g1t/deploy/self-host/docker-compose.yml

179 lines7,118 bytesCodeBlame

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Running g1t yourself: the design, a docker compose proof, and a guide to what works today1# Self-hosted g1t, phase 1: the core forge on your own machine.
2#
3# docker compose -f deploy/self-host/docker-compose.yml up --build
4#
5# Then open http://localhost:8787. Mail (the confirmation link at sign-up)
Self-hosting: the clone pack cache on S3 (MinIO, expiring), the API and MCP on their own port with PUBLIC_URL-derived addresses across the site, API and mail, scheduler --once, and smoke.sh covering pull requests from branches and forks and the merge queue6# lands in Mailpit at http://localhost:8025. The API is at
7# http://localhost:8789 and the MCP server at http://localhost:8789/mcp.
Running g1t yourself: the design, a docker compose proof, and a guide to what works today8#
9# What runs: the site and every core service in one workerd (g1t), git
Self-hosting: the clone pack cache on S3 (MinIO, expiring), the API and MCP on their own port with PUBLIC_URL-derived addresses across the site, API and mail, scheduler --once, and smoke.sh covering pull requests from branches and forks and the merge queue10# repositories as bare repos on a volume (gitstore), the API in a second
11# workerd beside it, packages' files, backups and the clone pack cache in
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member12# MinIO, and Mailpit for mail.
Running g1t yourself: the design, a docker compose proof, and a guide to what works today13# Agents, deployments, context search and billing are off. See
14# docs/SELF_HOSTING.md.
15name: g1t
16
17services:
18 g1t:
19 build:
20 context: ../..
21 dockerfile: deploy/self-host/Dockerfile
22 ports:
23 - "${G1T_PORT:-8787}:8787"
Self-hosting: the clone pack cache on S3 (MinIO, expiring), the API and MCP on their own port with PUBLIC_URL-derived addresses across the site, API and mail, scheduler --once, and smoke.sh covering pull requests from branches and forks and the merge queue24 - "${API_PORT:-8789}:8789"
Running g1t yourself: the design, a docker compose proof, and a guide to what works today25 environment:
Self-hosting: the clone pack cache on S3 (MinIO, expiring), the API and MCP on their own port with PUBLIC_URL-derived addresses across the site, API and mail, scheduler --once, and smoke.sh covering pull requests from branches and forks and the merge queue26 # Where people reach this installation. Links in mail, clone URLs and
27 # the site's meta tags point here.
Running g1t yourself: the design, a docker compose proof, and a guide to what works today28 PUBLIC_URL: ${PUBLIC_URL:-http://localhost:8787}
Self-hosting: the clone pack cache on S3 (MinIO, expiring), the API and MCP on their own port with PUBLIC_URL-derived addresses across the site, API and mail, scheduler --once, and smoke.sh covering pull requests from branches and forks and the merge queue29 # Where the API (REST, OAuth) is reached, and its OAuth issuer; empty
30 # means PUBLIC_URL's host on API_PORT. MCP_URL, empty, is API_URL/mcp.
31 API_URL: ${API_URL:-}
32 MCP_URL: ${MCP_URL:-}
33 API_PORT: ${API_PORT:-8789}
Running g1t yourself: the design, a docker compose proof, and a guide to what works today34 GITSTORE_URL: http://gitstore:8080
35 GITSTORE_SECRET_FILE: /secrets/gitstore
36 MAIL_URL: ${MAIL_URL:-http://mailpit:8025}
37 MAIL_FROM: ${MAIL_FROM:-g1t <noreply@localhost>}
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look38 # Your own GitHub App, for "Continue with GitHub" and importing from
39 # GitHub. Leave these unset to have neither. See the self-hosting guide.
40 GITHUB_APP_ID: ${GITHUB_APP_ID:-}
41 GITHUB_APP_SLUG: ${GITHUB_APP_SLUG:-}
42 GITHUB_APP_CLIENT_ID: ${GITHUB_APP_CLIENT_ID:-}
43 GITHUB_APP_CLIENT_SECRET: ${GITHUB_APP_CLIENT_SECRET:-}
44 GITHUB_APP_PRIVATE_KEY: ${GITHUB_APP_PRIVATE_KEY:-}
45 GITHUB_APP_WEBHOOK_SECRET: ${GITHUB_APP_WEBHOOK_SECRET:-}
46 # open: anyone may register. invite: a new account needs an invite
47 # code, as on g1t.sh; the owners of INVITE_STAFF_WORKSPACES (slugs,
48 # comma separated) invite without limit, everyone else INVITES_PER_USER.
49 REGISTRATION_MODE: ${REGISTRATION_MODE:-open}
50 INVITE_STAFF_WORKSPACES: ${INVITE_STAFF_WORKSPACES:-}
51 INVITES_PER_USER: ${INVITES_PER_USER:-}
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas52 # Where summaries of new access requests go; empty sends none.
53 WAITLIST_NOTIFY_EMAIL: ${WAITLIST_NOTIFY_EMAIL:-}
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member54 # Packages' files (container images and the rest), in MinIO below or
55 # any S3-compatible store. S3_PUBLIC_ENDPOINT, when clients can reach
56 # the store, sends large downloads there directly.
57 S3_ENDPOINT: ${S3_ENDPOINT:-http://minio:9000}
58 S3_BUCKET: ${S3_BUCKET:-g1t-packages}
59 S3_REGION: ${S3_REGION:-us-east-1}
60 S3_ACCESS_KEY_ID: ${S3_ACCESS_KEY_ID:-g1t}
61 S3_SECRET_ACCESS_KEY: ${S3_SECRET_ACCESS_KEY:-g1t-packages-secret}
62 S3_PUBLIC_ENDPOINT: ${S3_PUBLIC_ENDPOINT:-}
Merge branch 'worktree-agent-ac5b181a013e54348'63 # Nightly backups' bundles and manifests, in a bucket of their own on
64 # the same store (docs/SELF_HOSTING.md, "Backups").
65 BACKUP_S3_BUCKET: ${BACKUP_S3_BUCKET:-g1t-backups}
Self-hosting: the clone pack cache on S3 (MinIO, expiring), the API and MCP on their own port with PUBLIC_URL-derived addresses across the site, API and mail, scheduler --once, and smoke.sh covering pull requests from branches and forks and the merge queue66 # Packs kept for fresh clones, so the next clone of the same commit
67 # does not rebuild one; minio-setup expires them after 7 days.
68 PACK_S3_BUCKET: ${PACK_S3_BUCKET:-g1t-git-packs}
Running g1t yourself: the design, a docker compose proof, and a guide to what works today69 volumes:
70 - g1t-data:/data
71 - g1t-secrets:/secrets:ro
72 depends_on:
73 gitstore:
74 condition: service_healthy
75 mailpit:
76 condition: service_started
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member77 minio-setup:
78 condition: service_completed_successfully
Running g1t yourself: the design, a docker compose proof, and a guide to what works today79 restart: unless-stopped
80
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas81 # The status page, in a process of its own so it stays up when the site
82 # does not: http://localhost:8788. It checks the site every minute.
83 status:
84 build:
85 context: ../..
86 dockerfile: deploy/self-host/Dockerfile
87 command: ["bash", "deploy/self-host/status.sh"]
88 ports:
89 - "${STATUS_PORT:-8788}:8788"
90 environment:
91 PUBLIC_URL: ${PUBLIC_URL:-http://localhost:8787}
92 # How the status page reaches the site, from inside Compose.
93 STATUS_CHECK_URL: http://g1t:8787
94 # A public repository, `workspace/repo`, whose branches it lists as a
95 # clone would. Empty: git is not checked.
96 STATUS_PROBE_REPO: ${STATUS_PROBE_REPO:-}
97 volumes:
98 - g1t-status:/data
99 restart: unless-stopped
100
Running g1t yourself: the design, a docker compose proof, and a guide to what works today101 gitstore:
102 build:
103 context: ./gitstore
104 environment:
105 GITSTORE_URL: http://gitstore:8080
106 GITSTORE_SECRET_FILE: /secrets/gitstore
107 volumes:
108 - g1t-git:/data/git
109 - g1t-secrets:/secrets
110 # Not published: only the g1t container reaches it.
111 restart: unless-stopped
112
Self-hosting: the clone pack cache on S3 (MinIO, expiring), the API and MCP on their own port with PUBLIC_URL-derived addresses across the site, API and mail, scheduler --once, and smoke.sh covering pull requests from branches and forks and the merge queue113 # Packages' files, backups and clone packs. Not published: only the g1t
114 # container reaches it, unless you publish 9000 and set
115 # S3_PUBLIC_ENDPOINT. MinIO no longer publishes images of its own;
116 # MINIO_IMAGE is a community build of the same server, with `mc` in it.
117 # Any S3-compatible store works in its place (S3_ENDPOINT).
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member118 minio:
Self-hosting: the clone pack cache on S3 (MinIO, expiring), the API and MCP on their own port with PUBLIC_URL-derived addresses across the site, API and mail, scheduler --once, and smoke.sh covering pull requests from branches and forks and the merge queue119 image: ${MINIO_IMAGE:-pgsty/minio:latest}
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member120 command: ["server", "/data"]
121 environment:
122 MINIO_ROOT_USER: ${S3_ACCESS_KEY_ID:-g1t}
123 MINIO_ROOT_PASSWORD: ${S3_SECRET_ACCESS_KEY:-g1t-packages-secret}
Self-hosting: the clone pack cache on S3 (MinIO, expiring), the API and MCP on their own port with PUBLIC_URL-derived addresses across the site, API and mail, scheduler --once, and smoke.sh covering pull requests from branches and forks and the merge queue124 # What the health check's `mc ready local` asks.
125 MC_HOST_local: http://localhost:9000
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member126 volumes:
127 - g1t-packages:/data
128 healthcheck:
129 test: ["CMD", "mc", "ready", "local"]
130 interval: 5s
131 retries: 20
132 restart: unless-stopped
133
Self-hosting: the clone pack cache on S3 (MinIO, expiring), the API and MCP on their own port with PUBLIC_URL-derived addresses across the site, API and mail, scheduler --once, and smoke.sh covering pull requests from branches and forks and the merge queue134 # Makes the buckets once, then exits: packages' files, backups, and
135 # clone packs with a rule that deletes packs 7 days old. (MinIO itself
136 # removes uploads left unfinished after 24 hours.)
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member137 minio-setup:
Self-hosting: the clone pack cache on S3 (MinIO, expiring), the API and MCP on their own port with PUBLIC_URL-derived addresses across the site, API and mail, scheduler --once, and smoke.sh covering pull requests from branches and forks and the merge queue138 image: ${MINIO_IMAGE:-pgsty/minio:latest}
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member139 depends_on:
140 minio:
141 condition: service_healthy
142 entrypoint:
143 - sh
144 - -c
Self-hosting: the clone pack cache on S3 (MinIO, expiring), the API and MCP on their own port with PUBLIC_URL-derived addresses across the site, API and mail, scheduler --once, and smoke.sh covering pull requests from branches and forks and the merge queue145 - >-
146 set -e;
147 mc alias set local http://minio:9000 "$$MINIO_ROOT_USER" "$$MINIO_ROOT_PASSWORD";
148 mc mb --ignore-existing "local/$$S3_BUCKET";
149 mc mb --ignore-existing "local/$$BACKUP_S3_BUCKET";
150 mc mb --ignore-existing "local/$$PACK_S3_BUCKET";
151 if ! mc ilm rule ls "local/$$PACK_S3_BUCKET" >/dev/null 2>&1; then
152 mc ilm rule add --prefix packs/ --expire-days 7 "local/$$PACK_S3_BUCKET";
153 fi
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member154 environment:
155 MINIO_ROOT_USER: ${S3_ACCESS_KEY_ID:-g1t}
156 MINIO_ROOT_PASSWORD: ${S3_SECRET_ACCESS_KEY:-g1t-packages-secret}
157 S3_BUCKET: ${S3_BUCKET:-g1t-packages}
Merge branch 'worktree-agent-ac5b181a013e54348'158 BACKUP_S3_BUCKET: ${BACKUP_S3_BUCKET:-g1t-backups}
Self-hosting: the clone pack cache on S3 (MinIO, expiring), the API and MCP on their own port with PUBLIC_URL-derived addresses across the site, API and mail, scheduler --once, and smoke.sh covering pull requests from branches and forks and the merge queue159 PACK_S3_BUCKET: ${PACK_S3_BUCKET:-g1t-git-packs}
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member160
Running g1t yourself: the design, a docker compose proof, and a guide to what works today161 mailpit:
162 image: axllent/mailpit:latest
163 ports:
164 - "${MAILPIT_PORT:-8025}:8025"
165 # To deliver for real, relay through your SMTP server:
166 # environment:
167 # MP_SMTP_RELAY_HOST: smtp.example.com
168 # MP_SMTP_RELAY_PORT: "587"
169 # MP_SMTP_RELAY_USERNAME: ...
170 # MP_SMTP_RELAY_PASSWORD: ...
171 # MP_SMTP_RELAY_ALL: "true"
172 restart: unless-stopped
173
174volumes:
175 g1t-data:
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member176 g1t-packages:
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas177 g1t-status:
Running g1t yourself: the design, a docker compose proof, and a guide to what works today178 g1t-git:
179 g1t-secrets:

This file's history is long; its oldest lines are credited to the oldest commit read.