Update README for ALB-backed HTTPS setup

This commit is contained in:
Adam Moussa 2026-05-11 18:13:54 -04:00
parent ed41fd4eac
commit 0a4119880e

View file

@ -1,23 +1,23 @@
# forgejo
Self-hosted Forgejo git server for archiving GitHub repos and mirroring active ones. Runs on a single EC2 instance within the Sea Haven VPC, accessible only via VPN.
Self-hosted Forgejo git server for archiving GitHub repos and mirroring active ones. Runs on a single EC2 instance within the Sea Haven VPC, fronted by the `seahaven-com` ALB for HTTPS.
## Architecture
- **EC2**: t4g.small (arm64), Amazon Linux 2023, 50GB gp3 EBS
- **Network**: Private subnet (us-east-1a), VPC + VPN access only
- **DNS**: `forgejo.seahaven.com` (Route53 A record → private IP)
- **Network**: Private subnet (us-east-1a), behind `seahaven-com` ALB for SSL termination
- **DNS**: `forgejo.seahaven.com` (Route53 alias → ALB)
- **TLS**: Wildcard cert on ALB, HTTP internally on port 3000
- **Backup**: Nightly EBS snapshots via DLM, 7-day retention
- **Admin access**: SSM Session Manager (no SSH port exposed)
### Ports
| Port | Protocol | Purpose |
|------|----------|---------|
| 3000 | HTTP | Web UI + HTTP git clone |
| 2222 | SSH | Git SSH operations |
Both ports are restricted to VPC (10.20.0.0/16) and office VPN (10.10.0.0/16).
| Port | Protocol | Source | Purpose |
|------|----------|--------|---------|
| 443 | HTTPS | ALB (public) | Web UI + HTTP git clone |
| 3000 | HTTP | ALB → instance | Internal traffic from ALB |
| 2222 | SSH | VPC + VPN | Git SSH operations |
## First-time setup
@ -34,7 +34,9 @@ sudo -u forgejo /usr/local/bin/forgejo admin user create \
--config /etc/forgejo/app.ini
```
Then access the web UI at `http://forgejo.seahaven.com:3000`.
Admin password is stored in Secrets Manager at `forgejo/admin-password`.
Access the web UI at `https://forgejo.seahaven.com`.
## Migrating repos from GitHub