mirror of
https://github.com/Sea-Haven-Industries/forgejo.git
synced 2026-09-30 07:43:11 +00:00
Update README for ALB-backed HTTPS setup
This commit is contained in:
parent
ed41fd4eac
commit
0a4119880e
1 changed files with 12 additions and 10 deletions
22
README.md
22
README.md
|
|
@ -1,23 +1,23 @@
|
||||||
# forgejo
|
# forgejo
|
||||||
|
|
||||||
Self-hosted Forgejo git server for archiving GitHub repos and mirroring active ones. Runs on a single EC2 instance within the Sea Haven VPC, accessible only via VPN.
|
Self-hosted Forgejo git server for archiving GitHub repos and mirroring active ones. Runs on a single EC2 instance within the Sea Haven VPC, fronted by the `seahaven-com` ALB for HTTPS.
|
||||||
|
|
||||||
## Architecture
|
## Architecture
|
||||||
|
|
||||||
- **EC2**: t4g.small (arm64), Amazon Linux 2023, 50GB gp3 EBS
|
- **EC2**: t4g.small (arm64), Amazon Linux 2023, 50GB gp3 EBS
|
||||||
- **Network**: Private subnet (us-east-1a), VPC + VPN access only
|
- **Network**: Private subnet (us-east-1a), behind `seahaven-com` ALB for SSL termination
|
||||||
- **DNS**: `forgejo.seahaven.com` (Route53 A record → private IP)
|
- **DNS**: `forgejo.seahaven.com` (Route53 alias → ALB)
|
||||||
|
- **TLS**: Wildcard cert on ALB, HTTP internally on port 3000
|
||||||
- **Backup**: Nightly EBS snapshots via DLM, 7-day retention
|
- **Backup**: Nightly EBS snapshots via DLM, 7-day retention
|
||||||
- **Admin access**: SSM Session Manager (no SSH port exposed)
|
- **Admin access**: SSM Session Manager (no SSH port exposed)
|
||||||
|
|
||||||
### Ports
|
### Ports
|
||||||
|
|
||||||
| Port | Protocol | Purpose |
|
| Port | Protocol | Source | Purpose |
|
||||||
|------|----------|---------|
|
|------|----------|--------|---------|
|
||||||
| 3000 | HTTP | Web UI + HTTP git clone |
|
| 443 | HTTPS | ALB (public) | Web UI + HTTP git clone |
|
||||||
| 2222 | SSH | Git SSH operations |
|
| 3000 | HTTP | ALB → instance | Internal traffic from ALB |
|
||||||
|
| 2222 | SSH | VPC + VPN | Git SSH operations |
|
||||||
Both ports are restricted to VPC (10.20.0.0/16) and office VPN (10.10.0.0/16).
|
|
||||||
|
|
||||||
## First-time setup
|
## First-time setup
|
||||||
|
|
||||||
|
|
@ -34,7 +34,9 @@ sudo -u forgejo /usr/local/bin/forgejo admin user create \
|
||||||
--config /etc/forgejo/app.ini
|
--config /etc/forgejo/app.ini
|
||||||
```
|
```
|
||||||
|
|
||||||
Then access the web UI at `http://forgejo.seahaven.com:3000`.
|
Admin password is stored in Secrets Manager at `forgejo/admin-password`.
|
||||||
|
|
||||||
|
Access the web UI at `https://forgejo.seahaven.com`.
|
||||||
|
|
||||||
## Migrating repos from GitHub
|
## Migrating repos from GitHub
|
||||||
|
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue