feat(forgejo): global repository, upload, attachment and mirror limits #515

Sammanfogat
supernaut sammanfogade 2 incheckningar från feat/495-per-user-limits in i main 2026-10-02 09:53:32 +00:00
Ägare

What

Global Forgejo limits in app.ini, as role defaults in roles/forgejo/defaults/main.yml. Keys verified against the v16.0.5 app.example.ini and the config cheat sheet.

Key Value Upstream
[repository] MAX_CREATION_LIMIT 10 -1
[repository.upload] FILE_MAX_SIZE / MAX_FILES 50 MB / 5 same, now pinned
[attachment] MAX_SIZE / MAX_FILES 100 MB / 5 2048 MB / 5
[mirror] MIN_INTERVAL / DEFAULT_INTERVAL 1h / 8h 10m / 8h

MAX_CREATION_LIMIT is a fail-closed default. The reconciler sets max_repo_creation per user on every run (10 for participants and exempt accounts, 100 for paid), which overrides it. The global value only applies to an account the reconciler has not reached yet, so it must not exceed the participant cap.

Runbook: new "Per-user limits (#495)" section. local/vars.local.yml mirrors the values; make render-only renders them.

Not done

  • A test account hitting each limit, after apply.
  • Forgejo has no mirror-count or per-tier setting for these keys.

Apply

Forgejo role only. app.ini changes, so Forgejo restarts once.

Refs #495

## What Global Forgejo limits in `app.ini`, as role defaults in `roles/forgejo/defaults/main.yml`. Keys verified against the v16.0.5 `app.example.ini` and the [config cheat sheet](https://forgejo.org/docs/v16.0/admin/config-cheat-sheet/). | Key | Value | Upstream | | --- | --- | --- | | `[repository] MAX_CREATION_LIMIT` | 10 | -1 | | `[repository.upload] FILE_MAX_SIZE` / `MAX_FILES` | 50 MB / 5 | same, now pinned | | `[attachment] MAX_SIZE` / `MAX_FILES` | 100 MB / 5 | 2048 MB / 5 | | `[mirror] MIN_INTERVAL` / `DEFAULT_INTERVAL` | 1h / 8h | 10m / 8h | `MAX_CREATION_LIMIT` is a fail-closed default. The reconciler sets `max_repo_creation` per user on every run (10 for participants and exempt accounts, 100 for paid), which overrides it. The global value only applies to an account the reconciler has not reached yet, so it must not exceed the participant cap. Runbook: new "Per-user limits (#495)" section. `local/vars.local.yml` mirrors the values; `make render-only` renders them. ## Not done - A test account hitting each limit, after apply. - Forgejo has no mirror-count or per-tier setting for these keys. ## Apply Forgejo role only. `app.ini` changes, so Forgejo restarts once. Refs #495
supernaut lade till 2 incheckningar 2026-10-02 09:11:20 +00:00
Cap repos per owner at 100, pin upload size and file count, cut the
attachment max to 100 MB and floor pull-mirror interval at 1h.
Document the values in the runbook.

Refs #495
fix(forgejo): default repo creation limit to the participant cap
Alla kontroller lyckades
ci / ci (pull_request) Successful in 2m3s
d2acb28208
The reconciler sets the per-user cap each run (10 participant, 100 paid),
so the global value only governs new accounts. Fail closed at 10.

Refs #495
supernaut sammanfogade incheckning 76a715b779 till main 2026-10-02 09:53:32 +00:00
supernaut tog bort grenen feat/495-per-user-limits 2026-10-02 09:53:33 +00:00
supernaut refererade denna ändringsförfrågan från en incheckning 2026-10-02 10:21:07 +00:00
supernaut refererade denna ändringsförfrågan från en incheckning 2026-10-02 17:56:58 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!515
Ingen beskrivning angiven.