{"thread":{"id":"15683","subject":"Internal, corporate, shared hosting solutions","startedAt":"2008-09-26T15:13:48Z","lastAt":"2008-09-26T18:17:15Z","messageCount":3,"participants":["Tom Lanyon","Shawn O. Pearce","Johan Herland"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"91699","messageId":"8B29890D-C03B-4ECE-9BEF-0A8E8EF7233E@netspot.com.au","threadId":"15683","inReplyTo":null,"subject":"Internal, corporate, shared hosting solutions","fromName":"Tom Lanyon","fromEmail":"tom@netspot.com.au","sentAt":"2008-09-26T15:13:48Z","receivedAt":"2008-09-26T15:13:48Z","isPatch":false,"sender":{"key":"tom@netspot.com.au","avatar":null},"body":"Hi list,\n\nI'm struggling. There's been a recent adoption of git here by our  \ndevelopment staff, which is great. However, from an administrative  \npoint of view, I'm having trouble finding a solution to provide some  \nkind of easy, shared, secure and accessible hosting solution to our  \ndevelopers.\n\nSo that these repositories can be centrally tracked and backed up, we  \nrequire a central git host for all of our projects from all our  \ndevelopment teams.\n\nWe have some pretty basic requirements:\n\t- authentication and authorisation; some repos are only readable/ \nwritable by specific people\n\t- accessible; many dev servers are on private subnets, ideally we  \nneed to be able to proxy git access\n\t- not too much messing with unix user accounts on the central git  \nhost (because they're tied to LDAP, for example)\n\nAccessibility is easily addressed by providing access to the git  \nrepositories via WebDAV with which we can proxy HTTP traffic.  \nSimilarly, HTTP gives us great authentication and authorisation;  \nfantastic, problem solved. Not so fast. We need git built with  \nUSE_CURL_MULTI to support push over HTTP, which requires curl >=  \n7.16.0. The most recent RedHat Enterprise Linux has 7.15.5 so we'd  \nneed to build many custom packages and compatibility packages for any  \nservers needing git access and this is plainly not acceptable from an  \nadministrative standpoint. Additionally, git over WebDAV is incredibly  \nslow. Pushing git's git repostory to a new, empty repository over  \ngigabit ethernet was ridiculously slow (I didn't bother to do it again  \nand time it).\n\nLooking at the git native protocol or git-over-ssh, then. We can  \ntunnel these if need be, so forget about the accessibility issue.  \nAuthentication becomes a problem here; the git daemon doesn't have  \nenough security controls to grant groupA r/w access to repoX, read  \naccess to repoY and no access to anything else. Is SSH a solution for  \nmy problems? Can we provide shared repositories to certain groups of  \npeople, while limiting access to others and is this going to require  \naccounts for each developer on the server (the git-shell seems to not  \nbe flexible enough for this)?\n\nAm I thinking about this conceptually wrong or am I missing something  \nsimple?\n\nThanks,\nTom\n\n--\nTom Lanyon\n"},{"id":"91700","messageId":"20080926153903.GC17584@spearce.org","threadId":"15683","inReplyTo":"8B29890D-C03B-4ECE-9BEF-0A8E8EF7233E@netspot.com.au","subject":"Re: Internal, corporate, shared hosting solutions","fromName":"Shawn O. Pearce","fromEmail":"spearce@spearce.org","sentAt":"2008-09-26T15:39:03Z","receivedAt":"2008-09-26T15:39:03Z","isPatch":false,"sender":{"key":"spearce@spearce.org","avatar":"https://avatars.githubusercontent.com/u/34844?v=4"},"body":"Tom Lanyon <tom@netspot.com.au> wrote:\n> We have some pretty basic requirements:\n> \t- authentication and authorisation; some repos are only readable/ \n> writable by specific people\n> \t- accessible; many dev servers are on private subnets, ideally we need \n> to be able to proxy git access\n> \t- not too much messing with unix user accounts on the central git host \n> (because they're tied to LDAP, for example)\n\nUse git over ssh, but use gitosis on the server side:\n\n  http://scie.nti.st/2007/11/14/hosting-git-repositories-the-easy-and-secure-way\n\nHave each developer supply their own SSH public key, install it\ninto the gitosis database, and they can only read/write repos\nthey have access to in the admin database.\n\nSecure, fast, yea, you can actually pick two out of two.  :)\n\n-- \nShawn.\n"},{"id":"91710","messageId":"200809262017.15916.johan@herland.net","threadId":"15683","inReplyTo":"8B29890D-C03B-4ECE-9BEF-0A8E8EF7233E@netspot.com.au","subject":"Re: Internal, corporate, shared hosting solutions","fromName":"Johan Herland","fromEmail":"johan@herland.net","sentAt":"2008-09-26T18:17:15Z","receivedAt":"2008-09-26T18:17:15Z","isPatch":false,"sender":{"key":"johan@herland.net","avatar":"https://avatars.githubusercontent.com/u/547031?v=4"},"body":"On Friday 26 September 2008, Tom Lanyon wrote:\n> Hi list,\n>\n> I'm struggling. There's been a recent adoption of git here by our\n> development staff, which is great. However, from an administrative\n> point of view, I'm having trouble finding a solution to provide some\n> kind of easy, shared, secure and accessible hosting solution to our\n> developers.\n>\n> [...]\n\nI'm pretty much in the exact same situation at $dayjob, and I'm \nresearching some alternatives as well. So far there seems to be a \ncouple of options:\n\n1. Gitosis [1]. This is a fairly thin layer of Python scripts running as \na non-privileged \"git\" user on the server. All users authenticate by \nregistering their SSH key with Gitosis, and then access repos using \nthis one \"git\" user over SSH. Further access control (i.e. read/write \naccess to each repo) is done by Gitosis itself, and administered by \ncloning a gitosis-admin repo, changing some configuration files and \npushing the result back to the server.\n\n2. Gitorious [2]. Don't confuse this with the repo hosting service at \ngitorious.org. You can clone the software that runs gitorious.org and \nset it up on your own server. This is a much more heavy-weight \nRuby-on-Rails application that provides a nice web interface for \npublishing and interacting with repositories. However, it is based on \nthe same underlying principle of registering your SSH-keys with \nGitorious, and running everything as a non-privileged \"git\" user.\n\n3. repo.or.cz. I don't know much about how this work, and if it's easily \ndeployed on an in-house server. However, the repo.or.cz admin (Petr \nBaudis, CCed) is active on this list, and can probably fill in the \ndetails.\n\n\nFeel free to keep me updated on your progress.\n\n\nHave fun! :)\n\n...Johan\n\n\n[1]: Gitosis: \nhttp://scie.nti.st/2007/11/14/hosting-git-repositories-the-easy-and-secure-way\nGet it at http://eagain.net/gitweb/?p=gitosis.git;a=summary\n\n[2]: Gitorious: http://gitorious.org/\nGet it at http://gitorious.org/projects/gitorious\n\n-- \nJohan Herland, <johan@herland.net>\nwww.herland.net\n"}]}