ci: six runners; SSO #8 Gitea sign-in hardening (staged)
- runner-5/6: 50+ jobs were queued with ~11 private repos onboarded. dind keeps the 12-core ceiling, so this adds concurrency, not CPU. - Gitea: password + passkey sign-in forms off (break-glass = CLI), and ACCOUNT_LINKING auto -> login. auto linked any hub login whose email matched an existing account, and SITE ADMIN windyadmin carries Grant's email. Grant is linked by the hub's stable sub, which matches first. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -11,7 +11,7 @@ log:
|
|||||||
|
|
||||||
runner:
|
runner:
|
||||||
file: /data/.runner
|
file: /data/.runner
|
||||||
capacity: 1 # per runner; parallelism = number of runner services (4). See docker-compose.yml
|
capacity: 1 # per runner; parallelism = number of runner services (6). See docker-compose.yml
|
||||||
timeout: 30m
|
timeout: 30m
|
||||||
shutdown_timeout: 3m
|
shutdown_timeout: 3m
|
||||||
insecure: false
|
insecure: false
|
||||||
|
|||||||
@@ -134,6 +134,23 @@ services:
|
|||||||
<<: *env2
|
<<: *env2
|
||||||
GITEA_RUNNER_NAME: veron-1-4
|
GITEA_RUNNER_NAME: veron-1-4
|
||||||
volumes: [./config.yaml:/config.yaml:ro, runner-data-4:/data]
|
volumes: [./config.yaml:/config.yaml:ro, runner-data-4:/data]
|
||||||
|
# 5 and 6 added the same day: with ~11 private repos onboarded (windy-chat
|
||||||
|
# alone queues ~24 jobs per push) four runners left 50+ jobs waiting. The
|
||||||
|
# CPU ceiling is dind's (12 of 24 cores, G1.5), not the runner count, so more
|
||||||
|
# runners add concurrency for I/O-bound jobs (npm ci, uv sync) without
|
||||||
|
# taking more of Grant's workstation.
|
||||||
|
runner-5:
|
||||||
|
<<: *runner
|
||||||
|
environment:
|
||||||
|
<<: *env2
|
||||||
|
GITEA_RUNNER_NAME: veron-1-5
|
||||||
|
volumes: [./config.yaml:/config.yaml:ro, runner-data-5:/data]
|
||||||
|
runner-6:
|
||||||
|
<<: *runner
|
||||||
|
environment:
|
||||||
|
<<: *env2
|
||||||
|
GITEA_RUNNER_NAME: veron-1-6
|
||||||
|
volumes: [./config.yaml:/config.yaml:ro, runner-data-6:/data]
|
||||||
|
|
||||||
networks:
|
networks:
|
||||||
jobs:
|
jobs:
|
||||||
@@ -146,4 +163,6 @@ volumes:
|
|||||||
runner-data-2:
|
runner-data-2:
|
||||||
runner-data-3:
|
runner-data-3:
|
||||||
runner-data-4:
|
runner-data-4:
|
||||||
|
runner-data-5:
|
||||||
|
runner-data-6:
|
||||||
|
|
||||||
|
|||||||
@@ -57,12 +57,26 @@ services:
|
|||||||
# G2.2 — OIDC only. No local password login, no self-registration.
|
# G2.2 — OIDC only. No local password login, no self-registration.
|
||||||
GITEA__service__DISABLE_REGISTRATION: "true"
|
GITEA__service__DISABLE_REGISTRATION: "true"
|
||||||
GITEA__service__ALLOW_ONLY_EXTERNAL_REGISTRATION: "true"
|
GITEA__service__ALLOW_ONLY_EXTERNAL_REGISTRATION: "true"
|
||||||
|
# SSO #8 (2026-09-23): the password and passkey forms are OFF. windyadmin
|
||||||
|
# is site admin with a local password; leaving the form up made that
|
||||||
|
# password a second, phishable way into the whole forge. Break-glass is
|
||||||
|
# the CLI on Veron (`docker exec -u git windy-git-gitea-1 gitea admin ...`).
|
||||||
|
GITEA__service__ENABLE_PASSWORD_SIGNIN_FORM: "false"
|
||||||
|
GITEA__service__ENABLE_PASSKEY_AUTHENTICATION: "false"
|
||||||
# G3.1 — a Windy account IS the account. Signing in with Windy provisions
|
# G3.1 — a Windy account IS the account. Signing in with Windy provisions
|
||||||
# the Gitea user on first arrival; nobody is asked to invent a second
|
# the Gitea user on first arrival; nobody is asked to invent a second
|
||||||
# identity for the same person, and no local password ever exists.
|
# identity for the same person, and no local password ever exists.
|
||||||
GITEA__oauth2_client__ENABLE_AUTO_REGISTRATION: "true"
|
GITEA__oauth2_client__ENABLE_AUTO_REGISTRATION: "true"
|
||||||
GITEA__oauth2_client__USERNAME: email
|
GITEA__oauth2_client__USERNAME: email
|
||||||
GITEA__oauth2_client__ACCOUNT_LINKING: auto
|
# 🔴 `login`, NOT `auto` (SSO #8). `auto` linked any hub login whose EMAIL
|
||||||
|
# matched an existing account — and windyadmin (SITE ADMIN) carries Grant's
|
||||||
|
# email, so the forge's admin rights rested on the hub never letting anyone
|
||||||
|
# else hold that address. `login` makes an email match prove possession of
|
||||||
|
# the existing account first. Grant is unaffected: his account is already
|
||||||
|
# linked by the hub's stable `sub`, which is matched before email.
|
||||||
|
# ⚠️ env-to-ini SETS but never UNSETS — this value must also be edited in
|
||||||
|
# /srv/windygit/git/gitea/conf/app.ini if it is ever removed from here.
|
||||||
|
GITEA__oauth2_client__ACCOUNT_LINKING: login
|
||||||
# The email is asserted by account-server, which is the authority on it.
|
# The email is asserted by account-server, which is the authority on it.
|
||||||
# Asking the user to re-verify an address their identity provider already
|
# Asking the user to re-verify an address their identity provider already
|
||||||
# verified is friction that buys nothing.
|
# verified is friction that buys nothing.
|
||||||
|
|||||||
Reference in New Issue
Block a user