1amends "../../config/Service.pkl"
2
3import "../../config/OpenID.pkl" as sso
4
5meta {
6 name = "Shale"
7}
8requirements {
9 new sso.Client {
10 clientId = module.id
11 name = module.meta.name
12 redirectUris { "https://\(module.container.http.hostname)/-/callback" }
13 usernameAliases { ["snow"] = "clover" }
14 allowGuests = true
15 usernameRequired = true
16 }
17}
18prepare = "prepare.py"
19
20container {
21 image = "docker.io/astheno/shale@sha256:0c507bb2d2f0d6390b8411f644d5c7c7579a384d14ccae2cf82eb51c2eb6466e"
22 extraHosts { "\(sso.hostname):host-gateway" }
23
24 http {
25 containerPort = 8000
26 subdomain = "shale"
27 overrideFiles {
28 ["/-/theme.css"] = "theme.css"
29 ["/-/repo-icons/"] = "icons"
30 ["/-/studio-readme/"] = "readme"
31 }
32 headHtml {
33 ["/*"] = """
34 <script defer src="/-/studio-readme/markdown-it.min.js"></script><script defer src="/-/studio-readme/purify.min.js"></script><script defer src="/-/studio-readme/readme.js"></script>
35 """
36 }
37 }
38
39 volumes {
40 ["/data"] {}
41 ["/repositories_owned"] {}
42 ["/repositories_mirrors"] {}
43 ["/etc/crontabs"] {}
44 ["/etc/shale/theme.css"] { config = "theme.css" }
45 ["/etc/ssl/certs/ca-certificates.crt"] {
46 src = "/var/lib/studio/ca-bundle.crt"
47 readOnly = true
48 }
49 }
50
51 env {
52 ["DOMAIN"] = module.container.http.hostname
53 ["HOME"] = "/data"
54 ["SERVER_TITLE"] = "clover's git"
55 // Concurrent Markdown rendering shares capture state between request workers.
56 ["NPROC"] = "1"
57 ["SESSION_SECRET"] = "${secret.own.session_secret}"
58 ["OAUTH2_CLIENT"] = "oidc,\(sso.hostname)|${secret.oidc.clientId}|${secret.oidc.clientSecret}"
59 }
60}
61
62secrets {
63 ["session_secret"] {}
64}