Compare commits
11
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
942f369f78 | ||
|
|
9b2bff61d8 | ||
|
|
1c1b51d37e | ||
|
|
99e5b939d4 | ||
|
|
c602ec6994 | ||
|
|
902e8517ff | ||
|
|
ecfd565a3b | ||
|
|
843f2e2c2a | ||
|
|
e580f90655 | ||
|
|
86bb68fe74 | ||
|
|
af71828317 |
+6
-2
@@ -1,3 +1,7 @@
|
||||
## Manual deployment notes
|
||||
## Deployment notes
|
||||
### Gitea
|
||||
1. Create admin user in web UI on initial setup
|
||||
1. `cd ./gitea`
|
||||
1. Run the script `./run-this-first.sh`
|
||||
1. Bring up the gitea cluster `docker compose up -d`
|
||||
1. Run the script `./initialize-gitea.sh`
|
||||
1. Note the access token printed, it will be needed to publish packages.
|
||||
|
||||
@@ -6,7 +6,7 @@ networks:
|
||||
|
||||
services:
|
||||
server:
|
||||
image: gitea/gitea:1.17.1
|
||||
image: gitea/gitea:1.18.3
|
||||
container_name: gitea
|
||||
environment:
|
||||
- USER_UID=1000
|
||||
@@ -16,6 +16,10 @@ services:
|
||||
- GITEA__database__NAME=gitea
|
||||
- GITEA__database__USER=gitea
|
||||
- GITEA__database__PASSWD=gitea
|
||||
- GITEA__server__HTTP_PORT=3000
|
||||
- GITEA__server__LOCAL_ROOT_URL=http://gitea.local:3000/
|
||||
- GITEA__server__ROOT_URL=http://gitea.local:3000/
|
||||
- GITEA__security__INSTALL_LOCK=true
|
||||
restart: always
|
||||
networks:
|
||||
- gitea
|
||||
|
||||
Executable
+76
@@ -0,0 +1,76 @@
|
||||
#!/usr/bin/env bash
|
||||
# Run this script once after bringing up gitea in docker compose
|
||||
# TODO: add a check to detect that gitea has not fully initialized yet (no user relation error)
|
||||
GITEA_USER=gitea_admin
|
||||
GITEA_PASSWORD=admin1234
|
||||
GITEA_USER_EMAIL=${GITEA_USER}@example.com
|
||||
GITEA_NEW_ORGANIZATION=cerc-io
|
||||
GITEA_URL_PREFIX=http://localhost:3000
|
||||
CERC_GITEA_TOKEN_NAME=laconic-so-publication-token
|
||||
if [[ -n "$CERC_SCRIPT_DEBUG" ]]; then
|
||||
set -x
|
||||
fi
|
||||
# Create admin user
|
||||
# First check if it already exists
|
||||
if [[ -z ${CERC_SO_COMPOSE_PROJECT} ]] ; then
|
||||
compose_command="docker compose"
|
||||
else
|
||||
compose_command="docker compose -p ${CERC_SO_COMPOSE_PROJECT}"
|
||||
fi
|
||||
# HACK: sleep a bit because gitea may not be up yet (container reports it has started before service is available)
|
||||
sleep 5
|
||||
${compose_command} exec --user git server gitea admin user list --admin | grep -v -e "^ID" | awk '{ print $2 }' | grep ${GITEA_USER} > /dev/null
|
||||
if [[ $? == 1 ]] ; then
|
||||
# Then create if it wasn't found
|
||||
${compose_command} exec --user git server gitea admin user create --admin --username ${GITEA_USER} --password ${GITEA_PASSWORD} --email ${GITEA_USER_EMAIL}
|
||||
fi
|
||||
# Check if the token already exists
|
||||
token_response=$( curl -s "${GITEA_URL_PREFIX}/api/v1/users/${GITEA_USER}/tokens" \
|
||||
-u ${GITEA_USER}:${GITEA_PASSWORD} \
|
||||
-H "Content-Type: application/json")
|
||||
if [[ -n ${token_response} ]] ; then
|
||||
echo ${token_response} | jq --exit-status -r 'to_entries[] | select(.value.name == "'${CERC_GITEA_TOKEN_NAME}'")'
|
||||
if [[ $? == 0 ]] ; then
|
||||
token_found=1
|
||||
fi
|
||||
fi
|
||||
if [[ ${token_found} != 1 ]] ; then
|
||||
# Create access token if not found
|
||||
# Note that we either create the token here, or we needed to be passed
|
||||
# the token by the caller. This is because gitea won't release the token
|
||||
# plaintext post-creation.
|
||||
new_gitea_token=$( curl -s -X POST "${GITEA_URL_PREFIX}/api/v1/users/${GITEA_USER}/tokens" \
|
||||
-u ${GITEA_USER}:${GITEA_PASSWORD} \
|
||||
-H "Content-Type: application/json" \
|
||||
-d '{"name":"'${CERC_GITEA_TOKEN_NAME}'"}' \
|
||||
| jq -r .sha1 )
|
||||
echo "This is your gitea access token: ${new_gitea_token}. Keep it safe and secure, it can not be fetched again from gitea."
|
||||
CERC_GITEA_AUTH_TOKEN=${new_gitea_token}
|
||||
else
|
||||
# If the token exists, then we must have been passed its value.
|
||||
# If we were not, then we fail hard here.
|
||||
if [[ -z ${CERC_GITEA_AUTH_TOKEN} ]] ; then
|
||||
echo "FATAL error: gitea auth token \"${CERC_GITEA_TOKEN_NAME}\" already exists but no CERC_GITEA_AUTH_TOKEN was provided"
|
||||
exit 1
|
||||
fi
|
||||
fi
|
||||
# Now that we're sure the token exists and is set in CERC_GITEA_AUTH_TOKEN,
|
||||
# we can proceed with token-authenticated API requests below
|
||||
# Create org
|
||||
# First check if it already exists
|
||||
curl -s "${GITEA_URL_PREFIX}/api/v1/admin/users/${GITEA_USER}/orgs" \
|
||||
-H "Authorization: token ${CERC_GITEA_AUTH_TOKEN}" \
|
||||
-H "Content-Type: application/json" \
|
||||
-H "accept: application/json" \
|
||||
| jq --exit-status -r 'to_entries[] | select(.value.name == "'${GITEA_NEW_ORGANIZATION}'")' > /dev/null
|
||||
if [[ $? != 0 ]] ; then
|
||||
# If it doesn't exist, create it
|
||||
# See: https://discourse.gitea.io/t/create-remove-organization-through-api/478
|
||||
curl -s -X POST "${GITEA_URL_PREFIX}/api/v1/admin/users/${GITEA_USER}/orgs" \
|
||||
-H "Authorization: token ${CERC_GITEA_AUTH_TOKEN}" \
|
||||
-H "Content-Type: application/json" \
|
||||
-H "accept: application/json" \
|
||||
-d '{"username": "'${GITEA_NEW_ORGANIZATION}'"}' > /dev/null
|
||||
echo "Created the organization ${GITEA_NEW_ORGANIZATION}"
|
||||
fi
|
||||
echo "Success, gitea is properly initialized"
|
||||
@@ -1,3 +1,7 @@
|
||||
#!/bin/sh
|
||||
#!/usr/bin/env bash
|
||||
if [[ -n "$CERC_SCRIPT_DEBUG" ]]; then
|
||||
set -x
|
||||
fi
|
||||
mkdir -p ./gitea
|
||||
mkdir -p ./gitea/ssh
|
||||
mkdir -p ./postgres
|
||||
|
||||
Reference in New Issue
Block a user