A Forgejo Forge On Loopback, Proven By A Clone
Forgejo from the upstream release as a hardened service on loopback with sqlite and a configuration it never needs to write. The live test creates an administrator with Forgejo's own command, sees a wrong password refused and registration disabled, creates a private repository, hides it from an anonymous request and clones it over HTTP. Original role, live-tested on Rocky Linux 10.
Verification
Live-testedReally deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.
Conformance
- Static validation (yamllint · ansible-lint)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live-tested - applied, verified, destroyed
Last verified 2026-10-02 · podman 4.9.3 · ansible 2.21.4 · how we verify
Cite it in your README
badge · attributionPaste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.
[](https://www.iac-bazaar.com/catalog/ansible-forgejo?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
Ansible role 1.0.0, live-tested on IaC Bazaar: [A Forgejo Forge On Loopback, Proven By A Clone](https://www.iac-bazaar.com/catalog/ansible-forgejo?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
```yaml
# A Forgejo Forge On Loopback, Proven By A Clone: https://www.iac-bazaar.com/catalog/ansible-forgejo (download from your IaC Bazaar account)
```Preview:
Documentation
forgejo
Forgejo from the upstream release binary (sha256-verified against the vendor's per-asset checksum), as a hardened system service on loopback with sqlite and a root-owned configuration it never needs to write, for a proxy that terminates TLS. Original role for EL 10, live-tested with podman on Rocky Linux 10.
No package, so the checksum is the whole story. EL 10 carries no
forgejo; Forgejo ships a release with a checksum file beside it. The
role downloads both and has Ansible's get_url refuse the binary unless its
SHA-256 is the one in the vendor's file, then installs it as
root's in /usr/local/bin, pinned by forgejo_version.
A service account, a hardened unit, a loopback listener. forgejo
is a system user with no shell that owns the data directory and nothing
else; the unit runs with NoNewPrivileges, PrivateTmp, ProtectHome and
ProtectSystem=strict. The listener is 127.0.0.1:3000 by default,
for a proxy that authenticates or a client on the same host; the live test
reads the listening sockets and expects loopback only.
A configuration Forgejo never writes. Forgejo wants three secrets in
app.ini and writes them there itself when they are missing, which a
root-owned 0640 file forbids. The role generates each once with
forgejo generate secret and points app.ini at the files
(SECRET_KEY_URI, INTERNAL_TOKEN_URI, JWT_SECRET_URI). INSTALL_LOCK is
on: there is no web installer, and registration is off; the first
administrator is forgejo admin user create, which the live test runs.
Forgejo refuses outright to run as root, so the unit's service account is
not a nicety here, it is a requirement.
Proven by a clone, not only an API answer. The live test creates a
throwaway administrator with Forgejo's own command (a second run finds it),
sees a wrong password refused, creates a private repository through the API,
reads it back authenticated, sees an anonymous request answered 404 for it,
clones it over HTTP and finds the README the server committed, then
deletes it. git is installed by the role; the built-in SSH server stays off,
the host's OpenSSH being the usual door.
License
Commercial - IaC Bazaar EULA. (c) IaC Bazaar.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Variables
- Test
Related modules
ansible-atmos
atmos on EL 10 from the GitHub release, get_url refuses it unless its SHA-256 is the one in the vendor's SHA256SUMS, and the live test re-checks it, then writes an atmos.yaml, a stack and a component, validates the stacks and describes the component with no Terraform installed. Pinned. Original role, live-tested on Rocky Linux 10.
ansible-checkov
Checkov pinned in /opt/checkov, a virtual environment apart from the system Python. The live test runs pip check, scans a one-resource module with the built-in checks and --skip-download and expects a 'Failed checks:' summary with no network, and asserts the system Python cannot import it. Original role, live-tested on Rocky Linux 10.
ansible-conftest
conftest on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the project's checksums.txt, and re-checked with sha256sum -c by the live test, which then writes a one-rule Rego v1 policy and a one-line document, runs conftest test and expects the denial in the report. Original role, live-tested on Rocky Linux 10.
ansible-consul-cli
consul on EL 10 from releases.hashicorp.com: the client binary, not a server. HashiCorp's key lives in a GnuPG home of its own, pinned by fingerprint; the SHA256SUMS signature is verified before get_url checks the zip against that file, and the live test verifies it again, then runs consul members against nothing and expects the refused connection. Original role, live-tested on Rocky Linux 10.
ansible-gh-cli
gh on EL 10 from the release tarball, refused by Ansible's get_url unless its SHA-256 is the one in GitHub's checksums file, and re-checked with sha256sum -c by the live test; one more file to trust and no more repositories. Tokens are per user; gh auth status with none stops at 'not logged into any GitHub hosts', the live test's proof the client ran. Original role, live-tested on Rocky Linux 10.
ansible-glab
glab on EL 10 from the GitLab-hosted release, get_url refuses it unless its SHA-256 is the one in the vendor's checksums file, and the live test re-checks it, then runs auth status to the 401 gitlab.com returns and round-trips a config value offline. Pinned. Original role, live-tested on Rocky Linux 10.