diff --git a/site-cookbooks/kosmos_gitea/CHANGELOG.md b/site-cookbooks/kosmos_gitea/CHANGELOG.md index c0f750b..a973346 100644 --- a/site-cookbooks/kosmos_gitea/CHANGELOG.md +++ b/site-cookbooks/kosmos_gitea/CHANGELOG.md @@ -2,6 +2,18 @@ This file is used to list changes made in each version of the kosmos_gitea cookbook. +# 0.3.0 + +- Upgrade Gitea from 1.27.1 to 28.0.0 (Gitea dropped the `1.` version prefix). +- Remove `[server] DOMAIN`; Gitea 28 ignores it. Set `ROOT_URL` to the literal + domain, which is now the authoritative source for the instance/SSH domain. +- Drop the removed `external` host preset from `[security] ALLOWED_HOST_LIST` + (webhook egress). Lax mode still allows public hosts. +- Set `[actions] RUN_RETENTION_DAYS = 0` to preserve action run history, which + Gitea 28 would otherwise delete after 400 days. +- Set `proxy_http_version 1.1` in the nginx web vhost so the new WebSocket + notification endpoint (`/-/ws`) can be upgraded. + # 0.2.2 - Add `config.yaml` for the gitea actions runner, enabling the built-in cache diff --git a/site-cookbooks/kosmos_gitea/attributes/default.rb b/site-cookbooks/kosmos_gitea/attributes/default.rb index 262c8d1..4a56cbc 100644 --- a/site-cookbooks/kosmos_gitea/attributes/default.rb +++ b/site-cookbooks/kosmos_gitea/attributes/default.rb @@ -1,5 +1,5 @@ -node.default["gitea"]["version"] = "1.27.1" -node.default["gitea"]["checksum"] = "86a7ac26e7f9c9cca0f56c4fac07fff205d5fc3bca0e54af23a204f07b833bc9" +node.default["gitea"]["version"] = "28.0.0" +node.default["gitea"]["checksum"] = "7f82b522c4a98191e8ace49d85e17a2056a3cedc3054a6367c13c0a813d015a8" node.default["gitea"]["repo"] = nil node.default["gitea"]["revision"] = nil node.default["gitea"]["working_directory"] = "/var/lib/gitea" @@ -16,10 +16,11 @@ node.default["gitea"]["config"] = { "logger.access.MODE" => "" }, "actions": { - "enabled" => true + "enabled" => true, + "run_retention_days" => 0 }, "webhook": { - "allowed_host_list" => "external,127.0.1.1" + "allowed_host_list" => "127.0.1.1" } } diff --git a/site-cookbooks/kosmos_gitea/metadata.rb b/site-cookbooks/kosmos_gitea/metadata.rb index 820c55a..7fee7e8 100644 --- a/site-cookbooks/kosmos_gitea/metadata.rb +++ b/site-cookbooks/kosmos_gitea/metadata.rb @@ -4,7 +4,7 @@ maintainer_email 'ops@kosmos.org' license 'MIT' description 'Installs/configures Gitea' long_description 'Installs/configures Gitea' -version '0.2.2' +version '0.3.0' chef_version '>= 14.0' depends "firewall" diff --git a/site-cookbooks/kosmos_gitea/recipes/default.rb b/site-cookbooks/kosmos_gitea/recipes/default.rb index 8049a70..5214949 100644 --- a/site-cookbooks/kosmos_gitea/recipes/default.rb +++ b/site-cookbooks/kosmos_gitea/recipes/default.rb @@ -90,7 +90,7 @@ if node.chef_environment == "production" node.normal["gitea"]["config"] = { "webhook": { - "allowed_host_list" => "external,#{allowed_webhook_hosts.join(",")}" + "allowed_host_list" => allowed_webhook_hosts.join(",") } } end diff --git a/site-cookbooks/kosmos_gitea/templates/default/app.ini.erb b/site-cookbooks/kosmos_gitea/templates/default/app.ini.erb index d393806..33d5456 100644 --- a/site-cookbooks/kosmos_gitea/templates/default/app.ini.erb +++ b/site-cookbooks/kosmos_gitea/templates/default/app.ini.erb @@ -7,9 +7,9 @@ HTTP_PORT = 3000 DISABLE_SSH = false SSH_PORT = 22 PROTOCOL = http -DOMAIN = <%= @domain %> +# Gitea 28 ignores [server] DOMAIN; the domain now comes from ROOT_URL # Gitea is running behind an nginx reverse load balancer, use an HTTPS root URL -ROOT_URL = https://%(DOMAIN)s +ROOT_URL = https://<%= @domain %> # REDIRECT_OTHER_PORT = true # PORT_TO_REDIRECT = 3001 # ENABLE_LETSENCRYPT = true @@ -125,6 +125,7 @@ MINIO_USE_SSL=<%= c["use_ssl"] %> <% if @config["actions"]["enabled"] %> [actions] ENABLED = true +RUN_RETENTION_DAYS = <%= @config["actions"]["run_retention_days"] %> <% end %> [other] diff --git a/site-cookbooks/kosmos_gitea/templates/default/nginx_conf_web.erb b/site-cookbooks/kosmos_gitea/templates/default/nginx_conf_web.erb index f87d71c..9a5169c 100644 --- a/site-cookbooks/kosmos_gitea/templates/default/nginx_conf_web.erb +++ b/site-cookbooks/kosmos_gitea/templates/default/nginx_conf_web.erb @@ -26,6 +26,7 @@ server { location ~ ^/(avatars|repo-avatars)/.*$ { proxy_buffers 1024 8k; proxy_pass http://_gitea_web; + proxy_http_version 1.1; expires 30d; proxy_set_header Connection $http_connection; proxy_set_header Upgrade $http_upgrade; @@ -40,6 +41,7 @@ server { client_max_body_size 0; proxy_buffers 1024 8k; proxy_pass http://_gitea_web; + proxy_http_version 1.1; proxy_set_header Connection $http_connection; proxy_set_header Upgrade $http_upgrade; proxy_set_header Host $host; @@ -51,6 +53,7 @@ server { location / { proxy_buffers 1024 8k; proxy_pass http://_gitea_web; + proxy_http_version 1.1; proxy_set_header Connection $http_connection; proxy_set_header Upgrade $http_upgrade; proxy_set_header Host $host;