[cgit v1.2.3] [ build 2020-03-24 ] [amd64/arm64] cgit is a fast webinterface for the git dscm
1.1K
cgit is a hyperfast web frontend for git repositories written in C
cgit container image for cgit lovershttps://hub.docker.com/r/80x86/cgit
Scans and displays every repository under /git.
Gravatar and Libravatarthis container is SSL only
cgit access URL is:
https://your-domain-or-IP:your-port
assume that we use the port 8443 for WEB access, so the URL is:
https://your-domain-or-IP:8443
no latest tag !!! use specific tag please
the examples below uses 1.2.3-amd64 as the tag,
in the real world, you should always check and use the newest available tag
do not just copy and paste the sample commands below
you need to modify the commands for your needs!
change tag from xxx-amd64 to xxx-arm64 if you are on a aarch64/arm64 machine
if auto ACME enabled, you can simply map the volume /etc/nginx/ssl like:
-v path/to/cgit/ssl/dir:/etc/nginx/ssl:z
otherwise, you need also put your own
certificate file: /etc/nginx/ssl/ssl.crt
and the key file /etc/nginx/ssl/ssl.key
if you don't like the default self-signed certificate.
a simple example (just for test):
docker pull 80x86/cgit:1.2.3-amd64
docker run --name cgit -d -p 8443:443 -v my/git/repositories:/git:ro,z 80x86/cgit:1.2.3-amd64
enable optional authentication:
just set HTTP_AUTH_USER and HTTP_AUTH_PASSWD to none empty
be aware that in order to clone via https://foo.org:8443/$CGIT_REPO_URL
we need to set CGIT_ENABLE_HTTP_CLONE="1"
docker run --name cgit -d -p 8443:443 \
-e HTTP_AUTH_USER=user \
-e HTTP_AUTH_PASSWD=password \
-e CGIT_ROOT_TITLE="example.com git repositories" \
-e CGIT_ROOT_DESC="a fast webinterface for the git dscm" \
-e CGIT_ENABLE_HTTP_CLONE="1" \
-e CGIT_CLONE_URL='https://foo.org:8443/$CGIT_REPO_URL [email protected]:$CGIT_REPO_URL' \
-v my/git/repositories:/git:ro,z \
-v path/to/cgit/cache/dir:/var/cache/cgit:z \
80x86/cgit:1.2.3-amd64
Enable Automatic HTTPS via ACME (let's encrypt by default):
take cloudflare for example, your need add following env vars:
-e AUTOCERT_EMAIL=your-email-for-acme \
-e AUTOCERT_DOMAIN=you-domain.com \
-e AUTOCERT_DNS_PROVIDER=cloudflare \
-e CF_DNS_API_TOKEN="your-cf-token-here" \
an full example:
docker run --name cgit -d \
-e HTTP_AUTH_USER=admin \
-e HTTP_AUTH_PASSWD=admin \
-e AUTOCERT_EMAIL=your-email-for-acme \
-e AUTOCERT_DOMAIN=you-domain.com \
-e AUTOCERT_DNS_PROVIDER=cloudflare \
-e CF_DNS_API_TOKEN="your-cf-token-here" \
-e CGIT_CLONE_URL='https://you-domain.com:8443/$CGIT_REPO_URL [email protected]:$CGIT_REPO_URL' \
-p 8443:443 \
-v my/git/repositories:/git:ro,z \
-v path/to/cgit/cache/dir:/var/cache/cgit:z \
80x86/cgit:1.2.3-amd64
443
HTTP_AUTH_USER=""
HTTP_AUTH_PASSWD=""
TZ="Asia/Shanghai"
CGIT_ROOT_TITLE="example.com git repositories"
CGIT_ROOT_DESC="a fast webinterface for the git dscm"
CGIT_ROOT_README="/app/public/about.md"
# set to 0 to disable snapshot download feature
CGIT_SNAPSHOTS="tar.gz tar.bz2 zip"
# Allow http transport git clone, set to 0 to disable
CGIT_ENABLE_HTTP_CLONE="0"
CGIT_AVATAR_SERVER=" "
# set to empty string to hide the clone URL
CGIT_CLONE_URL='https://foo.org/$CGIT_REPO_URL [email protected]:$CGIT_REPO_URL'
# ACME related env vars
# acme check interval in hours, default to 24 hours
GO_ACME_INTERVAL=24
# change CA server to `https://acme-staging-v02.api.letsencrypt.org/directory` if you want to test
GO_ACME_CA_SERVER=""
# set to http://IP:PORT if you want to use http proxy for ACME
HTTP_PROXY=""
AUTOCERT_EMAIL=""
# ACME domain like `foo.com`, can be multi like `foo.com,b.bar.com`, can be wildcard like `*.foo.com`
AUTOCERT_DOMAIN=""
# must be one of `RSA2048`, `RSA4096`, `RSA8192`, `EC256`, `EC384`
AUTOCERT_KEYTYPE=EC256
# ACME DNS provider, default is cloudflare
AUTOCERT_DNS_PROVIDER=cloudflare
# this env var is only used by `cloudflare` DNS provider
CF_DNS_API_TOKEN=""
/var/cache/cgit
/etc/nginx/ssl
/git
alidns,azure,cloudflare,cloudxns,digitalocean,dnspod,gcloud,linodev4,namecheap,qcloud,rfc2136,vultr
cloudflare:
get token from "My Profile -> API Tokens" API token must include the following permissions:
Zone.Zone: ReadZone.DNS: EditZone Resources: All zones
| Environment Variable Name | description |
|---|---|
| CF_DNS_API_TOKEN | API Token |
dnspod:
| Environment Variable Name | description |
|---|---|
| DNSPOD_API_KEY | format is: id,token |
qcloud:
| Environment Variable Name | description |
|---|---|
| QCLOUD_SECRET_ID | The SecretId |
| QCLOUD_SECRET_KEY | The SecretKey |
alidns:
| Environment Variable Name | description |
|---|---|
| ALICLOUD_ACCESS_KEY | Access key ID |
| ALICLOUD_SECRET_KEY | Access Key secret |
for other provider please ref to: https://go-acme.github.io/lego/dns/#dns-providers
To test or experiment with your configuration,
make sure you change the ACME endpoint to a staging or development URL,
otherwise you are likely to hit rate limits which can block your access to HTTPS for up to a week,
depending on which rate limit you hit.
the default CA is Let's Encrypt, which has a staging endpoint that is not subject to the same rate limits:
https://acme-staging-v02.api.letsencrypt.org/directory
you can set it for your container by using env var
GO_ACME_CA_SERVER="https://acme-staging-v02.api.letsencrypt.org/directory"
❯ git clone https://127.0.0.1:6443/cgit.git
Cloning into 'cgit'...
fatal: unable to access 'https://127.0.0.1:6443/cgit.git/': SSL certificate problem: self signed certificate
Workaround:
git config --global http.sslVerify false
Content type
Image
Digest
Size
30.2 MB
Last updated
over 6 years ago
docker pull 80x86/cgit:arm64