Files

4.1 KiB

To integrate Forgejo running in a Docker container with the host's SSH server, follow these steps:

Step 1: Disable Forgejo's Internal SSH Server

In your docker-compose.yml file, add the environment variable to disable Forgejo's internal SSH server:

environment:
  - FORGEJO__server__START_SSH_SERVER=false

Step 2: Configure the Host SSH Server

Add a dedicated user for Forgejo (e.g., git) on your host:

sudo adduser --disabled-password --gecos 'Forgejo' git

Update the SSH configuration in /etc/ssh/sshd_config:

Match User git
    AllowTcpForwarding yes
    X11Forwarding no
    PermitTunnel no
    AllowAgentForwarding no
    ForceCommand docker exec -i forgejo /app/gitea/gitea serv key-$SSH_ORIGINAL_COMMAND

Restart the SSH server:

sudo systemctl restart sshd

Step 3: Update Forgejo Configuration

Ensure that Forgejo's SSH domain and port in the configuration match your host's SSH settings. You can do this in the Forgejo web interface or by modifying the app.ini file within the container.

This setup allows Forgejo to use the host's SSH server for Git operations while running in a Docker container.

create user

docker exec forgejo forgejo admin user create --username fengzhiqiang --password admingzzn --email fengzhq@it2000.com.cn --admin

email

HOST    = smtp.exmail.qq.com:465  
FROM    = server@it2000.com.cn  
USER    = server@it2000.com.cn  
PASSWD  = Gzzn1234

freeipa: add user forgejo/forgejopass for bind

To add FreeIPA LDAP as an authentication source in Forgejo, follow these steps:

Prerequisites

  1. FreeIPA Server: Ensure you have a FreeIPA server set up and running.
  2. Forgejo Installation: Have Forgejo installed and accessible.

Configuration Steps

1. Create a Bind Account in FreeIPA

  • Create a gitea.ldif file on the FreeIPA server, replacing dc=example,dc=com with your DN, and provide an appropriately secure password:

    dn: uid=gitea,cn=sysaccounts,cn=etc,dc=example,dc=com
    changetype: add
    objectclass: account
    objectclass: simplesecurityobject
    uid: gitea
    userPassword: secure password
    passwordExpirationTime: 20380119031407Z
    nsIdleTimeout: 0
    
  • Import the LDIF (change localhost to an IPA server if needed). Provide the Directory Manager password when prompted:

    ldapmodify -h localhost -p 389 -x -D "cn=Directory Manager" -W -f gitea.ldif
    
  • Add an IPA group for gitea_users:

    ipa group-add --desc="Gitea Users" gitea_users
    

2. Configure Forgejo

  • Log in to Forgejo as an Administrator and navigate to Admin Panel > Authentication.

  • Click on "Add New Source" and select "LDAP (via BindDN)".

  • Fill in the following fields, changing all where appropriate:

    • Authorization Name: FreeIPA
    • Host: ldap://<your-freeipa-server>
    • Port: 389
    • Bind DN: uid=gitea,cn=sysaccounts,cn=etc,dc=example,dc=com
    • Bind Password: secure password
    • User Search Base: ou=Users,dc=example,dc=com
    • User Filter: (&(objectClass=posixAccount)(uid=%s))
    • Admin Filter: (memberOf=cn=gitea_users,cn=groups,cn=accounts,dc=example,dc=com)
    • Username Attribute: uid
    • First Name Attribute: givenName
    • Surname Attribute: sn
    • Email Attribute: mail
  • Save the changes and test the authentication by logging out and trying to log in with a FreeIPA user account.

By following these steps, you can successfully integrate FreeIPA LDAP as an authentication source in Forgejo, allowing users to log in with their FreeIPA credentials.

Citations: [1] https://www.reddit.com/r/FreeIPA/comments/1ax8te1/can_i_use_an_existing_ldap_server_as_a_source_of/ [2] https://github.com/freeipa/freeipa [3] https://freeipa.readthedocs.io/en/latest/designs/external-idp/external-idp.html [4] https://fossies.org/linux/forgejo/docs/content/usage/authentication.en-us.md [5] https://forgejo.org/docs/latest/admin/config-cheat-sheet/ [6] https://huijzer.xyz/posts/forgejo-setup/ [7] https://forum.yunohost.org/t/how-to-authenticate-to-foregjo-over-https/25444 [8] https://forgejo.org/docs/latest/admin/email-setup/