app: id: gitea name: Gitea version: "1.27.3" # Where this app comes from, so scripts/check-upstream-releases.py can # tell us when the pin below has fallen behind. Without it nothing can: # container.image names our mirror, not the project it was mirrored from. upstream: kind: github repo: go-gitea/gitea description: Self-hosted Git service with built-in container registry, CI/CD, and package hosting. category: development container: image: source.archipelago-foundation.org/lfg2025/gitea:1.27.3 pull_policy: if-not-present # Preserve repositories, database, keys and configuration during runtime repairs. backup_before_runtime_change: true dependencies: # Source history, LFS objects, release artifacts and OCI layers all share # this persistent store. 500Mi was only suitable for an empty demo node. - storage: 50Gi resources: memory_limit: 256Mi disk_limit: 50Gi security: capabilities: [CHOWN, FOWNER, SETUID, SETGID, DAC_OVERRIDE, NET_BIND_SERVICE, SYS_CHROOT] readonly_root: false no_new_privileges: false network_policy: bridge ports: - host: 3001 container: 3000 protocol: tcp bind: 127.0.0.1 # open, not gated: Gitea carries a complete login of its own, and git # clients speak HTTP basic-auth — a cookie challenge in front of # git-over-HTTP breaks every clone/push. The gate still fronts the # port (iframe header fixes, retry page, Tor); the operator can force # the dashboard login back on from Settings → Gitea → Access control. auth: open auth_rationale: >- Gitea enforces its own account login on every page and API route; git clients authenticate with basic-auth/tokens and cannot complete a browser login challenge. - host: 2222 container: 22 protocol: tcp auth: none auth_rationale: >- Git over SSH, authenticated by the user's own SSH keypair. Not HTTP, so the gate cannot serve a login page here. volumes: - type: bind source: /var/lib/archipelago/gitea/data target: /data options: [rw] - type: bind source: /var/lib/archipelago/gitea/config target: /etc/gitea options: [rw] # Seed a fresh installation with the same origin advertised by the app gate. # Existing app.ini (including custom HTTPS/domain settings) is never replaced. files: - path: /var/lib/archipelago/gitea/data/gitea/conf/app.ini overwrite: false content: | [server] DOMAIN = {{HOST_IP}} SSH_DOMAIN = {{HOST_IP}} ROOT_URL = http://{{HOST_IP}}:3001/ environment: - GITEA__database__DB_TYPE=sqlite3 - GITEA__server__SSH_PORT=2222 - GITEA__server__SSH_LISTEN_PORT=22 - GITEA__server__LFS_START_SERVER=true - GITEA__packages__ENABLED=true # Package/LFS storage remains bounded by the node's disk, not an arbitrary # per-owner quota. Release artifacts allow installer/OTA images up to 10GiB. - GITEA__packages__LIMIT_TOTAL_OWNER_SIZE=-1 - GITEA__packages__LIMIT_SIZE_CONTAINER=-1 - GITEA__repository_0x2Erelease__FILE_MAX_SIZE=10240 - GITEA__repository_0x2Erelease__MAX_FILES=20 - GITEA__repository__ENABLE_PUSH_CREATE_USER=true - GITEA__repository__ENABLE_PUSH_CREATE_ORG=true health_check: type: http endpoint: http://localhost:3000 path: / interval: 120s timeout: 30s retries: 5 interfaces: main: name: Web UI description: Gitea web interface type: ui port: 3001 protocol: http path: / metadata: icon: /assets/img/app-icons/gitea.svg repo: https://gitea.com tier: optional launch: open_in_new_tab: true features: - Git repositories with web UI - Built-in container/package registry - Issue tracking and pull requests - CI/CD via Gitea Actions - Lightweight SQLite deployment