From d4882c6f3ed77cfe4630cf7f208196abe088cc26 Mon Sep 17 00:00:00 2001 From: tiennm99 Date: Sat, 3 Oct 2026 10:07:34 +0700 Subject: [PATCH] fix(gitea-mirror): read auth and encryption secrets from the environment Data encrypted under one secret is unreadable under another, so the secrets must move with the data instead of being regenerated by the image. --- gitea-mirror/.env.example | 2 ++ gitea-mirror/README.md | 12 +++++++++--- gitea-mirror/compose.yml | 2 ++ 3 files changed, 13 insertions(+), 3 deletions(-) diff --git a/gitea-mirror/.env.example b/gitea-mirror/.env.example index be06a71..b68109b 100644 --- a/gitea-mirror/.env.example +++ b/gitea-mirror/.env.example @@ -1,3 +1,5 @@ POSTGRES_PASSWORD=gitea GITEA_ROOT_URL=https://gitea.example.com/ +BETTER_AUTH_SECRET= +ENCRYPTION_SECRET= GITEA_MIRROR_URL=https://gitea-mirror.example.com diff --git a/gitea-mirror/README.md b/gitea-mirror/README.md index 44f71a1..d2e89f2 100644 --- a/gitea-mirror/README.md +++ b/gitea-mirror/README.md @@ -24,6 +24,8 @@ port, matching the two URL variables. | --- | --- | --- | | `POSTGRES_PASSWORD` | `db`, `gitea` | Defaults to `gitea`. | | `GITEA_ROOT_URL` | Gitea `server.ROOT_URL` | Public URL, with trailing slash. Gitea builds clone URLs and redirects from it. | +| `BETTER_AUTH_SECRET` | gitea-mirror | Signs sessions and encrypts its login keys. Generate with `openssl rand -base64 32`. | +| `ENCRYPTION_SECRET` | gitea-mirror | Encrypts the stored GitHub and Gitea tokens. Generate with `openssl rand -base64 48`. | | `GITEA_MIRROR_URL` | `BETTER_AUTH_URL`, `PUBLIC_BETTER_AUTH_URL`, `BETTER_AUTH_TRUSTED_ORIGINS` | Public URL of the mirror UI, no trailing slash. | Postgres sets the password only when it first initialises `db-data`. Changing @@ -36,9 +38,13 @@ docker compose exec db psql -U gitea -c "ALTER USER gitea PASSWORD '';" Behind a reverse proxy, gitea-mirror rejects sign-in with "invalid origin" unless all three Better Auth variables hold the external URL, so one variable -feeds them all. Its `BETTER_AUTH_SECRET` and `ENCRYPTION_SECRET` are left -unset: the image generates both on first start and keeps them in -`gitea-mirror-data`. +feeds them all. + +Both secrets are set explicitly rather than left to the image, which would +otherwise generate its own into `gitea-mirror-data`. Data encrypted under one +secret is unreadable under another, so moving the data to a new deployment +means carrying the secrets with it. Never change either on an existing +install. ## Choices diff --git a/gitea-mirror/compose.yml b/gitea-mirror/compose.yml index 509cbc8..08085ea 100644 --- a/gitea-mirror/compose.yml +++ b/gitea-mirror/compose.yml @@ -42,6 +42,8 @@ services: restart: unless-stopped pull_policy: always environment: + BETTER_AUTH_SECRET: ${BETTER_AUTH_SECRET:?required} + ENCRYPTION_SECRET: ${ENCRYPTION_SECRET:?required} BETTER_AUTH_URL: ${GITEA_MIRROR_URL:?required} PUBLIC_BETTER_AUTH_URL: ${GITEA_MIRROR_URL:?required} BETTER_AUTH_TRUSTED_ORIGINS: ${GITEA_MIRROR_URL:?required}