The mesh resolves both to <root>/gitea/<id> — where the 5.8G forge and its grant files already sit, so the roll-out its upgrade policy makes of this build changes no byte of the spec. The module root and the mesh's plumbing stay stated.
240 lines
6.0 KiB
JSON
240 lines
6.0 KiB
JSON
{
|
|
"module": "gitea",
|
|
"version": "1",
|
|
"requires": [
|
|
"postgres-database",
|
|
"route",
|
|
"secret"
|
|
],
|
|
"contributes": {
|
|
"postgres-database": {
|
|
"name": "gitea"
|
|
},
|
|
"route": {
|
|
"web": {
|
|
"label": "git",
|
|
"port": 3000
|
|
},
|
|
"internal-api-refused": {
|
|
"label": "git",
|
|
"path": "/api/internal",
|
|
"deny": true,
|
|
"priority": 100000
|
|
}
|
|
}
|
|
},
|
|
"binds": {
|
|
"postgres-database": "${dir:data}base.json",
|
|
"route": "/var/lib/gitea/route.json"
|
|
},
|
|
"secrets": {
|
|
"postgres-database": "${dir:data}base.secret",
|
|
"secret": {
|
|
"internal-token": "/var/lib/gitea/internal-token.secret",
|
|
"admin": "/var/lib/gitea/admin.secret"
|
|
}
|
|
},
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"emits": [
|
|
"module.gitea.repo.created",
|
|
"module.gitea.issue.opened",
|
|
"module.gitea.pull.merged"
|
|
],
|
|
"listens": [
|
|
{
|
|
"port": 3000,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "the forge, over http"
|
|
},
|
|
{
|
|
"port": 22,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "git over ssh, gitea's own unmodified sshd. Published on the machine's own side at 222, the mesh's fixed public convention \u2014 not 22, which the machine's own daemon holds and a module does not take"
|
|
}
|
|
],
|
|
"serves": {
|
|
"npm-package-registry": {
|
|
"scheme": "http",
|
|
"port": 3000,
|
|
"npm-path": "/api/packages/novox/npm/"
|
|
},
|
|
"git": {
|
|
"scheme": "http",
|
|
"port": 3000
|
|
}
|
|
},
|
|
"receives": {
|
|
"npm-package-registry": "${dir:grants}/npm.json"
|
|
},
|
|
"grants": {
|
|
"npm-package-registry": "${dir:grants}"
|
|
},
|
|
"claims": [
|
|
{
|
|
"name": "npm-package-registry",
|
|
"scope": "mesh"
|
|
},
|
|
{
|
|
"name": "git",
|
|
"scope": "mesh"
|
|
}
|
|
],
|
|
"own-secrets": {
|
|
"broker": "/var/lib/mesh/gitea/broker"
|
|
},
|
|
"resources": [
|
|
{
|
|
"id": "mesh-state",
|
|
"type": "directory",
|
|
"path": "/var/lib/mesh/gitea",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "runtime-state",
|
|
"type": "directory",
|
|
"path": "/var/lib/mesh/gitea/state",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"path": "/var/lib/gitea",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "grants",
|
|
"type": "directory",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "server-env",
|
|
"type": "file",
|
|
"path": "/var/lib/gitea/server.env",
|
|
"mode": "0600",
|
|
"content": "GITEA__security__INTERNAL_TOKEN=${secret:internal-token}\nGITEA__database__DB_TYPE=postgres\nGITEA__database__HOST=${bound:postgres-database:at}:${bound:postgres-database:port}\nGITEA__database__NAME=${bound:postgres-database:as}\nGITEA__database__USER=${bound:postgres-database:as}\nGITEA__database__PASSWD=${secret:postgres-database}\n"
|
|
},
|
|
{
|
|
"id": "data",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"owner": "1000:1000"
|
|
},
|
|
{
|
|
"id": "server",
|
|
"type": "container",
|
|
"name": "gitea",
|
|
"image": "gitea/gitea@sha256:87a67ee09d3ae0d1df5fda5dcda3e2a1f9236a45b0a59025d6e00e46adc43bef",
|
|
"env": {
|
|
"DB_TYPE": "postgres",
|
|
"USER_UID": "1000",
|
|
"USER_GID": "1000"
|
|
},
|
|
"env-file": [
|
|
"/var/lib/gitea/server.env"
|
|
],
|
|
"ports": [
|
|
"3000",
|
|
"222:22"
|
|
],
|
|
"volumes": [
|
|
"${dir:data}:/data"
|
|
],
|
|
"secrets-in-environment": "gitea honours GITEA__database__PASSWD__FILE and GITEA__security__INTERNAL_TOKEN__FILE; convertible, awaiting a bed that proves it"
|
|
},
|
|
{
|
|
"id": "admin-bootstrap",
|
|
"type": "container",
|
|
"name": "mesh-gitea-admin",
|
|
"image": "gitea/gitea@sha256:87a67ee09d3ae0d1df5fda5dcda3e2a1f9236a45b0a59025d6e00e46adc43bef",
|
|
"run-once": true,
|
|
"env": {
|
|
"USER_UID": "1000",
|
|
"USER_GID": "1000",
|
|
"MESH_GITEA_ADMIN_USER": "mesh-admin"
|
|
},
|
|
"env-file": [
|
|
"/var/lib/gitea/server.env"
|
|
],
|
|
"volumes": [
|
|
"${dir:data}:/data",
|
|
"/var/lib/gitea/admin.secret:/run/secrets/admin:ro"
|
|
],
|
|
"args": [
|
|
"/bin/sh",
|
|
"-c",
|
|
"su-exec git gitea admin user create --admin --username \"$MESH_GITEA_ADMIN_USER\" --email mesh-admin@localhost --password \"$(cat /run/secrets/admin)\" --must-change-password=false || true"
|
|
],
|
|
"secrets-in-environment": "gitea honours GITEA__database__PASSWD__FILE and GITEA__security__INTERNAL_TOKEN__FILE; convertible, awaiting a bed that proves it"
|
|
},
|
|
{
|
|
"id": "runtime-config",
|
|
"type": "file",
|
|
"path": "/var/lib/mesh/gitea/config.json",
|
|
"mode": "0600",
|
|
"content": "{}\n",
|
|
"merge": "json"
|
|
},
|
|
{
|
|
"id": "runtime",
|
|
"type": "container",
|
|
"name": "mesh-gitea",
|
|
"network": "host",
|
|
"volumes": [
|
|
"/var/lib/mesh/gitea/broker:/run/secrets/broker:ro",
|
|
"/var/lib/mesh/gitea/config.json:/run/config/config.json:ro",
|
|
"${dir:grants}:${dir:grants}:ro",
|
|
"/var/lib/gitea/admin.secret:/run/secrets/admin:ro",
|
|
"/var/lib/mesh/gitea/state:/run/state"
|
|
],
|
|
"env": {
|
|
"MESH_BROKER_FILE": "/run/secrets/broker",
|
|
"MESH_GITEA_URL": "http://127.0.0.1:${port:3000}",
|
|
"MESH_GITEA_CONFIG_FILE": "/run/config/config.json",
|
|
"MESH_GITEA_ADMIN_USER": "mesh-admin",
|
|
"MESH_GITEA_ADMIN_PASSWORD_FILE": "/run/secrets/admin",
|
|
"MESH_GITEA_STATE_DIR": "/run/state",
|
|
"MESH_RECEIVES": "${dir:grants}/npm.json"
|
|
},
|
|
"artifact": "runtime",
|
|
"restart-on": [
|
|
"runtime-config"
|
|
]
|
|
}
|
|
],
|
|
"provides": [
|
|
{
|
|
"name": "npm-package-registry",
|
|
"scope": "mesh"
|
|
},
|
|
{
|
|
"name": "git",
|
|
"scope": "mesh"
|
|
}
|
|
],
|
|
"build": {
|
|
"on": [
|
|
{
|
|
"arg": "BUILD_BASE",
|
|
"module": "mesh-tools",
|
|
"artifact": "build"
|
|
},
|
|
{
|
|
"arg": "RUNTIME_BASE",
|
|
"module": "mesh-tools",
|
|
"artifact": "runtime"
|
|
}
|
|
],
|
|
"artifacts": [
|
|
{
|
|
"name": "runtime",
|
|
"kind": "image",
|
|
"from": "Dockerfile"
|
|
}
|
|
]
|
|
}
|
|
}
|