Reduce secret syncing to just .env
All checks were successful
Deploy with Docker Compose / deploy (push) Successful in 7s

Strip hardcoded secrets from gitea/config/app.ini (already injected
via GITEA__ env vars) and commit it to git. Add download.sh to fetch
the act_runner binary on demand instead of syncing it. Everything else
(searxng settings, certbot certs, runner registration, Spotify tokens)
is generated at runtime.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
2026-04-07 14:22:50 +01:00
parent 67771777cd
commit 494f61f9c6
4 changed files with 127 additions and 1 deletions

1
.gitignore vendored
View File

@@ -6,7 +6,6 @@ certbot/www
backend/token/
.env
gitea/config/app.ini
gitea/data/*
# Gitea runner