diff --git a/.gitignore b/.gitignore index 31eceb0..fb55182 100644 --- a/.gitignore +++ b/.gitignore @@ -1,2 +1,4 @@ .env -gitea-dump \ No newline at end of file +gitea-dump +.DS_Store +runner_data/ \ No newline at end of file diff --git a/README.md b/README.md index 421dec7..36a8621 100644 --- a/README.md +++ b/README.md @@ -111,4 +111,71 @@ restore the DB backup that matches the version you’re rolling back to. - The Mermaid size cap (`GITEA__markup__MERMAID_MAX_SOURCE_CHARACTERS=50000`) and the Jupyter renderer env vars carry forward unchanged across versions. - Major Gitea versions occasionally change bundled git requirements; the official - image ships its own git, so host git version is irrelevant here. \ No newline at end of file + image ships its own git, so host git version is irrelevant here. + +### Actions runner, CORS & OAuth (for the ever-near site) + +The `ever-near` site uses Sveltia CMS backed by this Gitea instance. That needs three +things Gitea didn't have before: **Actions** (to build + deploy on push), **CORS** +(so the CMS in the browser can call the Gitea API), and an **OAuth2 app** (so editors +sign in with PKCE instead of a personal token). `docker-compose.yml` now enables the +first two via env vars and adds a `runner` service behind a `runner` profile. + +**1. Ship the updated compose file and runner config to the VPS:** +```bash +scp docker-compose.yml runner_config.yaml ubuntu@vps-123c23bd.vps.ovh.net:~/gitea/ +``` + +**2. Rebuild the server.** The compose network is now pinned to the literal name `gitea` +(so job containers can join it — see `runner_config.yaml`), which is a one-time network +change, so do a clean `down`/`up` (~10s downtime; Caddy restarts too): +```bash +cd ~/gitea +sudo docker compose down +sudo docker compose up -d --build +sudo docker compose logs -f server # watch for actions/cors config lines on boot +``` + +**3. Enable Actions on the repo** (one-off, in the web UI): +`gitea.jms.rocks/jameshtwose/ever-near` → Settings → Actions → Enable Actions. + +**4. Get a runner registration token** (pick one): +- Web UI: Site Administration → Actions → Runners → copy the **Registration token**. +- Or CLI: `sudo docker exec gitea_server gitea --config /data/gitea/conf/app.ini actions generate-runner-token` + +**5. Put the token in `~/gitea/.env`** (gitignored, never committed): +```bash +printf 'GITEA_RUNNER_REGISTRATION_TOKEN=%s\n' '' >> ~/gitea/.env +``` + +**6. Start the runner** (separate profile so it only runs once the token is set): +```bash +sudo docker compose --profile runner up -d runner +sudo docker compose logs -f runner # should log "Runner registered successfully" +``` +The first workflow run pulls the job image `docker.gitea.com/runner-images:ubuntu-latest` +(Node, git, Docker CLI) — give it a minute. `runner_config.yaml` attaches each job +container to the `gitea` network so `actions/checkout` can resolve `server:3000`. + +**7. Register the OAuth2 app for Sveltia CMS** (web UI, no server restart): +- Site Administration → OAuth2 Applications → **Add a new OAuth2 application**. +- Application name: `ever-near CMS` +- Redirect URI: `https://ever-near.web.app/admin/index.html` +- **Uncheck "Confidential client"** (PKCE needs a public client). +- Copy the **Client ID** into `ever-near/public/admin/config.yml` as `app_id`, commit, + and push — the Gitea Action rebuilds + redeploys the site with it. + +**Gotchas** +- **Job containers must join the `gitea` network** or `actions/checkout` fails with + `Could not resolve host: server`. That's what `runner_config.yaml` + (`container.network: gitea`) does — don't remove it. The compose network is pinned to + the literal name `gitea` via `networks.gitea.name` so the config matches regardless of + the compose project name. +- `uses: actions/checkout@v4` / `actions/setup-node@v4` resolve through Gitea's default + actions mirror (`gitea.com/actions/*`). If a job can't find an action, set + `GITEA__actions__DEFAULT_ACTIONS_URL=https://gitea.com` (already the default) or + reference the action fully: `uses: https://gitea.com/actions/checkout@v4`. +- CORS is scoped to `ever-near.web.app` only. Add more origins to + `GITEA__cors__ALLOW_DOMAINS` (comma-separated) if you connect a custom domain later. +- The runner is behind the `runner` profile; a plain `docker compose up -d` won't start + it. Use `docker compose --profile runner up -d runner`. \ No newline at end of file diff --git a/docker-compose.yml b/docker-compose.yml index 3257454..d02f95c 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -1,6 +1,7 @@ networks: gitea: external: false + name: gitea services: # 1. Gitea Core Engine (SQLite Variant) @@ -36,6 +37,14 @@ services: - GITEA__markup.jupyter__RENDER_COMMAND=jupyter-nbconvert --stdin --stdout --to html --template basic - GITEA__markup.jupyter__IS_INPUT_FILE=false - GITEA__markup.sanitizer.jupyter.img__ALLOW_DATA_URI_IMAGES=true + # Gitea Actions — lets .gitea/workflows/*.yml run on push + - GITEA__actions__ENABLED=true + # No self-signup — only an admin creates accounts, so only invited users exist + - GITEA__service__DISABLE_REGISTRATION=true + # CORS — lets the Sveltia CMS on Firebase call the Gitea API from the browser + - GITEA__cors__ENABLED=true + - GITEA__cors__SCHEME=https + - GITEA__cors__ALLOW_DOMAINS=ever-near.web.app,ever-near.me ports: - "127.0.0.1:3000:3000" - "2222:22" @@ -53,4 +62,28 @@ services: - ./caddy_data:/data - ./caddy_config:/config networks: - - gitea \ No newline at end of file + - gitea + + # 3. Gitea Actions runner — executes workflow jobs in Docker containers. + # Behind a profile so it only starts once you've set the registration token + # in .env (GITEA_RUNNER_REGISTRATION_TOKEN) — see README §Actions runner. + runner: + image: gitea/runner:latest + container_name: gitea_runner + restart: always + profiles: [runner] + depends_on: + - server + networks: + - gitea + volumes: + - ./runner_data:/data + - ./runner_config.yaml:/config.yaml:ro + - /var/run/docker.sock:/var/run/docker.sock + environment: + - CONFIG_FILE=/config.yaml + - GITEA_INSTANCE_URL=http://server:3000 + - GITEA_RUNNER_REGISTRATION_TOKEN=${GITEA_RUNNER_REGISTRATION_TOKEN:-} + - GITEA_RUNNER_NAME=ever-near-runner + # Map the workflow's `runs-on: ubuntu-latest` to this job image + - GITEA_RUNNER_LABELS=ubuntu-latest:docker://docker.gitea.com/runner-images:ubuntu-latest \ No newline at end of file diff --git a/runner_config.yaml b/runner_config.yaml new file mode 100644 index 0000000..d29dc81 --- /dev/null +++ b/runner_config.yaml @@ -0,0 +1,5 @@ +# act_runner config. Only the job-container network is overridden so workflow jobs +# (actions/checkout, etc.) can resolve `server` on this compose network — everything +# else uses act_runner's built-in defaults. See README §Actions runner. +container: + network: gitea \ No newline at end of file