From 0a4119880ee0b05bc2d1d8ec7ae1c306d01243c5 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Mon, 11 May 2026 18:13:54 -0400 Subject: [PATCH] Update README for ALB-backed HTTPS setup --- README.md | 22 ++++++++++++---------- 1 file changed, 12 insertions(+), 10 deletions(-) diff --git a/README.md b/README.md index c05eda8..a4dfb9e 100644 --- a/README.md +++ b/README.md @@ -1,23 +1,23 @@ # forgejo -Self-hosted Forgejo git server for archiving GitHub repos and mirroring active ones. Runs on a single EC2 instance within the Sea Haven VPC, accessible only via VPN. +Self-hosted Forgejo git server for archiving GitHub repos and mirroring active ones. Runs on a single EC2 instance within the Sea Haven VPC, fronted by the `seahaven-com` ALB for HTTPS. ## Architecture - **EC2**: t4g.small (arm64), Amazon Linux 2023, 50GB gp3 EBS -- **Network**: Private subnet (us-east-1a), VPC + VPN access only -- **DNS**: `forgejo.seahaven.com` (Route53 A record → private IP) +- **Network**: Private subnet (us-east-1a), behind `seahaven-com` ALB for SSL termination +- **DNS**: `forgejo.seahaven.com` (Route53 alias → ALB) +- **TLS**: Wildcard cert on ALB, HTTP internally on port 3000 - **Backup**: Nightly EBS snapshots via DLM, 7-day retention - **Admin access**: SSM Session Manager (no SSH port exposed) ### Ports -| Port | Protocol | Purpose | -|------|----------|---------| -| 3000 | HTTP | Web UI + HTTP git clone | -| 2222 | SSH | Git SSH operations | - -Both ports are restricted to VPC (10.20.0.0/16) and office VPN (10.10.0.0/16). +| Port | Protocol | Source | Purpose | +|------|----------|--------|---------| +| 443 | HTTPS | ALB (public) | Web UI + HTTP git clone | +| 3000 | HTTP | ALB → instance | Internal traffic from ALB | +| 2222 | SSH | VPC + VPN | Git SSH operations | ## First-time setup @@ -34,7 +34,9 @@ sudo -u forgejo /usr/local/bin/forgejo admin user create \ --config /etc/forgejo/app.ini ``` -Then access the web UI at `http://forgejo.seahaven.com:3000`. +Admin password is stored in Secrets Manager at `forgejo/admin-password`. + +Access the web UI at `https://forgejo.seahaven.com`. ## Migrating repos from GitHub