Skip to content

feat(deploy): git.chovy.com, a public Forgejo forge on chovy's build host - #134

Merged
ralyodio merged 2 commits into
mainfrom
feat/git-chovy-forgejo
Oct 1, 2026
Merged

ralyodio merged 2 commits into
mainfrom
feat/git-chovy-forgejo

Conversation

@ralyodio

@ralyodio ralyodio commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Adds deploy/git-chovy/install.sh, which stands up https://git.chovy.com on dev.chovy.com the same way AgentGit runs git.profullstack.com (setup.sh §9d). It is already live: this is the script that built it, rerun cleanly to prove it is idempotent.

Same as AgentGit: Forgejo binary + systemd, SQLite, loopback HTTP behind the host proxy, built-in SSH on :2222, DISABLE_REGISTRATION = true, REQUIRE_SIGNIN_VIEW = false, no mailer, no backup job (setup.sh has none).

Different, because of the host:

  • dev.chovy.com's nginx already owns :80/:443 and serves chovy's customer apps, so the script adds one exact-name vhost (sites-available/git.chovy.com) and edits no other one. It runs nginx -t before every reload and puts the old file back if that fails. Any vhost it replaces is backed up first as .bak-NNN.
  • The cert comes from certbot http-01 into /var/www/acme, the webroot chovy already uses, with a deploy hook that reloads nginx.
  • Forgejo listens on 127.0.0.1:3010 because :3000 is taken there. MemoryMax=2G (MemoryHigh 1.5G) keeps it from starving chovy's builds.
  • Branding is APP_NAME = chovy git, with chovy's mark as the logo and favicon.
  • Forgejo is pinned to 11.0.15, the same as setup.sh. git.profullstack.com itself still reports 11.0.1.

Bug found along the way: with SSH_USER = git alone, Forgejo advertises git@ clone URLs, but its built-in server only accepts BUILTIN_SSH_SERVER_USER, which defaults to RUN_USER (forgejo). It refuses with Invalid SSH username git. This script sets the key, and it also patches an existing app.ini. setup.sh's AgentGit app.ini has the same gap, so git.profullstack.com would still refuse git@ even once :2222 is reachable. That is left for a separate change.

Verified live: https://git.chovy.com returns 200 with a Let's Encrypt cert, and /api/v1/version reports 11.0.15+gitea-1.22.0. Anonymous explore works and sign-up shows "Registration is disabled". I created a public repo through the API, cloned it anonymously over HTTPS, cloned it over ssh://git@git.chovy.com:2222/..., and pushed over both SSH and HTTPS. Then I deleted the repo and the throwaway key. chovy.com, a customer custom-domain app, a dev preview app, dev.chovy.com and mcp.profullstack.com all still return 200, and the platform root key is still in place.

🤖 Generated with Claude Code

…host

deploy/git-chovy/install.sh brings up the AgentGit recipe (setup.sh section
9d) on dev.chovy.com: the Forgejo 11.0.15 binary under systemd, SQLite,
loopback HTTP, built-in SSH on :2222, registration off, anonymous read of
public repos on. It is idempotent and has been run live.

Differences forced by that host: it adds one exact-name vhost to the
existing nginx (which serves chovy's customer apps) instead of a Caddy
block, validating with nginx -t and restoring on failure; certbot http-01
into chovy's /var/www/acme webroot; 127.0.0.1:3010 since :3000 is taken;
MemoryMax=2G so the forge cannot starve builds; chovy's mark as the logo.

Also sets BUILTIN_SSH_SERVER_USER = git. Without it Forgejo's built-in SSH
server only accepts the RUN_USER name and refuses git@ ("Invalid SSH
username git"), although SSH_USER = git advertises git@ clone URLs.
setup.sh's AgentGit app.ini has the same gap; not changed here.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Comment thread deploy/git-chovy/install.sh Fixed
Comment thread deploy/git-chovy/install.sh Fixed
@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

ThreatCrush Security Scan

10 finding(s)

HIGH/CRITICAL: 7 | LOW: 3

Severity Rule Location
HIGH secret-generic-credential deploy/ergo/ircd.yaml:162
HIGH secret-generic-credential deploy/ergo/ircd.yaml:221
HIGH secret-generic-credential deploy/ergo/ircd.yaml:638
HIGH secret-generic-credential deploy/ergo/ircd.yaml:787
HIGH secret-database-url deploy/ergo/ircd.yaml:893
HIGH secret-generic-credential deploy/ergo/ircd.yaml:1025
HIGH secret-generic-credential deploy/ergo/ircd.yaml:1033
LOW secret-generic-credential deploy/ergo/ircd.yaml:772
LOW tls-verification-disabled internal/mail/mail.go:109
LOW secret-generic-credential internal/mailu/mailu_test.go:44

Snippets are redacted; ThreatCrush never prints matched credential material.

ThreatCrush flags any curl to an http:// URL (CWE-319). The probe was
loopback-only, but ss answers the same question without an HTTP request.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@ralyodio
ralyodio merged commit 2537977 into main Oct 1, 2026
6 checks passed
@ralyodio
ralyodio deleted the feat/git-chovy-forgejo branch October 1, 2026 09:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants