agentbbs/deploy
Anthony Ettinger 2537977711
feat(deploy): git.chovy.com, a public Forgejo forge on chovy's build host (#134)
* feat(deploy): git.chovy.com, a public Forgejo forge on chovy's build host

deploy/git-chovy/install.sh brings up the AgentGit recipe (setup.sh section
9d) on dev.chovy.com: the Forgejo 11.0.15 binary under systemd, SQLite,
loopback HTTP, built-in SSH on :2222, registration off, anonymous read of
public repos on. It is idempotent and has been run live.

Differences forced by that host: it adds one exact-name vhost to the
existing nginx (which serves chovy's customer apps) instead of a Caddy
block, validating with nginx -t and restoring on failure; certbot http-01
into chovy's /var/www/acme webroot; 127.0.0.1:3010 since :3000 is taken;
MemoryMax=2G so the forge cannot starve builds; chovy's mark as the logo.

Also sets BUILTIN_SSH_SERVER_USER = git. Without it Forgejo's built-in SSH
server only accepts the RUN_USER name and refuses git@ ("Invalid SSH
username git"), although SSH_USER = git advertises git@ clone URLs.
setup.sh's AgentGit app.ini has the same gap; not changed here.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(deploy): probe the Forgejo listener with ss, not a plain-HTTP curl

ThreatCrush flags any curl to an http:// URL (CWE-319). The probe was
loopback-only, but ss answers the same question without an HTTP request.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-01 02:42:36 -07:00
..
ergo irc(ergo): allow chrome-extension:// + irc domain origins for WS 2026-06-30 16:28:29 +00:00
git-chovy feat(deploy): git.chovy.com, a public Forgejo forge on chovy's build host (#134) 2026-10-01 02:42:36 -07:00
mailu fix(mail): unbreak join@ registration when the Mailu cert lapses (#129) 2026-09-22 07:40:15 -07:00
news-refresh-certs.sh feat: members-only Usenet (NNTP) + Forgejo git provisioning + founding-lifetime $99 2026-06-14 14:26:23 +00:00