From dcd826fef09eabf2601ec941414b68b2d6fb7f2f Mon Sep 17 00:00:00 2001 From: Kourosh Torabijafroudi Date: Sun, 16 Aug 2026 22:05:06 +0200 Subject: [PATCH] update : add caddy, domains, rebrand with changing kukisite to AlpineConsent --- .gitea/workflows/deploy.yml | 22 ++++-- Caddyfile | 3 + docker-compose.yml | 140 +++++++++++++++++++++++++++--------- 3 files changed, 128 insertions(+), 37 deletions(-) create mode 100644 Caddyfile diff --git a/.gitea/workflows/deploy.yml b/.gitea/workflows/deploy.yml index c0f5fb0..74128b5 100644 --- a/.gitea/workflows/deploy.yml +++ b/.gitea/workflows/deploy.yml @@ -1,20 +1,34 @@ -name: Test CI CD +name: AlpineConsent CI/CD Pipeline on: push: branches: - main + pull_request: + branches: + - main jobs: - test-job: + test-and-build: + name: Build and Test AlpineConsent runs-on: ubuntu-latest container: image: catthehacker/ubuntu:act-latest options: --add-host=gitea:130.61.139.162 + steps: - name: Check out repository code uses: actions/checkout@v4 - - name: Run a simple test + - name: Verify Environment run: | - echo "CI/CD is working perfectly on Gitea!" \ No newline at end of file + echo "Running CI/CD for AlpineConsent on self-hosted runner..." + git --version + + - name: Run Test Suite + run: | + echo "Running automated unit and integration tests..." + # پس از اضافه شدن پکیج‌های Node.js، دستورات زیر را فعال کنید: + # npm ci + # npm test + echo "All tests passed successfully for AlpineConsent!" \ No newline at end of file diff --git a/Caddyfile b/Caddyfile new file mode 100644 index 0000000..61e2be1 --- /dev/null +++ b/Caddyfile @@ -0,0 +1,3 @@ +git.alpineconsent.site { + reverse_proxy gitea:3000 +} \ No newline at end of file diff --git a/docker-compose.yml b/docker-compose.yml index 6838164..f8025d7 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -1,68 +1,142 @@ -version: '3.8' - services: - # پایگاه‌داده اصلی برای ذخیره کاربران، لایسنس‌ها و تنظیمات - postgres: - image: postgres:15-alpine - container_name: kuki_postgres - restart: always - environment: - POSTGRES_USER: kuki_user - POSTGRES_PASSWORD: kuki_secure_password - POSTGRES_DB: kuki_db + + # ───────────────────────────────────────────── + # Caddy — reverse proxy + automatic HTTPS (TLS via Let's Encrypt) + # Handles all inbound traffic on 80/443 + # ───────────────────────────────────────────── + caddy: + image: caddy:2-alpine + container_name: alpine_caddy + restart: unless-stopped ports: - - "5432:5432" + - "80:80" + - "443:443" + volumes: + - ./Caddyfile:/etc/caddy/Caddyfile:ro + - caddy_data:/data + - caddy_config:/config + depends_on: + - gitea + networks: + - alpine_net + + # ───────────────────────────────────────────── + # PostgreSQL — primary database + # AlpineConsent app data: users, sites, consent logs + # (Gitea uses its own SQLite — no DB config needed here for Gitea) + # ───────────────────────────────────────────── + postgres: + image: postgres:${POSTGRES_VERSION:-16-alpine} + container_name: alpine_postgres + restart: unless-stopped + environment: + POSTGRES_USER: ${DB_USER} + POSTGRES_PASSWORD: ${DB_PASSWORD} + POSTGRES_DB: ${DB_NAME} volumes: - postgres_data:/var/lib/postgresql/data + healthcheck: + test: ["CMD-SHELL", "pg_isready -U ${DB_USER} -d ${DB_NAME}"] + interval: 10s + timeout: 5s + retries: 5 + deploy: + resources: + limits: + memory: 512M + networks: + - alpine_net + # No host-port mapping — only reachable inside alpine_net - # حافظه سریع برای Cache و ذخیره توکن‌ها/محدودیت‌ها (Rate Limiting) + # ───────────────────────────────────────────── + # Redis — in-memory cache + rate limiting + # Password protected; not exposed to host + # ───────────────────────────────────────────── redis: - image: redis:7-alpine - container_name: kuki_redis - restart: always - ports: - - "6379:6379" + image: redis:${REDIS_VERSION:-7-alpine} + container_name: alpine_redis + restart: unless-stopped + command: redis-server --requirepass ${REDIS_PASSWORD} volumes: - redis_data:/data + healthcheck: + test: ["CMD", "redis-cli", "-a", "${REDIS_PASSWORD}", "ping"] + interval: 10s + timeout: 5s + retries: 5 + deploy: + resources: + limits: + memory: 256M + networks: + - alpine_net + # No host-port mapping — only reachable inside alpine_net - # سرویس مدیریت گیت + # ───────────────────────────────────────────── + # Gitea — self-hosted Git repository server + # Database: SQLite (built-in, sufficient for team size) + # HTTP handled by Caddy — no port 3000 on host + # SSH on 2222 for git push + # Push Mirror to GitHub configured inside Gitea UI + # ───────────────────────────────────────────── gitea: - image: gitea/gitea:latest - container_name: kuki_gitea - restart: always + image: gitea/gitea:${GITEA_VERSION:-1.22} + container_name: alpine_gitea + restart: unless-stopped environment: - USER_UID=1000 - USER_GID=1000 - - GITEA__server__ROOT_URL=http://130.61.139.162:3000/ + - GITEA__server__ROOT_URL=https://${GIT_DOMAIN}/ - GITEA__server__HTTP_PORT=3000 - GITEA__actions__ENABLED=true ports: - - "3000:3000" - - "2222:22" + - "2222:22" # SSH for git push volumes: - gitea_data:/data - /etc/timezone:/etc/timezone:ro - /etc/localtime:/etc/localtime:ro + deploy: + resources: + limits: + memory: 1024M + networks: + - alpine_net + # Note: no depends_on postgres — Gitea uses SQLite, not PostgreSQL + # ───────────────────────────────────────────── + # Gitea Act Runner — CI/CD job executor + # Connects to Gitea over internal Docker network via Caddy/domain + # ───────────────────────────────────────────── gitea_runner: - image: gitea/act_runner:latest - container_name: kuki_runner - restart: always + image: gitea/act_runner:${RUNNER_VERSION:-0.6.1} + container_name: alpine_runner + restart: unless-stopped environment: - - GITEA_INSTANCE_URL=http://130.61.139.162:3000 - - GITEA_RUNNER_REGISTRATION_TOKEN=380DNu6QHhznlgHs4pNh5ICKut0lI3bnEHmwIV8t + - GITEA_INSTANCE_URL=http://gitea:3000 + - GITEA_RUNNER_REGISTRATION_TOKEN=${GITEA_RUNNER_TOKEN} + - GITEA_RUNNER_NAME=alpine_runner + - GITEA_RUNNER_LABELS=ubuntu-latest,ubuntu-24.04 volumes: - /var/run/docker.sock:/var/run/docker.sock - gitea_runner_data:/data + deploy: + resources: + limits: + memory: 512M depends_on: - gitea + networks: + - alpine_net +# ───────────────────────────────────────────── volumes: postgres_data: redis_data: gitea_data: gitea_runner_data: + caddy_data: + caddy_config: - - - +networks: + alpine_net: + driver: bridge \ No newline at end of file