forgejo/README.md
2026-05-11 18:13:54 -04:00

2.4 KiB

forgejo

Self-hosted Forgejo git server for archiving GitHub repos and mirroring active ones. Runs on a single EC2 instance within the Sea Haven VPC, fronted by the seahaven-com ALB for HTTPS.

Architecture

  • EC2: t4g.small (arm64), Amazon Linux 2023, 50GB gp3 EBS
  • Network: Private subnet (us-east-1a), behind seahaven-com ALB for SSL termination
  • DNS: forgejo.seahaven.com (Route53 alias → ALB)
  • TLS: Wildcard cert on ALB, HTTP internally on port 3000
  • Backup: Nightly EBS snapshots via DLM, 7-day retention
  • Admin access: SSM Session Manager (no SSH port exposed)

Ports

Port Protocol Source Purpose
443 HTTPS ALB (public) Web UI + HTTP git clone
3000 HTTP ALB → instance Internal traffic from ALB
2222 SSH VPC + VPN Git SSH operations

First-time setup

After the stack deploys, connect via SSM and create the admin user:

aws ssm start-session --target <instance-id>

sudo -u forgejo /usr/local/bin/forgejo admin user create \
  --admin \
  --username adam \
  --password '<password>' \
  --email adam@seahavenind.com \
  --config /etc/forgejo/app.ini

Admin password is stored in Secrets Manager at forgejo/admin-password.

Access the web UI at https://forgejo.seahaven.com.

Migrating repos from GitHub

Archived repos (one-time import)

In the Forgejo web UI: New Migration → GitHub → paste the GitHub repo URL. Use a GitHub personal access token for private repos. These are full imports (code, issues, PRs, releases).

Active repos (mirror sync)

Same migration flow, but check This Repository Will Be A Mirror. Forgejo polls GitHub hourly (DEFAULT_INTERVAL = 1h in app.ini) and keeps the mirror in sync.

Deployment

npm install
npx cdk deploy

CI/CD is handled by GitHub Actions — PRs run CI, merges to main deploy via the reusable CDK workflow.

Updating Forgejo

Update the FORGEJO_VERSION constant in lib/forgejo-stack.ts and deploy. This replaces the instance, so ensure the latest EBS snapshot is available for data recovery if needed. Alternatively, update in-place via SSM:

aws ssm start-session --target <instance-id>

sudo systemctl stop forgejo
sudo curl -Lo /usr/local/bin/forgejo "https://codeberg.org/forgejo/forgejo/releases/download/v<NEW_VERSION>/forgejo-<NEW_VERSION>-linux-arm64"
sudo chmod +x /usr/local/bin/forgejo
sudo systemctl start forgejo