# forgejo Self-hosted Forgejo git server for archiving GitHub repos and mirroring active ones. Runs on a single EC2 instance within the Sea Haven VPC, fronted by the `seahaven-com` ALB for HTTPS. ## Architecture - **EC2**: t4g.small (arm64), Amazon Linux 2023, 50GB gp3 EBS - **Network**: Private subnet (us-east-1a), behind `seahaven-com` ALB for SSL termination - **DNS**: `forgejo.seahaven.com` (Route53 alias → ALB) - **TLS**: Wildcard cert on ALB, HTTP internally on port 3000 - **Backup**: Nightly EBS snapshots via DLM, 7-day retention - **Admin access**: SSM Session Manager (no SSH port exposed) ### Ports | Port | Protocol | Source | Purpose | |------|----------|--------|---------| | 443 | HTTPS | ALB (public) | Web UI + HTTP git clone | | 3000 | HTTP | ALB → instance | Internal traffic from ALB | | 2222 | SSH | VPC + VPN | Git SSH operations | ## First-time setup After the stack deploys, connect via SSM and create the admin user: ```bash aws ssm start-session --target sudo -u forgejo /usr/local/bin/forgejo admin user create \ --admin \ --username adam \ --password '' \ --email adam@seahavenind.com \ --config /etc/forgejo/app.ini ``` Admin password is stored in Secrets Manager at `forgejo/admin-password`. Access the web UI at `https://forgejo.seahaven.com`. ## Migrating repos from GitHub ### Archived repos (one-time import) In the Forgejo web UI: **New Migration → GitHub** → paste the GitHub repo URL. Use a GitHub personal access token for private repos. These are full imports (code, issues, PRs, releases). ### Active repos (mirror sync) Same migration flow, but check **This Repository Will Be A Mirror**. Forgejo polls GitHub hourly (`DEFAULT_INTERVAL = 1h` in app.ini) and keeps the mirror in sync. ## Deployment ```bash npm install npx cdk deploy ``` CI/CD is handled by GitHub Actions — PRs run CI, merges to `main` deploy via the reusable CDK workflow. ## Updating Forgejo Update the `FORGEJO_VERSION` constant in `lib/forgejo-stack.ts` and deploy. This replaces the instance, so ensure the latest EBS snapshot is available for data recovery if needed. Alternatively, update in-place via SSM: ```bash aws ssm start-session --target sudo systemctl stop forgejo sudo curl -Lo /usr/local/bin/forgejo "https://codeberg.org/forgejo/forgejo/releases/download/v/forgejo--linux-arm64" sudo chmod +x /usr/local/bin/forgejo sudo systemctl start forgejo ```