diff --git a/gitea-docker-traefik/Vagrantfile b/gitea-docker-traefik/Vagrantfile new file mode 100644 index 0000000..9784244 --- /dev/null +++ b/gitea-docker-traefik/Vagrantfile @@ -0,0 +1,71 @@ +# -*- mode: ruby -*- +# vi: set ft=ruby : + +# All Vagrant configuration is done below. The "2" in Vagrant.configure +# configures the configuration version (we support older styles for +# backwards compatibility). Please don't change it unless you know what +# you're doing. +Vagrant.configure("2") do |config| + # The most common configuration options are documented and commented below. + # For a complete reference, please see the online documentation at + # https://docs.vagrantup.com. + + # Every Vagrant development environment requires a box. You can search for + # boxes at https://vagrantcloud.com/search. + config.vm.box = "debian/bookworm" + config.vm.hostname = "gitea-traefik" + + # Disable automatic box update checking. If you disable this, then + # boxes will only be checked for updates when the user runs + # `vagrant box outdated`. This is not recommended. + # config.vm.box_check_update = false + + # Create a forwarded port mapping which allows access to a specific port + # within the machine from a port on the host machine. In the example below, + # accessing "localhost:8080" will access port 80 on the guest machine. + # NOTE: This will enable public access to the opened port + # config.vm.network "forwarded_port", guest: 80, host: 8080 + + # Create a forwarded port mapping which allows access to a specific port + # within the machine from a port on the host machine and only allow access + # via 127.0.0.1 to disable public access + # config.vm.network "forwarded_port", guest: 80, host: 8080, host_ip: "127.0.0.1" + + # Create a private network, which allows host-only access to the machine + # using a specific IP. + # config.vm.network "private_network", ip: "192.168.33.10" + + # Create a public network, which generally matched to bridged network. + # Bridged networks make the machine appear as another physical device on + # your network. + config.vm.network "public_network" + + # Share an additional folder to the guest VM. The first argument is + # the path on the host to the actual folder. The second argument is + # the path on the guest to mount the folder. And the optional third + # argument is a set of non-required options. + # config.vm.synced_folder "../data", "/vagrant_data" + + # Provider-specific configuration so you can fine-tune various + # backing providers for Vagrant. These expose provider-specific options. + # Example for VirtualBox: + # + config.vm.provider "virtualbox" do |vb| + # # Display the VirtualBox GUI when booting the machine + # vb.gui = true + # + # # Customize the amount of memory on the VM: + vb.memory = "1024" + end + # + # View the documentation for the provider you are using for more + # information on available options. + + # Enable provisioning with a shell script. Additional provisioners such as + # Ansible, Chef, Docker, Puppet and Salt are also available. Please see the + # documentation for more information about their specific syntax and use. + config.vm.provision "shell", + inline: "sudo apt-get update ; sudo apt-get install -y vim curl wget" + config.vm.provision "shell", path: "provision/setup.sh" +end + diff --git a/gitea-docker-traefik/provision/docker-compose.yml b/gitea-docker-traefik/provision/docker-compose.yml new file mode 100644 index 0000000..ee8d24f --- /dev/null +++ b/gitea-docker-traefik/provision/docker-compose.yml @@ -0,0 +1,82 @@ +version: '3' +volumes: + nextcloud: + db: + +networks: + proxy: + external: true + nxc: + external: false + +services: + reverse-proxy: + # The official v2 Traefik docker image + image: traefik:latest + container_name: traefik + # Enables the web UI and tells Traefik to listen to docker + command: --api.insecure=true --providers.docker + ports: + # The HTTP port + - "80:80" + - "443:443" + # The Web UI (enabled by --api.insecure=true) + - "8080:8080" + volumes: + # So that Traefik can listen to the Docker events + - /var/run/docker.sock:/var/run/docker.sock:ro + # Map the static configuration into the container + - ./config/static.yml:/etc/traefik/traefik.yml:ro + # Map the dynamic configuration into the container + - ./config/dynamic.yml:/etc/traefik/dynamic.yml:ro + # Map the certificats into the container + - ./certs:/etc/certs:ro + networks: + - proxy + + db: + image: mariadb:10.5 + container_name: db + restart: always + command: --transaction-isolation=READ-COMMITTED --binlog-format=ROW + volumes: + - db:/var/lib/mysql + networks: + - nxc + environment: + - MYSQL_ROOT_PASSWORD=Azerty1+ + - MYSQL_PASSWORD=Azerty1+ + - MYSQL_DATABASE=nextcloud + - MYSQL_USER=nextcloud + + app: + image: nextcloud + container_name: app + restart: always + ports: + - 8081:80 + #links: + depends_on: + - db + volumes: + - nextcloud:/var/www/html + networks: + - proxy + - nxc + labels: +# - "traefik.enable=true" + - "traefik.http.routers.app.rule=Host(`mon.nxc`)" + - "traefik.http.routers.app.tls=true" + - "traefik.enable=true" + - "traefik.docker.network=proxy" + # - "traefik.http.routers.app.entrypoints=websecure" + # - "traefik.http.routers.app.rule=Host(`mon.nxc`)" + - "traefik.http.routers.app.service=app-service" + - "traefik.http.services.app-service.loadbalancer.server.port=80" + environment: + - MYSQL_PASSWORD=Azerty1+ + - MYSQL_DATABASE=nextcloud + - MYSQL_USER=nextcloud + - MYSQL_HOST=db + + diff --git a/gitea-docker-traefik/provision/setup.sh b/gitea-docker-traefik/provision/setup.sh new file mode 100644 index 0000000..10d3ca9 --- /dev/null +++ b/gitea-docker-traefik/provision/setup.sh @@ -0,0 +1,164 @@ +#!/bin/bash +apt-get update +apt-get install -y wget curl git vim +if ! which docker ; then + curl -s -o getdocker.sh https://get.docker.com + bash getdocker.sh + gpasswd -a vagrant docker +fi +mkdir -p gitea && cd gitea +wget -O mkcert https://github.com/FiloSottile/mkcert/releases/download/v1.4.4/mkcert-v1.4.4-linux-amd64 +chmod +x mkcert +mv mkcert /usr/local/bin +sudo apt-get install -y libnss3-tools +mkdir certs config +mkcert -install +mkcert -cert-file certs/local-cert.pem -key-file certs/local-key.pem "gitea.local" "*.gitea.local" +cat > traefik.yml < ./config/static.yml < ./config/dynamic.yml < gitea.yml <<'EOT' +version: '2' + +volumes: + gitea: + db: + +networks: + proxy: + external: true + gitea: + external: false + +services: + db: + image: mariadb + container_name: db + restart: always +# command: --transaction-isolation=READ-COMMITTED --binlog-format=ROW + volumes: + - db:/var/lib/mysql + networks: + - gitea + traefik-enable: false + environment: + - MYSQL_ROOT_PASSWORD=Azerty1+ + - MYSQL_PASSWORD=Azerty1+ + - MYSQL_DATABASE=gitea + - MYSQL_USER=gitea + + app: + image: gitea + container_name: gitea + restart: always + # ports: + # - 8081:80 + #links: + depends_on: + - db + volumes: + - gitea:/var/www/html + networks: + - proxy + - gitea + labels: + - "traefik.enable=true" + - "traefik.http.routers.app.rule=Host(`gitea.local`)" + - "traefik.http.routers.app.tls=true" + - "traefik.http.services.app.loadbalancer.server.port=3000" + + environment: + - MYSQL_PASSWORD=Azerty1+ + - MYSQL_DATABASE=gitea + - MYSQL_USER=gitea + - MYSQL_HOST=db:3006 +'EOT' + +docker network create proxy +docker compose -f traefik.yml up -d +docker compose -f gitea.yml up -d +ip -br a +