diff --git a/.env.example b/.env.example index 7fe4886..9549401 100644 --- a/.env.example +++ b/.env.example @@ -3,7 +3,7 @@ GITEA_DOMAIN=git.example.com LETSENCRYPT_EMAIL=admin@example.com HTTP_PORT=8680 HTTPS_PORT=8643 -GITEA_SSH_PORT=2222 +GITEA_HTTP_PORT=3000 # letsencrypt: manage a certificate automatically with Certbot. # custom: read the named certificate files from ./config/ssl. diff --git a/README.md b/README.md index e2b875b..d8c2725 100644 --- a/README.md +++ b/README.md @@ -14,7 +14,7 @@ The production layout is a self-contained, single-VM Docker deployment: - explicit runtime storage under `config/` beside the Compose files No external database or load balancer is required. The datacenter edge only -needs to forward TCP 80, 443, and 2222 to the Docker VM. +needs to forward public TCP 80 and 443 to the configured Docker VM ports. See [docs/deployment.md](docs/deployment.md) for the installation, Gitea setup, TLS bootstrap, repository move, renewal, backup, and update procedures. The diff --git a/compose.yaml b/compose.yaml index b18052a..3daae12 100644 --- a/compose.yaml +++ b/compose.yaml @@ -2,6 +2,7 @@ name: tapm services: broker: + container_name: tapm-broker build: . image: tai/tapm-deployment-broker:local env_file: @@ -55,4 +56,5 @@ services: networks: edge: + external: true name: tapm-edge diff --git a/deploy/gitea/compose.yaml b/deploy/gitea/compose.yaml index 422a8a3..04e6eb9 100644 --- a/deploy/gitea/compose.yaml +++ b/deploy/gitea/compose.yaml @@ -2,6 +2,7 @@ name: tapm-gitea services: gitea: + container_name: tapm-gitea image: docker.gitea.com/gitea:1.26.4-rootless restart: unless-stopped env_file: @@ -10,7 +11,7 @@ services: networks: - edge ports: - - "${GITEA_SSH_PORT:-2222}:2222" + - "${GITEA_HTTP_PORT:-3000}:3000" volumes: - ../../config/gitea/data:/var/lib/gitea - ../../config/gitea/config:/etc/gitea @@ -19,10 +20,7 @@ services: GITEA__database__PATH: /var/lib/gitea/data/gitea.db GITEA__server__DOMAIN: ${GITEA_DOMAIN} GITEA__server__ROOT_URL: https://${GITEA_DOMAIN}/ - GITEA__server__SSH_DOMAIN: ${GITEA_DOMAIN} - GITEA__server__SSH_PORT: ${GITEA_SSH_PORT:-2222} - GITEA__server__START_SSH_SERVER: "true" - GITEA__server__SSH_LISTEN_PORT: "2222" + GITEA__server__DISABLE_SSH: "true" GITEA__service__DISABLE_REGISTRATION: "true" GITEA__security__INSTALL_LOCK: "true" security_opt: diff --git a/docs/deployment.md b/docs/deployment.md index 4456511..a3fe15f 100644 --- a/docs/deployment.md +++ b/docs/deployment.md @@ -11,17 +11,17 @@ It consists of four containers: - Nginx, terminating TLS for the broker and Gitea - Certbot, run on demand for certificate issuance and renewal -Only the configured Nginx HTTP/HTTPS ports and Gitea SSH port are published. -They default to 8680, 8643, and 2222. Inside Docker, Nginx continues to listen -on ports 80 and 443. The broker and Gitea HTTP services are reachable only on -the private `tapm-edge` Docker network. +The configured Nginx HTTP/HTTPS ports and Gitea HTTP port are published. They +default to 8680, 8643, and 3000. Inside Docker, Nginx continues to listen on +ports 80 and 443 and Gitea listens on port 3000. Gitea SSH is disabled. ## 1. VM and network -Install Docker Engine with Compose v2. Permit the selected HTTP, HTTPS, and SSH -ports and forward public TCP 80, 443, and the selected SSH port from the -datacenter edge to them. Create public DNS A/AAAA records for both application -names before requesting the certificate. +Install Docker Engine with Compose v2. Permit the selected HTTP and HTTPS ports +and forward public TCP 80 and 443 from the datacenter edge to them. The +`GITEA_HTTP_PORT` binding is intended for direct local or management access and +should be firewalled from untrusted networks. Create public DNS A/AAAA records +for both application names before requesting the certificate. Public port 80 must reach the container's port 80 for HTTP-01 certificate renewal. For example, if `HTTP_PORT=8080`, the edge must forward public port 80 @@ -41,8 +41,9 @@ chmod 600 .env Set `BROKER_DOMAIN`, `GITEA_DOMAIN`, and `LETSENCRYPT_EMAIL` first. `HTTP_PORT` and `HTTPS_PORT` control the VM-side Docker bindings and default to 8680 and 8643. The datacenter edge should therefore forward public ports 80 and 443 to -VM ports 8680 and 8643. Replace all example domains in the TAPM variables. -Generate the cookie secret with: +VM ports 8680 and 8643. `GITEA_HTTP_PORT` controls the host binding for Gitea's +port 3000 and defaults to 3000. Replace all example domains in the TAPM +variables. Generate the cookie secret with: ```sh openssl rand -base64 48 @@ -129,7 +130,7 @@ Gitea and mirror all refs: ```sh git clone --mirror OLD-REPOSITORY-URL cd REPOSITORY.git -git push --mirror ssh://git@GITEA_DOMAIN:2222/TAI/REPOSITORY.git +git push --mirror https://GITEA_DOMAIN/TAI/REPOSITORY.git ``` Update developer remotes, CI credentials, submodules, documentation, and the Go