Commit b1b9cddc02
b1b9cddc02117181510c5e0d11bd9fcf7ab38cc0
parent: 54013eb4e0
Verified · cmc
cmc <hello@cleberg.net> · 2026-08-25 16:58 UTC
docs: CI builds, runner setup, pages
Layout: unified · split
Admin.org
+28
| @@ -182,6 +182,34 @@ Replace the binary, restart the unit. Migrations apply automatically and |
| 182 | 182 | are transactional; hook scripts under =<root>/hooks= are rewritten at |
| 183 | 183 | startup to point at the current binary path. |
| 184 | 184 | |
| 185 | * CI runner |
| 186 | |
| 187 | =gitbay-runner= executes builds queued by pushes. It polls over SSH as |
| 188 | an admin account (runner commands are admin-only: a runner executes |
| 189 | arbitrary repo code), clones, runs the steps, streams the log back, and |
| 190 | resolves the commit status. Run it as a dedicated unprivileged user: |
| 191 | |
| 192 | #+begin_src sh |
| 193 | useradd --system --create-home --home-dir /var/lib/gitbay-runner ci-runner |
| 194 | sudo -u ci-runner ssh-keygen -t ed25519 -N "" -f /var/lib/gitbay-runner/.ssh/id_ed25519 |
| 195 | gitbayd --config /etc/gitbay/config.toml admin user create ci --admin \ |
| 196 | --key /var/lib/gitbay-runner/.ssh/id_ed25519.pub |
| 197 | gitbay-runner -remote git@127.0.0.1 -workdir /var/lib/gitbay-runner/work |
| 198 | #+end_src |
| 199 | |
| 200 | v1 runs steps directly on the host — no containers — so treat the |
| 201 | runner machine as executing whatever your users push. Install the |
| 202 | toolchains your builds need on it. |
| 203 | |
| 204 | * Pages |
| 205 | |
| 206 | =[pages] domain = "example.site"= serves public repos' =pages= branches |
| 207 | on =<owner>.<domain>=. DNS needs a wildcard record =*.<domain>= to the |
| 208 | server; ACME issues per-subdomain certificates on demand (only for |
| 209 | owners that exist). The domain must not be the site host or a parent of |
| 210 | it — pages content runs its own scripts and must stay off the forge's |
| 211 | origin. |
| 212 | |
| 185 | 213 | * Security |
| 186 | 214 | |
| 187 | 215 | The [[Threat-Model]] file is the reference for what the forge |
Roadmap.org
+6 −3
| @@ -82,10 +82,13 @@ work to it. |
| 82 | 82 | |
| 83 | 83 | Bigger bets, each valuable independently; order by appetite. |
| 84 | 84 | |
| 85 | | - [[https://gitbay.org/krz/gitbay/issues/13][#13]] CI/CD via external runners (after #1; the forge never executes |
| 86 | | repository content) |
| 85 | - [[https://gitbay.org/krz/gitbay/issues/13][#13]] CI/CD — done 2026-08-25 (.gitbay/ci.yml jobs, gitbay-runner over |
| 86 | SSH on bay1, statuses feed require-checks; the forge never executes |
| 87 | repository content itself) |
| 87 | 88 | - [[https://gitbay.org/krz/gitbay/issues/16][#16]] Git LFS |
| 88 | | - [[https://gitbay.org/krz/gitbay/issues/15][#15]] static page hosting (needs the separate-origin decision) |
| 89 | - [[https://gitbay.org/krz/gitbay/issues/15][#15]] static pages — done 2026-08-25 (public repos' =pages= branches on |
| 90 | <owner>.<pages domain>, separate origin; gitbay.org deployment awaits |
| 91 | the domain) |
| 89 | 92 | - [[https://gitbay.org/krz/gitbay/issues/11][#11]] iOS app (hutch-based) and [[https://gitbay.org/krz/gitbay/issues/12][#12]] Android |
| 90 | 93 | - [[https://gitbay.org/krz/gitbay/issues/21][#21]] teams within orgs — done 2026-08-25 (members-role scoping + per-repo team grants) |
| 91 | 94 | - [[https://gitbay.org/krz/gitbay/issues/25][#25]] wikis — done 2026-08-25 (push-edited .wiki companions; krz/gitbay has one) |
Users.org
+28
| @@ -301,6 +301,34 @@ Threads render inline on the MR page. A force-push marks them stale |
| 301 | 301 | anchors; =mr show= reports the unresolved count. Resolving is for the |
| 302 | 302 | thread author, the MR author, or anyone with write. |
| 303 | 303 | |
| 304 | * CI builds |
| 305 | |
| 306 | A =.gitbay/ci.yml= in the repo runs jobs on every branch push: |
| 307 | |
| 308 | #+begin_src yaml |
| 309 | jobs: |
| 310 | test: |
| 311 | steps: |
| 312 | - go test ./... |
| 313 | #+end_src |
| 314 | |
| 315 | Each job becomes a build (=build list=, =build log=, the builds tab on |
| 316 | the web) and a =ci/<job>= commit status, which =repo settings |
| 317 | require-checks= can gate merges on. Steps run with =sh -c= on the |
| 318 | instance's runner, stopping at the first failure; a broken config |
| 319 | surfaces as a failed =ci/config= status. Environment: =GITBAY_REPO=, |
| 320 | =GITBAY_SHA=, =GITBAY_REF=, =GITBAY_JOB=, =CI=true=. |
| 321 | |
| 322 | * Pages |
| 323 | |
| 324 | On instances with =[pages] domain= set, a =pages= branch in any public |
| 325 | repo is served as a static site: the repo named =pages= at |
| 326 | =https://<you>.<domain>/=, every other repo at |
| 327 | =https://<you>.<domain>/<repo>/=. Push HTML to publish; a CI job can |
| 328 | build and push the branch for automatic deploys. Sites run on a |
| 329 | separate origin — your scripts work, and the forge's cookies are out of |
| 330 | reach. |
| 331 | |
| 304 | 332 | * Notifications |
| 305 | 333 | |
| 306 | 334 | When the instance has SMTP configured, activity mails you: someone |