mirror of
https://github.com/profullstack/agentbbs.git
synced 2026-10-01 11:33:48 +00:00
* feat(deploy): git.chovy.com, a public Forgejo forge on chovy's build host
deploy/git-chovy/install.sh brings up the AgentGit recipe (setup.sh section
9d) on dev.chovy.com: the Forgejo 11.0.15 binary under systemd, SQLite,
loopback HTTP, built-in SSH on :2222, registration off, anonymous read of
public repos on. It is idempotent and has been run live.
Differences forced by that host: it adds one exact-name vhost to the
existing nginx (which serves chovy's customer apps) instead of a Caddy
block, validating with nginx -t and restoring on failure; certbot http-01
into chovy's /var/www/acme webroot; 127.0.0.1:3010 since :3000 is taken;
MemoryMax=2G so the forge cannot starve builds; chovy's mark as the logo.
Also sets BUILTIN_SSH_SERVER_USER = git. Without it Forgejo's built-in SSH
server only accepts the RUN_USER name and refuses git@ ("Invalid SSH
username git"), although SSH_USER = git advertises git@ clone URLs.
setup.sh's AgentGit app.ini has the same gap; not changed here.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix(deploy): probe the Forgejo listener with ss, not a plain-HTTP curl
ThreatCrush flags any curl to an http:// URL (CWE-319). The probe was
loopback-only, but ss answers the same question without an HTTP request.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
||
|---|---|---|
| .. | ||
| install.sh | ||