Compare commits
3
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
4256150ed4 | ||
|
|
758303acfd | ||
|
|
313677fcf2 |
@@ -0,0 +1,32 @@
|
|||||||
|
# Deploy drone CI system
|
||||||
|
|
||||||
|
services:
|
||||||
|
drone:
|
||||||
|
image: drone/drone:2
|
||||||
|
environment:
|
||||||
|
- DRONE_GITEA_SERVER=http://gitea.local
|
||||||
|
- DRONE_GITEA_CLIENT_ID=put_the_real_client_id_here
|
||||||
|
- DRONE_GITEA_CLIENT_SECRET=put_the_real_secret_here
|
||||||
|
- DRONE_RPC_SECRET=super-duper-secret
|
||||||
|
- DRONE_SERVER_HOST=gitea.local # TODO: make this more generic
|
||||||
|
- DRONE_SERVER_PROTO=http
|
||||||
|
restart: always
|
||||||
|
volumes:
|
||||||
|
- ./drone:/data
|
||||||
|
ports:
|
||||||
|
- 80
|
||||||
|
- 443
|
||||||
|
|
||||||
|
drone-runner:
|
||||||
|
image: drone/drone-runner-docker:1
|
||||||
|
environment:
|
||||||
|
- DRONE_RPC_PROTO=http
|
||||||
|
- DRONE_RPC_HOST=drone
|
||||||
|
- DRONE_RPC_SECRET=super-duper-secret
|
||||||
|
- DRONE_RUNNER_CAPACITY=2
|
||||||
|
- DRONE_RUNNER_NAME=drone-runner-1
|
||||||
|
restart: always
|
||||||
|
volumes:
|
||||||
|
- /var/run/docker.sock:/var/run/docker.sock
|
||||||
|
ports:
|
||||||
|
- 3000
|
||||||
Executable
+5
@@ -0,0 +1,5 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
if [[ -n "$CERC_SCRIPT_DEBUG" ]]; then
|
||||||
|
set -x
|
||||||
|
fi
|
||||||
|
mkdir -p ./drone
|
||||||
@@ -1,14 +0,0 @@
|
|||||||
FROM ubuntu:22.04
|
|
||||||
|
|
||||||
# Install basic tools
|
|
||||||
RUN apt update && apt install -y gpg curl apt-transport-https ca-certificates lsb-release build-essential
|
|
||||||
|
|
||||||
# Add Docker repo
|
|
||||||
RUN curl -fsSL https://download.docker.com/linux/ubuntu/gpg | gpg --dearmor -o /usr/share/keyrings/docker-archive-keyring.gpg
|
|
||||||
RUN echo "deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/docker-archive-keyring.gpg] https://download.docker.com/linux/ubuntu $(lsb_release -cs) stable" | tee /etc/apt/sources.list.d/docker.list > /dev/null
|
|
||||||
|
|
||||||
# Add NodeJS repo
|
|
||||||
RUN curl -fsSL https://deb.nodesource.com/setup_18.x | bash -
|
|
||||||
|
|
||||||
# Install Docker and NodeJS packages.
|
|
||||||
RUN apt update && apt install -y docker-ce nodejs && rm -rf /var/lib/apt/lists/*
|
|
||||||
+1
-20
@@ -1,26 +1,7 @@
|
|||||||
## Deployment Notes
|
## Deployment notes
|
||||||
### Gitea
|
### Gitea
|
||||||
|
|
||||||
#### Build gitea/act_runner Docker Container
|
|
||||||
1. To build the `act_runner` container from Gitea, in another directory run:
|
|
||||||
```
|
|
||||||
git clone https://gitea.com/gitea/act_runner
|
|
||||||
cd act_runner
|
|
||||||
docker build -t cerc/act-runner:local .
|
|
||||||
```
|
|
||||||
|
|
||||||
#### Deploy Gitea Stack
|
|
||||||
1. `cd ./gitea`
|
1. `cd ./gitea`
|
||||||
1. Build the task executor container: `docker build -t cerc/act-runner-task-executor:local -f Dockerfile.task-executor .`
|
|
||||||
1. Run the script `./run-this-first.sh`
|
1. Run the script `./run-this-first.sh`
|
||||||
1. Bring up the gitea cluster `docker compose up -d`
|
1. Bring up the gitea cluster `docker compose up -d`
|
||||||
1. Run the script `./initialize-gitea.sh`
|
1. Run the script `./initialize-gitea.sh`
|
||||||
1. Note the access token printed, it will be needed to publish packages.
|
1. Note the access token printed, it will be needed to publish packages.
|
||||||
|
|
||||||
#### Debugging
|
|
||||||
Gitea server logs can be seen via docker logs <container-id>.
|
|
||||||
To enable more verbose log output add an environment variable definition like:
|
|
||||||
```
|
|
||||||
GITEA__log__LEVEL=TRACE
|
|
||||||
```
|
|
||||||
to the `server` definition in `docker-compose.yml` and re-start.
|
|
||||||
|
|||||||
@@ -1,48 +0,0 @@
|
|||||||
# Example configuration file, it's safe to copy this as the default config file without any modification.
|
|
||||||
|
|
||||||
log:
|
|
||||||
# The level of logging, can be trace, debug, info, warn, error, fatal
|
|
||||||
level: info
|
|
||||||
|
|
||||||
runner:
|
|
||||||
# Where to store the registration result.
|
|
||||||
file: /data/.runner
|
|
||||||
# Execute how many tasks concurrently at the same time.
|
|
||||||
capacity: 1
|
|
||||||
# # Extra environment variables to run jobs.
|
|
||||||
# envs:
|
|
||||||
# A_TEST_ENV_NAME_1: a_test_env_value_1
|
|
||||||
# A_TEST_ENV_NAME_2: a_test_env_value_2
|
|
||||||
# # Extra environment variables to run jobs from a file.
|
|
||||||
# # It will be ignored if it's empty or the file doesn't exist.
|
|
||||||
# env_file: .env
|
|
||||||
# # The timeout for a job to be finished.
|
|
||||||
# # Please note that the Gitea instance also has a timeout (3h by default) for the job.
|
|
||||||
# # So the job could be stopped by the Gitea instance if it's timeout is shorter than this.
|
|
||||||
timeout: 3h
|
|
||||||
# Whether skip verifying the TLS certificate of the Gitea instance.
|
|
||||||
insecure: false
|
|
||||||
# The timeout for fetching the job from the Gitea instance.
|
|
||||||
fetch_timeout: 5s
|
|
||||||
# The interval for fetching the job from the Gitea instance.
|
|
||||||
fetch_interval: 2s
|
|
||||||
|
|
||||||
cache:
|
|
||||||
# Enable cache server to use actions/cache.
|
|
||||||
enabled: true
|
|
||||||
# The directory to store the cache data.
|
|
||||||
# If it's empty, the cache data will be stored in $HOME/.cache/actcache.
|
|
||||||
dir: ""
|
|
||||||
# The host of the cache server.
|
|
||||||
# It's not for the address to listen, but the address to connect from job containers.
|
|
||||||
# So 0.0.0.0 is a bad choice, leave it empty to detect automatically.
|
|
||||||
host: ""
|
|
||||||
# The port of the cache server.
|
|
||||||
# 0 means to use a random available port.
|
|
||||||
port: 0
|
|
||||||
|
|
||||||
container:
|
|
||||||
# Whether to use privileged mode or not when launching task containers (privileged mode is required for Docker-in-Docker).
|
|
||||||
privileged: true
|
|
||||||
# And other options to be used when the container is started (eg, --add-host=my.gitea.url:host-gateway).
|
|
||||||
options: --add-host=gitea.local:host-gateway --volume "/var/lib/docker"
|
|
||||||
@@ -1,46 +0,0 @@
|
|||||||
#!/usr/bin/env bash
|
|
||||||
# Script that calls the Giteap API to delete one repo
|
|
||||||
|
|
||||||
if [[ -n "$CERC_SCRIPT_DEBUG" ]]; then
|
|
||||||
set -x
|
|
||||||
fi
|
|
||||||
|
|
||||||
if ! [[ $# -eq 1 ]]; then
|
|
||||||
echo "Illegal number of parameters" >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
repo_to_delete=$1
|
|
||||||
|
|
||||||
if [[ -z "${CERC_GITEA_AUTH_TOKEN}" ]]; then
|
|
||||||
echo "CERC_GITEA_AUTH_TOKEN is not set" >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
if [[ -z "${CERC_GITEA_API_URL}" ]]; then
|
|
||||||
echo "CERC_GITEA_API_URL is not set" >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
if [[ "${CERC_GITEA_MIRROR_REPO}" == "true" ]]; then
|
|
||||||
is_mirror=true
|
|
||||||
else
|
|
||||||
is_mirror=false
|
|
||||||
fi
|
|
||||||
|
|
||||||
gitea_target_org=$(dirname ${repo_to_delete})
|
|
||||||
gitea_target_repo_name=$(basename ${repo_to_delete})
|
|
||||||
# Sanity check the repo name
|
|
||||||
if [[ -z "${gitea_target_org}" ]]; then
|
|
||||||
echo "${repo_to_delete} is not a valid repo name" >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
if [[ -z "${gitea_target_repo_name}" ]]; then
|
|
||||||
echo "${repo_to_delete} is not a valid repo name" >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
echo "****** DELETING repo: ${repo_to_delete}"
|
|
||||||
# Note use: --trace-ascii - \ below to see the raw request
|
|
||||||
delete_response=$( curl -s -X DELETE "${CERC_GITEA_API_URL}/api/v1/repos/${repo_to_delete}" \
|
|
||||||
-H "Authorization: token ${CERC_GITEA_AUTH_TOKEN}" \
|
|
||||||
-H "accept: application/json" \
|
|
||||||
)
|
|
||||||
echo ${delete_response} | jq -r
|
|
||||||
+11
-19
@@ -1,7 +1,13 @@
|
|||||||
|
version: "3"
|
||||||
|
# TODO: remove version since it is now redundant
|
||||||
|
# remove this network definition unless there's a reason for it
|
||||||
|
networks:
|
||||||
|
gitea:
|
||||||
|
external: false
|
||||||
|
|
||||||
services:
|
services:
|
||||||
server:
|
server:
|
||||||
image: gitea/gitea:1.19.3
|
image: gitea/gitea:1.18.3
|
||||||
environment:
|
environment:
|
||||||
- USER_UID=1000
|
- USER_UID=1000
|
||||||
- USER_GID=1000
|
- USER_GID=1000
|
||||||
@@ -13,11 +19,10 @@ services:
|
|||||||
- GITEA__server__HTTP_PORT=3000
|
- GITEA__server__HTTP_PORT=3000
|
||||||
- GITEA__server__LOCAL_ROOT_URL=http://gitea.local:3000/
|
- GITEA__server__LOCAL_ROOT_URL=http://gitea.local:3000/
|
||||||
- GITEA__server__ROOT_URL=http://gitea.local:3000/
|
- GITEA__server__ROOT_URL=http://gitea.local:3000/
|
||||||
- GITEA__actions__ENABLED=true
|
|
||||||
- GITEA__security__INSTALL_LOCK=true
|
- GITEA__security__INSTALL_LOCK=true
|
||||||
restart: always
|
restart: always
|
||||||
extra_hosts:
|
networks:
|
||||||
- "gitea.local:host-gateway"
|
- gitea
|
||||||
volumes:
|
volumes:
|
||||||
- ./gitea:/data
|
- ./gitea:/data
|
||||||
- /etc/timezone:/etc/timezone:ro
|
- /etc/timezone:/etc/timezone:ro
|
||||||
@@ -39,20 +44,7 @@ services:
|
|||||||
# Workaround below for lack of docker uid mapping. Change the container's postgres user's uid/gid to match the host user's
|
# Workaround below for lack of docker uid mapping. Change the container's postgres user's uid/gid to match the host user's
|
||||||
entrypoint: bash
|
entrypoint: bash
|
||||||
command: -c 'usermod -u ${CERC_HOST_UID:-1000} postgres;groupmod -g ${CERC_HOST_GID:-1000} postgres;exec /usr/local/bin/docker-entrypoint.sh postgres'
|
command: -c 'usermod -u ${CERC_HOST_UID:-1000} postgres;groupmod -g ${CERC_HOST_GID:-1000} postgres;exec /usr/local/bin/docker-entrypoint.sh postgres'
|
||||||
|
networks:
|
||||||
|
- gitea
|
||||||
volumes:
|
volumes:
|
||||||
- ./postgres:/var/lib/postgresql/data
|
- ./postgres:/var/lib/postgresql/data
|
||||||
|
|
||||||
runner:
|
|
||||||
image: cerc/act-runner:local
|
|
||||||
restart: always
|
|
||||||
environment:
|
|
||||||
- GITEA_RUNNER_REGISTRATION_TOKEN=eMdEwIzSo87nBh0UFWZlbp308j6TNWr3WhWxQqIc
|
|
||||||
- GITEA_INSTANCE_URL=http://gitea.local:3000
|
|
||||||
- GITEA_RUNNER_LABELS=ubuntu-latest:docker://cerc/act-runner-task-executor:local,ubuntu-22.04:docker://cerc/act-runner-task-executor:local
|
|
||||||
- CONFIG_FILE=/config/act-runner-config.yml
|
|
||||||
extra_hosts:
|
|
||||||
- "gitea.local:host-gateway"
|
|
||||||
volumes:
|
|
||||||
- /var/run/docker.sock:/var/run/docker.sock
|
|
||||||
- ./act-runner:/data
|
|
||||||
- ./config:/config:ro
|
|
||||||
|
|||||||
@@ -7,7 +7,6 @@ GITEA_USER_EMAIL=${GITEA_USER}@example.com
|
|||||||
GITEA_NEW_ORGANIZATION=cerc-io
|
GITEA_NEW_ORGANIZATION=cerc-io
|
||||||
GITEA_URL_PREFIX=http://localhost:3000
|
GITEA_URL_PREFIX=http://localhost:3000
|
||||||
CERC_GITEA_TOKEN_NAME=laconic-so-publication-token
|
CERC_GITEA_TOKEN_NAME=laconic-so-publication-token
|
||||||
CERC_GITEA_RUNNER_REGISTRATION_TOKEN=eMdEwIzSo87nBh0UFWZlbp308j6TNWr3WhWxQqIc
|
|
||||||
if [[ -n "$CERC_SCRIPT_DEBUG" ]]; then
|
if [[ -n "$CERC_SCRIPT_DEBUG" ]]; then
|
||||||
set -x
|
set -x
|
||||||
fi
|
fi
|
||||||
@@ -18,7 +17,8 @@ if [[ -z ${CERC_SO_COMPOSE_PROJECT} ]] ; then
|
|||||||
else
|
else
|
||||||
compose_command="docker compose -p ${CERC_SO_COMPOSE_PROJECT}"
|
compose_command="docker compose -p ${CERC_SO_COMPOSE_PROJECT}"
|
||||||
fi
|
fi
|
||||||
sleep 15
|
# HACK: sleep a bit because gitea may not be up yet (container reports it has started before service is available)
|
||||||
|
sleep 5
|
||||||
${compose_command} exec --user git server gitea admin user list --admin | grep -v -e "^ID" | awk '{ print $2 }' | grep ${GITEA_USER} > /dev/null
|
${compose_command} exec --user git server gitea admin user list --admin | grep -v -e "^ID" | awk '{ print $2 }' | grep ${GITEA_USER} > /dev/null
|
||||||
if [[ $? == 1 ]] ; then
|
if [[ $? == 1 ]] ; then
|
||||||
# Then create if it wasn't found
|
# Then create if it wasn't found
|
||||||
@@ -44,7 +44,7 @@ if [[ ${token_found} != 1 ]] ; then
|
|||||||
new_gitea_token=$( curl -s -X POST "${GITEA_URL_PREFIX}/api/v1/users/${GITEA_USER}/tokens" \
|
new_gitea_token=$( curl -s -X POST "${GITEA_URL_PREFIX}/api/v1/users/${GITEA_USER}/tokens" \
|
||||||
-u ${GITEA_USER}:${GITEA_PASSWORD} \
|
-u ${GITEA_USER}:${GITEA_PASSWORD} \
|
||||||
-H "Content-Type: application/json" \
|
-H "Content-Type: application/json" \
|
||||||
-d '{"name":"'${CERC_GITEA_TOKEN_NAME}'", "scopes": [ "sudo", "package" ] }' \
|
-d '{"name":"'${CERC_GITEA_TOKEN_NAME}'"}' \
|
||||||
| jq -r .sha1 )
|
| jq -r .sha1 )
|
||||||
echo "This is your gitea access token: ${new_gitea_token}. Keep it safe and secure, it can not be fetched again from gitea."
|
echo "This is your gitea access token: ${new_gitea_token}. Keep it safe and secure, it can not be fetched again from gitea."
|
||||||
echo "To use with laconic-so set this environment variable: export CERC_NPM_AUTH_TOKEN=${new_gitea_token}"
|
echo "To use with laconic-so set this environment variable: export CERC_NPM_AUTH_TOKEN=${new_gitea_token}"
|
||||||
@@ -76,10 +76,5 @@ if [[ $? != 0 ]] ; then
|
|||||||
-d '{"username": "'${GITEA_NEW_ORGANIZATION}'"}' > /dev/null
|
-d '{"username": "'${GITEA_NEW_ORGANIZATION}'"}' > /dev/null
|
||||||
echo "Created the organization ${GITEA_NEW_ORGANIZATION}"
|
echo "Created the organization ${GITEA_NEW_ORGANIZATION}"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
|
||||||
# Seed a token for act_runner registration.
|
|
||||||
docker compose -p ${CERC_SO_COMPOSE_PROJECT} exec db psql -U gitea -d gitea -c "INSERT INTO public.action_runner_token(token, owner_id, repo_id, is_active, created, updated, deleted) VALUES('${CERC_GITEA_RUNNER_REGISTRATION_TOKEN}', 0, 0, 'f', 1679000000, 1679000000, NULL);" >/dev/null
|
|
||||||
|
|
||||||
echo "Gitea was configured to use host name: gitea.local, ensure that this resolves to localhost, e.g. with sudo vi /etc/hosts"
|
echo "Gitea was configured to use host name: gitea.local, ensure that this resolves to localhost, e.g. with sudo vi /etc/hosts"
|
||||||
echo "Success, gitea is properly initialized"
|
echo "Success, gitea is properly initialized"
|
||||||
|
|||||||
@@ -1,54 +0,0 @@
|
|||||||
#!/bin/bash
|
|
||||||
|
|
||||||
ORG=$1
|
|
||||||
|
|
||||||
#USERNAME=$1
|
|
||||||
USER_API_URL="https://api.github.com/users/$USERNAME/repos"
|
|
||||||
|
|
||||||
API_URL="https://api.github.com/orgs/$ORG/repos"
|
|
||||||
PAGE=1
|
|
||||||
|
|
||||||
# appears uncoupled from limit of 100 repos
|
|
||||||
PER_PAGE=100
|
|
||||||
|
|
||||||
# Function to retrieve repositories for a given page
|
|
||||||
get_repos() {
|
|
||||||
local page=$1
|
|
||||||
curl -s "$USER_API_URL?page=$page&per_page=$PER_PAGE"
|
|
||||||
}
|
|
||||||
|
|
||||||
# Query GitHub API for the first page of repositories
|
|
||||||
response=$(get_repos $PAGE)
|
|
||||||
|
|
||||||
# Check if organization exists
|
|
||||||
if [[ $response =~ "Not Found" ]]; then
|
|
||||||
echo "Organization not found."
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
# Get total number of repositories
|
|
||||||
total_repos=$(echo "$response" | grep -oE '"full_name": "[^"]+"' | wc -l)
|
|
||||||
|
|
||||||
# Initialize array for repositories
|
|
||||||
repos=()
|
|
||||||
|
|
||||||
# Parse repository names and add to the array
|
|
||||||
repos+=($(echo "$response" | grep -oE '"full_name": "[^"]+"' | awk -F': "' '{print $2}' | tr -d '"'))
|
|
||||||
|
|
||||||
# Calculate number of pages needed
|
|
||||||
num_pages=$((($total_repos + $PER_PAGE - 1) / $PER_PAGE))
|
|
||||||
|
|
||||||
# Loop through the remaining pages and retrieve repositories
|
|
||||||
for ((page=2; page<=num_pages; page++)); do
|
|
||||||
response=$(get_repos $page)
|
|
||||||
repos+=($(echo "$response" | grep -oE '"full_name": "[^"]+"' | awk -F': "' '{print $2}' | tr -d '"'))
|
|
||||||
done
|
|
||||||
|
|
||||||
# Loop through the array and output each repository
|
|
||||||
for repo in "${repos[@]}"; do
|
|
||||||
echo "$repo"
|
|
||||||
bash migrate-repo.sh $repo
|
|
||||||
done
|
|
||||||
|
|
||||||
# Display count of repositories
|
|
||||||
echo "Total Repositories: $total_repos"
|
|
||||||
@@ -1,57 +0,0 @@
|
|||||||
#!/usr/bin/env bash
|
|
||||||
# Script that calls the Giteap API to migrate one repo from
|
|
||||||
# a source hosting platform into that Gitea instance
|
|
||||||
|
|
||||||
if [[ -n "$CERC_SCRIPT_DEBUG" ]]; then
|
|
||||||
set -x
|
|
||||||
fi
|
|
||||||
|
|
||||||
if ! [[ $# -eq 1 ]]; then
|
|
||||||
echo "Illegal number of parameters" >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
repo_to_migrate=$1
|
|
||||||
|
|
||||||
if [[ -z "${CERC_GITEA_AUTH_TOKEN}" ]]; then
|
|
||||||
echo "CERC_GITEA_AUTH_TOKEN is not set" >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
if [[ -z "${CERC_GITEA_API_URL}" ]]; then
|
|
||||||
echo "CERC_GITEA_API_URL is not set" >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
if [[ "${CERC_GITEA_MIRROR_REPO}" == "true" ]]; then
|
|
||||||
is_mirror=true
|
|
||||||
else
|
|
||||||
is_mirror=false
|
|
||||||
fi
|
|
||||||
|
|
||||||
gitea_target_org=$(dirname ${repo_to_migrate})
|
|
||||||
gitea_target_repo_name=$(basename ${repo_to_migrate})
|
|
||||||
# Sanity check the repo name
|
|
||||||
if [[ -z "${gitea_target_org}" ]]; then
|
|
||||||
echo "${repo_to_migrate} is not a valid repo name" >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
if [[ -z "${gitea_target_repo_name}" ]]; then
|
|
||||||
echo "${repo_to_migrate} is not a valid repo name" >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
github_repo_url="https://github.com/${repo_to_migrate}"
|
|
||||||
echo "Migrating repo: ${repo_to_migrate} (mirror:${is_mirror})"
|
|
||||||
# Note use: --trace-ascii - \ below to see the raw request
|
|
||||||
migrate_response=$( curl -s -X POST "${CERC_GITEA_API_URL}/api/v1/repos/migrate" \
|
|
||||||
-H "Authorization: token ${CERC_GITEA_AUTH_TOKEN}" \
|
|
||||||
-H "Content-Type: application/json" \
|
|
||||||
-H "accept: application/json" \
|
|
||||||
-d @- << EOF
|
|
||||||
{
|
|
||||||
"clone_addr": "${github_repo_url}",
|
|
||||||
"mirror": ${is_mirror},
|
|
||||||
"repo_name": "${gitea_target_repo_name}",
|
|
||||||
"repo_owner": "${gitea_target_org}"
|
|
||||||
}
|
|
||||||
EOF
|
|
||||||
)
|
|
||||||
echo Migrated to: $(echo ${migrate_response} | jq -r .html_url)
|
|
||||||
@@ -4,4 +4,3 @@ if [[ -n "$CERC_SCRIPT_DEBUG" ]]; then
|
|||||||
fi
|
fi
|
||||||
mkdir -p ./gitea
|
mkdir -p ./gitea
|
||||||
mkdir -p ./gitea/ssh
|
mkdir -p ./gitea/ssh
|
||||||
mkdir -p ./act-runner
|
|
||||||
|
|||||||
@@ -1,2 +0,0 @@
|
|||||||
# tls-proxy
|
|
||||||
Automated deployment of TLS reverse proxy provisioned with Let's Encrypt certificate
|
|
||||||
@@ -1,27 +0,0 @@
|
|||||||
services:
|
|
||||||
|
|
||||||
proxy:
|
|
||||||
image: nginx:stable-bullseye
|
|
||||||
command: "/bin/sh -c 'while :; do sleep 6h & wait $${!}; nginx -s reload; done & nginx -g \"daemon off;\"'"
|
|
||||||
ports:
|
|
||||||
- 80:80
|
|
||||||
- 443:443
|
|
||||||
volumes:
|
|
||||||
- ./nginx/nginx.conf:/etc/nginx/nginx.conf:ro
|
|
||||||
- ./certbot/challenge:/data/certbot-challenge:ro
|
|
||||||
- ./certbot/certificates:/data/certificates:ro
|
|
||||||
|
|
||||||
certbot:
|
|
||||||
image: certbot/certbot:v2.5.0
|
|
||||||
volumes:
|
|
||||||
- ./certbot/certificates:/etc/letsencrypt
|
|
||||||
- ./certbot/challenge:/data-www-challenge
|
|
||||||
entrypoint: "/bin/sh -c 'sleep 300; trap exit TERM; while :; do certbot renew; sleep 12h & wait $${!}; done;'"
|
|
||||||
|
|
||||||
# Hello-world http container useful for test/debugging the proxy
|
|
||||||
# an actual service would be used for production
|
|
||||||
example-webservice:
|
|
||||||
image: crccheck/hello-world
|
|
||||||
ports:
|
|
||||||
- 8000
|
|
||||||
|
|
||||||
@@ -1,20 +0,0 @@
|
|||||||
#!/usr/bin/env bash
|
|
||||||
if [[ -n "$CERC_SCRIPT_DEBUG" ]]; then
|
|
||||||
set -x
|
|
||||||
fi
|
|
||||||
# TODO: get from the caller
|
|
||||||
LACONIC_TLS_DOMAIN=example.com
|
|
||||||
# When we're called nginx and certbot container are up and running and certbot is sleeping before executing renew
|
|
||||||
# So we can now ask certbot to issue our initial cert
|
|
||||||
tls_certificate_directory=./certbot/certificates/live/${LACONIC_TLS_DOMAIN}
|
|
||||||
rm -rf ${tls_certificate_directory}
|
|
||||||
# TODO: pass in email from caller
|
|
||||||
# TODO: allow staging/dry-run mode
|
|
||||||
docker compose exec certbot \
|
|
||||||
certbot certonly --webroot -w /data-www-challenge \
|
|
||||||
--staging \
|
|
||||||
--email ${EMAIL} \
|
|
||||||
-d ${LACONIC_TLS_DOMAIN} \
|
|
||||||
--rsa-key-size 4096 \
|
|
||||||
--agree-tos \
|
|
||||||
--force-renewal
|
|
||||||
@@ -1,39 +0,0 @@
|
|||||||
events {
|
|
||||||
worker_connections 1024;
|
|
||||||
}
|
|
||||||
|
|
||||||
http {
|
|
||||||
server_tokens off;
|
|
||||||
charset utf-8;
|
|
||||||
|
|
||||||
server {
|
|
||||||
listen 80 default_server;
|
|
||||||
|
|
||||||
server_name _;
|
|
||||||
|
|
||||||
location ~ /.well-known/acme-challenge/ {
|
|
||||||
root /data/certbot-challenge;
|
|
||||||
}
|
|
||||||
|
|
||||||
location / {
|
|
||||||
proxy_pass ${LACONIC_ORIGIN_SERVICE_URL};
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
server {
|
|
||||||
listen 443 ssl http2;
|
|
||||||
ssl_certificate /data/certificates/live/${LACONIC_TLS_DOMAIN}/fullchain.pem;
|
|
||||||
ssl_certificate_key /data/certificates/live/${LACONIC_TLS_DOMAIN}/privkey.pem;
|
|
||||||
server_name ${LACONIC_TLS_DOMAIN};
|
|
||||||
root /var/www/html;
|
|
||||||
index index.php index.html index.htm;
|
|
||||||
|
|
||||||
location / {
|
|
||||||
proxy_pass ${LACONIC_ORIGIN_SERVICE_URL};
|
|
||||||
}
|
|
||||||
|
|
||||||
location ~ /.well-known/acme-challenge/ {
|
|
||||||
root /data/certbot-challenge;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,29 +0,0 @@
|
|||||||
#!/usr/bin/env bash
|
|
||||||
if [[ -n "$CERC_SCRIPT_DEBUG" ]]; then
|
|
||||||
set -x
|
|
||||||
fi
|
|
||||||
set -e
|
|
||||||
mkdir -p ./nginx
|
|
||||||
mkdir -p ./certbot/certificates
|
|
||||||
mkdir -p ./certbot/challenge
|
|
||||||
# TODO: get from the caller
|
|
||||||
LACONIC_TLS_DOMAIN=example.com
|
|
||||||
LACONIC_ORIGIN_SERVICE_URL=http://example-webservice:8000/
|
|
||||||
# Expand the config template into the nginx config file
|
|
||||||
cat ./nginx-config-template | sed 's/${LACONIC_TLS_DOMAIN}/'${LACONIC_TLS_DOMAIN}'/' | \
|
|
||||||
sed 's/${LACONIC_ORIGIN_SERVICE_URL}/'${LACONIC_ORIGIN_SERVICE_URL}'/' > ./nginx/nginx.conf
|
|
||||||
# Create a self-signed cert so nginx will start without us changing its config between pre and post certbot invocation.
|
|
||||||
# Check if we have a cert already
|
|
||||||
tls_certificate_directory=./certbot/certificates/live/${LACONIC_TLS_DOMAIN}
|
|
||||||
tls_certificate_directory_in_container=/etc/letsencrypt/live/${LACONIC_TLS_DOMAIN}
|
|
||||||
tls_certificate_file_name=${tls_certificate_directory}/fullchain.pem
|
|
||||||
# TODO: this won't work if there's a delay of more than one day between generating the
|
|
||||||
# self signed cert and starting the certbot enrollment process
|
|
||||||
if [[ ! -f ${tls_certificate_file_name} ]] ; then
|
|
||||||
echo "Generating self-signed certificate for ${LACONIC_TLS_DOMAIN}:"
|
|
||||||
mkdir -p ${tls_certificate_directory}
|
|
||||||
docker compose run --rm --entrypoint "\
|
|
||||||
openssl req -x509 -nodes -newkey rsa:4096 -days 1 -keyout '${tls_certificate_directory_in_container}/privkey.pem' \
|
|
||||||
-out '${tls_certificate_directory_in_container}/fullchain.pem' -subj '/CN=${LACONIC_TLS_DOMAIN}'" certbot
|
|
||||||
echo
|
|
||||||
fi
|
|
||||||
Reference in New Issue
Block a user