vault backup: 2026-01-05 13:03:55

This commit is contained in:
windyboy
2026-01-05 13:03:55 +08:00
parent 21460fc35d
commit be7c6cdcc9
589 changed files with 396508 additions and 27 deletions
@@ -0,0 +1,131 @@
To integrate Forgejo running in a Docker container with the host's SSH server, follow these steps:
### Step 1: Disable Forgejo's Internal SSH Server
In your `docker-compose.yml` file, add the environment variable to disable Forgejo's internal SSH server:
```yaml
environment:
- FORGEJO__server__START_SSH_SERVER=false
```
### Step 2: Configure the Host SSH Server
Add a dedicated user for Forgejo (e.g., `git`) on your host:
```bash
sudo adduser --disabled-password --gecos 'Forgejo' git
```
Update the SSH configuration in `/etc/ssh/sshd_config`:
```bash
Match User git
AllowTcpForwarding yes
X11Forwarding no
PermitTunnel no
AllowAgentForwarding no
ForceCommand docker exec -i forgejo /app/gitea/gitea serv key-$SSH_ORIGINAL_COMMAND
```
Restart the SSH server:
```bash
sudo systemctl restart sshd
```
### Step 3: Update Forgejo Configuration
Ensure that Forgejo's SSH domain and port in the configuration match your host's SSH settings. You can do this in the Forgejo web interface or by modifying the `app.ini` file within the container.
This setup allows Forgejo to use the host's SSH server for Git operations while running in a Docker container.
create user
```bash
docker exec forgejo forgejo admin user create --username fengzhiqiang --password admingzzn --email fengzhq@it2000.com.cn --admin
```
email
```
HOST    = smtp.exmail.qq.com:465
FROM    = server@it2000.com.cn
USER    = server@it2000.com.cn
PASSWD  = Gzzn1234
```
freeipa:
add user forgejo/forgejopass for bind
To add FreeIPA LDAP as an authentication source in Forgejo, follow these steps:
## Prerequisites
1. **FreeIPA Server**: Ensure you have a FreeIPA server set up and running.
2. **Forgejo Installation**: Have Forgejo installed and accessible.
## Configuration Steps
### 1. Create a Bind Account in FreeIPA
- **Create a gitea.ldif file** on the FreeIPA server, replacing `dc=example,dc=com` with your DN, and provide an appropriately secure password:
```ldif
dn: uid=gitea,cn=sysaccounts,cn=etc,dc=example,dc=com
changetype: add
objectclass: account
objectclass: simplesecurityobject
uid: gitea
userPassword: secure password
passwordExpirationTime: 20380119031407Z
nsIdleTimeout: 0
```
- **Import the LDIF** (change localhost to an IPA server if needed). Provide the Directory Manager password when prompted:
```bash
ldapmodify -h localhost -p 389 -x -D "cn=Directory Manager" -W -f gitea.ldif
```
- **Add an IPA group for gitea_users**:
```bash
ipa group-add --desc="Gitea Users" gitea_users
```
### 2. Configure Forgejo
- **Log in to Forgejo as an Administrator** and navigate to Admin Panel > Authentication.
- **Click on "Add New Source"** and select "LDAP (via BindDN)".
- **Fill in the following fields**, changing all where appropriate:
- **Authorization Name**: FreeIPA
- **Host**: `ldap://<your-freeipa-server>`
- **Port**: 389
- **Bind DN**: `uid=gitea,cn=sysaccounts,cn=etc,dc=example,dc=com`
- **Bind Password**: secure password
- **User Search Base**: `ou=Users,dc=example,dc=com`
- **User Filter**: `(&(objectClass=posixAccount)(uid=%s))`
- **Admin Filter**: `(memberOf=cn=gitea_users,cn=groups,cn=accounts,dc=example,dc=com)`
- **Username Attribute**: uid
- **First Name Attribute**: givenName
- **Surname Attribute**: sn
- **Email Attribute**: mail
- **Save the changes** and test the authentication by logging out and trying to log in with a FreeIPA user account.
By following these steps, you can successfully integrate FreeIPA LDAP as an authentication source in Forgejo, allowing users to log in with their FreeIPA credentials.
Citations:
[1] https://www.reddit.com/r/FreeIPA/comments/1ax8te1/can_i_use_an_existing_ldap_server_as_a_source_of/
[2] https://github.com/freeipa/freeipa
[3] https://freeipa.readthedocs.io/en/latest/designs/external-idp/external-idp.html
[4] https://fossies.org/linux/forgejo/docs/content/usage/authentication.en-us.md
[5] https://forgejo.org/docs/latest/admin/config-cheat-sheet/
[6] https://huijzer.xyz/posts/forgejo-setup/
[7] https://forum.yunohost.org/t/how-to-authenticate-to-foregjo-over-https/25444
[8] https://forgejo.org/docs/latest/admin/email-setup/