diff options
author | Renken <renken@shione.net> | 2024-05-27 22:32:36 +0200 |
---|---|---|
committer | Renken <renken@shione.net> | 2024-05-27 22:35:48 +0200 |
commit | 44353ca9862475eb35befcc4cca7dfa318935bda (patch) | |
tree | 9c4e4d48f9fe9cccd83d333c5f41f5777d804274 /images/forgejo/setup.sh | |
parent | a1e2bb5c3a5d16d7b170539f0f0008640f4d1d05 (diff) | |
download | shione-44353ca9862475eb35befcc4cca7dfa318935bda.tar.gz shione-44353ca9862475eb35befcc4cca7dfa318935bda.zip |
feat(containers): self-contained forgejo image
Support for PostgreSQL et al will be added later on.
Diffstat (limited to 'images/forgejo/setup.sh')
-rwxr-xr-x | images/forgejo/setup.sh | 49 |
1 files changed, 49 insertions, 0 deletions
diff --git a/images/forgejo/setup.sh b/images/forgejo/setup.sh new file mode 100755 index 0000000..af46ac5 --- /dev/null +++ b/images/forgejo/setup.sh @@ -0,0 +1,49 @@ +#!/bin/sh + +set -eux + +# Secure forgejo files before anything. +adduser \ + --system \ + --shell /bin/bash \ + --gecos 'Git Version Control' \ + --group \ + --disabled-password \ + --home /home/git git + +mkdir -p /var/lib/forgejo +chown git:git /var/lib/forgejo +chmod 750 /var/lib/forgejo + +mkdir -p /etc/forgejo +chown -R root:git /etc/forgejo + +for file in app.ini lfs_jwt_secret secret_key internal_token oauth2_jwt_secret; do + chmod 0640 /etc/forgejo/"$file" +done + +apt-get update -y + +apt-get upgrade -y + +apt-get --no-install-recommends install -y \ + ca-certificates \ + dirmngr \ + gpg \ + gpg-agent \ + curl \ + git \ + git-lfs \ + systemd + +version=7.0.3 +curl -LO \ + "https://codeberg.org/forgejo/forgejo/releases/download/v$version/forgejo-$version-linux-amd64" +gpg --keyserver keys.openpgp.org --recv EB114F5E6C0DC2BCDD183550A4B61A2DC5923710 +curl -LO \ + "https://codeberg.org/forgejo/forgejo/releases/download/v$version/forgejo-$version-linux-amd64.asc" +gpg --verify forgejo-$version-linux-amd64.asc forgejo-$version-linux-amd64 + + +chmod +x "forgejo-$version-linux-amd64" +mv "forgejo-$version-linux-amd64" /usr/local/bin/forgejo |