irongit

Git hosting and a container registry in one Rust binary (axum + Astro)

README: production deployment on git.hygo.ai

huncholanehuncholaneauthored
parent 96dacb2commit dd59a203ae0d8b21ecca6962b31d3e924be9712dBrowse files

1 file changed, +22 -5

+22-5README.md
@@ -107,8 +107,25 @@ frontend/ Astro: landing, docs, the page shell, CSS and client JS
107107
108108 ## Deploying
109109
110-Repos need a persistent disk, so the server runs on a VM, not serverless.
111-Put the git and registry hostname on Cloudflare **DNS-only** (grey cloud):
112-the proxy caps request bodies at 100 MB, which breaks large `docker push`
113-layers and big HTTPS git pushes. Set `SECRET_KEY`, `PUBLIC_URL`,
114-`R2_BUCKET=irongit` and the SMTP and Google variables in production.
110+Production is `https://git.hygo.ai` on the rybbit server (`ssh rybbit`), as
111+the `irongit` service in `/opt/hygo/docker-compose.yml`: same shared Postgres
112+(database `irongit`) and Caddy as the other hygo services, config in
113+`/opt/hygo/irongit.env`, data in the `irongit-data` volume.
114+
115+```sh
116+./deploy.sh # build the image, docker load it on rybbit, roll irongit, wait for healthy,
117+ # publish the bundled ig to R2 when cli/Cargo.toml's version changed
118+```
119+
120+Roll back:
121+
122+```sh
123+ssh rybbit 'cd /opt/hygo && docker tag irongit:$(cat .irongit.prev) irongit:latest && docker compose up -d --no-deps irongit'
124+```
125+
126+The DNS record is **DNS-only** (grey cloud): the Cloudflare proxy caps request
127+bodies at 100 MB, which breaks large `docker push` layers and big HTTPS git
128+pushes. Caddy gets its own Let's Encrypt certificate. Git over SSH is
129+published directly on port 2222 (`ssh://git@git.hygo.ai:2222/owner/repo.git`).
130+Admin commands run inside the container, e.g.
131+`ssh rybbit docker exec irongit irongit admin promote <user>`.