mirror of
https://github.com/tiennm99/composes.git
synced 2026-10-11 03:13:16 +00:00
fix(gitea-mirror): read auth and encryption secrets from the environment
Data encrypted under one secret is unreadable under another, so the secrets must move with the data instead of being regenerated by the image.
This commit is contained in:
1 parent
3c737b05cd
commit
d4882c6f3e
3 files changed
+13
-3
No files matched your search
@@ -1,3 +1,5 @@
|
||||
POSTGRES_PASSWORD=gitea
|
||||
GITEA_ROOT_URL=https://gitea.example.com/
|
||||
BETTER_AUTH_SECRET=
|
||||
ENCRYPTION_SECRET=
|
||||
GITEA_MIRROR_URL=https://gitea-mirror.example.com
|
||||
@@ -24,6 +24,8 @@ port, matching the two URL variables.
|
||||
| --- | --- | --- |
|
||||
| `POSTGRES_PASSWORD` | `db`, `gitea` | Defaults to `gitea`. |
|
||||
| `GITEA_ROOT_URL` | Gitea `server.ROOT_URL` | Public URL, with trailing slash. Gitea builds clone URLs and redirects from it. |
|
||||
| `BETTER_AUTH_SECRET` | gitea-mirror | Signs sessions and encrypts its login keys. Generate with `openssl rand -base64 32`. |
|
||||
| `ENCRYPTION_SECRET` | gitea-mirror | Encrypts the stored GitHub and Gitea tokens. Generate with `openssl rand -base64 48`. |
|
||||
| `GITEA_MIRROR_URL` | `BETTER_AUTH_URL`, `PUBLIC_BETTER_AUTH_URL`, `BETTER_AUTH_TRUSTED_ORIGINS` | Public URL of the mirror UI, no trailing slash. |
|
||||
|
||||
Postgres sets the password only when it first initialises `db-data`. Changing
|
||||
@@ -36,9 +38,13 @@ docker compose exec db psql -U gitea -c "ALTER USER gitea PASSWORD '<new>';"
|
||||
|
||||
Behind a reverse proxy, gitea-mirror rejects sign-in with "invalid origin"
|
||||
unless all three Better Auth variables hold the external URL, so one variable
|
||||
feeds them all. Its `BETTER_AUTH_SECRET` and `ENCRYPTION_SECRET` are left
|
||||
unset: the image generates both on first start and keeps them in
|
||||
`gitea-mirror-data`.
|
||||
feeds them all.
|
||||
|
||||
Both secrets are set explicitly rather than left to the image, which would
|
||||
otherwise generate its own into `gitea-mirror-data`. Data encrypted under one
|
||||
secret is unreadable under another, so moving the data to a new deployment
|
||||
means carrying the secrets with it. Never change either on an existing
|
||||
install.
|
||||
|
||||
## Choices
|
||||
|
||||
|
||||
@@ -42,6 +42,8 @@ services:
|
||||
restart: unless-stopped
|
||||
pull_policy: always
|
||||
environment:
|
||||
BETTER_AUTH_SECRET: ${BETTER_AUTH_SECRET:?required}
|
||||
ENCRYPTION_SECRET: ${ENCRYPTION_SECRET:?required}
|
||||
BETTER_AUTH_URL: ${GITEA_MIRROR_URL:?required}
|
||||
PUBLIC_BETTER_AUTH_URL: ${GITEA_MIRROR_URL:?required}
|
||||
BETTER_AUTH_TRUSTED_ORIGINS: ${GITEA_MIRROR_URL:?required}
|
||||
|
||||
Reference in new issue
Block a user