Commit e1063b0300
e1063b03005e952d4e50e0c504459005bd2dd642
parent: 9cdfb3a89d
Verified · cmc
cmc <hello@cleberg.net> · 2026-08-24 01:03 UTC
deploy: Vultr/Ubuntu 24.04 kit
- cloud-init: admin sshd moved to 2222 (sshd_config drop-in plus
ssh.socket override — 24.04 socket-activates sshd), gitbay system
user, hardened systemd unit with CAP_NET_BIND_SERVICE for 22/80/443,
production config.toml (embedded SSH on 22, acme TLS, view_only,
closed registration), nightly backup timer keeping 7, ufw for
22/80/443/2222
- install.sh: scp the binary, check-config, restart, status
- dist/ (cross-compiled binaries) gitignored
Layout: unified · split
.gitignore
+1
| @@ -1,3 +1,4 @@ |
| 1 | 1 | /gitbay |
| 2 | 2 | /gitbayd |
| 3 | 3 | *.db |
| 4 | /dist/ |
deploy/cloud-init.yaml
added
+130
| @@ -0,0 +1,130 @@ |
| 1 | #cloud-config |
| 2 | # gitbay VPS bootstrap (Ubuntu 24.04). |
| 3 | # |
| 4 | # What this does on first boot: |
| 5 | # - moves the host's admin sshd to port 2222 (gitbay's embedded SSH |
| 6 | # listener owns port 22) — CONNECT ON 2222 AFTER FIRST BOOT |
| 7 | # - creates the unprivileged gitbay user and directory layout |
| 8 | # - installs /etc/gitbay/config.toml, the systemd unit (with |
| 9 | # CAP_NET_BIND_SERVICE so ports 22/80/443 work without root), and a |
| 10 | # nightly backup timer |
| 11 | # - opens ufw for 22, 80, 443, 2222 |
| 12 | # |
| 13 | # It does NOT install the gitbayd binary (it is not hosted anywhere yet); |
| 14 | # scp it to /usr/local/bin/gitbayd afterward and `systemctl start gitbayd`. |
| 15 | |
| 16 | package_update: true |
| 17 | packages: |
| 18 | - git |
| 19 | - ufw |
| 20 | |
| 21 | write_files: |
| 22 | # Admin sshd on 2222. Ubuntu 24.04 socket-activates sshd, so the port |
| 23 | # must change in BOTH sshd_config and the socket unit. |
| 24 | - path: /etc/ssh/sshd_config.d/60-gitbay-port.conf |
| 25 | content: | |
| 26 | Port 2222 |
| 27 | PasswordAuthentication no |
| 28 | - path: /etc/systemd/system/ssh.socket.d/override.conf |
| 29 | content: | |
| 30 | [Socket] |
| 31 | ListenStream= |
| 32 | ListenStream=2222 |
| 33 | |
| 34 | - path: /etc/gitbay/config.toml |
| 35 | permissions: "0640" |
| 36 | content: | |
| 37 | [server] |
| 38 | root = "/var/lib/gitbay" |
| 39 | site_url = "https://gitbay.org" |
| 40 | |
| 41 | [ssh] |
| 42 | mode = "embedded" |
| 43 | port = 22 |
| 44 | |
| 45 | [http] |
| 46 | addr = ":443" |
| 47 | tls = "acme" |
| 48 | acme_email = "hello@gitbay.org" |
| 49 | acme_http_addr = ":80" |
| 50 | |
| 51 | [web] |
| 52 | mode = "view_only" |
| 53 | |
| 54 | [registration] |
| 55 | mode = "closed" |
| 56 | |
| 57 | - path: /etc/systemd/system/gitbayd.service |
| 58 | content: | |
| 59 | [Unit] |
| 60 | Description=gitbay forge daemon |
| 61 | After=network-online.target |
| 62 | Wants=network-online.target |
| 63 | |
| 64 | [Service] |
| 65 | User=gitbay |
| 66 | Group=gitbay |
| 67 | ExecStart=/usr/local/bin/gitbayd --config /etc/gitbay/config.toml serve |
| 68 | Restart=on-failure |
| 69 | RestartSec=3 |
| 70 | |
| 71 | # Bind 22/80/443 without root; no privilege escalation afterward. |
| 72 | AmbientCapabilities=CAP_NET_BIND_SERVICE |
| 73 | CapabilityBoundingSet=CAP_NET_BIND_SERVICE |
| 74 | NoNewPrivileges=yes |
| 75 | ProtectSystem=strict |
| 76 | ProtectHome=yes |
| 77 | ReadWritePaths=/var/lib/gitbay /var/backups/gitbay |
| 78 | PrivateTmp=yes |
| 79 | ProtectKernelTunables=yes |
| 80 | ProtectControlGroups=yes |
| 81 | RestrictSUIDSGID=yes |
| 82 | |
| 83 | [Install] |
| 84 | WantedBy=multi-user.target |
| 85 | |
| 86 | - path: /usr/local/bin/gitbay-backup.sh |
| 87 | permissions: "0755" |
| 88 | content: | |
| 89 | #!/bin/sh |
| 90 | # Nightly consistent backup; keeps the last 7 locally. |
| 91 | # To ship offsite, add an rclone/s3 upload of $out here. |
| 92 | set -eu |
| 93 | dir=/var/backups/gitbay |
| 94 | out="$dir/gitbay-$(date -u +%Y%m%d-%H%M%S).tar.gz" |
| 95 | /usr/local/bin/gitbayd --config /etc/gitbay/config.toml admin backup --out "$out" |
| 96 | ls -1t "$dir"/gitbay-*.tar.gz | tail -n +8 | xargs -r rm -- |
| 97 | |
| 98 | - path: /etc/systemd/system/gitbay-backup.service |
| 99 | content: | |
| 100 | [Unit] |
| 101 | Description=gitbay nightly backup |
| 102 | [Service] |
| 103 | Type=oneshot |
| 104 | User=gitbay |
| 105 | ExecStart=/usr/local/bin/gitbay-backup.sh |
| 106 | |
| 107 | - path: /etc/systemd/system/gitbay-backup.timer |
| 108 | content: | |
| 109 | [Unit] |
| 110 | Description=gitbay nightly backup |
| 111 | [Timer] |
| 112 | OnCalendar=*-*-* 09:00:00 UTC |
| 113 | RandomizedDelaySec=15m |
| 114 | Persistent=true |
| 115 | [Install] |
| 116 | WantedBy=timers.target |
| 117 | |
| 118 | runcmd: |
| 119 | - adduser --system --group --home /var/lib/gitbay --shell /usr/sbin/nologin gitbay |
| 120 | - install -d -o gitbay -g gitbay -m 750 /var/lib/gitbay /var/backups/gitbay |
| 121 | - chgrp gitbay /etc/gitbay/config.toml /etc/gitbay |
| 122 | - ufw allow 22/tcp |
| 123 | - ufw allow 80/tcp |
| 124 | - ufw allow 443/tcp |
| 125 | - ufw allow 2222/tcp |
| 126 | - ufw --force enable |
| 127 | - systemctl daemon-reload |
| 128 | - systemctl restart ssh.socket || systemctl restart ssh |
| 129 | - systemctl enable gitbayd gitbay-backup.timer |
| 130 | - systemctl start gitbay-backup.timer |
deploy/install.sh
added
+20
| @@ -0,0 +1,20 @@ |
| 1 | #!/bin/sh |
| 2 | # Push the gitbayd binary to a freshly cloud-inited host and start it. |
| 3 | # Usage: deploy/install.sh <host-or-ip> [ssh-port] |
| 4 | set -eu |
| 5 | host=${1:?usage: install.sh <host-or-ip> [ssh-port]} |
| 6 | port=${2:-2222} |
| 7 | bin=dist/gitbayd-linux-amd64 |
| 8 | |
| 9 | [ -f "$bin" ] || { echo "build first: CGO_ENABLED=0 GOOS=linux GOARCH=amd64 go build -o $bin ./cmd/gitbayd" >&2; exit 1; } |
| 10 | |
| 11 | scp -P "$port" "$bin" "root@$host:/usr/local/bin/gitbayd.new" |
| 12 | ssh -p "$port" "root@$host" ' |
| 13 | set -eu |
| 14 | chmod 755 /usr/local/bin/gitbayd.new |
| 15 | mv /usr/local/bin/gitbayd.new /usr/local/bin/gitbayd |
| 16 | /usr/local/bin/gitbayd --config /etc/gitbay/config.toml check-config --no-host-checks |
| 17 | systemctl restart gitbayd |
| 18 | sleep 1 |
| 19 | systemctl --no-pager --lines=5 status gitbayd |
| 20 | ' |