diff --git a/README.md b/README.md index 77adeea..eeacb44 100644 --- a/README.md +++ b/README.md @@ -2,7 +2,7 @@ This repository contains the infrastructure configuration, deployment files and operational documentation for the SilverLinux server. -SilverLinux is the primary self-hosted platform for Silver Solutions and hosts source control, project management, collaboration, communication and future CI/CD services. +SilverLinux is the primary self-hosted platform for Silver Solutions and hosts source control, project management, collaboration, communication and CI/CD services. --- @@ -30,12 +30,12 @@ SilverLinux is the primary self-hosted platform for Silver Solutions and hosts s * Jitsi Meet * Portainer * Nginx Proxy Manager +* BaGet +* Gitea Actions Runner ### Planned -* BaGet * Sentry -* CI/CD Runners * Nextcloud ### Removed @@ -65,6 +65,7 @@ Secrets are stored outside the repository: ## Repository Structure ```text +baget/ docs/ gitea/ jitsi/ @@ -93,6 +94,14 @@ The goal is that the entire environment can be rebuilt from this repository and --- +## CI/CD + +Gitea Actions is enabled globally and uses the self-hosted `silverlinux-runner` on SilverLinux. The operational Silver 2.0 package workflow builds and publishes NuGet packages to the internal BaGet feed. + +See [docs/cicd.md](docs/cicd.md) for the runner, workflow triggers, pipeline stages and secret locations. + +--- + ## Security Never commit: diff --git a/SUMMARY.md b/SUMMARY.md index 5804b02..738d410 100644 --- a/SUMMARY.md +++ b/SUMMARY.md @@ -18,6 +18,7 @@ The platform hosts source control, project management, video conferencing, conta | OpenProject | https://team.silveressence.net | | Portainer | https://portainer.silveressence.net | | Jitsi Meet | https://meet.silveressence.net | +| BaGet | https://nuget.silveressence.net | --- @@ -30,7 +31,9 @@ Purpose: * Git repositories * Pull requests * Issue tracking -* Future CI/CD integration +* Gitea Actions enabled globally +* Self-hosted Actions runner operational +* NuGet package publishing to BaGet Authentication: @@ -108,6 +111,34 @@ Purpose: --- +### BaGet + +Purpose: + +* Private NuGet package hosting +* Internal Silver.* package distribution + +Access: + +* Routed through Nginx Proxy Manager +* https://nuget.silveressence.net + +--- + +### Gitea Actions Runner + +Purpose: + +* Execute Gitea Actions workflows +* Build and package Silver 2.0 libraries +* Publish NuGet packages to BaGet + +Status: + +* Global runner operational as `silverlinux-runner` + +--- + ## Shared Infrastructure ### Docker @@ -172,8 +203,7 @@ All shared credentials are stored in: ### Phase 2 -* Deploy BaGet -* Configure private NuGet feeds +* Expand package publishing to additional repositories ### Phase 3 @@ -181,7 +211,6 @@ All shared credentials are stored in: ### Phase 4 -* Implement CI/CD pipelines * Automated deployment to Windows IIS servers --- diff --git a/baget/README.md b/baget/README.md index e69de29..bbdf777 100644 --- a/baget/README.md +++ b/baget/README.md @@ -0,0 +1,83 @@ +# BaGet + +## Overview + +BaGet is the private NuGet package server for Silver Solutions. + +URL: + +```text +https://nuget.silveressence.net +``` + +Status: + +```text +Running +``` + +Public HTTPS access is routed through Nginx Proxy Manager. The BaGet container is connected to the external `proxy` Docker network. + +NuGet v3 feed: + +```text +https://nuget.silveressence.net/v3/index.json +``` + +## Configuration + +Current configuration is stored directly in the Docker Compose file. + +Location: + +```text +/srv/docker/baget/docker-compose.yml +``` + +Current configuration includes: + +* ApiKey +* Storage configuration +* Database configuration +* Search configuration + +## Data Storage + +```text +/srv/docker/baget/data +``` + +This directory contains the SQLite database and hosted NuGet packages and should be included in backups. + +## Reverse Proxy + +| Setting | Value | +| ---------------- | ----------------------------------- | +| Public URL | `https://nuget.silveressence.net` | +| Target container | `baget` | +| Target port | `80` | +| Docker network | `proxy` | + +## Gitea Actions Integration + +The Silver 2.0 workflow at `.gitea/workflows/package.yml` publishes packages to this feed through the global `silverlinux-runner`. + +Publishing requires the repository Actions secret: + +```text +BAGET_API_KEY +``` + +It is stored under **Repository Settings -> Actions -> Secrets** and must never be committed to a repository. + +The end-to-end Gitea Actions to BaGet publishing pipeline is operational. + +### Future Improvement + +BaGet configuration should eventually be migrated to: + +```text +/srv/secrets/company.env +``` + +to centralize secret management across SilverLinux services. diff --git a/baget/docker-compose.yml b/baget/docker-compose.yml index e69de29..47cd010 100644 --- a/baget/docker-compose.yml +++ b/baget/docker-compose.yml @@ -0,0 +1,26 @@ +services: + baget: + image: loicsharma/baget:latest + container_name: baget + restart: unless-stopped + + ports: + - "5555:80" + + environment: + ApiKey: "your api key" + Storage__Type: FileSystem + Storage__Path: /var/baget/packages + Database__Type: Sqlite + Database__ConnectionString: Data Source=/var/baget/baget.db + Search__Type: Database + + volumes: + - /srv/docker/baget/data:/var/baget + + networks: + - proxy + +networks: + proxy: + external: true \ No newline at end of file diff --git a/docs/AI_CONTEXT.md b/docs/AI_CONTEXT.md index 179cd0d..3fefb1a 100644 --- a/docs/AI_CONTEXT.md +++ b/docs/AI_CONTEXT.md @@ -24,6 +24,8 @@ Public IP: 51.255.83.140 * Jitsi Meet * Portainer * Nginx Proxy Manager +* BaGet +* Gitea Actions Runner (`silverlinux-runner`) ## Domains @@ -35,6 +37,8 @@ meet.silveressence.net -> Jitsi portainer.silveressence.net -> Portainer +nuget.silveressence.net -> BaGet (through Nginx Proxy Manager) + ## Secrets Secrets are stored in: @@ -55,6 +59,16 @@ internal Gitea: * Local accounts + +## CI/CD + +Gitea Actions is enabled globally. + +The global self-hosted runner is operational at `/srv/docker/gitea-runner` with the name `silverlinux-runner`. + +Silver 2.0 uses `.gitea/workflows/package.yml` to publish NuGet packages to BaGet when a push to `net-8-version` has a commit message containing `[Package]`. + +The runner registration token is stored in `/srv/secrets/company.env`. The BaGet publishing key is stored as the repository Actions secret `BAGET_API_KEY`. * OpenID disabled * Google OAuth planned * GitHub OAuth planned @@ -78,3 +92,5 @@ and the README.md of each service folder before making infrastructure recommenda * Centralized secrets implemented * Nginx Proxy Manager selected * PostgreSQL selected as shared database platform +* BaGet deployed at nuget.silveressence.net through Nginx Proxy Manager +* Gitea Actions and a global self-hosted runner selected for package publishing diff --git a/docs/backups.md b/docs/backups.md index 398fc2d..5e084bd 100644 --- a/docs/backups.md +++ b/docs/backups.md @@ -156,6 +156,46 @@ Medium --- +#### BaGet Data + +Location: + +```text +/srv/docker/baget/data +``` + +Contains: + +* Hosted NuGet packages +* SQLite database + +Importance: + +Medium + +--- + +#### Gitea Actions Runner Configuration + +Location: + +```text +/srv/docker/gitea-runner +``` + +Contains: + +* Runner deployment configuration +* Runner state + +The registration token is stored separately in `/srv/secrets/company.env`. + +Importance: + +Medium + +--- + ## Backup Storage Current Location: @@ -214,6 +254,8 @@ Restore order: 5. OpenProject 6. Portainer 7. Jitsi +8. BaGet +9. Gitea Actions Runner --- diff --git a/docs/cicd.md b/docs/cicd.md index 10780fd..b71b3f9 100644 --- a/docs/cicd.md +++ b/docs/cicd.md @@ -2,246 +2,159 @@ ## Overview -The goal of SilverLinux is to become the central deployment platform for Silver Solutions applications. - -Source code is managed through Gitea and future deployments should be automated through CI/CD pipelines. +SilverLinux provides CI/CD through globally enabled Gitea Actions and a self-hosted runner. Package publishing is operational; application deployment to Windows IIS and Linux targets remains future work. --- -## Current Situation +## Gitea Actions -Application deployments are currently performed manually. - -Typical process: - -1. Developer commits code. -2. Developer publishes application. -3. Files are deployed manually. -4. IIS application is restarted if necessary. +Gitea Actions is enabled in Gitea's `app.ini` and is available globally. Status: ```text -Manual +Operational ``` --- -## Future Goal +## Self-Hosted Runner -Automate deployments from Gitea repositories to target servers. +| Property | Value | +| --- | --- | +| Location | `/srv/docker/gitea-runner` | +| Image | `gitea/act_runner:latest` | +| Runner name | `silverlinux-runner` | +| Runner type | Global Runner | +| Status | Operational | -Examples: +Runner labels: -* Windows IIS servers -* Application servers -* Test environments -* Future Linux deployments +* `ubuntu-latest` +* `ubuntu-24.04` +* `ubuntu-22.04` + +The global runner can execute Actions workflows for repositories hosted by the SilverLinux Gitea instance. --- -## Planned Architecture +## Silver 2.0 Package Publishing + +Workflow: ```text -Developer - ↓ -Git Commit - ↓ -Gitea - ↓ -Gitea Actions - ↓ -Build - ↓ -Test - ↓ -Deploy - ↓ -Target Server +.gitea/workflows/package.yml +``` + +The workflow runs when both conditions are satisfied: + +1. Code is pushed to the `net-8-version` branch. +2. The commit message contains `[Package]`. + +Example commit message: + +```text +Package Silver 2.0 libraries [Package] +``` + +Pipeline steps: + +1. Check out the repository. +2. Install the .NET 8 SDK. +3. Restore the solution. +4. Build the solution using the `Deploy` configuration. +5. Pack the NuGet packages. +6. Push the packages to BaGet. + +NuGet feed: + +```text +https://nuget.silveressence.net/v3/index.json ``` --- -## Deployment Targets +## Operational Flow + +```text +Git push + -> Gitea Actions + -> silverlinux-runner + -> dotnet restore + -> dotnet build + -> dotnet pack + -> BaGet package publish +``` + +The complete workflow has been tested successfully and is operational. + +--- + +## Secrets + +Runner registration token: + +```text +/srv/secrets/company.env +GITEA_RUNNER_REGISTRATION_TOKEN +``` + +BaGet publishing credential: + +```text +Repository Settings -> Actions -> Secrets +BAGET_API_KEY +``` + +No credentials are stored in repositories. Infrastructure-level secrets belong in `company.env`; repository workflow secrets belong in Gitea Actions Secrets. + +--- + +## Future Deployment Targets ### Windows IIS -Purpose: - -Deploy: - -* ASP.NET Core -* Blazor Server -* Blazor Web App - -Method: +Planned targets include ASP.NET Core, Blazor Server and Blazor Web App deployments. ```text -Publish -→ Copy Files -→ Restart IIS Site +Publish -> Copy files -> Restart IIS site ``` -Status: - -Planned - ---- +Status: Planned ### Linux Containers -Purpose: - -Future Docker deployments. - -Method: - ```text -Build Docker Image -→ Push Image -→ Deploy Stack +Build image -> Push image -> Deploy stack ``` -Status: - -Future - ---- - -## Planned Tooling - -### Gitea Actions - -Purpose: - -* Build automation -* Testing -* Deployment automation - -Status: - -Planned - ---- - -### Self-Hosted Runner - -Purpose: - -Execute build pipelines. - -Potential Location: - -```text -SilverLinux -``` - -Status: - -Planned - ---- - -## Pipeline Stages - -### Build - -Examples: - -* Restore NuGet packages -* Build solution -* Publish application - ---- - -### Test - -Examples: - -* Unit tests -* Integration tests -* Build validation - ---- - -### Deploy - -Examples: - -* IIS deployment -* Docker deployment -* Environment updates - ---- - -## Notifications - -Future CI/CD notifications should use: - -```text -noreply@silveressence.net -``` - -Examples: - -* Build succeeded -* Build failed -* Deployment completed -* Deployment failed - ---- - -## Security - -Deployment credentials should never be stored in repositories. - -Store credentials in: - -```text -/ srv/secrets/company.env -``` - -or platform-specific secret stores. - ---- - -## Initial Target - -First automated deployment target: - -```text -Gitea - → -Windows Server IIS - → -Blazor Applications -``` - -This provides the highest immediate value. +Status: Future --- ## Future Enhancements -* Automatic testing -* Automatic deployment +* Automated tests +* Automated Windows IIS deployment +* Linux container deployment * Release pipelines -* Docker image registry -* BaGet integration * Multi-environment deployments +* Package publishing for additional repositories --- ## Related Services * Gitea +* Gitea Actions Runner +* BaGet * Portainer * Nginx Proxy Manager ---- - ## Related Documentation * gitea/README.md +* baget/README.md * docs/server.md * docs/security.md +* docs/secrets.md diff --git a/docs/decisions.md b/docs/decisions.md index 0aec5e3..51b2407 100644 --- a/docs/decisions.md +++ b/docs/decisions.md @@ -228,6 +228,52 @@ Implemented --- +## 2026-06-21 - Adopt Gitea Actions + Self-Hosted Runner for Package Publishing + +Decision: + +* Replace GitHub Actions with self-hosted Gitea Actions. +* Execute package publishing on SilverLinux using the global `silverlinux-runner`. +* Publish internal NuGet packages to BaGet. +* Store the runner registration token in `/srv/secrets/company.env` and publishing credentials in Gitea Actions Secrets. +* Use `[Package]` in commit messages to request commit-driven package publishing. + +Reason: + +* Keep source control, build execution and package hosting inside SilverLinux. +* Avoid storing credentials in repositories. +* Provide a simple, explicit package-release convention. + +Status: + +```text +Accepted +``` + +--- + +## 2026-06-21 - BaGet Secret Storage + +Decision: + +The BaGet API key is currently stored directly in the BaGet Docker Compose configuration. + +Reason: + +* Simplicity during initial deployment. + +Future Plan: + +Move the API key into the centralized SilverLinux secrets management system located at: + +```text +/srv/secrets/company.env +``` + +when additional services begin consuming the same secret management approach. + +--- + ## Future Decisions Document future decisions using the following template: diff --git a/docs/domains.md b/docs/domains.md index 3a3de1a..f7446f1 100644 --- a/docs/domains.md +++ b/docs/domains.md @@ -113,8 +113,6 @@ portainer --- -## Planned Domains - ### BaGet Domain: @@ -127,10 +125,22 @@ Purpose: * Private NuGet package hosting +Container: + +```text +baget +``` + +Routing: + +```text +Nginx Proxy Manager -> baget:80 +``` + Status: ```text -Planned +Active ``` --- diff --git a/docs/secrets.md b/docs/secrets.md index 4d6d86e..4039117 100644 --- a/docs/secrets.md +++ b/docs/secrets.md @@ -79,6 +79,21 @@ Used by: --- +### Gitea Actions Runner + +```text +GITEA_RUNNER_REGISTRATION_TOKEN +``` + +Used by: + +* The global `silverlinux-runner` +* Runner registration and reconnection + +Repository workflow credentials, including `BAGET_API_KEY`, are stored in Gitea under **Repository Settings -> Actions -> Secrets** and are not stored in repositories. + +--- + ### Jitsi ```text diff --git a/docs/server.md b/docs/server.md index f615248..a4a865f 100644 --- a/docs/server.md +++ b/docs/server.md @@ -104,6 +104,8 @@ Examples: * Jitsi Meet * Portainer * Nginx Proxy Manager +* BaGet +* Gitea Actions Runner --- @@ -124,6 +126,8 @@ Contains: /srv/docker/jitsi /srv/docker/portainer /srv/docker/nginx-proxy-manager +/srv/docker/baget +/srv/docker/gitea-runner ``` --- @@ -202,6 +206,28 @@ Suggested structure: --- +### BaGet + +```text +/srv/docker/baget/data +``` + +--- + +### Gitea Actions Runner + +```text +/srv/docker/gitea-runner +``` + +Runner: + +```text +silverlinux-runner +``` + +--- + ## SSH Access Primary user: diff --git a/docs/services.md b/docs/services.md index 6a92fd8..1752c50 100644 --- a/docs/services.md +++ b/docs/services.md @@ -135,6 +135,73 @@ Running --- +### BaGet + +URL: + +```text +https://nuget.silveressence.net +``` + +Purpose: + +* Private NuGet repository +* Internal Silver.* package distribution +* Package source for CI/CD +* Package source for team development + +Access: + +* Routed through Nginx Proxy Manager + +Status: + +```text +Running +``` + +--- + +### Gitea Actions Runner + +Location: + +```text +/srv/docker/gitea-runner +``` + +Image: + +```text +gitea/act_runner:latest +``` + +Runner Name: + +```text +silverlinux-runner +``` + +Type: + +```text +Global Runner +``` + +Labels: + +* `ubuntu-latest` +* `ubuntu-24.04` +* `ubuntu-22.04` + +Status: + +```text +Operational +``` + +--- + ## Shared Infrastructure ### Docker @@ -188,28 +255,6 @@ Active --- -## Planned Services - -### BaGet - -URL: - -```text -https://nuget.silveressence.net -``` - -Purpose: - -* Private NuGet package hosting - -Status: - -```text -Planned -``` - ---- - ## Removed Services ### Plane.so diff --git a/gitea/README.md b/gitea/README.md index 88bc0ae..eba4325 100644 --- a/gitea/README.md +++ b/gitea/README.md @@ -57,7 +57,7 @@ Gitea is used for: * Pull requests * Issue management * Release management -* Future CI/CD pipelines +* Gitea Actions CI/CD pipelines --- @@ -205,9 +205,45 @@ This directory is critical and must be included in backups. --- +## Gitea Actions + +Gitea Actions is enabled in `app.ini` and available globally. + +Status: + +```text +Operational +``` + +### Global Runner + +| Property | Value | +| --- | --- | +| Location | `/srv/docker/gitea-runner` | +| Image | `gitea/act_runner:latest` | +| Name | `silverlinux-runner` | +| Type | Global Runner | +| Status | Operational | + +Labels: + +* `ubuntu-latest` +* `ubuntu-24.04` +* `ubuntu-22.04` + +The runner registration token is loaded from `GITEA_RUNNER_REGISTRATION_TOKEN` in `/srv/secrets/company.env`. + +### Package Publishing + +Silver 2.0 uses `.gitea/workflows/package.yml` to build and publish NuGet packages to BaGet. A push to `net-8-version` triggers packaging when the commit message contains `[Package]`. + +The publishing credential is stored as the repository Actions secret `BAGET_API_KEY`. + +--- + ## Secrets -The following secrets are loaded from: +Gitea and its Actions runner use infrastructure secrets stored in: ```text /srv/secrets/company.env @@ -222,8 +258,12 @@ SMTP_HOST SMTP_PORT SMTP_USERNAME SMTP_PASSWORD + +GITEA_RUNNER_REGISTRATION_TOKEN ``` +The Gitea container uses the database and SMTP variables. The Actions runner uses `GITEA_RUNNER_REGISTRATION_TOKEN`. + Future variables: ```text @@ -334,9 +374,8 @@ To restore Gitea: ### Long Term -* Implement CI/CD pipelines * Deploy applications directly from Gitea -* Host private NuGet packages through BaGet +* Expand package publishing to additional repositories --- @@ -346,6 +385,8 @@ To restore Gitea: * Nginx Proxy Manager * OpenProject * Portainer +* BaGet +* Gitea Actions Runner --- @@ -356,3 +397,4 @@ To restore Gitea: * docs/secrets.md * docs/backups.md * postgres/README.md +* docs/cicd.md diff --git a/nginx-proxy-manager/README.md b/nginx-proxy-manager/README.md index 1192557..7ea8d9f 100644 --- a/nginx-proxy-manager/README.md +++ b/nginx-proxy-manager/README.md @@ -98,6 +98,7 @@ Examples: | team.silveressence.net | OpenProject | | meet.silveressence.net | Jitsi | | portainer.silveressence.net | Portainer | +| nuget.silveressence.net | BaGet | --- @@ -193,6 +194,7 @@ Without these directories: * OpenProject * Jitsi Meet * Portainer +* BaGet ---