feat(deploy): git.chovy.com, a public Forgejo forge on chovy's build host - #134
Merged
Merged
Conversation
…host
deploy/git-chovy/install.sh brings up the AgentGit recipe (setup.sh section
9d) on dev.chovy.com: the Forgejo 11.0.15 binary under systemd, SQLite,
loopback HTTP, built-in SSH on :2222, registration off, anonymous read of
public repos on. It is idempotent and has been run live.
Differences forced by that host: it adds one exact-name vhost to the
existing nginx (which serves chovy's customer apps) instead of a Caddy
block, validating with nginx -t and restoring on failure; certbot http-01
into chovy's /var/www/acme webroot; 127.0.0.1:3010 since :3000 is taken;
MemoryMax=2G so the forge cannot starve builds; chovy's mark as the logo.
Also sets BUILTIN_SSH_SERVER_USER = git. Without it Forgejo's built-in SSH
server only accepts the RUN_USER name and refuses git@ ("Invalid SSH
username git"), although SSH_USER = git advertises git@ clone URLs.
setup.sh's AgentGit app.ini has the same gap; not changed here.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
ThreatCrush Security Scan10 finding(s) HIGH/CRITICAL: 7 | LOW: 3
Snippets are redacted; ThreatCrush never prints matched credential material. |
ThreatCrush flags any curl to an http:// URL (CWE-319). The probe was loopback-only, but ss answers the same question without an HTTP request. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds
deploy/git-chovy/install.sh, which stands up https://git.chovy.com on dev.chovy.com the same way AgentGit runs git.profullstack.com (setup.sh §9d). It is already live: this is the script that built it, rerun cleanly to prove it is idempotent.Same as AgentGit: Forgejo binary + systemd, SQLite, loopback HTTP behind the host proxy, built-in SSH on
:2222,DISABLE_REGISTRATION = true,REQUIRE_SIGNIN_VIEW = false, no mailer, no backup job (setup.sh has none).Different, because of the host:
sites-available/git.chovy.com) and edits no other one. It runsnginx -tbefore every reload and puts the old file back if that fails. Any vhost it replaces is backed up first as.bak-NNN./var/www/acme, the webroot chovy already uses, with a deploy hook that reloads nginx.127.0.0.1:3010because :3000 is taken there.MemoryMax=2G(MemoryHigh1.5G) keeps it from starving chovy's builds.APP_NAME = chovy git, with chovy's mark as the logo and favicon.Bug found along the way: with
SSH_USER = gitalone, Forgejo advertisesgit@clone URLs, but its built-in server only acceptsBUILTIN_SSH_SERVER_USER, which defaults to RUN_USER (forgejo). It refuses withInvalid SSH username git. This script sets the key, and it also patches an existing app.ini. setup.sh's AgentGit app.ini has the same gap, so git.profullstack.com would still refusegit@even once :2222 is reachable. That is left for a separate change.Verified live:
https://git.chovy.comreturns 200 with a Let's Encrypt cert, and/api/v1/versionreports11.0.15+gitea-1.22.0. Anonymous explore works and sign-up shows "Registration is disabled". I created a public repo through the API, cloned it anonymously over HTTPS, cloned it overssh://git@git.chovy.com:2222/..., and pushed over both SSH and HTTPS. Then I deleted the repo and the throwaway key. chovy.com, a customer custom-domain app, a dev preview app, dev.chovy.com and mcp.profullstack.com all still return 200, and the platform root key is still in place.🤖 Generated with Claude Code