From ef34b26068c4e25f929a584edda63b8878c063b3 Mon Sep 17 00:00:00 2001 From: Akshay Nair Date: Sat, 4 Jul 2026 16:31:13 +0530 Subject: Create local dockerfiles override to manage send/cgit users/groups --- cgit/Dockerfile | 67 ++++++++++++++++++++++++++++++++++++++ cgit/docker-entrypoint.sh | 17 ++++++++++ cgit/nginx.conf | 35 -------------------- cgit/nginx/conf.d/default.conf | 35 ++++++++++++++++++++ cgit/nginx/nginx.conf | 73 ++++++++++++++++++++++++++++++++++++++++++ 5 files changed, 192 insertions(+), 35 deletions(-) create mode 100644 cgit/Dockerfile create mode 100755 cgit/docker-entrypoint.sh delete mode 100644 cgit/nginx.conf create mode 100644 cgit/nginx/conf.d/default.conf create mode 100644 cgit/nginx/nginx.conf (limited to 'cgit') diff --git a/cgit/Dockerfile b/cgit/Dockerfile new file mode 100644 index 0000000..86b3005 --- /dev/null +++ b/cgit/Dockerfile @@ -0,0 +1,67 @@ +FROM nginx:1.28.1-alpine3.23 + +ARG VERSION=0.0.0 +ENV VERSION=${VERSION} + +RUN addgroup -S git -g 1001 && adduser -S -G git -u 1001 -D git + +# CGit +ARG CGIT_VERSION=1.2.3-r5 +ENV CGIT_VERSION=${CGIT_VERSION} + +LABEL version="${VERSION}" \ + description="The hyperfast web frontend for Git repositories on top of Alpine and Nginx." \ + maintainer="Jose Quintana " + +RUN set -eux \ + && apk add --no-cache \ + ca-certificates \ + cgit=${CGIT_VERSION} \ + fcgiwrap \ + git \ + lua5.3-libs \ + py3-markdown \ + py3-pygments \ + py3-docutils \ + groff \ + python3 \ + spawn-fcgi \ + tzdata \ + xz \ + zlib \ + && rm -rf /var/cache/apk/* \ + && rm -rf /tmp/* \ + && true + +COPY docker-entrypoint.sh / +RUN chmod +x /docker-entrypoint.sh +COPY nginx/ /etc/nginx + +# RUN set -eux \ +# && echo "Creating application directories..." \ +# && mkdir -p /var/cache/cgit \ +# && mkdir -p /srv/git \ +# && true + +RUN set -eux \ + && echo "Testing Nginx server configuration files..." \ + && nginx -c /etc/nginx/nginx.conf -t \ + && true + +RUN ls -la /docker-entrypoint.sh + +ENTRYPOINT [ "/docker-entrypoint.sh" ] + +EXPOSE 80 + +STOPSIGNAL SIGQUIT + +CMD [ "nginx", "-g", "daemon off;" ] + +# Metadata +LABEL org.opencontainers.image.vendor="Jose Quintana" \ + org.opencontainers.image.url="https://github.com/joseluisq/alpine-cgit" \ + org.opencontainers.image.title="cgit" \ + org.opencontainers.image.description="The hyperfast web frontend for Git repositories on top of Alpine and Nginx." \ + org.opencontainers.image.version="${VERSION}" \ + org.opencontainers.image.documentation="https://github.com/joseluisq/alpine-cgit" diff --git a/cgit/docker-entrypoint.sh b/cgit/docker-entrypoint.sh new file mode 100755 index 0000000..0c13086 --- /dev/null +++ b/cgit/docker-entrypoint.sh @@ -0,0 +1,17 @@ +#!/bin/sh + +set -eux + +CGIT_USER=git +CGIT_GROUP=git + +id + +chown $CGIT_USER:$CGIT_GROUP /var/cache/cgit +chmod u+g /var/cache/cgit + +spawn-fcgi \ + -u $CGIT_USER -g $CGIT_GROUP \ + -s /var/run/fcgiwrap.sock \ + -n -- /usr/bin/fcgiwrap \ + & exec "$@" diff --git a/cgit/nginx.conf b/cgit/nginx.conf deleted file mode 100644 index a850744..0000000 --- a/cgit/nginx.conf +++ /dev/null @@ -1,35 +0,0 @@ -server { - listen 80; - server_name localhost; - root /usr/share/webapps/cgit; - - location / { - try_files $uri @cgit; - } - - location ~* ^.+(favicon.ico|robots.txt) { - root /usr/share/webapps/cgit; - expires 30d; - } - - location @cgit { - include /etc/nginx/fastcgi_params; - fastcgi_param SCRIPT_FILENAME $document_root/cgit.cgi; - fastcgi_param PATH_INFO $uri; - fastcgi_param QUERY_STRING $args; - fastcgi_param HTTP_HOST $server_name; - fastcgi_pass unix:/var/run/fcgiwrap.sock; - } - - error_page 404 /404.html; - error_page 401 /401.html; - - error_page 500 502 503 504 /50x.html; - location = /50x.html { - root /usr/share/nginx/html; - } - - location ~ /\.ht { - deny all; - } -} diff --git a/cgit/nginx/conf.d/default.conf b/cgit/nginx/conf.d/default.conf new file mode 100644 index 0000000..a850744 --- /dev/null +++ b/cgit/nginx/conf.d/default.conf @@ -0,0 +1,35 @@ +server { + listen 80; + server_name localhost; + root /usr/share/webapps/cgit; + + location / { + try_files $uri @cgit; + } + + location ~* ^.+(favicon.ico|robots.txt) { + root /usr/share/webapps/cgit; + expires 30d; + } + + location @cgit { + include /etc/nginx/fastcgi_params; + fastcgi_param SCRIPT_FILENAME $document_root/cgit.cgi; + fastcgi_param PATH_INFO $uri; + fastcgi_param QUERY_STRING $args; + fastcgi_param HTTP_HOST $server_name; + fastcgi_pass unix:/var/run/fcgiwrap.sock; + } + + error_page 404 /404.html; + error_page 401 /401.html; + + error_page 500 502 503 504 /50x.html; + location = /50x.html { + root /usr/share/nginx/html; + } + + location ~ /\.ht { + deny all; + } +} diff --git a/cgit/nginx/nginx.conf b/cgit/nginx/nginx.conf new file mode 100644 index 0000000..c5a713f --- /dev/null +++ b/cgit/nginx/nginx.conf @@ -0,0 +1,73 @@ +user git; +worker_processes auto; +error_log stderr crit; +pid /var/run/nginx.pid; + +events { + worker_connections 2048; + use epoll; +} + +http { + include /etc/nginx/mime.types; + default_type application/octet-stream; + + open_file_cache max=200000 inactive=20s; + open_file_cache_valid 30s; + open_file_cache_min_uses 2; + open_file_cache_errors on; + + access_log off; + error_log stderr crit; + + sendfile on; + sendfile_max_chunk 512k; + tcp_nopush on; + tcp_nodelay on; + types_hash_max_size 4096; + + keepalive_timeout 35; + + gzip on; + gzip_min_length 10240; + gzip_comp_level 1; + gzip_vary on; + gzip_disable msie6; + gzip_proxied expired no-cache no-store private auth; + # text/html is always compressed by HttpGzipModule + gzip_types + text/css + text/javascript + text/xml + text/plain + text/x-component + application/javascript + application/x-javascript + application/json + application/xml + application/rss+xml + application/atom+xml + font/truetype + font/opentype + application/vnd.ms-fontobject + image/svg+xml; + + reset_timedout_connection on; + client_body_timeout 10; + send_timeout 5; + + server_tokens off; + add_header X-Frame-Options SAMEORIGIN; + add_header X-Content-Type-Options nosniff; + add_header X-XSS-Protection "1; mode=block"; + + client_body_buffer_size 128k; + large_client_header_buffers 4 256k; + + map $http_upgrade $connection_upgrade { + default upgrade; + '' close; + } + + include /etc/nginx/conf.d/*.conf; +} -- cgit v1.3.1