheme": "http",
|
|
"port": 3000,
|
|
"npm-path": "/api/packages/novox/npm/"
|
|
},
|
|
"git": {
|
|
"scheme": "http",
|
|
"port": 3000
|
|
}
|
|
},
|
|
"receives": {
|
|
"npm-package-registry": "${dir:grants}/npm.json"
|
|
},
|
|
"grants": {
|
|
"npm-package-registry": "${dir:grants}"
|
|
},
|
|
"claims": [
|
|
{
|
|
"name": "npm-package-registry",
|
|
"scope": "mesh"
|
|
},
|
|
{
|
|
"name": "git",
|
|
"scope": "mesh"
|
|
}
|
|
],
|
|
"data": {
|
|
"own": [
|
|
{
|
|
"id": "data",
|
|
"path": "${dir:data}",
|
|
"class": "valuable",
|
|
"why": "every repository, its issues and attachments, and the package registry"
|
|
}
|
|
],
|
|
"consumers": {
|
|
"npm-package-registry": {
|
|
"class": "rebuildable",
|
|
"in": "data",
|
|
"why": "a consumer's packages are published again from its source"
|
|
}
|
|
}
|
|
},
|
|
"resources": [
|
|
{
|
|
"id": "mesh-state",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"place": "mesh"
|
|
},
|
|
{
|
|
"id": "runtime-state",
|
|
"type": "directory",
|
|
"path": "${dir:mesh-state}/state",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"place": "."
|
|
},
|
|
{
|
|
"id": "grants",
|
|
"type": "directory",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "server-env",
|
|
"type": "file",
|
|
"path": "${dir:state}/server.env",
|
|
"mode": "0600",
|
|
"content": "GITEA__security__INTERNAL_TOKEN=${secret:internal-token}\nGITEA__database__DB_TYPE=postgres\nGITEA__database__HOST=${bound:postgres-database:at}:${bound:postgres-database:port}\nGITEA__database__NAME=${bound:postgres-database:as}\nGITEA__database__USER=${bound:postgres-database:as}\nGITEA__database__PASSWD=${secret:postgres-database}\n"
|
|
},
|
|
{
|
|
"id": "data",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"owner": "1000:1000"
|
|
},
|
|
{
|
|
"id": "server",
|
|
"type": "container",
|
|
"name": "gitea",
|
|
"image": "gitea/gitea@sha256:87a67ee09d3ae0d1df5fda5dcda3e2a1f9236a45b0a59025d6e00e46adc43bef",
|
|
"env": {
|
|
"DB_TYPE": "postgres",
|
|
"USER_UID": "1000",
|
|
"USER_GID": "1000"
|
|
},
|
|
"env-file": [
|
|
"${dir:state}/server.env"
|
|
],
|
|
"ports": [
|
|
"3000",
|
|
"222:22"
|
|
],
|
|
"volumes": [
|
|
"${dir:data}:/data"
|
|
],
|
|
"secrets-in-environment": "gitea honours GITEA__database__PASSWD__FILE and GITEA__security__INTERNAL_TOKEN__FILE; convertible, awaiting a bed that proves it",
|
|
"logging": "journald"
|
|
},
|
|
{
|
|
"id": "admin-bootstrap",
|
|
"type": "container",
|
|
"name": "mesh-gitea-admin",
|
|
"image": "gitea/gitea@sha256:87a67ee09d3ae0d1df5fda5dcda3e2a1f9236a45b0a59025d6e00e46adc43bef",
|
|
"run-once": true,
|
|
"env": {
|
|
"USER_UID": "1000",
|
|
"USER_GID": "1000",
|
|
"MESH_GITEA_ADMIN_USER": "mesh-admin"
|
|
},
|
|
"env-file": [
|
|
"${dir:state}/server.env"
|
|
],
|
|
"volumes": [
|
|
"${dir:data}:/data",
|
|
"${dir:state}/admin.secret:/run/secrets/admin:ro"
|
|
],
|
|
"args": [
|
|
"/bin/sh",
|
|
"-c",
|
|
"su-exec git gitea admin user create --admin --username \"$MESH_GITEA_ADMIN_USER\" --email mesh-admin@localhost --password \"$(cat /run/secrets/admin)\" --must-change-password=false || true"
|
|
],
|
|
"secrets-in-environment": "gitea honours GITEA__database__PASSWD__FILE and GITEA__security__INTERNAL_TOKEN__FILE; convertible, awaiting a bed that proves it"
|
|
},
|
|
{
|
|
"id": "runtime-config",
|
|
"type": "file",
|
|
"path": "${dir:mesh-state}/config.json",
|
|
"mode": "0600",
|
|
"content": "{}\n",
|
|
"merge": "json"
|
|
}
|
|
],
|
|
"provides": [
|
|
{
|
|
"name": "npm-package-registry",
|
|
"scope": "mesh",
|
|
"identity": {
|
|
"max": 40,
|
|
"in": "a Gitea user name"
|
|
}
|
|
},
|
|
{
|
|
"name": "git",
|
|
"scope": "mesh"
|
|
}
|
|
],
|
|
"build": {
|
|
"artifacts": [
|
|
{
|
|
"name": "code",
|
|
"kind": "bundle",
|
|
"language": "typescript",
|
|
"entrypoints": [
|
|
"index.js",
|
|
"tools/index.js",
|
|
"provisioner/index.js"
|
|
],
|
|
"loads": [
|
|
"index.js",
|
|
"tools/index.js",
|
|
"provisioner/index.js"
|
|
],
|
|
"env": {
|
|
"MESH_GITEA_URL": "http://127.0.0.1:${port:3000}",
|
|
"MESH_GITEA_CONFIG_FILE": "${dir:mesh-state}/config.json",
|
|
"MESH_GITEA_ADMIN_USER": "mesh-admin",
|
|
"MESH_GITEA_ADMIN_PASSWORD_FILE": "${dir:state}/admin.secret",
|
|
"MESH_GITEA_STATE_DIR": "${dir:runtime-state}",
|
|
"MESH_RECEIVES": "${dir:grants}/npm.json"
|
|
}
|
|
}
|
|
]
|
|
},
|
|
"jails": [
|
|
{
|
|
"name": "gitea",
|
|
"failregex": "^.*Failed authentication attempt for .* from <HOST>(?::\\d+)?\\s*$\n ^.*Invalid user .* from <HOST> port \\d+\\s*$\n ^.*User \\S+ from <HOST> not allowed because .*$",
|
|
"jail": "backend = systemd\njournalmatch = CONTAINER_NAME=gitea\nport = http,https,222\nmaxretry = 3\nfindtime = 1d\nbantime = 1d"
|
|
}
|
|
]
|
|
}
|