| Filename | Latest commit message | Latest commit date |
|---|---|---|
|
Some checks failed
ci/woodpecker/push/linting Pipeline failed
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> |
||
| .woodpecker | ||
| meta | ||
| roles | ||
| tasks | ||
| .ansible-lint | ||
| .editorconfig | ||
| .gitattributes | ||
| .gitignore | ||
| .markdownlint-cli2.jsonc | ||
| .sops.yaml | ||
| .yamllint | ||
| ansible.cfg | ||
| playbook.yaml | ||
| readme.md | ||
| renovate.json | ||
Ansible Role: Forgejo
Install and configure Forgejo - a self-hosted lightweight software forge - as a Docker container.
Requirements
A Docker host with a data directory at /mnt/forgejo (for example a mounted volume). The role itself does not
install Docker.
Dependencies
The playbook (playbook.yaml) runs these roles, in order, before forgejo:
dockertraefik
Both are installed from roles/requirements.yml.
Variables
The role has no defaults/main.yaml and defines no variables of its own. It does use one variable that must come
from the inventory.
| Variable | Required | Default | Description |
|---|---|---|---|
timezone |
Yes | Timezone passed to the container as TZ, for example Europe/Amsterdam |
Everything else is hardcoded in tasks/forgejo.yaml.
Example
timezone: "Europe/Amsterdam"
What the role does
- Creates
/mnt/forgejo/data(owner and group1000, mode0755). - Runs the
forgejocontainer fromcr.simoncor.net/dockerhub/forgejoclone/forgejo:16.0.3(always pulled, restart policyunless-stopped, json-file logs max 10m x 3). - Publishes port
3000/tcpand mounts/mnt/forgejo/dataon/data. - Configures Forgejo through
FORGEJO__*environment variables:- domain
git.simoncor.net, root URLhttps://git.simoncor.net, HTTP port 3000; - SSH disabled (
DISABLE_SSH,START_SSH_SERVER); - SQLite database at
/data/gitea/forgejo.dbin WAL mode; - attachments in
/data/releases(max 128 MB, 20 files); - mailer and OpenID sign-in/sign-up disabled, registration disabled;
- migrations allowed from
github.com, API default page size 50, webhooks allowed to any host.
- domain
- Cleans up Docker afterwards (
tasks/cleanup.yaml):docker_pruneanddocker system prune --all --force --volumes. Unused images and volumes on the host are removed, so do not share the host with workloads that rely on stopped containers or unattached volumes.
Because the domain, URL and image are hardcoded, change them in tasks/forgejo.yaml to deploy elsewhere.
Traefik is expected to route the domain to port 3000.
Usage
Run playbook.yaml through Semaphore. It first runs ansible-galaxy install -f -r roles/requirements.yml on the
controller (works around a Semaphore bug), then the docker, traefik and forgejo roles on all hosts.