步骤 1:安装Docker
确保你的服务器上已安装Docker,如果尚未安装,按照以下步骤操作:
- 更新包仓库索引:
sudo apt update
- 安装Docker:
sudo apt install docker-ce docker-ce-cli containerd runc
- 启动并管理Docker服务:
sudo systemctl restart docker sudo systemctl enable docker
步骤 2:获取Stash镜像
选择适合你的镜像版本,假设你使用Debian/Ubuntu,可以选择以下镜像:
docker pull ghcr.io/gitchurch/stash:latest
步骤 3:配置Stash容器
创建或编辑配置文件 stash.yml:
version: 1..
name: stash
image: ghcr.io/gitchurch/stash:latest
restart_policy: always
volumes:
- name: stash-data
driver: local
services:
- name: stash
image: ghcr.io/gitchurch/stash:latest
command: -c 'echo "Stash is running"' && echo "Ready to accept connections on port 808"
- name: stash-intranet
image: ghcr.io/gitchurch/stash:latest
command: -c 'echo "Intranet service is running"' && echo "Ready for internal HTTP traffic only"
- name: stash-ingress
image: ghcr.io/gitchurch/stash:latest
command: -c 'echo "Ingress service is running"' && echo "Ready for external HTTP traffic through Nginx"
- name: stash-redis
image: ghcr.io/gitchurch/stash:latest
command: -c 'echo "Redis cache is running"' && echo "Ready for caching"
- name: stash-mysql
image: ghcr.io/gitchurch/stash:latest
command: -c 'echo "MySQL database is running"' && echo "Ready for database connections"
- name: stash-pg
image: ghcr.io/gitchurch/stash:latest
command: -c 'echo "PostgreSQL database is running"' && echo "Ready for database connections"
- name: stash-ldap
image: ghcr.io/gitchurch/stash:latest
command: -c 'echo "LDAP server is running"' && echo "Ready for LDAP integration"
- name: stash-logging
image: ghcr.io/gitchurch/stash:latest
command: -c 'echo "Logging service is running"' && echo "Ready for log collection"
- name: stash-notifications
image: ghcr.io/gitchurch/stash:latest
command: -c 'echo "Notifications service is running"' && echo "Ready for notifications"
步骤 4:运行Stash容器
使用Docker运行配置文件:
docker run -d --name stash -v /var/lib/stash -v /var/log/stash -e STASH_DB_CREDENTIALS=yourdbuser:yourdbpass stash.yml
步骤 5:配置Ingress(Nginx)
创建或编辑Nginx配置文件 stash.conf:
server {
listen 80;
server_name stash.example.com;
location / {
proxy_pass http://stash:808;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_max_connect_timeout 10m;
proxy_read_timeout 10m;
proxy_send_timeout 10m;
proxy_buffer_size 4m;
proxy_buffer_pool_size 8m;
proxy_min_write_buffer_size 8m;
proxy_max_write_buffer_size 16m;
}
# Handle SSL
ssl {
listen 443;
server_name stash.example.com;
ssl_certificate /etc/letsencrypt/live/stash.example.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/stash.example.com/privkey.pem;
ssl_protocols TLS:TLSv1.2 TLSv1.3;
ssl_ciphers ECDHE-ECDSA-AECDH:EDHP-EDHP;
ssl_prefer_server_ciphers on;
ssl_session_cache shared:SSL:10m;
ssl_session_timeout 10m;
}
}
安装并启动Nginx:
sudo apt install nginx sudo systemctl restart nginx
步骤 6:验证部署
访问 http://stash.example.com,你应该看到Stash的登录界面,如果出现问题,检查Nginx配置和容器日志:
docker logs -f stash
高级配置
- 数据库选择:根据你的需求选择MySQL、PostgreSQL或其他数据库。
- Ingress设置:确保域名解析正确,可能需要配置DNS记录。
- SSL证书:使用Let's Encrypt自动签发证书,或者自签发。
- 高级功能:如LDAP集成、rbac、审计等,可以在后续添加配置。
完成以上步骤后,Stash 应该已经正常运行,私有镜像仓库建立成功,你可以开始推送和管理镜像了!









