Git hosting and a container registry in one Rust binary (axum + Astro)
README: production deployment on git.hygo.ai
1 file changed, +22 -5
+22-5README.md
| @@ -107,8 +107,25 @@ frontend/ Astro: landing, docs, the page shell, CSS and client JS | ||
| 107 | 107 | |
| 108 | 108 | ## Deploying |
| 109 | 109 | |
| 110 | -Repos need a persistent disk, so the server runs on a VM, not serverless. | |
| 111 | -Put the git and registry hostname on Cloudflare **DNS-only** (grey cloud): | |
| 112 | -the proxy caps request bodies at 100 MB, which breaks large `docker push` | |
| 113 | -layers and big HTTPS git pushes. Set `SECRET_KEY`, `PUBLIC_URL`, | |
| 114 | -`R2_BUCKET=irongit` and the SMTP and Google variables in production. | |
| 110 | +Production is `https://git.hygo.ai` on the rybbit server (`ssh rybbit`), as | |
| 111 | +the `irongit` service in `/opt/hygo/docker-compose.yml`: same shared Postgres | |
| 112 | +(database `irongit`) and Caddy as the other hygo services, config in | |
| 113 | +`/opt/hygo/irongit.env`, data in the `irongit-data` volume. | |
| 114 | + | |
| 115 | +```sh | |
| 116 | +./deploy.sh # build the image, docker load it on rybbit, roll irongit, wait for healthy, | |
| 117 | + # publish the bundled ig to R2 when cli/Cargo.toml's version changed | |
| 118 | +``` | |
| 119 | + | |
| 120 | +Roll back: | |
| 121 | + | |
| 122 | +```sh | |
| 123 | +ssh rybbit 'cd /opt/hygo && docker tag irongit:$(cat .irongit.prev) irongit:latest && docker compose up -d --no-deps irongit' | |
| 124 | +``` | |
| 125 | + | |
| 126 | +The DNS record is **DNS-only** (grey cloud): the Cloudflare proxy caps request | |
| 127 | +bodies at 100 MB, which breaks large `docker push` layers and big HTTPS git | |
| 128 | +pushes. Caddy gets its own Let's Encrypt certificate. Git over SSH is | |
| 129 | +published directly on port 2222 (`ssh://git@git.hygo.ai:2222/owner/repo.git`). | |
| 130 | +Admin commands run inside the container, e.g. | |
| 131 | +`ssh rybbit docker exec irongit irongit admin promote <user>`. |