Installing the Semaphore UI
Installation
sudo apt install ansible python3-jmespath yq
sudo wget "https://github.com/semaphoreui/semaphore/releases/download/v2.19.12/semaphore_2.19.12_linux_amd64.deb" -O "/usr/local/src/semaphore_2.19.12_linux_amd64.deb"
sudo apt install "/usr/local/src/semaphore_2.19.12_linux_amd64.deb"
sudo useradd --create-home -d "/var/lib/semaphore" --shell "/usr/sbin/nologin" --system semaphore
sudo chmod 0750 "/var/lib/semaphore"
sudo -u semaphore semaphore setup
sudo chmod 0640 "/var/lib/semaphore/config.json"
sudo chmod 0600 "/var/lib/semaphore/database.sqlite"
sudo tee "/etc/systemd/system/semaphoreui.service" >/dev/null <<'EOF'
[Unit]
Description=Ansible's Semaphore UI
Documentation=https://semaphoreui.com/docs
Wants=network-online.target
After=network-online.target
ConditionPathExists=/usr/bin/semaphore
ConditionPathExists=/var/lib/semaphore/config.json
[Service]
ExecStart=/usr/bin/semaphore server --config=/var/lib/semaphore/config.json
ExecReload=/bin/kill -HUP $MAINPID
Restart=always
RestartSec=10s
User=semaphore
Group=semaphore
SyslogIdentifier=semaphore
[Install]
WantedBy=multi-user.target
EOF
sudo systemctl daemon-reload
sudo systemctl enable --now semaphoreui
ReverseNGINX Reverse-Proxy
server {
listen 443 ssl;
http2 on;
add_header X-Frame-Options "SAMEORIGIN";
add_header X-Content-Type-Options "nosniff";
add_header Strict-Transport-Security "max-age=63072000" always;
# requiredRequired to avoid HTTP 411: see Issue #1486#1486.
# (https://github.com/docker/docker/issues/1486)
chunked_transfer_encoding on;
location / {
proxy_pass http://127.0.0.1:3000/;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_buffering off;
proxy_request_buffering off;
}
location /api/ws {
proxy_pass http://127.0.0.1:3000/api/ws;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_set_header Origin "";
}
}
Create GitLab Acecss Token
read_api read_repository