diff options
| author | Paul Buetow <paul@buetow.org> | 2026-07-26 10:08:45 +0300 |
|---|---|---|
| committer | Paul Buetow <paul@buetow.org> | 2026-07-26 10:08:45 +0300 |
| commit | a3692f68bace2dc171dbceed274bc26eeadd38aa (patch) | |
| tree | 37c4419b4418977e8ebdf2a2df81b1cf819ba852 /f3s/forgejo/README.md | |
| parent | a3f216fc2cce2299cf66e174fb927cc05dde97dd (diff) | |
forgejo: fix admin creation and reverse-proxy handling from review
Review of the initial chart turned up one blocker and several correctness gaps:
- `just create-admin` could never work. `admin user create` does not prompt; it
exits with "must set either password or random-password flag". With the
installer locked and registration disabled that recipe was the only way into
the instance, so first login was impossible. Use --random-password, which
prints the generated password once, rather than passing one on the command
line where it would reach shell history and ps.
- SSH_DOMAIN advertised code.f3s.buetow.org, but that name resolves to the
OpenBSD gateways (443 only) and *.f3s.lan points at the CARP storage VIP, not
a k3s node. Every clone URL Forgejo rendered would have been unreachable.
Advertise r0.lan.buetow.org, which actually answers on the NodePort.
- No REVERSE_PROXY_TRUSTED_PROXIES, so behind relayd -> Traefik every request
was attributed to the Traefik pod IP: real client IPs absent from the audit
trail and per-IP rate limiting defeated, on an internet-facing instance.
- Pin both PVCs with volumeName. The 1Gi config claim also matched the 20Gi
data PV, leaving the choice to the binder's smallest-sufficient heuristic.
README: add the gogios task to the frontends deploy (the new host otherwise
gets no TLS/HTTP checks); drop the false claim that pushing alone deploys the
Application, since nothing watches f3s/argocd-apps/; keep .nfs-sentinel at 0644
instead of sweeping it into a recursive 0750; note that the real certificate is
only issued on the gateway holding the DNS master IP.
Still not activated. Re-verified: helm template renders, and all 9 objects pass
kubectl apply --dry-run=server.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Diffstat (limited to 'f3s/forgejo/README.md')
| -rw-r--r-- | f3s/forgejo/README.md | 28 |
1 files changed, 21 insertions, 7 deletions
diff --git a/f3s/forgejo/README.md b/f3s/forgejo/README.md index ecc35a6..9758b29 100644 --- a/f3s/forgejo/README.md +++ b/f3s/forgejo/README.md @@ -49,9 +49,14 @@ doas mkdir -p /data/nfs/k3svolumes/forgejo/data /data/nfs/k3svolumes/forgejo/con doas touch /data/nfs/k3svolumes/forgejo/data/.nfs-sentinel \ /data/nfs/k3svolumes/forgejo/config/.nfs-sentinel doas chown -R 1000:1000 /data/nfs/k3svolumes/forgejo -doas chmod -R 0750 /data/nfs/k3svolumes/forgejo +doas chmod 0750 /data/nfs/k3svolumes/forgejo/data /data/nfs/k3svolumes/forgejo/config +doas chmod 0644 /data/nfs/k3svolumes/forgejo/data/.nfs-sentinel \ + /data/nfs/k3svolumes/forgejo/config/.nfs-sentinel ``` +The sentinel files are 0644 per `f3s/docs/nfs-sentinel-initcontainer.md` — do not +sweep them up in a recursive chmod of the directories. + The PVs use `type: Directory`, so the pod will not schedule until these exist. ### 2. Publish the hostname @@ -65,14 +70,21 @@ so the certificate has to exist first: ```sh cd frontends -rex -H blowfish.buetow.org:2 nsd httpd acme acme_invoke relayd -rex -H fishfinger.buetow.org:2 nsd httpd acme acme_invoke relayd +rex -H blowfish.buetow.org:2 nsd httpd acme acme_invoke relayd gogios +rex -H fishfinger.buetow.org:2 nsd httpd acme acme_invoke relayd gogios ``` `acme.sh` copies the `foo.zone` cert as a placeholder for any host that has none -yet, so relayd will still start on the first pass; the real certificate arrives -on the same run. Deploying one gateway at a time avoids restarting both public -frontends simultaneously. +yet, so relayd will still start on the first pass. The *real* certificate is only +issued on the gateway currently holding the DNS master IP — `acme.sh` skips +`acme-client` on the standby, which keeps the placeholder until a failover. That +is normal; the standby is not serving the name yet. + +`gogios` is included because the TLS and HTTP checks for the new host are +rendered from `@acme_hosts`; without it `code.f3s.buetow.org` gets no monitoring. + +Deploying one gateway at a time avoids restarting both public frontends +simultaneously. ### 3. Deploy @@ -80,7 +92,9 @@ frontends simultaneously. kubectl apply -f ../argocd-apps/services/forgejo.yaml ``` -Or just push — ArgoCD picks it up automatically. +This apply is required and cannot be skipped: there is no app-of-apps or +ApplicationSet watching `f3s/argocd-apps/`, so pushing the repo alone does +nothing. Once the Application exists, later edits to the chart do auto-sync. ### 4. Create the admin user |
