Compare commits

..
6 Commits
Author SHA1 Message Date
magnusandClaude Opus 5 58dfcd2ebb Move to dedicated Postgres and netbird-only SSH; DB password to .env
docker-compose.yml had drifted from the committed version during the move to
this host: a dedicated gitea-postgres service replaces the shared postgres-db
on the LAN box, and SSH is now published on the netbird interface only
(100.75.252.111:2222) instead of 0.0.0.0.

The database password is no longer inline — both POSTGRES_PASSWORD and
GITEA__database__PASSWD read ${POSTGRES_PASSWORD} from .env (gitignored,
mode 0600). .env.example documents the key, and *.bak-* is now ignored.

Note: run docker compose from this directory, otherwise .env is not picked up
and the variable resolves empty.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Kjn2zm5PJ5y9t4HjpGouWR
2026-09-08 16:06:44 +00:00
magnusandClaude Opus 4.6 242fa8a927 Change backup directory to /data/backup/gitea
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-06 15:53:44 +01:00
magnusandClaude Opus 4.6 ffdd8bb4b2 Fix backup permission denied by using docker cp instead of direct mount write
The git user inside the gitea container couldn't write to the NAS-mounted
/tmp/backup directory. Now dumps to /tmp first, then uses docker cp to
extract the file to the sidecar's backup directory.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-28 08:22:09 +01:00
magnusandClaude Opus 4.6 e17ee68fbd Change backup path from /mnt/nasen to /mnt/nas
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-21 10:47:48 +01:00
magnusandClaude Opus 4.6 1f06472140 Add README with setup and backup instructions
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-21 10:15:26 +01:00
magnusandClaude Opus 4.6 26af7784e7 Add .gitignore
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-21 10:14:07 +01:00
5 changed files with 63 additions and 12 deletions
+2
View File
@@ -0,0 +1,2 @@
# Copy to .env and fill in. Used by docker-compose.yml.
POSTGRES_PASSWORD=change-me
+4
View File
@@ -0,0 +1,4 @@
*.zip
*.log
.env
*.bak-*
+29 -1
View File
@@ -1,2 +1,30 @@
# gitea # Gitea
Self-hosted Gitea instance running on Docker Compose with a remote PostgreSQL database and automated daily backups.
## Services
- **gitea** — Web UI on port `3008`, SSH on port `2222`
- **gitea-backup** — Alpine sidecar running a daily cron job at 2 AM
## Setup
```bash
docker-compose up -d
```
## Backups
Backups run automatically at 2 AM daily, writing `gitea-dump-*.zip` files to `/mnt/nasen/backup/gitea` with 7-day retention.
Run a manual backup:
```bash
docker exec gitea-backup /usr/local/bin/backup.sh
```
Check backup logs:
```bash
docker exec gitea-backup cat /var/log/backup.log
```
+8 -5
View File
@@ -16,18 +16,21 @@ if ! docker inspect gitea >/dev/null 2>&1; then
exit 1 exit 1
fi fi
# Ensure backup directory exists inside gitea container # Run gitea dump to /tmp (writable by git user)
docker exec -u git gitea sh -c "mkdir -p /tmp/backup"
# Run gitea dump
echo "Running gitea dump..." echo "Running gitea dump..."
docker exec -u git -w /tmp gitea \ docker exec -u git -w /tmp gitea \
/app/gitea/gitea dump \ /app/gitea/gitea dump \
-c /data/gitea/conf/app.ini \ -c /data/gitea/conf/app.ini \
--file "/tmp/backup/${BACKUP_FILE}" \ --file "/tmp/${BACKUP_FILE}" \
--skip-log \ --skip-log \
--type zip --type zip
# Copy dump out of gitea container into sidecar's backup dir
docker cp "gitea:/tmp/${BACKUP_FILE}" "${BACKUP_DIR}/${BACKUP_FILE}"
# Clean up temp file inside gitea container
docker exec gitea rm -f "/tmp/${BACKUP_FILE}"
# Verify backup was created # Verify backup was created
if [ ! -f "${BACKUP_DIR}/${BACKUP_FILE}" ]; then if [ ! -f "${BACKUP_DIR}/${BACKUP_FILE}" ]; then
echo "ERROR: Backup file not found at ${BACKUP_DIR}/${BACKUP_FILE}" echo "ERROR: Backup file not found at ${BACKUP_DIR}/${BACKUP_FILE}"
+20 -6
View File
@@ -1,24 +1,37 @@
services: services:
postgres:
image: postgres:16-alpine
container_name: gitea-postgres
restart: unless-stopped
environment:
- POSTGRES_USER=gitea
- POSTGRES_PASSWORD=${POSTGRES_PASSWORD}
- POSTGRES_DB=gitea
volumes:
- postgres_data:/var/lib/postgresql/data
gitea: gitea:
image: gitea/gitea:latest image: gitea/gitea:latest
container_name: gitea container_name: gitea
depends_on:
- postgres
environment: environment:
- USER_UID=1000 - USER_UID=1000
- USER_GID=1000 - USER_GID=1000
- GITEA__database__DB_TYPE=postgres - GITEA__database__DB_TYPE=postgres
- GITEA__database__HOST=192.168.50.42:5432 - GITEA__database__HOST=postgres:5432
- GITEA__database__NAME=gitea - GITEA__database__NAME=gitea
- GITEA__database__USER=postgres - GITEA__database__USER=gitea
- GITEA__database__PASSWD=ratata,123 - GITEA__database__PASSWD=${POSTGRES_PASSWORD}
restart: unless-stopped restart: unless-stopped
volumes: volumes:
- gitea_data:/data - gitea_data:/data
- /etc/timezone:/etc/timezone:ro - /etc/timezone:/etc/timezone:ro
- /etc/localtime:/etc/localtime:ro - /etc/localtime:/etc/localtime:ro
- /mnt/nasen/backup/gitea:/tmp/backup - ./backup:/tmp/backup
ports: ports:
- "3008:3000" - "3008:3000"
- "2222:22" - "100.75.252.111:2222:22"
gitea-backup: gitea-backup:
image: alpine:3.21 image: alpine:3.21
@@ -30,7 +43,7 @@ services:
- BACKUP_RETAIN_DAYS=7 - BACKUP_RETAIN_DAYS=7
volumes: volumes:
- /var/run/docker.sock:/var/run/docker.sock - /var/run/docker.sock:/var/run/docker.sock
- /mnt/nasen/backup/gitea:/backup - ./backup:/backup
- ./backup.sh:/usr/local/bin/backup.sh:ro - ./backup.sh:/usr/local/bin/backup.sh:ro
- /etc/timezone:/etc/timezone:ro - /etc/timezone:/etc/timezone:ro
- /etc/localtime:/etc/localtime:ro - /etc/localtime:/etc/localtime:ro
@@ -45,3 +58,4 @@ services:
volumes: volumes:
gitea_data: gitea_data:
postgres_data: