From 4901314cdceeee0516431729b98dfb96087617ea Mon Sep 17 00:00:00 2001 From: anorien90 Date: Wed, 3 Dec 2025 11:32:08 +0000 Subject: [PATCH] added base files --- conf/app.ini | 84 +++++++++++++++++++++++++++++++++ config.yaml | 113 +++++++++++++++++++++++++++++++++++++++++++++ docker-compose.yml | 52 +++++++++++++++++++++ logs/README.md | 1 + 4 files changed, 250 insertions(+) create mode 100644 conf/app.ini create mode 100644 config.yaml create mode 100644 docker-compose.yml create mode 100644 logs/README.md diff --git a/conf/app.ini b/conf/app.ini new file mode 100644 index 0000000..f5ef9ec --- /dev/null +++ b/conf/app.ini @@ -0,0 +1,84 @@ +APP_NAME = nxs.solutions +RUN_USER = git +WORK_PATH = /data/gitea +RUN_MODE = prod + +[log] +logger.router.MODE = +logger.access.MODE = access-file +MODE = console +LEVEL = info +ROOT_PATH = /data/gitea/log + +[log.access-file] +MODE = file +LEVEL = Warn +FILE_NAME = access.log + +[database] +DB_TYPE = sqlite3 +HOST = 127.0.0.1:3306 +NAME = gitea +USER = gitea +PASSWD = +SCHEMA = +SSL_MODE = disable +PATH = /data/gitea/data/gitea.db +LOG_SQL = false + +[repository] +ROOT = /data/gitea/data/gitea-repositories + +[server] +SSH_DOMAIN = git.nxs.solutions +DOMAIN = git.nxs.solutions +HTTP_PORT = 3000 +ROOT_URL = https://git.nxs.solutions/ +APP_DATA_PATH = /data/gitea/data +DISABLE_SSH = false +SSH_PORT = 22 +LFS_START_SERVER = true +LFS_JWT_SECRET = N7_c4dACvWqfNLo75PI9OrxqKVPJ5doVyNKxLlyY-c4 +OFFLINE_MODE = true + +[lfs] +PATH = /data/gitea/data/lfs + +[mailer] +ENABLED = false + +[service] +REGISTER_EMAIL_CONFIRM = false +ENABLE_NOTIFY_MAIL = false +DISABLE_REGISTRATION = false +ALLOW_ONLY_EXTERNAL_REGISTRATION = false +ENABLE_CAPTCHA = false +REQUIRE_SIGNIN_VIEW = false +DEFAULT_KEEP_EMAIL_PRIVATE = false +DEFAULT_ALLOW_CREATE_ORGANIZATION = true +DEFAULT_ENABLE_TIMETRACKING = true +NO_REPLY_ADDRESS = noreply.localhost + +[openid] +ENABLE_OPENID_SIGNIN = true +ENABLE_OPENID_SIGNUP = true + +[cron.update_checker] +ENABLED = false + +[session] +PROVIDER = file + +[repository.pull-request] +DEFAULT_MERGE_STYLE = merge + +[repository.signing] +DEFAULT_TRUST_MODEL = committer + +[security] +INSTALL_LOCK = true +INTERNAL_TOKEN = eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJuYmYiOjE3NjQ2MDQxMDZ9.G2cJPI_OpO43cMdAF6tHGBKNfXs9kt2AuyyyMBB9R8Q +PASSWORD_HASH_ALGO = pbkdf2 + +[oauth2] +JWT_SECRET = WSWVvUpIQ6mC1ir2O6efBP0jMaC0mi8OjwZVWUpj5W0 diff --git a/config.yaml b/config.yaml new file mode 100644 index 0000000..11b503f --- /dev/null +++ b/config.yaml @@ -0,0 +1,113 @@ +# Example configuration file, it's safe to copy this as the default config file without any modification. + +# You don't have to copy this file to your instance, +# just run `./act_runner generate-config > config.yaml` to generate a config file. + +log: + # The level of logging, can be trace, debug, info, warn, error, fatal + level: info + +runner: + # Where to store the registration result. + file: .runner + # Execute how many tasks concurrently at the same time. + capacity: 1 + # Extra environment variables to run jobs. + envs: + A_TEST_ENV_NAME_1: a_test_env_value_1 + A_TEST_ENV_NAME_2: a_test_env_value_2 + # Extra environment variables to run jobs from a file. + # It will be ignored if it's empty or the file doesn't exist. + env_file: .env + # The timeout for a job to be finished. + # Please note that the Gitea instance also has a timeout (3h by default) for the job. + # So the job could be stopped by the Gitea instance if it's timeout is shorter than this. + timeout: 3h + # The timeout for the runner to wait for running jobs to finish when shutting down. + # Any running jobs that haven't finished after this timeout will be cancelled. + shutdown_timeout: 0s + # Whether skip verifying the TLS certificate of the Gitea instance. + insecure: false + # The timeout for fetching the job from the Gitea instance. + fetch_timeout: 5s + # The interval for fetching the job from the Gitea instance. + fetch_interval: 2s + # The github_mirror of a runner is used to specify the mirror address of the github that pulls the action repository. + # It works when something like `uses: actions/checkout@v4` is used and DEFAULT_ACTIONS_URL is set to github, + # and github_mirror is not empty. In this case, + # it replaces https://github.com with the value here, which is useful for some special network environments. + github_mirror: '' + # The labels of a runner are used to determine which jobs the runner can run, and how to run them. + # Like: "macos-arm64:host" or "ubuntu-latest:docker://docker.gitea.com/runner-images:ubuntu-latest" + # Find more images provided by Gitea at https://gitea.com/docker.gitea.com/runner-images . + # If it's empty when registering, it will ask for inputting labels. + # If it's empty when execute `daemon`, will use labels in `.runner` file. + labels: + - "ubuntu-latest:docker://docker.gitea.com/runner-images:ubuntu-latest" + - "ubuntu-22.04:docker://docker.gitea.com/runner-images:ubuntu-22.04" + - "ubuntu-20.04:docker://docker.gitea.com/runner-images:ubuntu-20.04" + +cache: + # Enable cache server to use actions/cache. + enabled: true + # The directory to store the cache data. + # If it's empty, the cache data will be stored in $HOME/.cache/actcache. + dir: "" + # The host of the cache server. + # It's not for the address to listen, but the address to connect from job containers. + # So 0.0.0.0 is a bad choice, leave it empty to detect automatically. + host: "" + # The port of the cache server. + # 0 means to use a random available port. + port: 0 + # The external cache server URL. Valid only when enable is true. + # If it's specified, act_runner will use this URL as the ACTIONS_CACHE_URL rather than start a server by itself. + # The URL should generally end with "/". + external_server: "" + +container: + # Specifies the network to which the container will connect. + # Could be host, bridge or the name of a custom network. + # If it's empty, act_runner will create a network automatically. + network: "" + # Whether to use privileged mode or not when launching task containers (privileged mode is required for Docker-in-Docker). + privileged: true + # And other options to be used when the container is started (eg, --add-host=my.gitea.url:host-gateway). + options: + # The parent directory of a job's working directory. + # NOTE: There is no need to add the first '/' of the path as act_runner will add it automatically. + # If the path starts with '/', the '/' will be trimmed. + # For example, if the parent directory is /path/to/my/dir, workdir_parent should be path/to/my/dir + # If it's empty, /workspace will be used. + workdir_parent: + # Volumes (including bind mounts) can be mounted to containers. Glob syntax is supported, see https://github.com/gobwas/glob + # You can specify multiple volumes. If the sequence is empty, no volumes can be mounted. + # For example, if you only allow containers to mount the `data` volume and all the json files in `/src`, you should change the config to: + # valid_volumes: + # - data + # - /src/*.json + # If you want to allow any volume, please use the following configuration: + # valid_volumes: + # - '**' + valid_volumes: [ + /prod/* + ] + + # overrides the docker client host with the specified one. + # If it's empty, act_runner will find an available docker host automatically. + # If it's "-", act_runner will find an available docker host automatically, but the docker host won't be mounted to the job containers and service containers. + # If it's not empty or "-", the specified docker host will be used. An error will be returned if it doesn't work. + docker_host: "" + # Pull docker image(s) even if already present + force_pull: true + # Rebuild docker image(s) even if already present + force_rebuild: false + # Always require a reachable docker daemon, even if not required by act_runner + require_docker: false + # Timeout to wait for the docker daemon to be reachable, if docker is required by require_docker or act_runner + docker_timeout: 0s + +host: + # The parent directory of a job's working directory. + # If it's empty, $HOME/.cache/act/ will be used. + workdir_parent: diff --git a/docker-compose.yml b/docker-compose.yml new file mode 100644 index 0000000..8b659c8 --- /dev/null +++ b/docker-compose.yml @@ -0,0 +1,52 @@ +services: + runner: + image: docker.io/gitea/act_runner:nightly + environment: + CONFIG_FILE: /config.yaml + GITEA_INSTANCE_URL: http://gitea:3000/ + GITEA_RUNNER_REGISTRATION_TOKEN: znrn4iy94Zx2OWwQx4UHkdWMOH6ISBQ6NVfdkf4K + GITEA_RUNNER_NAME: FastFlaskRunner + volumes: + - ./config.yaml:/config.yaml + - /prod/pkgs:/prod/pkgs + - /prod/data:/prod/data + - /prod/develop/data:/develop/data + - /var/run/docker.sock:/var/run/docker.sock + depends_on: + - gitea + restart: always + networks: + - fast-services + + gitea: + image: gitea/gitea:latest + container_name: gitea + restart: always + environment: + - ROOT_URL=https://git.nxs.solutions/ + # Map container ports to host ports (Web UI: 3000, SSH: 2222) + ports: + - "2222:22" + volumes: + # Persistent storage for Gitea data, configuration, repositories, etc. + # Maps a named volume 'gitea_data' to the container's /data directory. + - ./data:/data + # Timezone settings for consistent timekeeping + - /etc/timezone:/etc/timezone:ro + - /etc/localtime:/etc/localtime:ro + - /srv/git:/data/host_repos:ro # <--- ADD THIS LINE + - ./logs/:/data/gitea/log/:rw + + networks: + - fast-services + + healthcheck: + test: ["CMD", "curl", "-f", "http://localhost:3000/"] + interval: 1m30s + timeout: 10s + retries: 3 + + +networks: + fast-services: + external: true diff --git a/logs/README.md b/logs/README.md new file mode 100644 index 0000000..3fd8ee3 --- /dev/null +++ b/logs/README.md @@ -0,0 +1 @@ +# Logging directory for gitea