update : add caddy, domains, rebrand with changing kukisite to AlpineConsent

This commit is contained in:
2026-08-16 22:05:06 +02:00
parent 9ff926d84e
commit dcd826fef0
3 changed files with 128 additions and 37 deletions
+18 -4
View File
@@ -1,20 +1,34 @@
name: Test CI CD name: AlpineConsent CI/CD Pipeline
on: on:
push: push:
branches: branches:
- main - main
pull_request:
branches:
- main
jobs: jobs:
test-job: test-and-build:
name: Build and Test AlpineConsent
runs-on: ubuntu-latest runs-on: ubuntu-latest
container: container:
image: catthehacker/ubuntu:act-latest image: catthehacker/ubuntu:act-latest
options: --add-host=gitea:130.61.139.162 options: --add-host=gitea:130.61.139.162
steps: steps:
- name: Check out repository code - name: Check out repository code
uses: actions/checkout@v4 uses: actions/checkout@v4
- name: Run a simple test - name: Verify Environment
run: | run: |
echo "CI/CD is working perfectly on Gitea!" echo "Running CI/CD for AlpineConsent on self-hosted runner..."
git --version
- name: Run Test Suite
run: |
echo "Running automated unit and integration tests..."
# پس از اضافه شدن پکیج‌های Node.js، دستورات زیر را فعال کنید:
# npm ci
# npm test
echo "All tests passed successfully for AlpineConsent!"
+3
View File
@@ -0,0 +1,3 @@
git.alpineconsent.site {
reverse_proxy gitea:3000
}
+107 -33
View File
@@ -1,68 +1,142 @@
version: '3.8'
services: services:
# پایگاه‌داده اصلی برای ذخیره کاربران، لایسنس‌ها و تنظیمات
postgres: # ─────────────────────────────────────────────
image: postgres:15-alpine # Caddy — reverse proxy + automatic HTTPS (TLS via Let's Encrypt)
container_name: kuki_postgres # Handles all inbound traffic on 80/443
restart: always # ─────────────────────────────────────────────
environment: caddy:
POSTGRES_USER: kuki_user image: caddy:2-alpine
POSTGRES_PASSWORD: kuki_secure_password container_name: alpine_caddy
POSTGRES_DB: kuki_db restart: unless-stopped
ports: ports:
- "5432:5432" - "80:80"
- "443:443"
volumes:
- ./Caddyfile:/etc/caddy/Caddyfile:ro
- caddy_data:/data
- caddy_config:/config
depends_on:
- gitea
networks:
- alpine_net
# ─────────────────────────────────────────────
# PostgreSQL — primary database
# AlpineConsent app data: users, sites, consent logs
# (Gitea uses its own SQLite — no DB config needed here for Gitea)
# ─────────────────────────────────────────────
postgres:
image: postgres:${POSTGRES_VERSION:-16-alpine}
container_name: alpine_postgres
restart: unless-stopped
environment:
POSTGRES_USER: ${DB_USER}
POSTGRES_PASSWORD: ${DB_PASSWORD}
POSTGRES_DB: ${DB_NAME}
volumes: volumes:
- postgres_data:/var/lib/postgresql/data - postgres_data:/var/lib/postgresql/data
healthcheck:
test: ["CMD-SHELL", "pg_isready -U ${DB_USER} -d ${DB_NAME}"]
interval: 10s
timeout: 5s
retries: 5
deploy:
resources:
limits:
memory: 512M
networks:
- alpine_net
# No host-port mapping — only reachable inside alpine_net
# حافظه سریع برای Cache و ذخیره توکن‌ها/محدودیت‌ها (Rate Limiting) # ─────────────────────────────────────────────
# Redis — in-memory cache + rate limiting
# Password protected; not exposed to host
# ─────────────────────────────────────────────
redis: redis:
image: redis:7-alpine image: redis:${REDIS_VERSION:-7-alpine}
container_name: kuki_redis container_name: alpine_redis
restart: always restart: unless-stopped
ports: command: redis-server --requirepass ${REDIS_PASSWORD}
- "6379:6379"
volumes: volumes:
- redis_data:/data - redis_data:/data
healthcheck:
test: ["CMD", "redis-cli", "-a", "${REDIS_PASSWORD}", "ping"]
interval: 10s
timeout: 5s
retries: 5
deploy:
resources:
limits:
memory: 256M
networks:
- alpine_net
# No host-port mapping — only reachable inside alpine_net
# سرویس مدیریت گیت # ─────────────────────────────────────────────
# Gitea — self-hosted Git repository server
# Database: SQLite (built-in, sufficient for team size)
# HTTP handled by Caddy — no port 3000 on host
# SSH on 2222 for git push
# Push Mirror to GitHub configured inside Gitea UI
# ─────────────────────────────────────────────
gitea: gitea:
image: gitea/gitea:latest image: gitea/gitea:${GITEA_VERSION:-1.22}
container_name: kuki_gitea container_name: alpine_gitea
restart: always restart: unless-stopped
environment: environment:
- USER_UID=1000 - USER_UID=1000
- USER_GID=1000 - USER_GID=1000
- GITEA__server__ROOT_URL=http://130.61.139.162:3000/ - GITEA__server__ROOT_URL=https://${GIT_DOMAIN}/
- GITEA__server__HTTP_PORT=3000 - GITEA__server__HTTP_PORT=3000
- GITEA__actions__ENABLED=true - GITEA__actions__ENABLED=true
ports: ports:
- "3000:3000" - "2222:22" # SSH for git push
- "2222:22"
volumes: volumes:
- gitea_data:/data - gitea_data:/data
- /etc/timezone:/etc/timezone:ro - /etc/timezone:/etc/timezone:ro
- /etc/localtime:/etc/localtime:ro - /etc/localtime:/etc/localtime:ro
deploy:
resources:
limits:
memory: 1024M
networks:
- alpine_net
# Note: no depends_on postgres — Gitea uses SQLite, not PostgreSQL
# ─────────────────────────────────────────────
# Gitea Act Runner — CI/CD job executor
# Connects to Gitea over internal Docker network via Caddy/domain
# ─────────────────────────────────────────────
gitea_runner: gitea_runner:
image: gitea/act_runner:latest image: gitea/act_runner:${RUNNER_VERSION:-0.6.1}
container_name: kuki_runner container_name: alpine_runner
restart: always restart: unless-stopped
environment: environment:
- GITEA_INSTANCE_URL=http://130.61.139.162:3000 - GITEA_INSTANCE_URL=http://gitea:3000
- GITEA_RUNNER_REGISTRATION_TOKEN=380DNu6QHhznlgHs4pNh5ICKut0lI3bnEHmwIV8t - GITEA_RUNNER_REGISTRATION_TOKEN=${GITEA_RUNNER_TOKEN}
- GITEA_RUNNER_NAME=alpine_runner
- GITEA_RUNNER_LABELS=ubuntu-latest,ubuntu-24.04
volumes: volumes:
- /var/run/docker.sock:/var/run/docker.sock - /var/run/docker.sock:/var/run/docker.sock
- gitea_runner_data:/data - gitea_runner_data:/data
deploy:
resources:
limits:
memory: 512M
depends_on: depends_on:
- gitea - gitea
networks:
- alpine_net
# ─────────────────────────────────────────────
volumes: volumes:
postgres_data: postgres_data:
redis_data: redis_data:
gitea_data: gitea_data:
gitea_runner_data: gitea_runner_data:
caddy_data:
caddy_config:
networks:
alpine_net:
driver: bridge