adding the gitea runners and making it not possible for anyone to join the gitea

This commit is contained in:
itsamejms
2026-08-26 21:02:51 +01:00
parent e20d31955c
commit 8fc079880b
4 changed files with 110 additions and 3 deletions
+34 -1
View File
@@ -1,6 +1,7 @@
networks:
gitea:
external: false
name: gitea
services:
# 1. Gitea Core Engine (SQLite Variant)
@@ -36,6 +37,14 @@ services:
- GITEA__markup.jupyter__RENDER_COMMAND=jupyter-nbconvert --stdin --stdout --to html --template basic
- GITEA__markup.jupyter__IS_INPUT_FILE=false
- GITEA__markup.sanitizer.jupyter.img__ALLOW_DATA_URI_IMAGES=true
# Gitea Actions — lets .gitea/workflows/*.yml run on push
- GITEA__actions__ENABLED=true
# No self-signup — only an admin creates accounts, so only invited users exist
- GITEA__service__DISABLE_REGISTRATION=true
# CORS — lets the Sveltia CMS on Firebase call the Gitea API from the browser
- GITEA__cors__ENABLED=true
- GITEA__cors__SCHEME=https
- GITEA__cors__ALLOW_DOMAINS=ever-near.web.app,ever-near.me
ports:
- "127.0.0.1:3000:3000"
- "2222:22"
@@ -53,4 +62,28 @@ services:
- ./caddy_data:/data
- ./caddy_config:/config
networks:
- gitea
- gitea
# 3. Gitea Actions runner — executes workflow jobs in Docker containers.
# Behind a profile so it only starts once you've set the registration token
# in .env (GITEA_RUNNER_REGISTRATION_TOKEN) — see README §Actions runner.
runner:
image: gitea/runner:latest
container_name: gitea_runner
restart: always
profiles: [runner]
depends_on:
- server
networks:
- gitea
volumes:
- ./runner_data:/data
- ./runner_config.yaml:/config.yaml:ro
- /var/run/docker.sock:/var/run/docker.sock
environment:
- CONFIG_FILE=/config.yaml
- GITEA_INSTANCE_URL=http://server:3000
- GITEA_RUNNER_REGISTRATION_TOKEN=${GITEA_RUNNER_REGISTRATION_TOKEN:-}
- GITEA_RUNNER_NAME=ever-near-runner
# Map the workflow's `runs-on: ubuntu-latest` to this job image
- GITEA_RUNNER_LABELS=ubuntu-latest:docker://docker.gitea.com/runner-images:ubuntu-latest