forgejo/README.md
Adam Moussa a500d69716 Add Forgejo CDK stack
EC2 (t4g.small, arm64) in private subnet with VPN-only access,
DLM nightly snapshots, and Route53 DNS at forgejo.seahaven.com.
2026-05-11 17:52:37 -04:00

69 lines
2.2 KiB
Markdown

# forgejo
Self-hosted Forgejo git server for archiving GitHub repos and mirroring active ones. Runs on a single EC2 instance within the Sea Haven VPC, accessible only via VPN.
## Architecture
- **EC2**: t4g.small (arm64), Amazon Linux 2023, 50GB gp3 EBS
- **Network**: Private subnet (us-east-1a), VPC + VPN access only
- **DNS**: `forgejo.seahaven.com` (Route53 A record → private IP)
- **Backup**: Nightly EBS snapshots via DLM, 7-day retention
- **Admin access**: SSM Session Manager (no SSH port exposed)
### Ports
| Port | Protocol | Purpose |
|------|----------|---------|
| 3000 | HTTP | Web UI + HTTP git clone |
| 2222 | SSH | Git SSH operations |
Both ports are restricted to VPC (10.20.0.0/16) and office VPN (10.10.0.0/16).
## First-time setup
After the stack deploys, connect via SSM and create the admin user:
```bash
aws ssm start-session --target <instance-id>
sudo -u forgejo /usr/local/bin/forgejo admin user create \
--admin \
--username adam \
--password '<password>' \
--email adam@seahavenind.com \
--config /etc/forgejo/app.ini
```
Then access the web UI at `http://forgejo.seahaven.com:3000`.
## Migrating repos from GitHub
### Archived repos (one-time import)
In the Forgejo web UI: **New Migration → GitHub** → paste the GitHub repo URL. Use a GitHub personal access token for private repos. These are full imports (code, issues, PRs, releases).
### Active repos (mirror sync)
Same migration flow, but check **This Repository Will Be A Mirror**. Forgejo polls GitHub hourly (`DEFAULT_INTERVAL = 1h` in app.ini) and keeps the mirror in sync.
## Deployment
```bash
npm install
npx cdk deploy
```
CI/CD is handled by GitHub Actions — PRs run CI, merges to `main` deploy via the reusable CDK workflow.
## Updating Forgejo
Update the `FORGEJO_VERSION` constant in `lib/forgejo-stack.ts` and deploy. This replaces the instance, so ensure the latest EBS snapshot is available for data recovery if needed. Alternatively, update in-place via SSM:
```bash
aws ssm start-session --target <instance-id>
sudo systemctl stop forgejo
sudo curl -Lo /usr/local/bin/forgejo "https://codeberg.org/forgejo/forgejo/releases/download/v<NEW_VERSION>/forgejo-<NEW_VERSION>-linux-arm64"
sudo chmod +x /usr/local/bin/forgejo
sudo systemctl start forgejo
```