gitea-docker-traefik
This commit is contained in:
		
							
								
								
									
										71
									
								
								gitea-docker-traefik/Vagrantfile
									
									
									
									
										vendored
									
									
										Normal file
									
								
							
							
						
						
									
										71
									
								
								gitea-docker-traefik/Vagrantfile
									
									
									
									
										vendored
									
									
										Normal file
									
								
							@@ -0,0 +1,71 @@
 | 
				
			|||||||
 | 
					# -*- mode: ruby -*-
 | 
				
			||||||
 | 
					# vi: set ft=ruby :
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					# All Vagrant configuration is done below. The "2" in Vagrant.configure
 | 
				
			||||||
 | 
					# configures the configuration version (we support older styles for
 | 
				
			||||||
 | 
					# backwards compatibility). Please don't change it unless you know what
 | 
				
			||||||
 | 
					# you're doing.
 | 
				
			||||||
 | 
					Vagrant.configure("2") do |config|
 | 
				
			||||||
 | 
					  # The most common configuration options are documented and commented below.
 | 
				
			||||||
 | 
					  # For a complete reference, please see the online documentation at
 | 
				
			||||||
 | 
					  # https://docs.vagrantup.com.
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					  # Every Vagrant development environment requires a box. You can search for
 | 
				
			||||||
 | 
					  # boxes at https://vagrantcloud.com/search.
 | 
				
			||||||
 | 
					  config.vm.box = "debian/bookworm"
 | 
				
			||||||
 | 
					  config.vm.hostname = "gitea-traefik"
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					  # Disable automatic box update checking. If you disable this, then
 | 
				
			||||||
 | 
					  # boxes will only be checked for updates when the user runs
 | 
				
			||||||
 | 
					  # `vagrant box outdated`. This is not recommended.
 | 
				
			||||||
 | 
					  # config.vm.box_check_update = false
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					  # Create a forwarded port mapping which allows access to a specific port
 | 
				
			||||||
 | 
					  # within the machine from a port on the host machine. In the example below,
 | 
				
			||||||
 | 
					  # accessing "localhost:8080" will access port 80 on the guest machine.
 | 
				
			||||||
 | 
					  # NOTE: This will enable public access to the opened port
 | 
				
			||||||
 | 
					  # config.vm.network "forwarded_port", guest: 80, host: 8080
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					  # Create a forwarded port mapping which allows access to a specific port
 | 
				
			||||||
 | 
					  # within the machine from a port on the host machine and only allow access
 | 
				
			||||||
 | 
					  # via 127.0.0.1 to disable public access
 | 
				
			||||||
 | 
					  # config.vm.network "forwarded_port", guest: 80, host: 8080, host_ip: "127.0.0.1"
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					  # Create a private network, which allows host-only access to the machine
 | 
				
			||||||
 | 
					  # using a specific IP.
 | 
				
			||||||
 | 
					  # config.vm.network "private_network", ip: "192.168.33.10"
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					  # Create a public network, which generally matched to bridged network.
 | 
				
			||||||
 | 
					  # Bridged networks make the machine appear as another physical device on
 | 
				
			||||||
 | 
					  # your network.
 | 
				
			||||||
 | 
					  config.vm.network "public_network"
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					  # Share an additional folder to the guest VM. The first argument is
 | 
				
			||||||
 | 
					  # the path on the host to the actual folder. The second argument is
 | 
				
			||||||
 | 
					  # the path on the guest to mount the folder. And the optional third
 | 
				
			||||||
 | 
					  # argument is a set of non-required options.
 | 
				
			||||||
 | 
					  # config.vm.synced_folder "../data", "/vagrant_data"
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					  # Provider-specific configuration so you can fine-tune various
 | 
				
			||||||
 | 
					  # backing providers for Vagrant. These expose provider-specific options.
 | 
				
			||||||
 | 
					  # Example for VirtualBox:
 | 
				
			||||||
 | 
					  #
 | 
				
			||||||
 | 
					   config.vm.provider "virtualbox" do |vb|
 | 
				
			||||||
 | 
					  #   # Display the VirtualBox GUI when booting the machine
 | 
				
			||||||
 | 
					  #   vb.gui = true
 | 
				
			||||||
 | 
					  #
 | 
				
			||||||
 | 
					  #   # Customize the amount of memory on the VM:
 | 
				
			||||||
 | 
					     vb.memory = "1024"
 | 
				
			||||||
 | 
					   end
 | 
				
			||||||
 | 
					  #
 | 
				
			||||||
 | 
					  # View the documentation for the provider you are using for more
 | 
				
			||||||
 | 
					  # information on available options.
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					  # Enable provisioning with a shell script. Additional provisioners such as
 | 
				
			||||||
 | 
					  # Ansible, Chef, Docker, Puppet and Salt are also available. Please see the
 | 
				
			||||||
 | 
					  # documentation for more information about their specific syntax and use.
 | 
				
			||||||
 | 
					   config.vm.provision "shell",
 | 
				
			||||||
 | 
					      inline: "sudo apt-get update ; sudo apt-get install -y vim curl wget"
 | 
				
			||||||
 | 
					   config.vm.provision "shell", path: "provision/setup.sh"
 | 
				
			||||||
 | 
					end
 | 
				
			||||||
 | 
					
 | 
				
			||||||
							
								
								
									
										82
									
								
								gitea-docker-traefik/provision/docker-compose.yml
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										82
									
								
								gitea-docker-traefik/provision/docker-compose.yml
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,82 @@
 | 
				
			|||||||
 | 
					version: '3'
 | 
				
			||||||
 | 
					volumes:
 | 
				
			||||||
 | 
					  nextcloud:
 | 
				
			||||||
 | 
					  db:
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					networks:
 | 
				
			||||||
 | 
					  proxy:
 | 
				
			||||||
 | 
					    external: true
 | 
				
			||||||
 | 
					  nxc:
 | 
				
			||||||
 | 
					    external: false
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					services:
 | 
				
			||||||
 | 
					  reverse-proxy:
 | 
				
			||||||
 | 
					    # The official v2 Traefik docker image
 | 
				
			||||||
 | 
					    image: traefik:latest
 | 
				
			||||||
 | 
					    container_name: traefik
 | 
				
			||||||
 | 
					    # Enables the web UI and tells Traefik to listen to docker
 | 
				
			||||||
 | 
					    command: --api.insecure=true --providers.docker
 | 
				
			||||||
 | 
					    ports:
 | 
				
			||||||
 | 
					      # The HTTP port
 | 
				
			||||||
 | 
					      - "80:80"
 | 
				
			||||||
 | 
					      - "443:443"
 | 
				
			||||||
 | 
					      # The Web UI (enabled by --api.insecure=true)
 | 
				
			||||||
 | 
					      - "8080:8080"
 | 
				
			||||||
 | 
					    volumes:
 | 
				
			||||||
 | 
					      # So that Traefik can listen to the Docker events
 | 
				
			||||||
 | 
					      - /var/run/docker.sock:/var/run/docker.sock:ro
 | 
				
			||||||
 | 
					      # Map the static configuration into the container
 | 
				
			||||||
 | 
					      - ./config/static.yml:/etc/traefik/traefik.yml:ro
 | 
				
			||||||
 | 
					      # Map the dynamic configuration into the container
 | 
				
			||||||
 | 
					      - ./config/dynamic.yml:/etc/traefik/dynamic.yml:ro
 | 
				
			||||||
 | 
					      # Map the certificats into the container
 | 
				
			||||||
 | 
					      - ./certs:/etc/certs:ro
 | 
				
			||||||
 | 
					    networks:
 | 
				
			||||||
 | 
					      - proxy
 | 
				
			||||||
 | 
					  
 | 
				
			||||||
 | 
					  db:
 | 
				
			||||||
 | 
					    image: mariadb:10.5
 | 
				
			||||||
 | 
					    container_name: db
 | 
				
			||||||
 | 
					    restart: always
 | 
				
			||||||
 | 
					    command: --transaction-isolation=READ-COMMITTED --binlog-format=ROW
 | 
				
			||||||
 | 
					    volumes:
 | 
				
			||||||
 | 
					      - db:/var/lib/mysql
 | 
				
			||||||
 | 
					    networks:
 | 
				
			||||||
 | 
					      - nxc
 | 
				
			||||||
 | 
					    environment:
 | 
				
			||||||
 | 
					      - MYSQL_ROOT_PASSWORD=Azerty1+
 | 
				
			||||||
 | 
					      - MYSQL_PASSWORD=Azerty1+
 | 
				
			||||||
 | 
					      - MYSQL_DATABASE=nextcloud
 | 
				
			||||||
 | 
					      - MYSQL_USER=nextcloud
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					  app:
 | 
				
			||||||
 | 
					    image: nextcloud
 | 
				
			||||||
 | 
					    container_name: app
 | 
				
			||||||
 | 
					    restart: always
 | 
				
			||||||
 | 
					    ports:
 | 
				
			||||||
 | 
					      - 8081:80
 | 
				
			||||||
 | 
					    #links:
 | 
				
			||||||
 | 
					    depends_on:
 | 
				
			||||||
 | 
					      - db
 | 
				
			||||||
 | 
					    volumes:
 | 
				
			||||||
 | 
					      - nextcloud:/var/www/html
 | 
				
			||||||
 | 
					    networks:
 | 
				
			||||||
 | 
					      - proxy
 | 
				
			||||||
 | 
					      - nxc
 | 
				
			||||||
 | 
					    labels:
 | 
				
			||||||
 | 
					#      - "traefik.enable=true"
 | 
				
			||||||
 | 
					      - "traefik.http.routers.app.rule=Host(`mon.nxc`)"
 | 
				
			||||||
 | 
					      - "traefik.http.routers.app.tls=true"
 | 
				
			||||||
 | 
					      - "traefik.enable=true"
 | 
				
			||||||
 | 
					      - "traefik.docker.network=proxy"
 | 
				
			||||||
 | 
					        #      - "traefik.http.routers.app.entrypoints=websecure"
 | 
				
			||||||
 | 
					        #      - "traefik.http.routers.app.rule=Host(`mon.nxc`)"
 | 
				
			||||||
 | 
					      - "traefik.http.routers.app.service=app-service"
 | 
				
			||||||
 | 
					      - "traefik.http.services.app-service.loadbalancer.server.port=80"
 | 
				
			||||||
 | 
					    environment:
 | 
				
			||||||
 | 
					      - MYSQL_PASSWORD=Azerty1+
 | 
				
			||||||
 | 
					      - MYSQL_DATABASE=nextcloud
 | 
				
			||||||
 | 
					      - MYSQL_USER=nextcloud
 | 
				
			||||||
 | 
					      - MYSQL_HOST=db
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					
 | 
				
			||||||
							
								
								
									
										164
									
								
								gitea-docker-traefik/provision/setup.sh
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										164
									
								
								gitea-docker-traefik/provision/setup.sh
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,164 @@
 | 
				
			|||||||
 | 
					#!/bin/bash
 | 
				
			||||||
 | 
					apt-get update
 | 
				
			||||||
 | 
					apt-get install -y wget curl git vim
 | 
				
			||||||
 | 
					if ! which docker ; then
 | 
				
			||||||
 | 
					   curl -s -o getdocker.sh https://get.docker.com
 | 
				
			||||||
 | 
					   bash getdocker.sh
 | 
				
			||||||
 | 
					   gpasswd -a vagrant docker
 | 
				
			||||||
 | 
					fi
 | 
				
			||||||
 | 
					mkdir -p gitea && cd gitea
 | 
				
			||||||
 | 
					wget -O mkcert https://github.com/FiloSottile/mkcert/releases/download/v1.4.4/mkcert-v1.4.4-linux-amd64
 | 
				
			||||||
 | 
					chmod +x mkcert
 | 
				
			||||||
 | 
					mv mkcert /usr/local/bin
 | 
				
			||||||
 | 
					sudo apt-get install -y libnss3-tools
 | 
				
			||||||
 | 
					mkdir certs config
 | 
				
			||||||
 | 
					mkcert -install
 | 
				
			||||||
 | 
					mkcert -cert-file certs/local-cert.pem -key-file certs/local-key.pem "gitea.local" "*.gitea.local"
 | 
				
			||||||
 | 
					cat > traefik.yml  <<EOT
 | 
				
			||||||
 | 
					version: '3'
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					networks:
 | 
				
			||||||
 | 
					  proxy:
 | 
				
			||||||
 | 
					    external: true
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					services:
 | 
				
			||||||
 | 
					  reverse-proxy:
 | 
				
			||||||
 | 
					    # The official v2 Traefik docker image
 | 
				
			||||||
 | 
					    image: traefik:latest
 | 
				
			||||||
 | 
					    container_name: traefik
 | 
				
			||||||
 | 
					    # Enables the web UI and tells Traefik to listen to docker
 | 
				
			||||||
 | 
					    command: --api.insecure=true --providers.docker
 | 
				
			||||||
 | 
					    ports:
 | 
				
			||||||
 | 
					      # The HTTP port
 | 
				
			||||||
 | 
					      - "80:80"
 | 
				
			||||||
 | 
					      - "443:443"
 | 
				
			||||||
 | 
					      # The Web UI (enabled by --api.insecure=true)
 | 
				
			||||||
 | 
					      - "8080:8080"
 | 
				
			||||||
 | 
					    volumes:
 | 
				
			||||||
 | 
					      # So that Traefik can listen to the Docker events
 | 
				
			||||||
 | 
					      - /var/run/docker.sock:/var/run/docker.sock:ro
 | 
				
			||||||
 | 
					      # Map the static configuration into the container
 | 
				
			||||||
 | 
					      - ./config/static.yml:/etc/traefik/traefik.yml:ro
 | 
				
			||||||
 | 
					      # Map the dynamic configuration into the container
 | 
				
			||||||
 | 
					      - ./config/dynamic.yml:/etc/traefik/dynamic.yml:ro
 | 
				
			||||||
 | 
					      # Map the certificats into the container
 | 
				
			||||||
 | 
					      - ./certs:/etc/certs:ro
 | 
				
			||||||
 | 
					    networks:
 | 
				
			||||||
 | 
					      - proxy
 | 
				
			||||||
 | 
					EOT
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					cat > ./config/static.yml <<EOT
 | 
				
			||||||
 | 
					global:
 | 
				
			||||||
 | 
					  sendAnonymousUsage: false
 | 
				
			||||||
 | 
					api:
 | 
				
			||||||
 | 
					  dashboard: true
 | 
				
			||||||
 | 
					  insecure: true
 | 
				
			||||||
 | 
					providers:
 | 
				
			||||||
 | 
					  docker:
 | 
				
			||||||
 | 
					    endpoint: "unix:///var/run/docker.sock"
 | 
				
			||||||
 | 
					    watch: true
 | 
				
			||||||
 | 
					    exposedByDefault: false
 | 
				
			||||||
 | 
					  file:
 | 
				
			||||||
 | 
					    filename: /etc/traefik/dynamic.yml
 | 
				
			||||||
 | 
					    watch: true
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					log:
 | 
				
			||||||
 | 
					  level: INFO
 | 
				
			||||||
 | 
					  format: common
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					entryPoints:
 | 
				
			||||||
 | 
					  http:
 | 
				
			||||||
 | 
					    address: ":80"
 | 
				
			||||||
 | 
					    http:
 | 
				
			||||||
 | 
					      redirections:
 | 
				
			||||||
 | 
					        entryPoint:
 | 
				
			||||||
 | 
					          to: https
 | 
				
			||||||
 | 
					          scheme: https
 | 
				
			||||||
 | 
					  https:
 | 
				
			||||||
 | 
					    address: ":443"
 | 
				
			||||||
 | 
					EOT
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					cat > ./config/dynamic.yml <<EOT
 | 
				
			||||||
 | 
					http:
 | 
				
			||||||
 | 
					  routers:
 | 
				
			||||||
 | 
					    traefik:
 | 
				
			||||||
 | 
					      rule: "Host(`traefik.docker.localhost`)"
 | 
				
			||||||
 | 
					      service: "api@internal"
 | 
				
			||||||
 | 
					      tls:
 | 
				
			||||||
 | 
					        domains:
 | 
				
			||||||
 | 
					          - main: "docker.localhost"
 | 
				
			||||||
 | 
					            sans:
 | 
				
			||||||
 | 
					              - "*.docker.localhost"
 | 
				
			||||||
 | 
					          - main: "gitea.local"
 | 
				
			||||||
 | 
					            sans:
 | 
				
			||||||
 | 
					              - "*.gitea.local"
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					tls:
 | 
				
			||||||
 | 
					  certificates:
 | 
				
			||||||
 | 
					    - certFile: "/etc/certs/local-cert.pem"
 | 
				
			||||||
 | 
					      keyFile: "/etc/certs/local-key.pem"
 | 
				
			||||||
 | 
					EOT
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					cat > gitea.yml  <<'EOT'
 | 
				
			||||||
 | 
					version: '2'
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					volumes:
 | 
				
			||||||
 | 
					  gitea:
 | 
				
			||||||
 | 
					  db:
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					networks:
 | 
				
			||||||
 | 
					  proxy:
 | 
				
			||||||
 | 
					    external: true
 | 
				
			||||||
 | 
					  gitea:
 | 
				
			||||||
 | 
					    external: false
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					services:
 | 
				
			||||||
 | 
					  db:
 | 
				
			||||||
 | 
					    image: mariadb
 | 
				
			||||||
 | 
					    container_name: db
 | 
				
			||||||
 | 
					    restart: always
 | 
				
			||||||
 | 
					#    command: --transaction-isolation=READ-COMMITTED --binlog-format=ROW
 | 
				
			||||||
 | 
					    volumes:
 | 
				
			||||||
 | 
					      - db:/var/lib/mysql
 | 
				
			||||||
 | 
					    networks:
 | 
				
			||||||
 | 
					      - gitea
 | 
				
			||||||
 | 
					    traefik-enable: false
 | 
				
			||||||
 | 
					    environment:
 | 
				
			||||||
 | 
					      - MYSQL_ROOT_PASSWORD=Azerty1+
 | 
				
			||||||
 | 
					      - MYSQL_PASSWORD=Azerty1+
 | 
				
			||||||
 | 
					      - MYSQL_DATABASE=gitea
 | 
				
			||||||
 | 
					      - MYSQL_USER=gitea
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					  app:
 | 
				
			||||||
 | 
					    image: gitea
 | 
				
			||||||
 | 
					    container_name: gitea
 | 
				
			||||||
 | 
					    restart: always
 | 
				
			||||||
 | 
					      #    ports:
 | 
				
			||||||
 | 
					      #      - 8081:80
 | 
				
			||||||
 | 
					    #links:
 | 
				
			||||||
 | 
					    depends_on:
 | 
				
			||||||
 | 
					      - db
 | 
				
			||||||
 | 
					    volumes:
 | 
				
			||||||
 | 
					      - gitea:/var/www/html
 | 
				
			||||||
 | 
					    networks:
 | 
				
			||||||
 | 
					      - proxy
 | 
				
			||||||
 | 
					      - gitea
 | 
				
			||||||
 | 
					    labels:
 | 
				
			||||||
 | 
					      - "traefik.enable=true"
 | 
				
			||||||
 | 
					      - "traefik.http.routers.app.rule=Host(`gitea.local`)"
 | 
				
			||||||
 | 
					      - "traefik.http.routers.app.tls=true"
 | 
				
			||||||
 | 
					      - "traefik.http.services.app.loadbalancer.server.port=3000"
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					    environment:
 | 
				
			||||||
 | 
					      - MYSQL_PASSWORD=Azerty1+
 | 
				
			||||||
 | 
					      - MYSQL_DATABASE=gitea
 | 
				
			||||||
 | 
					      - MYSQL_USER=gitea
 | 
				
			||||||
 | 
					      - MYSQL_HOST=db:3006
 | 
				
			||||||
 | 
					'EOT'
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					docker network create proxy
 | 
				
			||||||
 | 
					docker compose -f traefik.yml up -d 
 | 
				
			||||||
 | 
					docker compose -f gitea.yml up -d 
 | 
				
			||||||
 | 
					ip -br a 
 | 
				
			||||||
 | 
					
 | 
				
			||||||
		Reference in New Issue
	
	Block a user