Ansible role to install and manage a Forgejo git server
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Simon Cornet 83f16e5313
Some checks failed
ci/woodpecker/push/linting Pipeline failed
docs: improve readme
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-05 17:27:49 +02:00
.woodpecker chore(package): update cr.simoncor.net/dockerhub/davidanson/markdownlint-cli2 docker tag to v0.23.3 2026-09-20 05:47:30 +00:00
meta feat: initial forgejo role setup 2026-05-10 14:10:22 +02:00
roles ci: migrate from gitlab ci to woodpecker 2026-05-15 14:31:03 +02:00
tasks feat: use default network_mode 2026-10-05 17:27:49 +02:00
.ansible-lint fix: exclude only sops yml files from lint 2026-07-14 16:23:39 +02:00
.editorconfig chore: add .editorconfig and .gitattributes 2026-05-27 14:23:44 +02:00
.gitattributes chore: add .editorconfig and .gitattributes 2026-05-27 14:23:44 +02:00
.gitignore feat: initial forgejo role setup 2026-05-10 14:10:22 +02:00
.markdownlint-cli2.jsonc ci: migrate from gitlab ci to woodpecker 2026-05-15 14:31:03 +02:00
.sops.yaml fix: correct sops regex to ya?ml 2026-07-14 16:01:46 +02:00
.yamllint chore: exclude .yml files from lint configs 2026-07-14 16:17:22 +02:00
ansible.cfg chore: sync linting and config files from common 2026-07-14 11:33:15 +02:00
playbook.yaml chore(playbook): run galaxy install only on first host 2026-08-13 08:49:30 +02:00
readme.md docs: improve readme 2026-10-05 17:27:49 +02:00
renovate.json feat: initial forgejo role setup 2026-05-10 14:10:22 +02:00

Ansible Role: Forgejo

Install and configure Forgejo - a self-hosted lightweight software forge - as a Docker container.

Requirements

A Docker host with a data directory at /mnt/forgejo (for example a mounted volume). The role itself does not install Docker.

Dependencies

The playbook (playbook.yaml) runs these roles, in order, before forgejo:

  • docker
  • traefik

Both are installed from roles/requirements.yml.

Variables

The role has no defaults/main.yaml and defines no variables of its own. It does use one variable that must come from the inventory.

Variable Required Default Description
timezone Yes Timezone passed to the container as TZ, for example Europe/Amsterdam

Everything else is hardcoded in tasks/forgejo.yaml.

Example

timezone: "Europe/Amsterdam"

What the role does

  • Creates /mnt/forgejo/data (owner and group 1000, mode 0755).
  • Runs the forgejo container from cr.simoncor.net/dockerhub/forgejoclone/forgejo:16.0.3 (always pulled, restart policy unless-stopped, json-file logs max 10m x 3).
  • Publishes port 3000/tcp and mounts /mnt/forgejo/data on /data.
  • Configures Forgejo through FORGEJO__* environment variables:
    • domain git.simoncor.net, root URL https://git.simoncor.net, HTTP port 3000;
    • SSH disabled (DISABLE_SSH, START_SSH_SERVER);
    • SQLite database at /data/gitea/forgejo.db in WAL mode;
    • attachments in /data/releases (max 128 MB, 20 files);
    • mailer and OpenID sign-in/sign-up disabled, registration disabled;
    • migrations allowed from github.com, API default page size 50, webhooks allowed to any host.
  • Cleans up Docker afterwards (tasks/cleanup.yaml): docker_prune and docker system prune --all --force --volumes. Unused images and volumes on the host are removed, so do not share the host with workloads that rely on stopped containers or unattached volumes.

Because the domain, URL and image are hardcoded, change them in tasks/forgejo.yaml to deploy elsewhere. Traefik is expected to route the domain to port 3000.

Usage

Run playbook.yaml through Semaphore. It first runs ansible-galaxy install -f -r roles/requirements.yml on the controller (works around a Semaphore bug), then the docker, traefik and forgejo roles on all hosts.