mirror of
https://github.com/Sea-Haven-Industries/forgejo.git
synced 2026-09-30 06:33:11 +00:00
Add Forgejo CDK stack
EC2 (t4g.small, arm64) in private subnet with VPN-only access, DLM nightly snapshots, and Route53 DNS at forgejo.seahaven.com.
This commit is contained in:
commit
a500d69716
10 changed files with 900 additions and 0 deletions
8
.github/workflows/ci.yaml
vendored
Normal file
8
.github/workflows/ci.yaml
vendored
Normal file
|
|
@ -0,0 +1,8 @@
|
||||||
|
name: CI
|
||||||
|
on:
|
||||||
|
pull_request:
|
||||||
|
branches: [main]
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
ci:
|
||||||
|
uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@main
|
||||||
18
.github/workflows/deploy.yaml
vendored
Normal file
18
.github/workflows/deploy.yaml
vendored
Normal file
|
|
@ -0,0 +1,18 @@
|
||||||
|
name: Deploy
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
branches: [main]
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
id-token: write
|
||||||
|
contents: read
|
||||||
|
|
||||||
|
concurrency:
|
||||||
|
group: deploy
|
||||||
|
cancel-in-progress: false
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
deploy:
|
||||||
|
uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@main
|
||||||
|
secrets:
|
||||||
|
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}
|
||||||
6
.gitignore
vendored
Normal file
6
.gitignore
vendored
Normal file
|
|
@ -0,0 +1,6 @@
|
||||||
|
node_modules/
|
||||||
|
cdk.out/
|
||||||
|
*.js
|
||||||
|
*.d.ts
|
||||||
|
*.js.map
|
||||||
|
cdk.context.json
|
||||||
69
README.md
Normal file
69
README.md
Normal file
|
|
@ -0,0 +1,69 @@
|
||||||
|
# forgejo
|
||||||
|
|
||||||
|
Self-hosted Forgejo git server for archiving GitHub repos and mirroring active ones. Runs on a single EC2 instance within the Sea Haven VPC, accessible only via VPN.
|
||||||
|
|
||||||
|
## Architecture
|
||||||
|
|
||||||
|
- **EC2**: t4g.small (arm64), Amazon Linux 2023, 50GB gp3 EBS
|
||||||
|
- **Network**: Private subnet (us-east-1a), VPC + VPN access only
|
||||||
|
- **DNS**: `forgejo.seahaven.com` (Route53 A record → private IP)
|
||||||
|
- **Backup**: Nightly EBS snapshots via DLM, 7-day retention
|
||||||
|
- **Admin access**: SSM Session Manager (no SSH port exposed)
|
||||||
|
|
||||||
|
### Ports
|
||||||
|
|
||||||
|
| Port | Protocol | Purpose |
|
||||||
|
|------|----------|---------|
|
||||||
|
| 3000 | HTTP | Web UI + HTTP git clone |
|
||||||
|
| 2222 | SSH | Git SSH operations |
|
||||||
|
|
||||||
|
Both ports are restricted to VPC (10.20.0.0/16) and office VPN (10.10.0.0/16).
|
||||||
|
|
||||||
|
## First-time setup
|
||||||
|
|
||||||
|
After the stack deploys, connect via SSM and create the admin user:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
aws ssm start-session --target <instance-id>
|
||||||
|
|
||||||
|
sudo -u forgejo /usr/local/bin/forgejo admin user create \
|
||||||
|
--admin \
|
||||||
|
--username adam \
|
||||||
|
--password '<password>' \
|
||||||
|
--email adam@seahavenind.com \
|
||||||
|
--config /etc/forgejo/app.ini
|
||||||
|
```
|
||||||
|
|
||||||
|
Then access the web UI at `http://forgejo.seahaven.com:3000`.
|
||||||
|
|
||||||
|
## Migrating repos from GitHub
|
||||||
|
|
||||||
|
### Archived repos (one-time import)
|
||||||
|
|
||||||
|
In the Forgejo web UI: **New Migration → GitHub** → paste the GitHub repo URL. Use a GitHub personal access token for private repos. These are full imports (code, issues, PRs, releases).
|
||||||
|
|
||||||
|
### Active repos (mirror sync)
|
||||||
|
|
||||||
|
Same migration flow, but check **This Repository Will Be A Mirror**. Forgejo polls GitHub hourly (`DEFAULT_INTERVAL = 1h` in app.ini) and keeps the mirror in sync.
|
||||||
|
|
||||||
|
## Deployment
|
||||||
|
|
||||||
|
```bash
|
||||||
|
npm install
|
||||||
|
npx cdk deploy
|
||||||
|
```
|
||||||
|
|
||||||
|
CI/CD is handled by GitHub Actions — PRs run CI, merges to `main` deploy via the reusable CDK workflow.
|
||||||
|
|
||||||
|
## Updating Forgejo
|
||||||
|
|
||||||
|
Update the `FORGEJO_VERSION` constant in `lib/forgejo-stack.ts` and deploy. This replaces the instance, so ensure the latest EBS snapshot is available for data recovery if needed. Alternatively, update in-place via SSM:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
aws ssm start-session --target <instance-id>
|
||||||
|
|
||||||
|
sudo systemctl stop forgejo
|
||||||
|
sudo curl -Lo /usr/local/bin/forgejo "https://codeberg.org/forgejo/forgejo/releases/download/v<NEW_VERSION>/forgejo-<NEW_VERSION>-linux-arm64"
|
||||||
|
sudo chmod +x /usr/local/bin/forgejo
|
||||||
|
sudo systemctl start forgejo
|
||||||
|
```
|
||||||
10
bin/app.ts
Normal file
10
bin/app.ts
Normal file
|
|
@ -0,0 +1,10 @@
|
||||||
|
#!/usr/bin/env node
|
||||||
|
import "source-map-support/register";
|
||||||
|
import * as cdk from "aws-cdk-lib";
|
||||||
|
import { ForgejoStack } from "../lib/forgejo-stack";
|
||||||
|
|
||||||
|
const app = new cdk.App();
|
||||||
|
new ForgejoStack(app, "forgejo", {
|
||||||
|
stackName: "forgejo",
|
||||||
|
env: { account: "328440206208", region: "us-east-1" },
|
||||||
|
});
|
||||||
21
cdk.json
Normal file
21
cdk.json
Normal file
|
|
@ -0,0 +1,21 @@
|
||||||
|
{
|
||||||
|
"app": "npx ts-node bin/app.ts",
|
||||||
|
"watch": {
|
||||||
|
"include": ["**"],
|
||||||
|
"exclude": [
|
||||||
|
"README.md",
|
||||||
|
"cdk*.json",
|
||||||
|
"**/*.d.ts",
|
||||||
|
"**/*.js",
|
||||||
|
"tsconfig.json",
|
||||||
|
"package*.json",
|
||||||
|
"node_modules",
|
||||||
|
"cdk.out"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"context": {
|
||||||
|
"@aws-cdk/aws-lambda:recognizeLayerVersion": true,
|
||||||
|
"@aws-cdk/core:checkSecretUsage": true,
|
||||||
|
"@aws-cdk/core:target-partitions": ["aws"]
|
||||||
|
}
|
||||||
|
}
|
||||||
195
lib/forgejo-stack.ts
Normal file
195
lib/forgejo-stack.ts
Normal file
|
|
@ -0,0 +1,195 @@
|
||||||
|
import * as cdk from "aws-cdk-lib";
|
||||||
|
import * as ec2 from "aws-cdk-lib/aws-ec2";
|
||||||
|
import * as iam from "aws-cdk-lib/aws-iam";
|
||||||
|
import * as route53 from "aws-cdk-lib/aws-route53";
|
||||||
|
import * as dlm from "aws-cdk-lib/aws-dlm";
|
||||||
|
import { Construct } from "constructs";
|
||||||
|
|
||||||
|
const FORGEJO_VERSION = "10.0.1";
|
||||||
|
|
||||||
|
export class ForgejoStack extends cdk.Stack {
|
||||||
|
constructor(scope: Construct, id: string, props?: cdk.StackProps) {
|
||||||
|
super(scope, id, props);
|
||||||
|
|
||||||
|
const vpc = ec2.Vpc.fromLookup(this, "SeaHavenVpc", {
|
||||||
|
vpcId: "vpc-0d3d4b67bd0cf8a68",
|
||||||
|
});
|
||||||
|
|
||||||
|
const privateSubnet1 = ec2.Subnet.fromSubnetId(
|
||||||
|
this, "PrivateSubnet1", "subnet-04e38c507e96f1926"
|
||||||
|
);
|
||||||
|
|
||||||
|
const sg = new ec2.SecurityGroup(this, "SecurityGroup", {
|
||||||
|
vpc,
|
||||||
|
securityGroupName: "forgejo",
|
||||||
|
description: "Forgejo git server - VPC and VPN access",
|
||||||
|
allowAllOutbound: true,
|
||||||
|
});
|
||||||
|
|
||||||
|
sg.addIngressRule(ec2.Peer.ipv4("10.20.0.0/16"), ec2.Port.tcp(3000), "HTTP from VPC");
|
||||||
|
sg.addIngressRule(ec2.Peer.ipv4("10.10.0.0/16"), ec2.Port.tcp(3000), "HTTP from office VPN");
|
||||||
|
sg.addIngressRule(ec2.Peer.ipv4("10.20.0.0/16"), ec2.Port.tcp(2222), "SSH git from VPC");
|
||||||
|
sg.addIngressRule(ec2.Peer.ipv4("10.10.0.0/16"), ec2.Port.tcp(2222), "SSH git from office VPN");
|
||||||
|
|
||||||
|
const role = new iam.Role(this, "InstanceRole", {
|
||||||
|
roleName: "forgejo-instance",
|
||||||
|
assumedBy: new iam.ServicePrincipal("ec2.amazonaws.com"),
|
||||||
|
managedPolicies: [
|
||||||
|
iam.ManagedPolicy.fromAwsManagedPolicyName("AmazonSSMManagedInstanceCore"),
|
||||||
|
],
|
||||||
|
});
|
||||||
|
|
||||||
|
const userData = ec2.UserData.forLinux();
|
||||||
|
userData.addCommands(
|
||||||
|
"set -euxo pipefail",
|
||||||
|
"",
|
||||||
|
`FORGEJO_VERSION="${FORGEJO_VERSION}"`,
|
||||||
|
"",
|
||||||
|
"dnf install -y git",
|
||||||
|
"",
|
||||||
|
"useradd --system --shell /bin/bash --home-dir /home/forgejo --create-home forgejo",
|
||||||
|
"",
|
||||||
|
"mkdir -p /var/lib/forgejo/{data,log}",
|
||||||
|
"chown -R forgejo:forgejo /var/lib/forgejo",
|
||||||
|
"chmod 750 /var/lib/forgejo",
|
||||||
|
"",
|
||||||
|
'curl -Lo /usr/local/bin/forgejo "https://codeberg.org/forgejo/forgejo/releases/download/v${FORGEJO_VERSION}/forgejo-${FORGEJO_VERSION}-linux-arm64"',
|
||||||
|
"chmod +x /usr/local/bin/forgejo",
|
||||||
|
"",
|
||||||
|
"mkdir -p /etc/forgejo",
|
||||||
|
"chown root:forgejo /etc/forgejo",
|
||||||
|
"chmod 770 /etc/forgejo",
|
||||||
|
"",
|
||||||
|
"cat > /etc/forgejo/app.ini << 'INIEOF'",
|
||||||
|
"APP_NAME = Sea Haven Git",
|
||||||
|
"",
|
||||||
|
"[server]",
|
||||||
|
"DOMAIN = forgejo.seahaven.com",
|
||||||
|
"ROOT_URL = http://forgejo.seahaven.com:3000/",
|
||||||
|
"HTTP_PORT = 3000",
|
||||||
|
"START_SSH_SERVER = true",
|
||||||
|
"SSH_PORT = 2222",
|
||||||
|
"SSH_LISTEN_PORT = 2222",
|
||||||
|
"LFS_START_SERVER = true",
|
||||||
|
"",
|
||||||
|
"[database]",
|
||||||
|
"DB_TYPE = sqlite3",
|
||||||
|
"PATH = /var/lib/forgejo/data/forgejo.db",
|
||||||
|
"",
|
||||||
|
"[repository]",
|
||||||
|
"ROOT = /var/lib/forgejo/data/repositories",
|
||||||
|
"",
|
||||||
|
"[log]",
|
||||||
|
"ROOT_PATH = /var/lib/forgejo/log",
|
||||||
|
"",
|
||||||
|
"[security]",
|
||||||
|
"INSTALL_LOCK = true",
|
||||||
|
"",
|
||||||
|
"[service]",
|
||||||
|
"DISABLE_REGISTRATION = true",
|
||||||
|
"",
|
||||||
|
"[mirror]",
|
||||||
|
"DEFAULT_INTERVAL = 1h",
|
||||||
|
"INIEOF",
|
||||||
|
"",
|
||||||
|
"chown root:forgejo /etc/forgejo/app.ini",
|
||||||
|
"chmod 660 /etc/forgejo/app.ini",
|
||||||
|
"",
|
||||||
|
"cat > /etc/systemd/system/forgejo.service << 'SVCEOF'",
|
||||||
|
"[Unit]",
|
||||||
|
"Description=Forgejo",
|
||||||
|
"After=network.target",
|
||||||
|
"",
|
||||||
|
"[Service]",
|
||||||
|
"Type=simple",
|
||||||
|
"User=forgejo",
|
||||||
|
"Group=forgejo",
|
||||||
|
"WorkingDirectory=/var/lib/forgejo",
|
||||||
|
"ExecStart=/usr/local/bin/forgejo web --config /etc/forgejo/app.ini",
|
||||||
|
"Restart=always",
|
||||||
|
"RestartSec=5",
|
||||||
|
"Environment=USER=forgejo HOME=/home/forgejo FORGEJO_WORK_DIR=/var/lib/forgejo",
|
||||||
|
"",
|
||||||
|
"[Install]",
|
||||||
|
"WantedBy=multi-user.target",
|
||||||
|
"SVCEOF",
|
||||||
|
"",
|
||||||
|
"systemctl daemon-reload",
|
||||||
|
"systemctl enable --now forgejo",
|
||||||
|
);
|
||||||
|
|
||||||
|
const instance = new ec2.Instance(this, "Instance", {
|
||||||
|
instanceName: "forgejo",
|
||||||
|
vpc,
|
||||||
|
vpcSubnets: { subnets: [privateSubnet1] },
|
||||||
|
instanceType: ec2.InstanceType.of(ec2.InstanceClass.T4G, ec2.InstanceSize.SMALL),
|
||||||
|
machineImage: ec2.MachineImage.latestAmazonLinux2023({
|
||||||
|
cpuType: ec2.AmazonLinuxCpuType.ARM_64,
|
||||||
|
}),
|
||||||
|
securityGroup: sg,
|
||||||
|
role,
|
||||||
|
userData,
|
||||||
|
blockDevices: [{
|
||||||
|
deviceName: "/dev/xvda",
|
||||||
|
volume: ec2.BlockDeviceVolume.ebs(50, {
|
||||||
|
volumeType: ec2.EbsDeviceVolumeType.GP3,
|
||||||
|
encrypted: true,
|
||||||
|
}),
|
||||||
|
}],
|
||||||
|
});
|
||||||
|
|
||||||
|
cdk.Tags.of(instance).add("forgejo-backup", "true");
|
||||||
|
|
||||||
|
const dlmRole = new iam.Role(this, "DlmRole", {
|
||||||
|
roleName: "forgejo-dlm",
|
||||||
|
assumedBy: new iam.ServicePrincipal("dlm.amazonaws.com"),
|
||||||
|
managedPolicies: [
|
||||||
|
iam.ManagedPolicy.fromAwsManagedPolicyName(
|
||||||
|
"service-role/AWSDataLifecycleManagerServiceRole"
|
||||||
|
),
|
||||||
|
],
|
||||||
|
});
|
||||||
|
|
||||||
|
new dlm.CfnLifecyclePolicy(this, "SnapshotPolicy", {
|
||||||
|
description: "Nightly EBS snapshots for Forgejo",
|
||||||
|
state: "ENABLED",
|
||||||
|
executionRoleArn: dlmRole.roleArn,
|
||||||
|
policyDetails: {
|
||||||
|
resourceTypes: ["INSTANCE"],
|
||||||
|
targetTags: [{ key: "forgejo-backup", value: "true" }],
|
||||||
|
schedules: [{
|
||||||
|
name: "forgejo-nightly",
|
||||||
|
createRule: { interval: 24, intervalUnit: "HOURS", times: ["06:00"] },
|
||||||
|
retainRule: { count: 7 },
|
||||||
|
copyTags: true,
|
||||||
|
}],
|
||||||
|
},
|
||||||
|
});
|
||||||
|
|
||||||
|
const hostedZone = route53.HostedZone.fromHostedZoneAttributes(
|
||||||
|
this, "SeaHavenZone", {
|
||||||
|
hostedZoneId: "Z06652411XKH89KTZD3XA",
|
||||||
|
zoneName: "seahaven.com",
|
||||||
|
}
|
||||||
|
);
|
||||||
|
|
||||||
|
new route53.ARecord(this, "DnsRecord", {
|
||||||
|
zone: hostedZone,
|
||||||
|
recordName: "forgejo",
|
||||||
|
target: route53.RecordTarget.fromIpAddresses(instance.instancePrivateIp),
|
||||||
|
ttl: cdk.Duration.minutes(5),
|
||||||
|
});
|
||||||
|
|
||||||
|
new cdk.CfnOutput(this, "ForgejoUrl", {
|
||||||
|
value: "http://forgejo.seahaven.com:3000",
|
||||||
|
});
|
||||||
|
|
||||||
|
new cdk.CfnOutput(this, "InstanceId", {
|
||||||
|
value: instance.instanceId,
|
||||||
|
});
|
||||||
|
|
||||||
|
new cdk.CfnOutput(this, "PrivateIp", {
|
||||||
|
value: instance.instancePrivateIp,
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
525
package-lock.json
generated
Normal file
525
package-lock.json
generated
Normal file
|
|
@ -0,0 +1,525 @@
|
||||||
|
{
|
||||||
|
"name": "forgejo",
|
||||||
|
"version": "1.0.0",
|
||||||
|
"lockfileVersion": 3,
|
||||||
|
"requires": true,
|
||||||
|
"packages": {
|
||||||
|
"": {
|
||||||
|
"name": "forgejo",
|
||||||
|
"version": "1.0.0",
|
||||||
|
"dependencies": {
|
||||||
|
"aws-cdk-lib": "^2.252.0",
|
||||||
|
"constructs": "^10.0.0"
|
||||||
|
},
|
||||||
|
"bin": {
|
||||||
|
"app": "bin/app.js"
|
||||||
|
},
|
||||||
|
"devDependencies": {
|
||||||
|
"@types/node": "^22.0.0",
|
||||||
|
"aws-cdk": "^2.252.0",
|
||||||
|
"source-map-support": "^0.5.21",
|
||||||
|
"typescript": "~5.7.0"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"node_modules/@aws-cdk/asset-awscli-v1": {
|
||||||
|
"version": "2.2.273",
|
||||||
|
"resolved": "https://registry.npmjs.org/@aws-cdk/asset-awscli-v1/-/asset-awscli-v1-2.2.273.tgz",
|
||||||
|
"integrity": "sha512-X57HYUtHt9BQrlrzUNcMyRsDUCoakYNnY6qh5lNwRCHPtQoTfXmuISkfLk0AjLkcbS5lw1LLTQFiQhTDXfiTvg==",
|
||||||
|
"license": "Apache-2.0"
|
||||||
|
},
|
||||||
|
"node_modules/@aws-cdk/asset-node-proxy-agent-v6": {
|
||||||
|
"version": "2.1.1",
|
||||||
|
"resolved": "https://registry.npmjs.org/@aws-cdk/asset-node-proxy-agent-v6/-/asset-node-proxy-agent-v6-2.1.1.tgz",
|
||||||
|
"integrity": "sha512-We4bmHaowOPHr+IQR4/FyTGjRfjgBj4ICMjtqmJeBDWad3Q/6St12NT07leNtyuukv2qMhtSZJQorD8KpKTwRA==",
|
||||||
|
"license": "Apache-2.0"
|
||||||
|
},
|
||||||
|
"node_modules/@aws-cdk/cloud-assembly-schema": {
|
||||||
|
"version": "53.22.0",
|
||||||
|
"resolved": "https://registry.npmjs.org/@aws-cdk/cloud-assembly-schema/-/cloud-assembly-schema-53.22.0.tgz",
|
||||||
|
"integrity": "sha512-2GLhjjf7Db697rRyYt6rjN06fwbBIiewPo/jxSCyUN259ejF7NQQRwvrdAQb9Aq2jPaIIp1cfHSoEdXyA6Bb7Q==",
|
||||||
|
"bundleDependencies": [
|
||||||
|
"jsonschema",
|
||||||
|
"semver"
|
||||||
|
],
|
||||||
|
"license": "Apache-2.0",
|
||||||
|
"dependencies": {
|
||||||
|
"jsonschema": "~1.4.1",
|
||||||
|
"semver": "^7.7.4"
|
||||||
|
},
|
||||||
|
"engines": {
|
||||||
|
"node": ">= 18.0.0"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"node_modules/@aws-cdk/cloud-assembly-schema/node_modules/jsonschema": {
|
||||||
|
"version": "1.4.1",
|
||||||
|
"inBundle": true,
|
||||||
|
"license": "MIT",
|
||||||
|
"engines": {
|
||||||
|
"node": "*"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"node_modules/@aws-cdk/cloud-assembly-schema/node_modules/semver": {
|
||||||
|
"version": "7.7.4",
|
||||||
|
"inBundle": true,
|
||||||
|
"license": "ISC",
|
||||||
|
"bin": {
|
||||||
|
"semver": "bin/semver.js"
|
||||||
|
},
|
||||||
|
"engines": {
|
||||||
|
"node": ">=10"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"node_modules/@types/node": {
|
||||||
|
"version": "22.19.18",
|
||||||
|
"resolved": "https://registry.npmjs.org/@types/node/-/node-22.19.18.tgz",
|
||||||
|
"integrity": "sha512-9v00a+dn2yWVsYDEunWC4g/TcRKVq3r8N5FuZp7u0SGrPvdN9c2yXI9bBuf5Fl0hNCb+QTIePTn5pJs2pwBOQQ==",
|
||||||
|
"dev": true,
|
||||||
|
"license": "MIT",
|
||||||
|
"dependencies": {
|
||||||
|
"undici-types": "~6.21.0"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"node_modules/aws-cdk": {
|
||||||
|
"version": "2.1121.0",
|
||||||
|
"resolved": "https://registry.npmjs.org/aws-cdk/-/aws-cdk-2.1121.0.tgz",
|
||||||
|
"integrity": "sha512-cG7CHt/SytYTfwrK+BUNQpqmS1dwhjt8z6ExKL6GK4n+8/6ZCwFzxlZWA/jUd2+Y9xPc+Q8cLKfMqGmgxEXbkg==",
|
||||||
|
"dev": true,
|
||||||
|
"license": "Apache-2.0",
|
||||||
|
"bin": {
|
||||||
|
"cdk": "bin/cdk"
|
||||||
|
},
|
||||||
|
"engines": {
|
||||||
|
"node": ">= 18.0.0"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"node_modules/aws-cdk-lib": {
|
||||||
|
"version": "2.253.1",
|
||||||
|
"resolved": "https://registry.npmjs.org/aws-cdk-lib/-/aws-cdk-lib-2.253.1.tgz",
|
||||||
|
"integrity": "sha512-vy+hA15/ZfSQpivkNdlIn2ZDA2hesp3WJgmtIZJDFwu6xzwv7wH7glbAdu5xCHGcOjepOaTKZSvCPC6sN+0/Vw==",
|
||||||
|
"bundleDependencies": [
|
||||||
|
"@balena/dockerignore",
|
||||||
|
"@aws-cdk/cloud-assembly-api",
|
||||||
|
"case",
|
||||||
|
"fs-extra",
|
||||||
|
"ignore",
|
||||||
|
"jsonschema",
|
||||||
|
"minimatch",
|
||||||
|
"punycode",
|
||||||
|
"semver",
|
||||||
|
"table",
|
||||||
|
"yaml",
|
||||||
|
"mime-types"
|
||||||
|
],
|
||||||
|
"license": "Apache-2.0",
|
||||||
|
"dependencies": {
|
||||||
|
"@aws-cdk/asset-awscli-v1": "2.2.273",
|
||||||
|
"@aws-cdk/asset-node-proxy-agent-v6": "^2.1.1",
|
||||||
|
"@aws-cdk/cloud-assembly-api": "^2.2.2",
|
||||||
|
"@aws-cdk/cloud-assembly-schema": "^53.18.0",
|
||||||
|
"@balena/dockerignore": "^1.0.2",
|
||||||
|
"case": "1.6.3",
|
||||||
|
"fs-extra": "^11.3.3",
|
||||||
|
"ignore": "^5.3.2",
|
||||||
|
"jsonschema": "^1.5.0",
|
||||||
|
"mime-types": "^2.1.35",
|
||||||
|
"minimatch": "^10.2.3",
|
||||||
|
"punycode": "^2.3.1",
|
||||||
|
"semver": "^7.7.4",
|
||||||
|
"table": "^6.9.0",
|
||||||
|
"yaml": "1.10.3"
|
||||||
|
},
|
||||||
|
"engines": {
|
||||||
|
"node": ">= 20.0.0"
|
||||||
|
},
|
||||||
|
"peerDependencies": {
|
||||||
|
"constructs": "^10.5.0"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"node_modules/aws-cdk-lib/node_modules/@aws-cdk/cloud-assembly-api": {
|
||||||
|
"version": "2.2.2",
|
||||||
|
"bundleDependencies": [
|
||||||
|
"jsonschema",
|
||||||
|
"semver"
|
||||||
|
],
|
||||||
|
"inBundle": true,
|
||||||
|
"license": "Apache-2.0",
|
||||||
|
"dependencies": {
|
||||||
|
"jsonschema": "~1.4.1",
|
||||||
|
"semver": "^7.7.4"
|
||||||
|
},
|
||||||
|
"engines": {
|
||||||
|
"node": ">= 18.0.0"
|
||||||
|
},
|
||||||
|
"peerDependencies": {
|
||||||
|
"@aws-cdk/cloud-assembly-schema": ">=53.15.0"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"node_modules/aws-cdk-lib/node_modules/@balena/dockerignore": {
|
||||||
|
"version": "1.0.2",
|
||||||
|
"inBundle": true,
|
||||||
|
"license": "Apache-2.0"
|
||||||
|
},
|
||||||
|
"node_modules/aws-cdk-lib/node_modules/ajv": {
|
||||||
|
"version": "8.18.0",
|
||||||
|
"inBundle": true,
|
||||||
|
"license": "MIT",
|
||||||
|
"dependencies": {
|
||||||
|
"fast-deep-equal": "^3.1.3",
|
||||||
|
"fast-uri": "^3.0.1",
|
||||||
|
"json-schema-traverse": "^1.0.0",
|
||||||
|
"require-from-string": "^2.0.2"
|
||||||
|
},
|
||||||
|
"funding": {
|
||||||
|
"type": "github",
|
||||||
|
"url": "https://github.com/sponsors/epoberezkin"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"node_modules/aws-cdk-lib/node_modules/ansi-regex": {
|
||||||
|
"version": "5.0.1",
|
||||||
|
"inBundle": true,
|
||||||
|
"license": "MIT",
|
||||||
|
"engines": {
|
||||||
|
"node": ">=8"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"node_modules/aws-cdk-lib/node_modules/ansi-styles": {
|
||||||
|
"version": "4.3.0",
|
||||||
|
"inBundle": true,
|
||||||
|
"license": "MIT",
|
||||||
|
"dependencies": {
|
||||||
|
"color-convert": "^2.0.1"
|
||||||
|
},
|
||||||
|
"engines": {
|
||||||
|
"node": ">=8"
|
||||||
|
},
|
||||||
|
"funding": {
|
||||||
|
"url": "https://github.com/chalk/ansi-styles?sponsor=1"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"node_modules/aws-cdk-lib/node_modules/astral-regex": {
|
||||||
|
"version": "2.0.0",
|
||||||
|
"inBundle": true,
|
||||||
|
"license": "MIT",
|
||||||
|
"engines": {
|
||||||
|
"node": ">=8"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"node_modules/aws-cdk-lib/node_modules/balanced-match": {
|
||||||
|
"version": "4.0.4",
|
||||||
|
"inBundle": true,
|
||||||
|
"license": "MIT",
|
||||||
|
"engines": {
|
||||||
|
"node": "18 || 20 || >=22"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"node_modules/aws-cdk-lib/node_modules/brace-expansion": {
|
||||||
|
"version": "5.0.5",
|
||||||
|
"inBundle": true,
|
||||||
|
"license": "MIT",
|
||||||
|
"dependencies": {
|
||||||
|
"balanced-match": "^4.0.2"
|
||||||
|
},
|
||||||
|
"engines": {
|
||||||
|
"node": "18 || 20 || >=22"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"node_modules/aws-cdk-lib/node_modules/case": {
|
||||||
|
"version": "1.6.3",
|
||||||
|
"inBundle": true,
|
||||||
|
"license": "(MIT OR GPL-3.0-or-later)",
|
||||||
|
"engines": {
|
||||||
|
"node": ">= 0.8.0"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"node_modules/aws-cdk-lib/node_modules/color-convert": {
|
||||||
|
"version": "2.0.1",
|
||||||
|
"inBundle": true,
|
||||||
|
"license": "MIT",
|
||||||
|
"dependencies": {
|
||||||
|
"color-name": "~1.1.4"
|
||||||
|
},
|
||||||
|
"engines": {
|
||||||
|
"node": ">=7.0.0"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"node_modules/aws-cdk-lib/node_modules/color-name": {
|
||||||
|
"version": "1.1.4",
|
||||||
|
"inBundle": true,
|
||||||
|
"license": "MIT"
|
||||||
|
},
|
||||||
|
"node_modules/aws-cdk-lib/node_modules/emoji-regex": {
|
||||||
|
"version": "8.0.0",
|
||||||
|
"inBundle": true,
|
||||||
|
"license": "MIT"
|
||||||
|
},
|
||||||
|
"node_modules/aws-cdk-lib/node_modules/fast-deep-equal": {
|
||||||
|
"version": "3.1.3",
|
||||||
|
"inBundle": true,
|
||||||
|
"license": "MIT"
|
||||||
|
},
|
||||||
|
"node_modules/aws-cdk-lib/node_modules/fast-uri": {
|
||||||
|
"version": "3.1.0",
|
||||||
|
"funding": [
|
||||||
|
{
|
||||||
|
"type": "github",
|
||||||
|
"url": "https://github.com/sponsors/fastify"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"type": "opencollective",
|
||||||
|
"url": "https://opencollective.com/fastify"
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"inBundle": true,
|
||||||
|
"license": "BSD-3-Clause"
|
||||||
|
},
|
||||||
|
"node_modules/aws-cdk-lib/node_modules/fs-extra": {
|
||||||
|
"version": "11.3.3",
|
||||||
|
"inBundle": true,
|
||||||
|
"license": "MIT",
|
||||||
|
"dependencies": {
|
||||||
|
"graceful-fs": "^4.2.0",
|
||||||
|
"jsonfile": "^6.0.1",
|
||||||
|
"universalify": "^2.0.0"
|
||||||
|
},
|
||||||
|
"engines": {
|
||||||
|
"node": ">=14.14"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"node_modules/aws-cdk-lib/node_modules/graceful-fs": {
|
||||||
|
"version": "4.2.11",
|
||||||
|
"inBundle": true,
|
||||||
|
"license": "ISC"
|
||||||
|
},
|
||||||
|
"node_modules/aws-cdk-lib/node_modules/ignore": {
|
||||||
|
"version": "5.3.2",
|
||||||
|
"inBundle": true,
|
||||||
|
"license": "MIT",
|
||||||
|
"engines": {
|
||||||
|
"node": ">= 4"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"node_modules/aws-cdk-lib/node_modules/is-fullwidth-code-point": {
|
||||||
|
"version": "3.0.0",
|
||||||
|
"inBundle": true,
|
||||||
|
"license": "MIT",
|
||||||
|
"engines": {
|
||||||
|
"node": ">=8"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"node_modules/aws-cdk-lib/node_modules/json-schema-traverse": {
|
||||||
|
"version": "1.0.0",
|
||||||
|
"inBundle": true,
|
||||||
|
"license": "MIT"
|
||||||
|
},
|
||||||
|
"node_modules/aws-cdk-lib/node_modules/jsonfile": {
|
||||||
|
"version": "6.2.0",
|
||||||
|
"inBundle": true,
|
||||||
|
"license": "MIT",
|
||||||
|
"dependencies": {
|
||||||
|
"universalify": "^2.0.0"
|
||||||
|
},
|
||||||
|
"optionalDependencies": {
|
||||||
|
"graceful-fs": "^4.1.6"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"node_modules/aws-cdk-lib/node_modules/jsonschema": {
|
||||||
|
"version": "1.5.0",
|
||||||
|
"inBundle": true,
|
||||||
|
"license": "MIT",
|
||||||
|
"engines": {
|
||||||
|
"node": "*"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"node_modules/aws-cdk-lib/node_modules/lodash.truncate": {
|
||||||
|
"version": "4.4.2",
|
||||||
|
"inBundle": true,
|
||||||
|
"license": "MIT"
|
||||||
|
},
|
||||||
|
"node_modules/aws-cdk-lib/node_modules/mime-db": {
|
||||||
|
"version": "1.52.0",
|
||||||
|
"inBundle": true,
|
||||||
|
"license": "MIT",
|
||||||
|
"engines": {
|
||||||
|
"node": ">= 0.6"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"node_modules/aws-cdk-lib/node_modules/mime-types": {
|
||||||
|
"version": "2.1.35",
|
||||||
|
"inBundle": true,
|
||||||
|
"license": "MIT",
|
||||||
|
"dependencies": {
|
||||||
|
"mime-db": "1.52.0"
|
||||||
|
},
|
||||||
|
"engines": {
|
||||||
|
"node": ">= 0.6"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"node_modules/aws-cdk-lib/node_modules/minimatch": {
|
||||||
|
"version": "10.2.5",
|
||||||
|
"inBundle": true,
|
||||||
|
"license": "BlueOak-1.0.0",
|
||||||
|
"dependencies": {
|
||||||
|
"brace-expansion": "^5.0.5"
|
||||||
|
},
|
||||||
|
"engines": {
|
||||||
|
"node": "18 || 20 || >=22"
|
||||||
|
},
|
||||||
|
"funding": {
|
||||||
|
"url": "https://github.com/sponsors/isaacs"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"node_modules/aws-cdk-lib/node_modules/punycode": {
|
||||||
|
"version": "2.3.1",
|
||||||
|
"inBundle": true,
|
||||||
|
"license": "MIT",
|
||||||
|
"engines": {
|
||||||
|
"node": ">=6"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"node_modules/aws-cdk-lib/node_modules/require-from-string": {
|
||||||
|
"version": "2.0.2",
|
||||||
|
"inBundle": true,
|
||||||
|
"license": "MIT",
|
||||||
|
"engines": {
|
||||||
|
"node": ">=0.10.0"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"node_modules/aws-cdk-lib/node_modules/semver": {
|
||||||
|
"version": "7.7.4",
|
||||||
|
"inBundle": true,
|
||||||
|
"license": "ISC",
|
||||||
|
"bin": {
|
||||||
|
"semver": "bin/semver.js"
|
||||||
|
},
|
||||||
|
"engines": {
|
||||||
|
"node": ">=10"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"node_modules/aws-cdk-lib/node_modules/slice-ansi": {
|
||||||
|
"version": "4.0.0",
|
||||||
|
"inBundle": true,
|
||||||
|
"license": "MIT",
|
||||||
|
"dependencies": {
|
||||||
|
"ansi-styles": "^4.0.0",
|
||||||
|
"astral-regex": "^2.0.0",
|
||||||
|
"is-fullwidth-code-point": "^3.0.0"
|
||||||
|
},
|
||||||
|
"engines": {
|
||||||
|
"node": ">=10"
|
||||||
|
},
|
||||||
|
"funding": {
|
||||||
|
"url": "https://github.com/chalk/slice-ansi?sponsor=1"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"node_modules/aws-cdk-lib/node_modules/string-width": {
|
||||||
|
"version": "4.2.3",
|
||||||
|
"inBundle": true,
|
||||||
|
"license": "MIT",
|
||||||
|
"dependencies": {
|
||||||
|
"emoji-regex": "^8.0.0",
|
||||||
|
"is-fullwidth-code-point": "^3.0.0",
|
||||||
|
"strip-ansi": "^6.0.1"
|
||||||
|
},
|
||||||
|
"engines": {
|
||||||
|
"node": ">=8"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"node_modules/aws-cdk-lib/node_modules/strip-ansi": {
|
||||||
|
"version": "6.0.1",
|
||||||
|
"inBundle": true,
|
||||||
|
"license": "MIT",
|
||||||
|
"dependencies": {
|
||||||
|
"ansi-regex": "^5.0.1"
|
||||||
|
},
|
||||||
|
"engines": {
|
||||||
|
"node": ">=8"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"node_modules/aws-cdk-lib/node_modules/table": {
|
||||||
|
"version": "6.9.0",
|
||||||
|
"inBundle": true,
|
||||||
|
"license": "BSD-3-Clause",
|
||||||
|
"dependencies": {
|
||||||
|
"ajv": "^8.0.1",
|
||||||
|
"lodash.truncate": "^4.4.2",
|
||||||
|
"slice-ansi": "^4.0.0",
|
||||||
|
"string-width": "^4.2.3",
|
||||||
|
"strip-ansi": "^6.0.1"
|
||||||
|
},
|
||||||
|
"engines": {
|
||||||
|
"node": ">=10.0.0"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"node_modules/aws-cdk-lib/node_modules/universalify": {
|
||||||
|
"version": "2.0.1",
|
||||||
|
"inBundle": true,
|
||||||
|
"license": "MIT",
|
||||||
|
"engines": {
|
||||||
|
"node": ">= 10.0.0"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"node_modules/aws-cdk-lib/node_modules/yaml": {
|
||||||
|
"version": "1.10.3",
|
||||||
|
"inBundle": true,
|
||||||
|
"license": "ISC",
|
||||||
|
"engines": {
|
||||||
|
"node": ">= 6"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"node_modules/buffer-from": {
|
||||||
|
"version": "1.1.2",
|
||||||
|
"resolved": "https://registry.npmjs.org/buffer-from/-/buffer-from-1.1.2.tgz",
|
||||||
|
"integrity": "sha512-E+XQCRwSbaaiChtv6k6Dwgc+bx+Bs6vuKJHHl5kox/BaKbhiXzqQOwK4cO22yElGp2OCmjwVhT3HmxgyPGnJfQ==",
|
||||||
|
"dev": true,
|
||||||
|
"license": "MIT"
|
||||||
|
},
|
||||||
|
"node_modules/constructs": {
|
||||||
|
"version": "10.6.0",
|
||||||
|
"resolved": "https://registry.npmjs.org/constructs/-/constructs-10.6.0.tgz",
|
||||||
|
"integrity": "sha512-TxHOnBO5zMo/G76ykzGF/wMpEHu257TbWiIxP9K0Yv/+t70UzgBQiTqjkAsWOPC6jW91DzJI0+ehQV6xDRNBuQ==",
|
||||||
|
"license": "Apache-2.0"
|
||||||
|
},
|
||||||
|
"node_modules/source-map": {
|
||||||
|
"version": "0.6.1",
|
||||||
|
"resolved": "https://registry.npmjs.org/source-map/-/source-map-0.6.1.tgz",
|
||||||
|
"integrity": "sha512-UjgapumWlbMhkBgzT7Ykc5YXUT46F0iKu8SGXq0bcwP5dz/h0Plj6enJqjz1Zbq2l5WaqYnrVbwWOWMyF3F47g==",
|
||||||
|
"dev": true,
|
||||||
|
"license": "BSD-3-Clause",
|
||||||
|
"engines": {
|
||||||
|
"node": ">=0.10.0"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"node_modules/source-map-support": {
|
||||||
|
"version": "0.5.21",
|
||||||
|
"resolved": "https://registry.npmjs.org/source-map-support/-/source-map-support-0.5.21.tgz",
|
||||||
|
"integrity": "sha512-uBHU3L3czsIyYXKX88fdrGovxdSCoTGDRZ6SYXtSRxLZUzHg5P/66Ht6uoUlHu9EZod+inXhKo3qQgwXUT/y1w==",
|
||||||
|
"dev": true,
|
||||||
|
"license": "MIT",
|
||||||
|
"dependencies": {
|
||||||
|
"buffer-from": "^1.0.0",
|
||||||
|
"source-map": "^0.6.0"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"node_modules/typescript": {
|
||||||
|
"version": "5.7.3",
|
||||||
|
"resolved": "https://registry.npmjs.org/typescript/-/typescript-5.7.3.tgz",
|
||||||
|
"integrity": "sha512-84MVSjMEHP+FQRPy3pX9sTVV/INIex71s9TL2Gm5FG/WG1SqXeKyZ0k7/blY/4FdOzI12CBy1vGc4og/eus0fw==",
|
||||||
|
"dev": true,
|
||||||
|
"license": "Apache-2.0",
|
||||||
|
"bin": {
|
||||||
|
"tsc": "bin/tsc",
|
||||||
|
"tsserver": "bin/tsserver"
|
||||||
|
},
|
||||||
|
"engines": {
|
||||||
|
"node": ">=14.17"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"node_modules/undici-types": {
|
||||||
|
"version": "6.21.0",
|
||||||
|
"resolved": "https://registry.npmjs.org/undici-types/-/undici-types-6.21.0.tgz",
|
||||||
|
"integrity": "sha512-iwDZqg0QAGrg9Rav5H4n0M64c3mkR59cJ6wQp+7C4nI0gsmExaedaYLNO44eT4AtBBwjbTiGPMlt2Md0T9H9JQ==",
|
||||||
|
"dev": true,
|
||||||
|
"license": "MIT"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
24
package.json
Normal file
24
package.json
Normal file
|
|
@ -0,0 +1,24 @@
|
||||||
|
{
|
||||||
|
"name": "forgejo",
|
||||||
|
"version": "1.0.0",
|
||||||
|
"bin": {
|
||||||
|
"app": "bin/app.js"
|
||||||
|
},
|
||||||
|
"scripts": {
|
||||||
|
"build": "tsc",
|
||||||
|
"cdk": "cdk",
|
||||||
|
"synth": "cdk synth",
|
||||||
|
"deploy": "cdk deploy",
|
||||||
|
"diff": "cdk diff"
|
||||||
|
},
|
||||||
|
"devDependencies": {
|
||||||
|
"@types/node": "^22.0.0",
|
||||||
|
"aws-cdk": "^2.252.0",
|
||||||
|
"source-map-support": "^0.5.21",
|
||||||
|
"typescript": "~5.7.0"
|
||||||
|
},
|
||||||
|
"dependencies": {
|
||||||
|
"aws-cdk-lib": "^2.252.0",
|
||||||
|
"constructs": "^10.0.0"
|
||||||
|
}
|
||||||
|
}
|
||||||
24
tsconfig.json
Normal file
24
tsconfig.json
Normal file
|
|
@ -0,0 +1,24 @@
|
||||||
|
{
|
||||||
|
"compilerOptions": {
|
||||||
|
"target": "ES2022",
|
||||||
|
"module": "commonjs",
|
||||||
|
"lib": ["ES2022"],
|
||||||
|
"types": ["node"],
|
||||||
|
"declaration": true,
|
||||||
|
"strict": true,
|
||||||
|
"noImplicitAny": true,
|
||||||
|
"strictNullChecks": true,
|
||||||
|
"noImplicitReturns": true,
|
||||||
|
"noFallthroughCasesInSwitch": true,
|
||||||
|
"inlineSourceMap": true,
|
||||||
|
"inlineSources": true,
|
||||||
|
"strictPropertyInitialization": false,
|
||||||
|
"outDir": "./cdk.out",
|
||||||
|
"rootDir": ".",
|
||||||
|
"skipLibCheck": true,
|
||||||
|
"forceConsistentCasingInFileNames": true,
|
||||||
|
"resolveJsonModule": true,
|
||||||
|
"esModuleInterop": true
|
||||||
|
},
|
||||||
|
"exclude": ["node_modules", "cdk.out"]
|
||||||
|
}
|
||||||
Loading…
Add table
Reference in a new issue