Files
app-catalog-felhom.eu/templates/gitea/docker-compose.yml
T
admin d7ba60c409
gates / gates (push) Successful in 2s
gitea: 1.27.0 -> 1.27.3, its first ladder step, both venues proven (R-462, R-624)
Bench 9401 (harness v4, swap 0): the first-run installer form posted, a repo seeded and read back
before and after, 10-min memory watch 0 kills (anon peak 26.6 %, cgroup 52.9 %). Box 9202: the
guarded Update done in 21.6 s through the setup gate, the repo read back. Written by
upgrade-test.py --write-ladder. 28.0.0 is a major (2026-09-02 ruling) and is not touched.

Evidence: felhom.eu/documentation/audits/more-night-apps-2026-09-30/

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-09-30 17:16:56 +02:00

61 lines
2.5 KiB
YAML

# Gitea - Könnyű, saját Git szerver webes felülettel
# Domain: ${SUBDOMAIN}.${DOMAIN}
# Database: None (file-based)
# RAM: ~100M (mem_limit: 512M) | Pi-compatible: Yes
#
# Environment variables:
# DOMAIN - Your domain (e.g., demo-felhom.eu)
services:
gitea:
image: gitea/gitea:1.27.3
container_name: gitea
restart: unless-stopped
environment:
# decision 47: the app's own sign-up switch — open until the box closes it after the first admin (after_setup)
- GITEA__service__DISABLE_REGISTRATION=${SIGNUP_CLOSED:-false}
- TZ=Europe/Budapest
- GITEA__server__ROOT_URL=https://${SUBDOMAIN}.${DOMAIN}
- GITEA__server__SSH_DOMAIN=${SUBDOMAIN}.${DOMAIN}
- GITEA__database__DB_TYPE=sqlite3
# App-email (managed relay). Injected by the controller only when app-email is on (global +
# per-app); empty ENABLED/ADDR keeps Gitea mail disabled. Gitea applies GITEA__* env on every
# boot (environment-to-ini), so the toggle takes effect on redeploy. See .felhom.yml smtp_mapping.
- GITEA__mailer__ENABLED=${GITEA__mailer__ENABLED:-false}
- GITEA__mailer__PROTOCOL=${GITEA__mailer__PROTOCOL:-smtp+starttls}
- GITEA__mailer__SMTP_ADDR=${GITEA__mailer__SMTP_ADDR:-}
- GITEA__mailer__SMTP_PORT=${GITEA__mailer__SMTP_PORT:-2525}
- GITEA__mailer__FROM=${GITEA__mailer__FROM:-}
- GITEA__mailer__FORCE_TRUST_SERVER_CERT=${GITEA__mailer__FORCE_TRUST_SERVER_CERT:-false}
volumes:
- gitea_data:/data
networks:
- traefik-public
deploy:
resources:
limits:
memory: 512M
# /api/healthz is gitea's dedicated health endpoint (200 once serving); /api/v1/version returns
# 404 until the install wizard is completed (INSTALL_LOCK), so it falsely reported unhealthy on a
# fresh deploy. The gitea image ships curl (verified). 90s start_period covers first-boot DB migration.
healthcheck:
test: ["CMD", "curl", "-f", "http://127.0.0.1:3000/api/healthz"]
interval: 30s
timeout: 5s
retries: 3
start_period: 90s
labels:
- "traefik.enable=true"
- "traefik.http.routers.gitea.rule=Host(`${SUBDOMAIN}.${DOMAIN}`)"
- "traefik.http.routers.gitea.entrypoints=websecure"
- "traefik.http.routers.gitea.tls=true"
- "traefik.http.routers.gitea.tls.certresolver=letsencrypt"
- "traefik.http.services.gitea.loadbalancer.server.port=3000"
volumes:
gitea_data:
networks:
traefik-public:
external: true