|
Some checks are pending
Deploy / deploy (push) Waiting to run
S3 bucket for Forgejo dumps (Standard 30d → Glacier, expire 365d). Cron runs forgejo dump at 5 AM UTC and uploads to S3. |
||
|---|---|---|
| .github/workflows | ||
| bin | ||
| lib | ||
| .gitignore | ||
| cdk.json | ||
| package-lock.json | ||
| package.json | ||
| README.md | ||
| tsconfig.json | ||
forgejo
Self-hosted Forgejo git server for archiving GitHub repos and mirroring active ones. Runs on a single EC2 instance within the Sea Haven VPC, fronted by the seahaven-com ALB for HTTPS.
Architecture
- EC2: t4g.small (arm64), Amazon Linux 2023, 50GB gp3 EBS
- Network: Private subnet (us-east-1a), behind
seahaven-comALB for SSL termination - DNS:
forgejo.seahaven.com(Route53 alias → ALB) - TLS: Wildcard cert on ALB, HTTP internally on port 3000
- Backup: Nightly EBS snapshots via DLM, 7-day retention
- Admin access: SSM Session Manager (no SSH port exposed)
Ports
| Port | Protocol | Source | Purpose |
|---|---|---|---|
| 443 | HTTPS | ALB (public) | Web UI + HTTP git clone |
| 3000 | HTTP | ALB → instance | Internal traffic from ALB |
| 2222 | SSH | VPC + VPN | Git SSH operations |
First-time setup
After the stack deploys, connect via SSM and create the admin user:
aws ssm start-session --target <instance-id>
sudo -u forgejo /usr/local/bin/forgejo admin user create \
--admin \
--username adam \
--password '<password>' \
--email adam@seahavenind.com \
--config /etc/forgejo/app.ini
Admin password is stored in Secrets Manager at forgejo/admin-password.
Access the web UI at https://forgejo.seahaven.com.
Migrating repos from GitHub
Archived repos (one-time import)
In the Forgejo web UI: New Migration → GitHub → paste the GitHub repo URL. Use a GitHub personal access token for private repos. These are full imports (code, issues, PRs, releases).
Active repos (mirror sync)
Same migration flow, but check This Repository Will Be A Mirror. Forgejo polls GitHub hourly (DEFAULT_INTERVAL = 1h in app.ini) and keeps the mirror in sync.
Deployment
npm install
npx cdk deploy
CI/CD is handled by GitHub Actions — PRs run CI, merges to main deploy via the reusable CDK workflow.
Updating Forgejo
Update the FORGEJO_VERSION constant in lib/forgejo-stack.ts and deploy. This replaces the instance, so ensure the latest EBS snapshot is available for data recovery if needed. Alternatively, update in-place via SSM:
aws ssm start-session --target <instance-id>
sudo systemctl stop forgejo
sudo curl -Lo /usr/local/bin/forgejo "https://codeberg.org/forgejo/forgejo/releases/download/v<NEW_VERSION>/forgejo-<NEW_VERSION>-linux-arm64"
sudo chmod +x /usr/local/bin/forgejo
sudo systemctl start forgejo