fix(gitea-mirror): read auth and encryption secrets from the environment

Data encrypted under one secret is unreadable under another, so the
secrets must move with the data instead of being regenerated by the image.
This commit is contained in:
tiennm99 committed 2026-10-03 10:07:34 +07:00
1 parent 3c737b05cd
commit d4882c6f3e
3 files changed
+13 -3

No files matched your search

+2
View File
@@ -1,3 +1,5 @@
POSTGRES_PASSWORD=gitea
GITEA_ROOT_URL=https://gitea.example.com/
BETTER_AUTH_SECRET=
ENCRYPTION_SECRET=
GITEA_MIRROR_URL=https://gitea-mirror.example.com
+9 -3
View File
@@ -24,6 +24,8 @@ port, matching the two URL variables.
| --- | --- | --- |
| `POSTGRES_PASSWORD` | `db`, `gitea` | Defaults to `gitea`. |
| `GITEA_ROOT_URL` | Gitea `server.ROOT_URL` | Public URL, with trailing slash. Gitea builds clone URLs and redirects from it. |
| `BETTER_AUTH_SECRET` | gitea-mirror | Signs sessions and encrypts its login keys. Generate with `openssl rand -base64 32`. |
| `ENCRYPTION_SECRET` | gitea-mirror | Encrypts the stored GitHub and Gitea tokens. Generate with `openssl rand -base64 48`. |
| `GITEA_MIRROR_URL` | `BETTER_AUTH_URL`, `PUBLIC_BETTER_AUTH_URL`, `BETTER_AUTH_TRUSTED_ORIGINS` | Public URL of the mirror UI, no trailing slash. |
Postgres sets the password only when it first initialises `db-data`. Changing
@@ -36,9 +38,13 @@ docker compose exec db psql -U gitea -c "ALTER USER gitea PASSWORD '<new>';"
Behind a reverse proxy, gitea-mirror rejects sign-in with "invalid origin"
unless all three Better Auth variables hold the external URL, so one variable
feeds them all. Its `BETTER_AUTH_SECRET` and `ENCRYPTION_SECRET` are left
unset: the image generates both on first start and keeps them in
`gitea-mirror-data`.
feeds them all.
Both secrets are set explicitly rather than left to the image, which would
otherwise generate its own into `gitea-mirror-data`. Data encrypted under one
secret is unreadable under another, so moving the data to a new deployment
means carrying the secrets with it. Never change either on an existing
install.
## Choices
+2
View File
@@ -42,6 +42,8 @@ services:
restart: unless-stopped
pull_policy: always
environment:
BETTER_AUTH_SECRET: ${BETTER_AUTH_SECRET:?required}
ENCRYPTION_SECRET: ${ENCRYPTION_SECRET:?required}
BETTER_AUTH_URL: ${GITEA_MIRROR_URL:?required}
PUBLIC_BETTER_AUTH_URL: ${GITEA_MIRROR_URL:?required}
BETTER_AUTH_TRUSTED_ORIGINS: ${GITEA_MIRROR_URL:?required}