Commit e1063b0300

e1063b03005e952d4e50e0c504459005bd2dd642

parent: 9cdfb3a89d

Verified · cmc

cmc <hello@cleberg.net> · 2026-08-24 01:03 UTC

deploy: Vultr/Ubuntu 24.04 kit

- cloud-init: admin sshd moved to 2222 (sshd_config drop-in plus
  ssh.socket override — 24.04 socket-activates sshd), gitbay system
  user, hardened systemd unit with CAP_NET_BIND_SERVICE for 22/80/443,
  production config.toml (embedded SSH on 22, acme TLS, view_only,
  closed registration), nightly backup timer keeping 7, ufw for
  22/80/443/2222
- install.sh: scp the binary, check-config, restart, status
- dist/ (cross-compiled binaries) gitignored

Layout: unified · split

.gitignore +1
@@ -1,3 +1,4 @@
11/gitbay
22/gitbayd
33*.db
4/dist/
deploy/cloud-init.yaml added +130
@@ -0,0 +1,130 @@
1#cloud-config
2# gitbay VPS bootstrap (Ubuntu 24.04).
3#
4# What this does on first boot:
5# - moves the host's admin sshd to port 2222 (gitbay's embedded SSH
6# listener owns port 22) — CONNECT ON 2222 AFTER FIRST BOOT
7# - creates the unprivileged gitbay user and directory layout
8# - installs /etc/gitbay/config.toml, the systemd unit (with
9# CAP_NET_BIND_SERVICE so ports 22/80/443 work without root), and a
10# nightly backup timer
11# - opens ufw for 22, 80, 443, 2222
12#
13# It does NOT install the gitbayd binary (it is not hosted anywhere yet);
14# scp it to /usr/local/bin/gitbayd afterward and `systemctl start gitbayd`.
15
16package_update: true
17packages:
18 - git
19 - ufw
20
21write_files:
22 # Admin sshd on 2222. Ubuntu 24.04 socket-activates sshd, so the port
23 # must change in BOTH sshd_config and the socket unit.
24 - path: /etc/ssh/sshd_config.d/60-gitbay-port.conf
25 content: |
26 Port 2222
27 PasswordAuthentication no
28 - path: /etc/systemd/system/ssh.socket.d/override.conf
29 content: |
30 [Socket]
31 ListenStream=
32 ListenStream=2222
33
34 - path: /etc/gitbay/config.toml
35 permissions: "0640"
36 content: |
37 [server]
38 root = "/var/lib/gitbay"
39 site_url = "https://gitbay.org"
40
41 [ssh]
42 mode = "embedded"
43 port = 22
44
45 [http]
46 addr = ":443"
47 tls = "acme"
48 acme_email = "hello@gitbay.org"
49 acme_http_addr = ":80"
50
51 [web]
52 mode = "view_only"
53
54 [registration]
55 mode = "closed"
56
57 - path: /etc/systemd/system/gitbayd.service
58 content: |
59 [Unit]
60 Description=gitbay forge daemon
61 After=network-online.target
62 Wants=network-online.target
63
64 [Service]
65 User=gitbay
66 Group=gitbay
67 ExecStart=/usr/local/bin/gitbayd --config /etc/gitbay/config.toml serve
68 Restart=on-failure
69 RestartSec=3
70
71 # Bind 22/80/443 without root; no privilege escalation afterward.
72 AmbientCapabilities=CAP_NET_BIND_SERVICE
73 CapabilityBoundingSet=CAP_NET_BIND_SERVICE
74 NoNewPrivileges=yes
75 ProtectSystem=strict
76 ProtectHome=yes
77 ReadWritePaths=/var/lib/gitbay /var/backups/gitbay
78 PrivateTmp=yes
79 ProtectKernelTunables=yes
80 ProtectControlGroups=yes
81 RestrictSUIDSGID=yes
82
83 [Install]
84 WantedBy=multi-user.target
85
86 - path: /usr/local/bin/gitbay-backup.sh
87 permissions: "0755"
88 content: |
89 #!/bin/sh
90 # Nightly consistent backup; keeps the last 7 locally.
91 # To ship offsite, add an rclone/s3 upload of $out here.
92 set -eu
93 dir=/var/backups/gitbay
94 out="$dir/gitbay-$(date -u +%Y%m%d-%H%M%S).tar.gz"
95 /usr/local/bin/gitbayd --config /etc/gitbay/config.toml admin backup --out "$out"
96 ls -1t "$dir"/gitbay-*.tar.gz | tail -n +8 | xargs -r rm --
97
98 - path: /etc/systemd/system/gitbay-backup.service
99 content: |
100 [Unit]
101 Description=gitbay nightly backup
102 [Service]
103 Type=oneshot
104 User=gitbay
105 ExecStart=/usr/local/bin/gitbay-backup.sh
106
107 - path: /etc/systemd/system/gitbay-backup.timer
108 content: |
109 [Unit]
110 Description=gitbay nightly backup
111 [Timer]
112 OnCalendar=*-*-* 09:00:00 UTC
113 RandomizedDelaySec=15m
114 Persistent=true
115 [Install]
116 WantedBy=timers.target
117
118runcmd:
119 - adduser --system --group --home /var/lib/gitbay --shell /usr/sbin/nologin gitbay
120 - install -d -o gitbay -g gitbay -m 750 /var/lib/gitbay /var/backups/gitbay
121 - chgrp gitbay /etc/gitbay/config.toml /etc/gitbay
122 - ufw allow 22/tcp
123 - ufw allow 80/tcp
124 - ufw allow 443/tcp
125 - ufw allow 2222/tcp
126 - ufw --force enable
127 - systemctl daemon-reload
128 - systemctl restart ssh.socket || systemctl restart ssh
129 - systemctl enable gitbayd gitbay-backup.timer
130 - systemctl start gitbay-backup.timer
deploy/install.sh added +20
@@ -0,0 +1,20 @@
1#!/bin/sh
2# Push the gitbayd binary to a freshly cloud-inited host and start it.
3# Usage: deploy/install.sh <host-or-ip> [ssh-port]
4set -eu
5host=${1:?usage: install.sh <host-or-ip> [ssh-port]}
6port=${2:-2222}
7bin=dist/gitbayd-linux-amd64
8
9[ -f "$bin" ] || { echo "build first: CGO_ENABLED=0 GOOS=linux GOARCH=amd64 go build -o $bin ./cmd/gitbayd" >&2; exit 1; }
10
11scp -P "$port" "$bin" "root@$host:/usr/local/bin/gitbayd.new"
12ssh -p "$port" "root@$host" '
13 set -eu
14 chmod 755 /usr/local/bin/gitbayd.new
15 mv /usr/local/bin/gitbayd.new /usr/local/bin/gitbayd
16 /usr/local/bin/gitbayd --config /etc/gitbay/config.toml check-config --no-host-checks
17 systemctl restart gitbayd
18 sleep 1
19 systemctl --no-pager --lines=5 status gitbayd
20'