4.1 KiB
To integrate Forgejo running in a Docker container with the host's SSH server, follow these steps:
Step 1: Disable Forgejo's Internal SSH Server
In your docker-compose.yml file, add the environment variable to disable Forgejo's internal SSH server:
environment:
- FORGEJO__server__START_SSH_SERVER=false
Step 2: Configure the Host SSH Server
Add a dedicated user for Forgejo (e.g., git) on your host:
sudo adduser --disabled-password --gecos 'Forgejo' git
Update the SSH configuration in /etc/ssh/sshd_config:
Match User git
AllowTcpForwarding yes
X11Forwarding no
PermitTunnel no
AllowAgentForwarding no
ForceCommand docker exec -i forgejo /app/gitea/gitea serv key-$SSH_ORIGINAL_COMMAND
Restart the SSH server:
sudo systemctl restart sshd
Step 3: Update Forgejo Configuration
Ensure that Forgejo's SSH domain and port in the configuration match your host's SSH settings. You can do this in the Forgejo web interface or by modifying the app.ini file within the container.
This setup allows Forgejo to use the host's SSH server for Git operations while running in a Docker container.
create user
docker exec forgejo forgejo admin user create --username fengzhiqiang --password admingzzn --email fengzhq@it2000.com.cn --admin
HOST = smtp.exmail.qq.com:465
FROM = server@it2000.com.cn
USER = server@it2000.com.cn
PASSWD = Gzzn1234
freeipa: add user forgejo/forgejopass for bind
To add FreeIPA LDAP as an authentication source in Forgejo, follow these steps:
Prerequisites
- FreeIPA Server: Ensure you have a FreeIPA server set up and running.
- Forgejo Installation: Have Forgejo installed and accessible.
Configuration Steps
1. Create a Bind Account in FreeIPA
-
Create a gitea.ldif file on the FreeIPA server, replacing
dc=example,dc=comwith your DN, and provide an appropriately secure password:dn: uid=gitea,cn=sysaccounts,cn=etc,dc=example,dc=com changetype: add objectclass: account objectclass: simplesecurityobject uid: gitea userPassword: secure password passwordExpirationTime: 20380119031407Z nsIdleTimeout: 0 -
Import the LDIF (change localhost to an IPA server if needed). Provide the Directory Manager password when prompted:
ldapmodify -h localhost -p 389 -x -D "cn=Directory Manager" -W -f gitea.ldif -
Add an IPA group for gitea_users:
ipa group-add --desc="Gitea Users" gitea_users
2. Configure Forgejo
-
Log in to Forgejo as an Administrator and navigate to Admin Panel > Authentication.
-
Click on "Add New Source" and select "LDAP (via BindDN)".
-
Fill in the following fields, changing all where appropriate:
- Authorization Name: FreeIPA
- Host:
ldap://<your-freeipa-server> - Port: 389
- Bind DN:
uid=gitea,cn=sysaccounts,cn=etc,dc=example,dc=com - Bind Password: secure password
- User Search Base:
ou=Users,dc=example,dc=com - User Filter:
(&(objectClass=posixAccount)(uid=%s)) - Admin Filter:
(memberOf=cn=gitea_users,cn=groups,cn=accounts,dc=example,dc=com) - Username Attribute: uid
- First Name Attribute: givenName
- Surname Attribute: sn
- Email Attribute: mail
-
Save the changes and test the authentication by logging out and trying to log in with a FreeIPA user account.
By following these steps, you can successfully integrate FreeIPA LDAP as an authentication source in Forgejo, allowing users to log in with their FreeIPA credentials.
Citations: [1] https://www.reddit.com/r/FreeIPA/comments/1ax8te1/can_i_use_an_existing_ldap_server_as_a_source_of/ [2] https://github.com/freeipa/freeipa [3] https://freeipa.readthedocs.io/en/latest/designs/external-idp/external-idp.html [4] https://fossies.org/linux/forgejo/docs/content/usage/authentication.en-us.md [5] https://forgejo.org/docs/latest/admin/config-cheat-sheet/ [6] https://huijzer.xyz/posts/forgejo-setup/ [7] https://forum.yunohost.org/t/how-to-authenticate-to-foregjo-over-https/25444 [8] https://forgejo.org/docs/latest/admin/email-setup/