devsetup1-9 Exercise 2: First-Run Setup and Locking It Down ============================================================ STEP 1: THE INSTALLER PAGE -------------------------- Browse to http://localhost:3000 (or the port that ss showed). Database type SQLite3 (keep the offered path) Server domain devserver (or the machine's IP address) Base URL http://devserver:3000/ (how you will really reach it) Administrator create one now, with a strong password Submit. The page takes a few moments and then shows the Gitea home page. STEP 2: TIGHTEN THE PERMISSIONS ------------------------------- sudo chmod 750 /etc/gitea sudo chmod 640 /etc/gitea/app.ini sudo systemctl restart gitea STEP 3: CONFIRM IT STILL WORKS ------------------------------ systemctl status gitea # active (running) ls -ld /etc/gitea # drwxr-x--- root git ls -l /etc/gitea/app.ini # -rw-r----- root git journalctl -u gitea -n 20 # no permission errors Reload the web page and log in. The service reads app.ini as the git user through the group permission, so read access for the group is all it needs. WHY TIGHTEN AFTER SETUP, NOT BEFORE ----------------------------------- The installer runs inside the Gitea process, as the git user, and has to WRITE app.ini into /etc/gitea. That is why the directory is group-writable (770) during installation. Once the file exists Gitea only needs to read it, so the write permission can be removed. Tightening first would make the installer fail to save its settings; leaving it loose afterwards would let the service, or anything that compromised it, rewrite its own configuration. If the service fails to start after tightening, read the journal: a message about opening or reading app.ini means the ownership (root:git) or the group read bit is wrong. WHY THIS WORKS AS AN ANSWER --------------------------- It shows the sequence (open, configure, close), verifies the result with ls and the journal instead of assuming, and gives the reason for the ordering, which is what lets you troubleshoot the same pattern elsewhere.