Compare commits

73 Commits

Author SHA1 Message Date
eeeec03ab8 Merge pull request 'fix' (#151) from master into prod
Reviewed-on: #151
2025-09-29 00:14:28 +03:00
Egor Matveev
7795898546 fix
All checks were successful
Deploy Prod / Build (pull_request) Successful in 19s
Deploy Prod / Push (pull_request) Successful in 11s
Deploy Prod / prepare (pull_request) Successful in 4s
Deploy Prod / Deploy prod (pull_request) Successful in 23s
2025-09-29 00:14:06 +03:00
ff5ae0220d Merge pull request 'fix' (#150) from master into prod
Reviewed-on: #150
2025-09-28 14:13:35 +03:00
Egor Matveev
d8c68a2307 fix
All checks were successful
Deploy Prod / Build (pull_request) Successful in 30s
Deploy Prod / Push (pull_request) Successful in 16s
Deploy Prod / prepare (pull_request) Successful in 7s
Deploy Prod / Deploy prod (pull_request) Successful in 27s
2025-09-28 14:13:03 +03:00
6ea0e23869 Merge pull request 'Update .deploy-infra/deploy-prod.yaml' (#149) from master into prod
Reviewed-on: #149
2025-09-20 17:08:57 +03:00
e706e91a2a Update .deploy-infra/deploy-prod.yaml
All checks were successful
Deploy Prod / Build (pull_request) Successful in 8s
Deploy Prod / Push (pull_request) Successful in 12s
Deploy Prod / prepare (pull_request) Successful in 4s
Deploy Prod / Deploy prod (pull_request) Successful in 22s
2025-09-20 17:08:44 +03:00
5fe5b5ed6f Merge pull request 'Update .deploy-infra/deploy-prod.yaml' (#147) from master into prod
Reviewed-on: #147
2025-09-20 13:07:24 +03:00
b0b3dbdbd6 Update .deploy-infra/deploy-prod.yaml
All checks were successful
Deploy Prod / Build (pull_request) Successful in 7s
Deploy Prod / Push (pull_request) Successful in 12s
Deploy Prod / prepare (pull_request) Successful in 6s
Deploy Prod / Deploy prod (pull_request) Successful in 25s
2025-09-20 13:07:11 +03:00
5d2c174fce Merge pull request 'master' (#146) from master into prod
Reviewed-on: #146
2025-09-15 10:10:37 +03:00
Egor Matveev
1347bcc321 fix
All checks were successful
Deploy Prod / Build (pull_request) Successful in 20s
Deploy Prod / Push (pull_request) Successful in 17s
Deploy Prod / prepare (pull_request) Successful in 6s
Deploy Prod / Deploy prod (pull_request) Successful in 25s
2025-09-15 10:10:00 +03:00
Egor Matveev
f6371f8813 fix
All checks were successful
Deploy Dev / Build (pull_request) Successful in 11s
Deploy Dev / Push (pull_request) Successful in 15s
Deploy Dev / prepare (pull_request) Successful in 4s
Deploy Dev / Deploy dev (pull_request) Successful in 22s
2025-09-15 01:39:13 +03:00
624eddee2a Merge pull request 'fix' (#144) from master into prod
Reviewed-on: #144
2025-09-15 01:12:17 +03:00
Egor Matveev
1af2cfa4e2 fix
All checks were successful
Deploy Dev / Build (pull_request) Successful in 9s
Deploy Dev / Push (pull_request) Successful in 11s
Deploy Dev / prepare (pull_request) Successful in 16s
Deploy Dev / Deploy dev (pull_request) Successful in 19s
Deploy Prod / Build (pull_request) Successful in 14s
Deploy Prod / Push (pull_request) Successful in 12s
Deploy Prod / prepare (pull_request) Successful in 8s
Deploy Prod / Deploy prod (pull_request) Successful in 26s
2025-09-15 00:12:03 +03:00
ba43261482 Merge pull request 'fix' (#142) from master into prod
Reviewed-on: #142
2025-09-15 00:06:57 +03:00
Egor Matveev
975ae0cedc fix
All checks were successful
Deploy Prod / Build (pull_request) Successful in 21s
Deploy Prod / Push (pull_request) Successful in 11s
Deploy Prod / prepare (pull_request) Successful in 9s
Deploy Prod / Deploy prod (pull_request) Successful in 30s
2025-09-15 00:06:34 +03:00
59287f8240 Merge pull request 'master' (#141) from master into prod
Reviewed-on: #141
2025-09-14 23:57:24 +03:00
Egor Matveev
0ba70d2e60 fix
Some checks are pending
Deploy Dev / Build (pull_request) Successful in 1m22s
Deploy Dev / Push (pull_request) Successful in 47s
Deploy Dev / prepare (pull_request) Successful in 4s
Deploy Dev / Deploy dev (pull_request) Successful in 20s
Deploy Prod / Deploy prod (pull_request) Blocked by required conditions
Deploy Prod / Build (pull_request) Successful in 32s
Deploy Prod / Push (pull_request) Successful in 46s
Deploy Prod / prepare (pull_request) Successful in 4s
2025-09-14 23:32:16 +03:00
Egor Matveev
5a7d51e253 fix 2025-09-14 23:31:24 +03:00
Egor Matveev
e4670693cd Merge branch 'master' of https://gitea.chocomarsh.com/self/infra 2025-09-14 23:18:27 +03:00
Egor Matveev
90b875752b fix 2025-09-10 10:11:00 +03:00
8f823afc21 Merge pull request 'fix' (#139) from master into prod
Reviewed-on: #139
2025-07-12 10:28:33 +03:00
489b5d00cc Merge pull request 'fix' (#138) from master into prod
Reviewed-on: #138
2025-07-12 10:22:15 +03:00
073ee88a84 Merge pull request 'fix' (#137) from master into prod
Reviewed-on: #137
2025-07-12 10:17:55 +03:00
054186bfcd Merge pull request 'fix' (#136) from master into prod
Reviewed-on: #136
2025-07-12 10:12:23 +03:00
2d66d20e41 Merge pull request 'fix' (#135) from master into prod
Reviewed-on: #135
2025-07-12 10:09:55 +03:00
49e99f2721 Merge pull request 'fix' (#134) from master into prod
Reviewed-on: #134
2025-07-11 22:46:40 +03:00
a6273a24dc Merge pull request 'fix' (#133) from master into prod
Reviewed-on: #133
2025-07-11 22:29:14 +03:00
5da9bc072b Merge pull request 'fix' (#132) from master into prod
Reviewed-on: #132
2025-07-11 22:23:22 +03:00
767ea96b31 Merge pull request 'fix' (#131) from master into prod
Reviewed-on: #131
2025-07-11 22:19:01 +03:00
9c8df2d4d4 Merge pull request 'fix' (#130) from master into prod
Reviewed-on: #130
2025-07-11 22:07:25 +03:00
e076d505f1 Merge pull request 'fix' (#129) from master into prod
Reviewed-on: #129
2025-07-11 21:50:17 +03:00
5a8e6cfa76 Merge pull request 'fix' (#128) from master into prod
Reviewed-on: #128
2025-07-11 21:28:33 +03:00
6647b0df21 Merge pull request 'fix' (#127) from master into prod
Reviewed-on: #127
2025-07-11 21:20:37 +03:00
0e0b2e57da Merge pull request 'fix' (#126) from master into prod
Reviewed-on: #126
2025-07-11 21:05:40 +03:00
cac1e5c4e0 Merge pull request 'fix' (#125) from master into prod
Reviewed-on: #125
2025-07-11 20:36:23 +03:00
45201de406 Merge pull request 'fix' (#124) from master into prod
Reviewed-on: #124
2025-07-11 20:24:33 +03:00
74a45eb95c Merge pull request 'fix' (#123) from master into prod
Reviewed-on: #123
2025-07-11 19:57:57 +03:00
26159bd068 Merge pull request 'fix' (#122) from master into prod
Reviewed-on: #122
2025-07-11 19:52:26 +03:00
f963a7e196 Merge pull request 'fix' (#121) from master into prod
Reviewed-on: #121
2025-07-10 18:43:34 +03:00
60d65bfd10 Merge pull request 'fix' (#120) from master into prod
Reviewed-on: #120
2025-07-10 18:19:12 +03:00
7c16255c61 Merge pull request 'fix' (#119) from master into prod
Reviewed-on: #119
2025-07-10 18:12:17 +03:00
ee6e9b7d12 Merge pull request 'Update .deploy-infra/deploy-prod.yaml' (#118) from master into prod
Reviewed-on: #118
2025-06-20 17:29:59 +03:00
1851bc0652 Merge pull request 'master' (#117) from master into prod
Reviewed-on: #117
2025-06-20 17:19:38 +03:00
0ba08e4a6d Merge pull request 'fix' (#115) from master into prod
Reviewed-on: #115
2025-06-14 23:01:18 +03:00
3e12bf6fe0 Merge pull request 'fix' (#114) from master into prod
Reviewed-on: #114
2025-06-14 22:55:18 +03:00
7fc4e7f086 Merge pull request 'master' (#113) from master into prod
Reviewed-on: #113
2025-06-14 22:45:41 +03:00
becb5c3aac Merge pull request 'fix' (#112) from master into prod
Reviewed-on: #112
2025-06-14 22:40:51 +03:00
a54f4a6eee Merge pull request 'fix' (#111) from master into prod
Reviewed-on: #111
2025-06-14 22:35:16 +03:00
fb4fcf5b27 Merge pull request 'fix' (#110) from master into prod
Reviewed-on: #110
2025-06-14 22:30:25 +03:00
45a035897d Merge pull request 'Update .deploy-infra/deploy-prod.yaml' (#109) from master into prod
Reviewed-on: #109
2025-06-14 20:21:54 +03:00
4da8e8e6e5 Merge pull request 'Update .deploy-infra/deploy-prod.yaml' (#108) from master into prod
Reviewed-on: #108
2025-06-14 20:12:41 +03:00
2a09bb0f48 Merge pull request 'Update .deploy-infra/deploy-prod.yaml' (#107) from master into prod
Reviewed-on: #107
2025-06-14 20:10:36 +03:00
d456e2d083 Merge pull request 'Update .deploy-infra/deploy-prod.yaml' (#106) from master into prod
Reviewed-on: #106
2025-06-14 20:07:01 +03:00
3f07d0ad84 Merge pull request 'Update .deploy-infra/deploy-prod.yaml' (#105) from master into prod
Reviewed-on: #105
2025-06-14 19:55:57 +03:00
f8488d72e7 Merge pull request 'Update .deploy-infra/deploy-prod.yaml' (#104) from master into prod
Reviewed-on: #104
2025-06-14 19:53:17 +03:00
7b0a5ca568 Merge pull request 'fix' (#103) from master into prod
Reviewed-on: #103
2025-06-14 13:02:27 +03:00
cab9ef5d08 Merge pull request 'fix' (#102) from master into prod
Reviewed-on: #102
2025-06-14 12:42:45 +03:00
e4f6078e63 Merge pull request 'fix' (#101) from master into prod
Reviewed-on: #101
2025-06-14 04:44:16 +03:00
8ebf434fb2 Merge pull request 'master' (#100) from master into prod
Reviewed-on: #100
2025-06-14 03:37:48 +03:00
2b0fc2dee3 Merge pull request 'master' (#96) from master into prod
Reviewed-on: #96
2025-06-13 02:48:50 +03:00
f72974a593 Merge pull request 'fix' (#92) from master into prod
Reviewed-on: #92
2025-06-12 22:14:37 +03:00
13518e77d6 Merge pull request 'fix' (#90) from master into prod
Reviewed-on: #90
2025-06-12 13:52:39 +03:00
a424d7950e Merge pull request 'master' (#88) from master into prod
Reviewed-on: #88
2025-06-12 13:27:18 +03:00
fe415f0bd8 Merge pull request 'master' (#84) from master into prod
Reviewed-on: #84
2025-06-12 01:13:26 +03:00
07008122a8 Merge pull request 'master' (#73) from master into prod
Reviewed-on: #73
2025-06-04 21:20:54 +03:00
031960c451 Merge pull request 'master' (#71) from master into prod
Reviewed-on: #71
2025-06-04 03:43:12 +03:00
a1fcd98eba Merge pull request 'master' (#69) from master into prod
Reviewed-on: #69
2025-06-04 02:47:18 +03:00
4e4bdf12cb Merge pull request 'fix' (#42) from master into prod
Reviewed-on: #42
2025-03-28 21:49:37 +03:00
e1b8bdb230 Merge pull request 'keycloak' (#41) from master into prod
Reviewed-on: #41
2025-03-28 21:45:31 +03:00
893a357eca Merge pull request 'keycloak' (#40) from master into prod
Reviewed-on: #40
2025-03-28 21:43:05 +03:00
feee9ffb6d Merge pull request 'keycloak' (#39) from master into prod
Reviewed-on: #39
2025-03-28 21:34:56 +03:00
dd63cf69cd Merge pull request 'master' (#38) from master into prod
Reviewed-on: #38
2025-03-28 21:28:13 +03:00
829d978ac8 Merge pull request 'master' (#36) from master into prod
Reviewed-on: #36
2025-02-14 01:10:55 +03:00
12 changed files with 45 additions and 144 deletions

View File

@@ -7,6 +7,7 @@ services:
networks:
- common-infra-nginx-development
- configurator
- minio-development
environment:
MINIO_SECRET_KEY: $MINIO_SECRET_KEY_DEV
ports:
@@ -48,6 +49,8 @@ services:
postgres:
image: postgres:14-alpine3.19
networks:
- postgres-development
volumes:
- /sprint-data/postgres-data:/var/lib/postgresql/data
environment:
@@ -74,6 +77,8 @@ services:
mongo:
image: mongo:6.0.2
networks:
- mongo-development
volumes:
- /sprint-data/mongo:/data/db
environment:
@@ -93,29 +98,6 @@ services:
parallelism: 1
order: start-first
rabbitmq:
image: rabbitmq:3.10.7-management
volumes:
- /sprint-data/rabbitmq:/var/lib/rabbitmq
ports:
- published: 5672
target: 5672
mode: host
- published: 15672
target: 15672
mode: host
environment:
RABBITMQ_DEFAULT_PASS: $RABBITMQ_PASSWORD_DEV
deploy:
mode: replicated
restart_policy:
condition: any
placement:
constraints: [node.labels.stage == development]
update_config:
parallelism: 1
order: start-first
redis:
image: redis:alpine3.16
volumes:
@@ -137,6 +119,8 @@ services:
minio:
image: bitnami/minio:2022.10.8
networks:
- minio-development
volumes:
- minio_data:/data
environment:
@@ -165,7 +149,7 @@ services:
- /var/run/docker.sock:/var/run/docker.sock
- /sprint-data:/sprint-data
environment:
GITEA_INSTANCE_URL: https://gitea.sprinthub.ru/
GITEA_INSTANCE_URL: https://gitea.chocomarsh.com/
GITEA_RUNNER_REGISTRATION_TOKEN: $REGISTRATION_TOKEN
GITEA_RUNNER_NAME: dev
GITEA_RUNNER_LABELS: dev
@@ -190,3 +174,9 @@ networks:
external: true
clickhouse-development:
external: true
postgres-development:
external: true
mongo-development:
external: true
minio-development:
external: true

View File

@@ -7,6 +7,7 @@ services:
networks:
- common-infra-nginx
- configurator
- minio
environment:
MINIO_SECRET_KEY: $MINIO_SECRET_KEY_PROD
ports:
@@ -26,57 +27,6 @@ services:
update_config:
parallelism: 1
# order: start-first
zitadel:
image: ghcr.io/zitadel/zitadel:latest
networks:
- common-infra-nginx
command: 'start-from-init --masterkey "MasterkeyNeedsToHave32Characters" --tlsMode disabled'
environment:
ZITADEL_DATABASE_POSTGRES_HOST: pg.sprinthub.ru
ZITADEL_DATABASE_POSTGRES_PORT: 5432
ZITADEL_DATABASE_POSTGRES_DATABASE: zitadel
ZITADEL_DATABASE_POSTGRES_USER_USERNAME: postgres
ZITADEL_DATABASE_POSTGRES_USER_PASSWORD: $DB_PASSWORD_PROD
ZITADEL_DATABASE_POSTGRES_USER_SSL_MODE: disable
ZITADEL_DATABASE_POSTGRES_ADMIN_USERNAME: postgres
ZITADEL_DATABASE_POSTGRES_ADMIN_PASSWORD: $DB_PASSWORD_PROD
ZITADEL_DATABASE_POSTGRES_ADMIN_SSL_MODE: disable
ZITADEL_EXTERNALSECURE: "false"
ZITADEL_EXTERNALDOMAIN: zitadel.chocomarsh.com
deploy:
mode: replicated
replicas: 1
restart_policy:
condition: any
update_config:
parallelism: 1
# authelia:
# image: mathwave/sprint-repo:authelia
# networks:
# - common-infra-nginx
# environment:
# AUTHELIA_JWT_SECRET: $AUTHTHELIA_JWT_SECRET
# AUTHELIA_SESSION_SECRET: $AUTHTHELIA_SESSION_SECRET
# AUTHELIA_STORAGE_ENCRYPTION_KEY: $AUTHELIA_STORAGE_ENCRYPTION_KEY
# AUTHELIA_STORAGE_POSTGRES_PORT: "5432"
# AUTHELIA_STORAGE_POSTGRES_DATABASE: "authelia"
# AUTHELIA_STORAGE_POSTGRES_USERNAME: "postgres"
# AUTHELIA_STORAGE_POSTGRES_PASSWORD: $DB_PASSWORD_PROD
# AUTHELIA_ACCESS_CONTROL_DEFAULT_POLICY: "one_factor"
# AUTHELIA_NOTIFIER_SMTP_ENABLED: "false"
# volumes:
# - /sprint-data/authelia/data:/var/lib/authelia
# deploy:
# mode: replicated
# replicas: 1
# restart_policy:
# condition: any
# placement:
# constraints: [node.labels.stage == production]
# update_config:
# parallelism: 1
grafana:
image: grafana/grafana
@@ -128,6 +78,8 @@ services:
postgres:
image: postgres:14-alpine3.19
networks:
- postgres
volumes:
- /sprint-data/postgres-data:/var/lib/postgresql/data
environment:
@@ -159,6 +111,8 @@ services:
mongo:
image: mongo:6.0.2
networks:
- mongo
volumes:
- /sprint-data/mongo:/data/db
environment:
@@ -199,6 +153,8 @@ services:
minio:
image: bitnami/minio:2022.10.8
networks:
- minio
volumes:
- minio_data:/data
environment:
@@ -222,7 +178,9 @@ services:
order: start-first
gitea:
image: gitea/gitea:1.22.3
image: gitea/gitea:1.24.6
networks:
- postgres
volumes:
- /sprint-data/gitea:/data
- /etc/timezone:/etc/timezone
@@ -234,7 +192,7 @@ services:
USER_UID: 1000
USER_GID: 1000
GITEA__database__DB_TYPE: postgres
GITEA__database__HOST: pg.sprinthub.ru:5432
GITEA__database__HOST: postgres:5432
GITEA__database__NAME: gitea
GITEA__database__USER: postgres
GITEA__database__PASSWD: $DB_PASSWORD_PROD
@@ -253,8 +211,9 @@ services:
volumes:
- /var/run/docker.sock:/var/run/docker.sock
- /sprint-data:/sprint-data
- /root/.cache/act:/root/.cache/act
environment:
GITEA_INSTANCE_URL: https://gitea.sprinthub.ru/
GITEA_INSTANCE_URL: https://gitea.chocomarsh.com/
GITEA_RUNNER_REGISTRATION_TOKEN: $REGISTRATION_TOKEN
GITEA_RUNNER_NAME: prod
GITEA_RUNNER_LABELS: prod
@@ -283,3 +242,9 @@ networks:
external: true
clickhouse:
external: true
postgres:
external: true
mongo:
external: true
minio:
external: true

View File

@@ -2,7 +2,7 @@ version: '3.2'
services:
agent:
image: portainer/agent:2.11.1
image: portainer/agent:2.33.1
volumes:
- /var/run/docker.sock:/var/run/docker.sock
- /var/lib/docker/volumes:/var/lib/docker/volumes
@@ -14,7 +14,7 @@ services:
constraints: [node.platform.os == linux]
portainer:
image: portainer/portainer-ce:2.11.1
image: portainer/portainer-ce:2.33.1
command: -H tcp://tasks.agent:9001 --tlsskipverify
ports:
- "9443:9443"

View File

@@ -19,8 +19,6 @@ jobs:
ref: dev
- name: build nginx dev
run: docker build -t mathwave/sprint-repo:sprint-infra-nginx-dev nginx/nginx-dev
- name: build gitea runner
run: docker build -t mathwave/sprint-repo:gitea-runner gitea-runner
push:
name: Push
runs-on: [ prod ]

View File

@@ -21,8 +21,6 @@ jobs:
run: docker build -t mathwave/sprint-repo:sprint-infra-nginx-prod nginx/nginx-prod
- name: build gitea runner
run: docker build -t mathwave/sprint-repo:gitea-runner gitea-runner
- name: build authelia
run: docker build -t mathwave/sprint-repo:authelia authelia
push:
name: Push
runs-on: [ prod ]
@@ -32,8 +30,6 @@ jobs:
run: docker push mathwave/sprint-repo:sprint-infra-nginx-prod
- name: push gitea runner
run: docker push mathwave/sprint-repo:gitea-runner
- name: push authelia
run: docker push mathwave/sprint-repo:authelia
prepare:
name: prepare
runs-on: [prod]
@@ -58,8 +54,6 @@ jobs:
uses: actions/checkout@v4
with:
ref: prod
- name: deploy swarmpit
run: docker stack deploy --with-registry-auth -c ./.deploy-swarmpit/deploy-prod.yaml swarmpit
- name: deploy portainer
run: docker stack deploy --with-registry-auth -c ./.deploy-portainer/deploy-prod.yaml portainer
- name: deploy infra

View File

@@ -1,3 +0,0 @@
FROM authelia/authelia
COPY configuration.yml /config/configuration.yml
COPY users.yml /config/users.yml

View File

@@ -1,44 +0,0 @@
theme: dark
jwt_secret: secret-jwt-will-be-overridden-by-env
server:
host: 0.0.0.0
port: 9091
log:
level: info
authentication_backend:
file:
path: /config/users.yml
access_control:
default_policy: one_factor
rules:
- domain: "*.chocomarsh.com"
policy: one_factor
session:
name: authelia_session
expiration: 1h
inactivity: 5m
remember_me_duration: 1w
cookies:
- domain: chocomarsh.com
authelia_url: https://auth.chocomarsh.com
default_redirection_url: https://login.chocomarsh.com
storage:
encryption_key: "a_very_long_secret_32_characters_minimum"
postgres:
host: pg.sprinthub.ru
port: 5432
database: authelia
schema: public
username: postgres
password: autheliapass # also override with env if preferred
notifier:
filesystem:
filename: /config/notification.txt

View File

@@ -1,5 +0,0 @@
users:
emmatveev:
password: "$argon2id$v=19$m=65536,t=1,p=4$CixMXaAilVof3yk1rtghwg$V/kcl1HNDWeybrV3SrVjjdI00D1lFtuvLldkwAklSOE"
displayname: "Egor Matveev"
email: emmtvv@gmail.com

View File

@@ -3,3 +3,4 @@ FROM gitea/act_runner:nightly
RUN apk add docker
RUN apk add git
RUN apk add --no-cache nodejs
RUN apk add --no-cache make

View File

@@ -6,7 +6,7 @@ from json import loads
minio_client = Minio(
"minio.dev.chocomarsh.com:9000",
"minio:9000",
access_key="serviceminioadmin",
secret_key=os.getenv("MINIO_SECRET_KEY", "minioadmin"),
secure=False,

View File

@@ -6,7 +6,7 @@ from json import loads
minio_client = Minio(
"minio.chocomarsh.com:9000",
"minio:9000",
access_key="serviceminioadmin",
secret_key=os.getenv("MINIO_SECRET_KEY", "minioadmin"),
secure=False,

View File

@@ -8,10 +8,15 @@ docker network create -d overlay --attachable configurator || true
docker network create -d overlay --attachable monitoring || true
docker network create -d overlay --attachable configurator-development || true
docker network create -d overlay --attachable clickhouse || true
docker network create -d overlay --attachable clickhouse-development || true
docker network create -d overlay --attachable postgres || true
docker network create -d overlay --attachable postgres-development || true
docker network create -d overlay --attachable mongo || true
docker network create -d overlay --attachable mongo-development || true
docker network create -d overlay --attachable minio || true
docker network create -d overlay --attachable minio-development || true
mkdir /sprint-data/mongo || true
mkdir /sprint-data/redis || true
mkdir /sprint-data/rabbitmq || true
mkdir /sprint-data/certs || true
mkdir /sprint-data/gitea || true
mkdir /sprint-data/clickhouse || true