gitoriaLog in with ident

gitoria

All repositories: gitoria

ReadmeCodePull requestsReleasesTicketsSettings
Commitfd981932fd981932State of 2026-09-27; bin/ no longer tracked (Hybriel commit is in README)mrefd981932/docker-compose.yml

2.3 KB

  1. # gitoria.worldapi.org on Byrodin — same pattern as tickets.worldapi.org: ./Dockerfile = debian:12-slim +
  2. # libssl3 + ca-certificates, host network, the app on 127.0.0.1:45004, nginx proxies it and ends TLS
  3. # (the vhost needs the WebSocket Upgrade headers: the live push rides `/`).
  4. # THE VHOST IS A WILDCARD: `server_name gitoria.worldapi.org *.gitoria.worldapi.org;` — every repo
  5. # is <slug>.gitoria.worldapi.org and reaches this one app; the app reads the host in the browser
  6. # (README "How a repo gets its address"). Wildcard DNS + a wildcard certificate are the architect's.
  7. # The whole folder is the bind mount: storage/mpackdb/ and .sessions/ live here and persist.
  8. # LOGIN VIA IDENT: IDENT_API_KEY and IDENT_API_SECRET come from `.env` in this folder (never written
  9. # here). The app is registered in ident with ONE origin, https://gitoria.worldapi.org (repo
  10. # addresses log in through it and come back: README "Login").
  11. # IDENT_EXCHANGE_URL: the server-side code exchange goes straight to ident's loopback port.
  12. services:
  13. gitoria:
  14. container_name: gitoria.worldapi.org
  15. build: .
  16. image: "worldapi-hybriel-runtime:debian12"
  17. working_dir: /home/gitoria
  18. network_mode: host
  19. restart: unless-stopped
  20. environment:
  21. - HL_HOST=127.0.0.1
  22. - GITORIA_PORT=45004
  23. - GITORIA_WATCH=0
  24. - IDENT_EXCHANGE_URL=http://127.0.0.1:45002
  25. - GITORIA_SSH_SECRET=${GITORIA_SSH_SECRET:-}
  26. - GITORIA_SSH_PORT=${GITORIA_SSH_PORT:-2222}
  27. - GITORIA_SSH_HOST=${GITORIA_SSH_HOST:-}
  28. volumes:
  29. - ./:/home/gitoria
  30. command: ./bin/hybriel project.hl
  31. # git over SSH (ticket gitoria#7): sshd that only runs git-upload-pack / git-receive-pack; keys and permissions are asked from the app
  32. # at 127.0.0.1:45004 (docker/sshd). Needs GITORIA_SSH_SECRET in `.env` (any long random text; the app gets the same) — without it SSH is
  33. # not offered on the site. The port must be open in the firewall and DNS must point gitoria.worldapi.org at this host (the architect's).
  34. gitoria-sshd:
  35. container_name: gitoria-sshd
  36. build: ./docker/sshd
  37. network_mode: host
  38. restart: unless-stopped
  39. environment:
  40. - GITORIA_SSH_SECRET=${GITORIA_SSH_SECRET:?set GITORIA_SSH_SECRET in .env}
  41. - GITORIA_SSH_PORT=${GITORIA_SSH_PORT:-2222}
  42. - GITORIA_URL=http://127.0.0.1:45004
  43. volumes:
  44. - ./storage/git:/repos
  45. - ./storage/sshd-hostkeys:/hostkeys

Branches

Latest commits

  • fd981932State of 2026-09-27; bin/ no longer tracked (Hybriel commit is in README)mre
  • 4a2d7125initial commitmre