feat(gitea): add LXC install script + README
New gitea/install.sh, modeled on openbao/install.sh's single-entrypoint three-mode pattern. Installs via `apk add gitea gitea-openrc` rather than a downloaded release binary: dl.gitea.com ships glibc/CGO-linked binaries, a bad fit for musl. check_gitea_channel() re-verifies on every install that the package is available via community (not edge) rather than trusting that to stay true. app.ini is owned exclusively by ini_set (#18) — never a heredoc overwrite — so a rejoué script adds newly-required keys without clobbering operator changes elsewhere in the file. INSTALL_LOCK is set before the service's first start so the web installer is never exposed. The Prometheus metrics token and admin account are each created once and left alone on reruns. gitea.log is forwarded to the proxy's rsyslog receiver (#20) tagged "gitea", scoped so the LXC's own local syslog traffic is never forwarded — a jail running in this LXC would only ever see the proxy's tailnet IP and end up banning the proxy itself. Root README's script table gets a line for the new script. Refs #19
This commit is contained in:
@@ -22,6 +22,7 @@ These scripts automate the deployment of personal infrastructure components. The
|
||||
| [`proxy/install.sh`](proxy/) | Reverse proxy with Tailscale + Nginx Proxy Manager | `curl -fsSL https://gitea.arnodo.fr/Damien/infra-scripts/raw/branch/main/proxy/install.sh` \| `bash` |
|
||||
| [`netlab/install.sh`](netlab/) | Network lab with ContainerLab | `curl -fsSL https://gitea.arnodo.fr/Damien/infra-scripts/raw/branch/main/netlab/install.sh` \| `bash` |
|
||||
| [`gitea-runner/install.sh`](gitea-runner/) | Gitea Act Runner on Alpine LXC (Proxmox) | `bash -c "$(curl -fsSL https://gitea.arnodo.fr/Damien/infra-scripts/raw/branch/main/gitea-runner/install.sh)"` |
|
||||
| [`gitea/install.sh`](gitea/) | Gitea Git service on Alpine LXC (Proxmox) | `bash -c "$(curl -fsSL https://gitea.arnodo.fr/Damien/infra-scripts/raw/branch/main/gitea/install.sh)"` |
|
||||
| [`openbao/install.sh`](openbao/) | OpenBao secrets manager on Alpine LXC (Proxmox) | `bash -c "$(curl -fsSL https://gitea.arnodo.fr/Damien/infra-scripts/raw/branch/main/openbao/install.sh)"` |
|
||||
| [`komodo/install.sh`](komodo/) | Komodo (Docker + MongoDB) on Alpine VM | `bash -c "$(curl -fsSL https://gitea.arnodo.fr/Damien/infra-scripts/raw/branch/main/komodo/install.sh)"` |
|
||||
|
||||
|
||||
Reference in New Issue
Block a user