devsetup1-9 Exercise 1: Install Gitea from the Binary ====================================================== STEP 1: CHECK FIRST ------------------- command -v gitea # nothing git --version # 2.0 or newer (Debian 13's is much newer) getent passwd git # nothing printed: no git user yet ss -tlnp | grep -E ':3000|:22' # port 22 is your sshd; nothing on 3000 STEP 2: DOWNLOAD AND VERIFY --------------------------- Check the current version at https://dl.gitea.com/gitea/ and set VER to it. VER=1.27.3 cd ~/Downloads wget -O gitea https://dl.gitea.com/gitea/$VER/gitea-$VER-linux-amd64 wget -O gitea.asc https://dl.gitea.com/gitea/$VER/gitea-$VER-linux-amd64.asc chmod +x gitea gpg --keyserver hkps://keys.openpgp.org --recv 7C9E68152594688862D62AF62D9AE806EC1592E2 gpg --verify gitea.asc gitea Expected: "Good signature from "Teabot "". A warning that the key is not certified with a trusted signature is normal for a freshly fetched key. "BAD signature" is not: delete both files and download again. STEP 3: USER, DIRECTORIES, PROGRAM ---------------------------------- sudo adduser --system --shell /bin/bash --gecos 'Git Version Control' \ --group --disabled-password --home /home/git git sudo mkdir -p /var/lib/gitea/{custom,data,log} sudo chown -R git:git /var/lib/gitea/ sudo chmod -R 750 /var/lib/gitea/ sudo mkdir /etc/gitea sudo chown root:git /etc/gitea sudo chmod 770 /etc/gitea sudo cp gitea /usr/local/bin/gitea STEP 4: THE SERVICE ------------------- Create /etc/systemd/system/gitea.service with the contents shown in the chapter (User=git, Group=git, WorkingDirectory=/var/lib/gitea/, ExecStart=/usr/local/bin/gitea web --config /etc/gitea/app.ini, Restart=always, WantedBy=multi-user.target). Then: sudo systemctl enable gitea --now STEP 5: THREE CHECKS -------------------- systemctl status gitea Active: active (running); the ExecStart line matches the unit file. ps -o user,pid,cmd -C gitea The USER column shows "git", not root and not you. ss -tlnp | grep gitea Shows the address and port it listens on (expected 3000). Note whether it is 127.0.0.1 (this machine only) or * / 0.0.0.0 (whole network). Also look at the log for errors: journalctl -u gitea -n 30 Before first-run setup it is normal for the log to say the installation has not been completed; that is what the web page in Exercise 2 finishes. WHY THIS WORKS AS AN ANSWER --------------------------- Every claim is checked from a different angle: systemd says it is running, the process list says who runs it, and the socket list says where it listens. The signature check happens before the file is copied anywhere it will be run.