mirror of
https://relay.ngit.dev/npub15qydau2hjma6ngxkl2cyar74wzyjshvl65za5k5rl69264ar2exs5cyejr/ngit-grasp.git
synced 2026-10-05 15:08:24 +00:00
The production guide was NixOS-only despite presenting itself as the general deployment entry point, and its examples referenced an unavailable GitHub source and a hardening control the module does not set. Turn the entry point into an environment chooser, preserve the corrected NixOS material in its own guide, add a hardened generic systemd unit and repeatable Linux installation, document the preferred unprivileged Proxmox layout, and update repository navigation and architecture references. Each path assumes the shared deployment contract from the container change. Kubernetes automation, remote host mutation, and changes to the existing NixOS module are deliberately excluded. Validated the canonical Git remote with git ls-remote, parsed and scored the systemd unit with systemd-analyze, checked all new deployment-guide links, removed trailing whitespace, scanned the staged diff for key-shaped nsec values, and ran git diff --check.
59 lines
2.1 KiB
Markdown
59 lines
2.1 KiB
Markdown
# Deploy in a Proxmox LXC container or VM
|
|
|
|
ngit-grasp has no kernel-virtualization or nested-container requirement. The
|
|
preferred Proxmox layout is an unprivileged Debian or Ubuntu LXC running the
|
|
static binary as a systemd service.
|
|
|
|
## Container requirements
|
|
|
|
- an unprivileged LXC or ordinary VM with systemd
|
|
- network access to public HTTPS and WebSocket relays
|
|
- inbound HTTP/HTTPS through the Proxmox network or an external proxy
|
|
- durable storage sized for Git repositories, LMDB, holding data, and backups
|
|
|
|
Docker nesting is not required for the direct binary path. Leave it disabled
|
|
unless using the Compose alternative below.
|
|
|
|
## Direct systemd path
|
|
|
|
Follow [Deploy a static binary with systemd](deploy-linux.md) inside the guest.
|
|
Keep `/var/lib/ngit-grasp` on storage included in the guest's snapshot and
|
|
backup policy.
|
|
|
|
When the Proxmox host bind-mounts a dataset into an unprivileged LXC, map its
|
|
ownership to the container's `ngit-grasp` UID/GID before starting the service.
|
|
Verify this from inside the container:
|
|
|
|
```bash
|
|
sudo -u ngit-grasp test -w /var/lib/ngit-grasp
|
|
sudo -u ngit-grasp git --version
|
|
```
|
|
|
|
Terminate TLS either inside the guest with Caddy or at an upstream proxy. If
|
|
the upstream proxy connects directly to ngit-grasp, add only that private
|
|
source address to `NGIT_TRUSTED_PROXY_CIDRS` and prevent other clients from
|
|
reaching port 7334.
|
|
|
|
## Compose alternative
|
|
|
|
If the guest already operates Docker or Podman, follow the
|
|
[Docker guide](deploy-docker.md). Docker inside LXC generally requires the
|
|
Proxmox nesting feature; the static binary path avoids that extra layer.
|
|
|
|
Do not mount the host Docker socket into the relay container. ngit-grasp needs
|
|
Git, not a container daemon.
|
|
|
|
## Backup and upgrade
|
|
|
|
For a simple consistent backup:
|
|
|
|
1. stop `ngit-grasp` inside the guest;
|
|
2. snapshot or back up the guest and its attached state storage;
|
|
3. start the service; and
|
|
4. verify the public endpoint.
|
|
|
|
Proxmox snapshots are not a substitute for an off-host backup. Before a
|
|
storage-changing upgrade, confirm that the state volume participates in the
|
|
snapshot and that the snapshot can be restored without starting a second
|
|
writer against the production domain.
|