配置Stash私有镜像仓库需要遵循以下步骤,确保顺利部署并通过Ingress控制访问

步骤 1:安装Docker

确保你的服务器上已安装Docker,如果尚未安装,按照以下步骤操作:

  1. 更新包仓库索引:
    sudo apt update
  2. 安装Docker:
    sudo apt install docker-ce docker-ce-cli containerd runc
  3. 启动并管理Docker服务:
    sudo systemctl restart docker
    sudo systemctl enable docker

步骤 2:获取Stash镜像

选择适合你的镜像版本,假设你使用Debian/Ubuntu,可以选择以下镜像:

docker pull ghcr.io/gitchurch/stash:latest

步骤 3:配置Stash容器

创建或编辑配置文件 stash.yml:

version: 1..
name: stash
image: ghcr.io/gitchurch/stash:latest
restart_policy: always
volumes:
  - name: stash-data
    driver: local
services:
  - name: stash
    image: ghcr.io/gitchurch/stash:latest
    command: -c 'echo "Stash is running"' && echo "Ready to accept connections on port 808"
  - name: stash-intranet
    image: ghcr.io/gitchurch/stash:latest
    command: -c 'echo "Intranet service is running"' && echo "Ready for internal HTTP traffic only"
  - name: stash-ingress
    image: ghcr.io/gitchurch/stash:latest
    command: -c 'echo "Ingress service is running"' && echo "Ready for external HTTP traffic through Nginx"
  - name: stash-redis
    image: ghcr.io/gitchurch/stash:latest
    command: -c 'echo "Redis cache is running"' && echo "Ready for caching"
  - name: stash-mysql
    image: ghcr.io/gitchurch/stash:latest
    command: -c 'echo "MySQL database is running"' && echo "Ready for database connections"
  - name: stash-pg
    image: ghcr.io/gitchurch/stash:latest
    command: -c 'echo "PostgreSQL database is running"' && echo "Ready for database connections"
  - name: stash-ldap
    image: ghcr.io/gitchurch/stash:latest
    command: -c 'echo "LDAP server is running"' && echo "Ready for LDAP integration"
  - name: stash-logging
    image: ghcr.io/gitchurch/stash:latest
    command: -c 'echo "Logging service is running"' && echo "Ready for log collection"
  - name: stash-notifications
    image: ghcr.io/gitchurch/stash:latest
    command: -c 'echo "Notifications service is running"' && echo "Ready for notifications"

步骤 4:运行Stash容器

使用Docker运行配置文件:

docker run -d --name stash -v /var/lib/stash -v /var/log/stash -e STASH_DB_CREDENTIALS=yourdbuser:yourdbpass stash.yml

步骤 5:配置Ingress(Nginx)

创建或编辑Nginx配置文件 stash.conf:

server {
    listen 80;
    server_name stash.example.com;
    location / {
        proxy_pass http://stash:808;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
        proxy_max_connect_timeout 10m;
        proxy_read_timeout 10m;
        proxy_send_timeout 10m;
        proxy_buffer_size 4m;
        proxy_buffer_pool_size 8m;
        proxy_min_write_buffer_size 8m;
        proxy_max_write_buffer_size 16m;
    }
    # Handle SSL
    ssl {
        listen 443;
        server_name stash.example.com;
        ssl_certificate /etc/letsencrypt/live/stash.example.com/fullchain.pem;
        ssl_certificate_key /etc/letsencrypt/live/stash.example.com/privkey.pem;
        ssl_protocols TLS:TLSv1.2 TLSv1.3;
        ssl_ciphers ECDHE-ECDSA-AECDH:EDHP-EDHP;
        ssl_prefer_server_ciphers on;
        ssl_session_cache shared:SSL:10m;
        ssl_session_timeout 10m;
    }
}

安装并启动Nginx:

sudo apt install nginx
sudo systemctl restart nginx

步骤 6:验证部署

访问 http://stash.example.com,你应该看到Stash的登录界面,如果出现问题,检查Nginx配置和容器日志:

docker logs -f stash

高级配置

  • 数据库选择:根据你的需求选择MySQL、PostgreSQL或其他数据库。
  • Ingress设置:确保域名解析正确,可能需要配置DNS记录。
  • SSL证书:使用Let's Encrypt自动签发证书,或者自签发。
  • 高级功能:如LDAP集成、rbac、审计等,可以在后续添加配置。

完成以上步骤后,Stash 应该已经正常运行,私有镜像仓库建立成功,你可以开始推送和管理镜像了!

配置Stash私有镜像仓库需要遵循以下步骤,确保顺利部署并通过Ingress控制访问

扫码添加原子VPN加速器微信

扫码添加原子VPN加速器微信

400-815-7263
扫码添加原子VPN加速器微信

扫码添加原子VPN加速器微信

网站地图