/README (4a18249bf06d04d1e27d97623f12a7a2d51f83c0) (5774 bytes) (mode 100644) (type blob)
== About ==
. Website: https://rocketgit.com
. Author: Catalin(ux) M. BOIE
. Description: Light and fast Git hosting solution
. License: Affero GPLv3+
. Language: PHP (plans to rewrite in C in the near future)
. Database: PostgreSQL
. Project start date: 2011-03-04
== Features ==
. Free software
. No Java
. No Javascript
. Upgrades with the standard tools of the distributions
. Very little dependencies, all packaged in main-stream distributions
. SELinux friendly
. Very small (RPM is around 400KiB)
. IPv6 ready
. Internationalization ready
== Install ==
. Install RocketGit from source (./configure && make && make install) or
with a package manager:
Fedora:
dnf install http://kernel.embedromix.ro/dinorepo-0.0.10-1.noarch.rpm
dnf install rocketgit
CentOS/RedHat/Oracle
yum install http://kernel.embedromix.ro/dinorepo-el-0.0.11-1.noarch.rpm
yum install rocketgit
Edit /etc/rocketgit/config.php
Edit /etc/rocketgit/php-fpm.conf
Edit /etc/rocketgit/pool.conf
. Activate rocketgit php-fpm:
systemd based distributions:
systemctl enable rocketgit-fpm
systemctl start rocketgit-fpm
RedHat/CentOS/Oracle
chkconfig rocketgit-fpm on
service rocketgit-fpm start
. PHP
Adjust php.ini to:
- allow enough RAM and execution time
- fix timezone
You may want to activate an op cache to speed up the PHP scripts:
yum/dnf install php-opcache
Also, we recommend to activate opcache also for cli:
change opcache.enable_cli to 1 in /etc/php.d/10-opcache.ini and
/etc/php-zts.d/10-opcache.ini.
. Install and prepare a web server: nginx/apache:
nginx is recommended because of the chunked encoding in POST requests.
yum/dnf install nginx
or
yum/dnf install httpd mod_ssl
Copy rocketgit.conf.sample from /etc/nginx/conf.d
(or /etc/httpd/conf.d) into rocketgit.conf and edit it.
Activate web server (nginx)
systemd based distributions:
systemctl enable nginx.service
systemctl restart nginx.service
RedHat/CentOS/Oracle
chkconfig nginx on
service nginx restart
Activate web server (apache)
systemd based distributions:
systemctl enable httpd.service
systemctl restart httpd.service
RedHat/CentOS/Oracle
chkconfig httpd on
service httpd restart
. Activate sshd (for ssh:// access)
systemd based distributions:
systemctl enable sshd.service
systemctl start sshd.service
RedHat/CentOS/Oracle
chkconfig sshd on
service sshd restart
. Activate xinetd (for git:// access, optional)
systemd based distributions:
systemctl enable xinetd.service
systemctl start xinetd.service
RedHat/CentOS/Oracle
chkconfig xinetd on
service xinetd restart
. Prepare PostgreSQL server
yum/dnf install postgresql-server
Add the following lines, before wildcard matches, in
/var/lib/pgsql/data/pg_hba.conf:
local rocketgit rocketgit trust
host rocketgit rocketgit 127.0.0.1/32 trust
host rocketgit rocketgit ::1/128 trust
systemd based distributions:
systemctl enable postgresql.service
export PGSETUP_INITDB_OPTIONS="--data-checksums" # recommended
postgresql-setup --initdb # (TAKE CARE! YOU MAY DESTROY ALL YOUR DATA!)
systemctl start postgresql.service
RedHat/CentOS/Oracle
chkconfig postgresql on
service postgresql initdb
service postgresql start
Notes:
- Check also the config file (/etc/rocketgit/config.php) and set
correctly the rg_sql string.
- If the web server and the db are not on the same host, you need to
replace 127.0.0.1 and ::1 with your "safe network". You may want to use
md5/etc. for authentication. Also, you may want to change
'listen_addresses' to '*'. You may also want to activate SSL.
# Create a PostgreSQL user and database
su - postgres
createuser --createdb --no-createrole --no-superuser rocketgit
createdb -O rocketgit rocketgit
. Prepare the mail
To be able to generate e-mails as other user, you have to:
For sendmail:
- Enable daemon:
systemd based distributions: systemctl enable sendmail.service
RedHat/CentOS/Oracle: chkconfig sendmail on
- Edit /etc/mail/trusted-users and add 'rocketgit' and 'apache'.
- Restart daemon:
systemd based distributions: systemctl restart sendmail.service
RedHat/CentOS/Oracle: service sendmail restart
. Edit firewall to permit ssh, git, http and https ports
In /etc/sysconfig/iptables (IPv4) and ip6tables (IPv6), add something
like this:
-A INPUT -m tcp -p tcp --dport ssh -j ACCEPT
-A INPUT -m tcp -p tcp --dport git -j ACCEPT
-A INPUT -m tcp -p tcp --dport http -j ACCEPT # optional
-A INPUT -m tcp -p tcp --dport https -j ACCEPT
If you use firewalld:
firewall-cmd --permanent --add-port=ssh/tcp
firewall-cmd --permanent --add-port=git/tcp
firewall-cmd --permanent --add-port=http/tcp # optional
firewall-cmd --permanent --add-port=https/tcp
firewall-cmd --reload
. Point your browser to the newly created server and you will be asked to
create the admin account.
. As admin user, go to Admin -> Settings and check if any setting should be
tweaked. It is very important to set the 'Host name' value.
. You may want to install 'qrencode' package to be able to be able to see the
two-factor authentication keys as QR images.
== Thanks ==
. Special thanks to my family that supports me in this project.
. Special thanks to my brother that contributed brain and time to this project.
. Special thanks to git people for the best tool to manage the sources.
. Special thanks to Petre Bandac for free hosting of rg2 server.
. Special thanks to a lot of people that came with suggestions.
. Special thanks to gitosys, Gitorious and other projects from where I learned
things.
. Special thanks to OWASP for their good documentation on how to write a
secure web application.
. See AUTHORS file for all the people who contributed to this project.
Mode |
Type |
Size |
Ref |
File |
100644 |
blob |
9 |
f3c7a7c5da68804a1bdf391127ba34aed33c3cca |
.exclude |
100644 |
blob |
102 |
eaeb7d777062c60a55cdd4b5734902cdf6e1790c |
.gitignore |
100644 |
blob |
289 |
fabbff669e768c05d6cfab4d9aeb651bf623e174 |
AUTHORS |
100644 |
blob |
1132 |
dd65951315f3de6d52d52a82fca59889d1d95187 |
Certs.txt |
100644 |
blob |
549 |
41c3bdbba8ec2523fe24b84bdd46777fc13e8345 |
History.txt |
100644 |
blob |
34520 |
dba13ed2ddf783ee8118c6a581dbf75305f816a3 |
LICENSE |
100644 |
blob |
3398 |
cf75b360b8a3e6ef86bc4a42648e353bd58c2a80 |
Makefile.in |
100644 |
blob |
5774 |
4a18249bf06d04d1e27d97623f12a7a2d51f83c0 |
README |
100644 |
blob |
118763 |
259c7b1871cb204da34bc36f9b635efb208c8a40 |
TODO |
100644 |
blob |
1294 |
f22911eb777f0695fcf81ad686eac133eb11fcc4 |
TODO-plans |
100644 |
blob |
203 |
a2863c67c3da44126b61a15a6f09738c25e0fbe0 |
TODO.perf |
100644 |
blob |
1044 |
9bb3652b3937eb624dba0f2d8efff7ce6c0ce0e2 |
TODO.vm |
040000 |
tree |
- |
21928e906ad2907a55c2e81c2a8b0502b586b8a0 |
artwork |
100644 |
blob |
4650 |
548f8c18609fa92b720aebfa5433f50a2c4ced78 |
compare.csv |
100755 |
blob |
30 |
92c4bc48245c00408cd7e1fd89bc1a03058f4ce4 |
configure |
040000 |
tree |
- |
1624fa67631f0dd10772e19016ffcd9af8e44773 |
debian |
040000 |
tree |
- |
3c08a24a998b6e80be5f4af4ac3599ab6acacba3 |
docker |
040000 |
tree |
- |
f67d3605efbd6422a8acdd953578991139266391 |
docs |
100755 |
blob |
16720 |
52405deef0d3708e7553022e1e9db73faa28d05c |
duilder |
100644 |
blob |
536 |
96c75f943c5bf93b54dbddf678e8a99d7ba4ff93 |
duilder.conf |
040000 |
tree |
- |
c503cf29ce2337a771fdfdbf4225b35d8e81ab98 |
hooks |
040000 |
tree |
- |
ee9eaf8711d6019f6e8d54b6181cbed36a1abfc6 |
inc |
040000 |
tree |
- |
ab5cc695f620de9abecc84af49866a45612067c6 |
misc |
100644 |
blob |
3742 |
dd0d01262f0ec9a6ac67aa549300631f6f3896b8 |
rocketgit.spec.in |
040000 |
tree |
- |
89c7458a4616213f0231101964ddb7528187102e |
root |
040000 |
tree |
- |
edfd5fcdabcb2a987269d8167dfe8d02eebe3e19 |
samples |
040000 |
tree |
- |
dadefbcdcd82cedbce7279cf8003cbc1da8112e0 |
scripts |
040000 |
tree |
- |
00c52dce99b99f5f59800512ffd8e145d5ffe2c9 |
selinux |
100755 |
blob |
256 |
462ccd108c431f54e380cdac2329129875a318b5 |
spell_check.sh |
040000 |
tree |
- |
cb54e074b3ca35943edfcda9dd9cfcd281bcd9e7 |
techdocs |
040000 |
tree |
- |
2295ccc932fb25c145117950c313db77b771f9cd |
tests |
040000 |
tree |
- |
63f68e921ac8d6a62ea9c3d180e072c7c4725b7d |
tools |
Hints:
Before first commit, do not forget to setup your git environment:
git config --global user.name "your_name_here"
git config --global user.email "your@email_here"
Clone this repository using HTTP(S):
git clone https://rocketgit.com/user/catalinux/rocketgit
Clone this repository using ssh (do not forget to upload a key first):
git clone ssh://rocketgit@ssh.rocketgit.com/user/catalinux/rocketgit
Clone this repository using git:
git clone git://git.rocketgit.com/user/catalinux/rocketgit
You are allowed to anonymously push to this repository.
This means that your pushed commits will automatically be transformed into a
merge request:
... clone the repository ...
... make some changes and some commits ...
git push origin main