adding the gitea runners and making it not possible for anyone to join the gitea
This commit is contained in:
@@ -1,2 +1,4 @@
|
||||
.env
|
||||
gitea-dump
|
||||
.DS_Store
|
||||
runner_data/
|
||||
@@ -112,3 +112,70 @@ restore the DB backup that matches the version you’re rolling back to.
|
||||
Jupyter renderer env vars carry forward unchanged across versions.
|
||||
- Major Gitea versions occasionally change bundled git requirements; the official
|
||||
image ships its own git, so host git version is irrelevant here.
|
||||
|
||||
### Actions runner, CORS & OAuth (for the ever-near site)
|
||||
|
||||
The `ever-near` site uses Sveltia CMS backed by this Gitea instance. That needs three
|
||||
things Gitea didn't have before: **Actions** (to build + deploy on push), **CORS**
|
||||
(so the CMS in the browser can call the Gitea API), and an **OAuth2 app** (so editors
|
||||
sign in with PKCE instead of a personal token). `docker-compose.yml` now enables the
|
||||
first two via env vars and adds a `runner` service behind a `runner` profile.
|
||||
|
||||
**1. Ship the updated compose file and runner config to the VPS:**
|
||||
```bash
|
||||
scp docker-compose.yml runner_config.yaml ubuntu@vps-123c23bd.vps.ovh.net:~/gitea/
|
||||
```
|
||||
|
||||
**2. Rebuild the server.** The compose network is now pinned to the literal name `gitea`
|
||||
(so job containers can join it — see `runner_config.yaml`), which is a one-time network
|
||||
change, so do a clean `down`/`up` (~10s downtime; Caddy restarts too):
|
||||
```bash
|
||||
cd ~/gitea
|
||||
sudo docker compose down
|
||||
sudo docker compose up -d --build
|
||||
sudo docker compose logs -f server # watch for actions/cors config lines on boot
|
||||
```
|
||||
|
||||
**3. Enable Actions on the repo** (one-off, in the web UI):
|
||||
`gitea.jms.rocks/jameshtwose/ever-near` → Settings → Actions → Enable Actions.
|
||||
|
||||
**4. Get a runner registration token** (pick one):
|
||||
- Web UI: Site Administration → Actions → Runners → copy the **Registration token**.
|
||||
- Or CLI: `sudo docker exec gitea_server gitea --config /data/gitea/conf/app.ini actions generate-runner-token`
|
||||
|
||||
**5. Put the token in `~/gitea/.env`** (gitignored, never committed):
|
||||
```bash
|
||||
printf 'GITEA_RUNNER_REGISTRATION_TOKEN=%s\n' '<TOKEN>' >> ~/gitea/.env
|
||||
```
|
||||
|
||||
**6. Start the runner** (separate profile so it only runs once the token is set):
|
||||
```bash
|
||||
sudo docker compose --profile runner up -d runner
|
||||
sudo docker compose logs -f runner # should log "Runner registered successfully"
|
||||
```
|
||||
The first workflow run pulls the job image `docker.gitea.com/runner-images:ubuntu-latest`
|
||||
(Node, git, Docker CLI) — give it a minute. `runner_config.yaml` attaches each job
|
||||
container to the `gitea` network so `actions/checkout` can resolve `server:3000`.
|
||||
|
||||
**7. Register the OAuth2 app for Sveltia CMS** (web UI, no server restart):
|
||||
- Site Administration → OAuth2 Applications → **Add a new OAuth2 application**.
|
||||
- Application name: `ever-near CMS`
|
||||
- Redirect URI: `https://ever-near.web.app/admin/index.html`
|
||||
- **Uncheck "Confidential client"** (PKCE needs a public client).
|
||||
- Copy the **Client ID** into `ever-near/public/admin/config.yml` as `app_id`, commit,
|
||||
and push — the Gitea Action rebuilds + redeploys the site with it.
|
||||
|
||||
**Gotchas**
|
||||
- **Job containers must join the `gitea` network** or `actions/checkout` fails with
|
||||
`Could not resolve host: server`. That's what `runner_config.yaml`
|
||||
(`container.network: gitea`) does — don't remove it. The compose network is pinned to
|
||||
the literal name `gitea` via `networks.gitea.name` so the config matches regardless of
|
||||
the compose project name.
|
||||
- `uses: actions/checkout@v4` / `actions/setup-node@v4` resolve through Gitea's default
|
||||
actions mirror (`gitea.com/actions/*`). If a job can't find an action, set
|
||||
`GITEA__actions__DEFAULT_ACTIONS_URL=https://gitea.com` (already the default) or
|
||||
reference the action fully: `uses: https://gitea.com/actions/checkout@v4`.
|
||||
- CORS is scoped to `ever-near.web.app` only. Add more origins to
|
||||
`GITEA__cors__ALLOW_DOMAINS` (comma-separated) if you connect a custom domain later.
|
||||
- The runner is behind the `runner` profile; a plain `docker compose up -d` won't start
|
||||
it. Use `docker compose --profile runner up -d runner`.
|
||||
@@ -1,6 +1,7 @@
|
||||
networks:
|
||||
gitea:
|
||||
external: false
|
||||
name: gitea
|
||||
|
||||
services:
|
||||
# 1. Gitea Core Engine (SQLite Variant)
|
||||
@@ -36,6 +37,14 @@ services:
|
||||
- GITEA__markup.jupyter__RENDER_COMMAND=jupyter-nbconvert --stdin --stdout --to html --template basic
|
||||
- GITEA__markup.jupyter__IS_INPUT_FILE=false
|
||||
- GITEA__markup.sanitizer.jupyter.img__ALLOW_DATA_URI_IMAGES=true
|
||||
# Gitea Actions — lets .gitea/workflows/*.yml run on push
|
||||
- GITEA__actions__ENABLED=true
|
||||
# No self-signup — only an admin creates accounts, so only invited users exist
|
||||
- GITEA__service__DISABLE_REGISTRATION=true
|
||||
# CORS — lets the Sveltia CMS on Firebase call the Gitea API from the browser
|
||||
- GITEA__cors__ENABLED=true
|
||||
- GITEA__cors__SCHEME=https
|
||||
- GITEA__cors__ALLOW_DOMAINS=ever-near.web.app,ever-near.me
|
||||
ports:
|
||||
- "127.0.0.1:3000:3000"
|
||||
- "2222:22"
|
||||
@@ -54,3 +63,27 @@ services:
|
||||
- ./caddy_config:/config
|
||||
networks:
|
||||
- gitea
|
||||
|
||||
# 3. Gitea Actions runner — executes workflow jobs in Docker containers.
|
||||
# Behind a profile so it only starts once you've set the registration token
|
||||
# in .env (GITEA_RUNNER_REGISTRATION_TOKEN) — see README §Actions runner.
|
||||
runner:
|
||||
image: gitea/runner:latest
|
||||
container_name: gitea_runner
|
||||
restart: always
|
||||
profiles: [runner]
|
||||
depends_on:
|
||||
- server
|
||||
networks:
|
||||
- gitea
|
||||
volumes:
|
||||
- ./runner_data:/data
|
||||
- ./runner_config.yaml:/config.yaml:ro
|
||||
- /var/run/docker.sock:/var/run/docker.sock
|
||||
environment:
|
||||
- CONFIG_FILE=/config.yaml
|
||||
- GITEA_INSTANCE_URL=http://server:3000
|
||||
- GITEA_RUNNER_REGISTRATION_TOKEN=${GITEA_RUNNER_REGISTRATION_TOKEN:-}
|
||||
- GITEA_RUNNER_NAME=ever-near-runner
|
||||
# Map the workflow's `runs-on: ubuntu-latest` to this job image
|
||||
- GITEA_RUNNER_LABELS=ubuntu-latest:docker://docker.gitea.com/runner-images:ubuntu-latest
|
||||
@@ -0,0 +1,5 @@
|
||||
# act_runner config. Only the job-container network is overridden so workflow jobs
|
||||
# (actions/checkout, etc.) can resolve `server` on this compose network — everything
|
||||
# else uses act_runner's built-in defaults. See README §Actions runner.
|
||||
container:
|
||||
network: gitea
|
||||
Reference in New Issue
Block a user