{"thread":{"id":"16457","subject":"How to hide a git repository?","startedAt":"2008-11-25T00:32:58Z","lastAt":"2008-11-25T21:46:10Z","messageCount":13,"participants":["Gary Yang","Heikki Orsila","Bruno Cesar Ribas","Nicolas Morey-Chaisemartin","Daniel Barkalow","Thomas Koch","Jakub Narebski","Junio C Hamano"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"96448","messageId":"962463.96236.qm@web37905.mail.mud.yahoo.com","threadId":"16457","inReplyTo":null,"subject":"How to hide a git repository?","fromName":"Gary Yang","fromEmail":"garyyang6@yahoo.com","sentAt":"2008-11-25T00:32:58Z","receivedAt":"2008-11-25T00:32:58Z","isPatch":false,"sender":{"key":"garyyang6@yahoo.com","avatar":null},"body":"\nWe have two repositories, one is /pub/git/dev/linux/kernel, another is /pub/git/pub/linux/kernel. The /pub/git/pub/linux/kernel is open to public for people to download released code. /pub/git/dev/linux/kernel is used for our development. We would like to hide /pub/git/dev/linux/kernel from public. How to do it?\n\nWhy we want to hide /pub/git/dev/linux/kernel from public?\nWe work on our development at /pub/git/dev/linux/kernel. We push our released code to /pub/git/pub/linux/kernel from /pub/git/dev/linux/kernel once we completed our development.  We do not want people to download code from /pub/git/dev/linux/kernel since it is not stable.  \n\n\n\n\n\n\n      \n"},{"id":"96452","messageId":"20081125003758.GA6115@zakalwe.fi","threadId":"16457","inReplyTo":"962463.96236.qm@web37905.mail.mud.yahoo.com","subject":"Re: How to hide a git repository?","fromName":"Heikki Orsila","fromEmail":"shdl@zakalwe.fi","sentAt":"2008-11-25T00:37:58Z","receivedAt":"2008-11-25T00:37:58Z","isPatch":false,"sender":{"key":"shdl@zakalwe.fi","avatar":null},"body":"On Mon, Nov 24, 2008 at 04:32:58PM -0800, Gary Yang wrote:\n> \n> We have two repositories, one is /pub/git/dev/linux/kernel, another \n> is /pub/git/pub/linux/kernel. The /pub/git/pub/linux/kernel is open to \n> public for people to download released code. /pub/git/dev/linux/kernel \n> is used for our development. We would like to hide \n> /pub/git/dev/linux/kernel from public. How to do it?\n\nTell \"git daemon\" only to publish /pub/git/pub/linux/kernel.\n\n-- \nHeikki Orsila\nheikki.orsila@iki.fi\nhttp://www.iki.fi/shd\n"},{"id":"96453","messageId":"940723.36955.qm@web37906.mail.mud.yahoo.com","threadId":"16457","inReplyTo":"20081125003758.GA6115@zakalwe.fi","subject":"Re: How to hide a git repository?","fromName":"Gary Yang","fromEmail":"garyyang6@yahoo.com","sentAt":"2008-11-25T01:40:22Z","receivedAt":"2008-11-25T01:40:22Z","isPatch":false,"sender":{"key":"garyyang6@yahoo.com","avatar":null},"body":"How to tell \"git daemon\" only to publish /pub/git/pub/linux/kernel ?\n\n\n--- On Mon, 11/24/08, Heikki Orsila <shdl@zakalwe.fi> wrote:\n\n> From: Heikki Orsila <shdl@zakalwe.fi>\n> Subject: Re: How to hide a git repository?\n> To: \"Gary Yang\" <garyyang6@yahoo.com>\n> Cc: git@vger.kernel.org\n> Date: Monday, November 24, 2008, 4:37 PM\n> On Mon, Nov 24, 2008 at 04:32:58PM -0800, Gary Yang wrote:\n> > \n> > We have two repositories, one is\n> /pub/git/dev/linux/kernel, another \n> > is /pub/git/pub/linux/kernel. The\n> /pub/git/pub/linux/kernel is open to \n> > public for people to download released code.\n> /pub/git/dev/linux/kernel \n> > is used for our development. We would like to hide \n> > /pub/git/dev/linux/kernel from public. How to do it?\n> \n> Tell \"git daemon\" only to publish\n> /pub/git/pub/linux/kernel.\n> \n> -- \n> Heikki Orsila\n> heikki.orsila@iki.fi\n> http://www.iki.fi/shd\n> --\n> To unsubscribe from this list: send the line\n> \"unsubscribe git\" in\n> the body of a message to majordomo@vger.kernel.org\n> More majordomo info at \n> http://vger.kernel.org/majordomo-info.html\n\n\n      \n"},{"id":"96454","messageId":"900638.56188.qm@web37904.mail.mud.yahoo.com","threadId":"16457","inReplyTo":"962463.96236.qm@web37905.mail.mud.yahoo.com","subject":"Re: How to hide a git repository?","fromName":"Gary Yang","fromEmail":"garyyang6@yahoo.com","sentAt":"2008-11-25T02:16:21Z","receivedAt":"2008-11-25T02:16:21Z","isPatch":false,"sender":{"key":"garyyang6@yahoo.com","avatar":null},"body":"Do I have to create two git servers? One is for public to download the released code. For example: gitpub.mycompany.com:/pub/linux/kernel. gitpub.mycompany.com is accessible to public. Another is for internal development. For example: gitdev.mycompany.com:/dev/linux/kernel. gitdev.mycompany.com is only accessible to our development team. I push code from gitdev.mycompany.com:/dev/linux/kernel to gitpub.mycompany.com:/publinux/kernel once we completed our development. Is this the only way to do it? \n\n\n--- On Mon, 11/24/08, Gary Yang <garyyang6@yahoo.com> wrote:\n\n> From: Gary Yang <garyyang6@yahoo.com>\n> Subject: How to hide a git repository?\n> To: git@vger.kernel.org\n> Date: Monday, November 24, 2008, 4:32 PM\n> We have two repositories, one is /pub/git/dev/linux/kernel,\n> another is /pub/git/pub/linux/kernel. The\n> /pub/git/pub/linux/kernel is open to public for people to\n> download released code. /pub/git/dev/linux/kernel is used\n> for our development. We would like to hide\n> /pub/git/dev/linux/kernel from public. How to do it?\n> \n> Why we want to hide /pub/git/dev/linux/kernel from public?\n> We work on our development at /pub/git/dev/linux/kernel. We\n> push our released code to /pub/git/pub/linux/kernel from\n> /pub/git/dev/linux/kernel once we completed our development.\n>  We do not want people to download code from\n> /pub/git/dev/linux/kernel since it is not stable.  \n> \n> \n> \n> \n> \n> \n>       \n> --\n> To unsubscribe from this list: send the line\n> \"unsubscribe git\" in\n> the body of a message to majordomo@vger.kernel.org\n> More majordomo info at \n> http://vger.kernel.org/majordomo-info.html\n\n\n      \n"},{"id":"96455","messageId":"20081125035858.GB25284@c3sl.ufpr.br","threadId":"16457","inReplyTo":"940723.36955.qm@web37906.mail.mud.yahoo.com","subject":"Re: How to hide a git repository?","fromName":"Bruno Cesar Ribas","fromEmail":"ribas@c3sl.ufpr.br","sentAt":"2008-11-25T03:58:58Z","receivedAt":"2008-11-25T03:58:58Z","isPatch":false,"sender":{"key":"ribas@c3sl.ufpr.br","avatar":null},"body":"On Mon, Nov 24, 2008 at 05:40:22PM -0800, Gary Yang wrote:\n> How to tell \"git daemon\" only to publish /pub/git/pub/linux/kernel ?\n\n$ man git-daemon\n\n<snip>\nIt verifies that the directory has the magic file\n       \"git-daemon-export-ok\", and it will refuse to export any git directory\n       that hasn´t explicitly been marked for export this way (unless the\n       --export-all parameter is specified). If you pass some directory paths\n       as git-daemon arguments, you can further restrict the offers to a\n       whitelist comprising of those.\n</snip>\n\nHope this helps\n\n> \n> \n> --- On Mon, 11/24/08, Heikki Orsila <shdl@zakalwe.fi> wrote:\n> \n> > From: Heikki Orsila <shdl@zakalwe.fi>\n> > Subject: Re: How to hide a git repository?\n> > To: \"Gary Yang\" <garyyang6@yahoo.com>\n> > Cc: git@vger.kernel.org\n> > Date: Monday, November 24, 2008, 4:37 PM\n> > On Mon, Nov 24, 2008 at 04:32:58PM -0800, Gary Yang wrote:\n> > > \n> > > We have two repositories, one is\n> > /pub/git/dev/linux/kernel, another \n> > > is /pub/git/pub/linux/kernel. The\n> > /pub/git/pub/linux/kernel is open to \n> > > public for people to download released code.\n> > /pub/git/dev/linux/kernel \n> > > is used for our development. We would like to hide \n> > > /pub/git/dev/linux/kernel from public. How to do it?\n> > \n> > Tell \"git daemon\" only to publish\n> > /pub/git/pub/linux/kernel.\n> > \n> > -- \n> > Heikki Orsila\n> > heikki.orsila@iki.fi\n> > http://www.iki.fi/shd\n> > --\n> > To unsubscribe from this list: send the line\n> > \"unsubscribe git\" in\n> > the body of a message to majordomo@vger.kernel.org\n> > More majordomo info at \n> > http://vger.kernel.org/majordomo-info.html\n> \n> \n>       \n> --\n> To unsubscribe from this list: send the line \"unsubscribe git\" in\n> the body of a message to majordomo@vger.kernel.org\n> More majordomo info at  http://vger.kernel.org/majordomo-info.html\n\n-- \nBruno Ribas - ribas@c3sl.ufpr.br\nhttp://www.inf.ufpr.br/ribas\nC3SL: http://www.c3sl.ufpr.br\n"},{"id":"96458","messageId":"492B97F0.5000409@morey-chaisemartin.com","threadId":"16457","inReplyTo":"900638.56188.qm@web37904.mail.mud.yahoo.com","subject":"Re: How to hide a git repository?","fromName":"Nicolas Morey-Chaisemartin","fromEmail":"devel@morey-chaisemartin.com","sentAt":"2008-11-25T06:15:12Z","receivedAt":"2008-11-25T06:15:12Z","isPatch":false,"sender":{"key":"devel@morey-chaisemartin.com","avatar":null},"body":"I guess you could export the public one through git daemon and/or your\nweb server, and access your private tree through SSH.\nThis way you ensure only authentificated people will be able to clone\nyour private tree.\n\n---\nNicolas Morey-Chaisemartin\n\n\n\nGary Yang a écrit :\n> Do I have to create two git servers? One is for public to download the released code. For example: gitpub.mycompany.com:/pub/linux/kernel. gitpub.mycompany.com is accessible to public. Another is for internal development. For example: gitdev.mycompany.com:/dev/linux/kernel. gitdev.mycompany.com is only accessible to our development team. I push code from gitdev.mycompany.com:/dev/linux/kernel to gitpub.mycompany.com:/publinux/kernel once we completed our development. Is this the only way to do it? \n>\n>\n> --- On Mon, 11/24/08, Gary Yang <garyyang6@yahoo.com> wrote:\n>\n>   \n>> From: Gary Yang <garyyang6@yahoo.com>\n>> Subject: How to hide a git repository?\n>> To: git@vger.kernel.org\n>> Date: Monday, November 24, 2008, 4:32 PM\n>> We have two repositories, one is /pub/git/dev/linux/kernel,\n>> another is /pub/git/pub/linux/kernel. The\n>> /pub/git/pub/linux/kernel is open to public for people to\n>> download released code. /pub/git/dev/linux/kernel is used\n>> for our development. We would like to hide\n>> /pub/git/dev/linux/kernel from public. How to do it?\n>>\n>> Why we want to hide /pub/git/dev/linux/kernel from public?\n>> We work on our development at /pub/git/dev/linux/kernel. We\n>> push our released code to /pub/git/pub/linux/kernel from\n>> /pub/git/dev/linux/kernel once we completed our development.\n>>  We do not want people to download code from\n>> /pub/git/dev/linux/kernel since it is not stable.  \n>>\n>>\n>>\n>>\n>>\n>>\n>>       \n>> --\n>> To unsubscribe from this list: send the line\n>> \"unsubscribe git\" in\n>> the body of a message to majordomo@vger.kernel.org\n>> More majordomo info at \n>> http://vger.kernel.org/majordomo-info.html\n>>     \n>\n>\n>       \n> --\n> To unsubscribe from this list: send the line \"unsubscribe git\" in\n> the body of a message to majordomo@vger.kernel.org\n> More majordomo info at  http://vger.kernel.org/majordomo-info.html\n>\n>\n>   \n"},{"id":"96485","messageId":"alpine.LNX.1.00.0811251327480.19665@iabervon.org","threadId":"16457","inReplyTo":"900638.56188.qm@web37904.mail.mud.yahoo.com","subject":"Re: How to hide a git repository?","fromName":"Daniel Barkalow","fromEmail":"barkalow@iabervon.org","sentAt":"2008-11-25T18:38:02Z","receivedAt":"2008-11-25T18:38:02Z","isPatch":false,"sender":{"key":"barkalow@iabervon.org","avatar":"https://avatars.githubusercontent.com/u/55364219?v=4"},"body":"On Mon, 24 Nov 2008, Gary Yang wrote:\n\n> Do I have to create two git servers? One is for public to download the \n> released code. For example: gitpub.mycompany.com:/pub/linux/kernel.\n\nThe public can't generally use this URL, because it's an ssh URL, and they \nwon't be able to connect with ssh. They can only really use \ngit://gitpub.mycompany.com/pub/linux/kernel or something similar.\n\nThe normal pattern is to have R/W access with ssh and anonymous read \naccess via git://...; you can then have multiple repositories on the same \nhost, with the git server only serving the public one. All of them will be \naccessible to the ssh methods (restricted by the user's UNIX permissions \non the files in those directories).\n\n\t-Daniel\n*This .sig left intentionally blank*\n"},{"id":"96486","messageId":"200811252001.37259.thomas@koch.ro","threadId":"16457","inReplyTo":"alpine.LNX.1.00.0811251327480.19665@iabervon.org","subject":"Re: How to hide a git repository?","fromName":"Thomas Koch","fromEmail":"thomas@koch.ro","sentAt":"2008-11-25T19:01:37Z","receivedAt":"2008-11-25T19:01:37Z","isPatch":false,"sender":{"key":"thomas@koch.ro","avatar":null},"body":"Am Tuesday 25 November 2008 19:38:02 schrieb Daniel Barkalow:\n> On Mon, 24 Nov 2008, Gary Yang wrote:\n> > Do I have to create two git servers? One is for public to download the\n> > released code. For example: gitpub.mycompany.com:/pub/linux/kernel.\n>\n> The public can't generally use this URL, because it's an ssh URL, and they\n> won't be able to connect with ssh. They can only really use\n> git://gitpub.mycompany.com/pub/linux/kernel or something similar.\n>\n> The normal pattern is to have R/W access with ssh and anonymous read\n> access via git://...; you can then have multiple repositories on the same\n> host, with the git server only serving the public one. All of them will be\n> accessible to the ssh methods (restricted by the user's UNIX permissions\n> on the files in those directories).\n>\n> \t-Daniel\n> *This .sig left intentionally blank*\n> --\nDo you now of a way to show public repos with gitweb to the public and\nprivate repos to the staff with the same gitweb installation?\n\nBest regards,\n-- \nThomas Koch, Software Developer\nhttp://www.koch.ro\n\nYoung Media Concepts GmbH\nSonnenstr. 4\nCH-8280 Kreuzlingen\nSwitzerland\n\nTel    +41 (0)71 / 508 24 86\nFax    +41 (0)71 / 560 53 89\nMobile +49 (0)170 / 753 89 16\nWeb    www.ymc.ch\n"},{"id":"96487","messageId":"alpine.LNX.1.00.0811251402360.19665@iabervon.org","threadId":"16457","inReplyTo":"200811252001.37259.thomas@koch.ro","subject":"Re: How to hide a git repository?","fromName":"Daniel Barkalow","fromEmail":"barkalow@iabervon.org","sentAt":"2008-11-25T19:08:32Z","receivedAt":"2008-11-25T19:08:32Z","isPatch":false,"sender":{"key":"barkalow@iabervon.org","avatar":"https://avatars.githubusercontent.com/u/55364219?v=4"},"body":"On Tue, 25 Nov 2008, Thomas Koch wrote:\n\n> Do you now of a way to show public repos with gitweb to the public and\n> private repos to the staff with the same gitweb installation?\n\nI don't really know much about gitweb, but I'd expect that you can have \nthe same physical machine, the same gitweb executable, the same \napache, different virtual hosts, and different configurations for each \nvirtual host. Without having different URLs in some way, there's no way \nfor the system to cause web browsers of staff members to authenticate \nthemselves in order to reveal the private repos.\n\n\t-Daniel\n*This .sig left intentionally blank*\n"},{"id":"96489","messageId":"m3skpfk1mp.fsf@localhost.localdomain","threadId":"16457","inReplyTo":"200811252001.37259.thomas@koch.ro","subject":"Re: How to hide a git repository?","fromName":"Jakub Narebski","fromEmail":"jnareb@gmail.com","sentAt":"2008-11-25T20:10:43Z","receivedAt":"2008-11-25T20:10:43Z","isPatch":false,"sender":{"key":"jnareb@gmail.com","avatar":"https://avatars.githubusercontent.com/u/2706?v=4"},"body":"Thomas Koch <thomas@koch.ro> writes:\n> Am Tuesday 25 November 2008 19:38:02 schrieb Daniel Barkalow:\n> > On Mon, 24 Nov 2008, Gary Yang wrote:\n\n> > > Do I have to create two git servers? One is for public to download the\n> > > released code. For example: gitpub.mycompany.com:/pub/linux/kernel.\n> >\n> > The public can't generally use this URL, because it's an ssh URL, and they\n> > won't be able to connect with ssh. They can only really use\n> > git://gitpub.mycompany.com/pub/linux/kernel or something similar.\n> >\n> > The normal pattern is to have R/W access with ssh and anonymous read\n> > access via git://...; you can then have multiple repositories on the same\n> > host, with the git server only serving the public one. All of them will be\n> > accessible to the ssh methods (restricted by the user's UNIX permissions\n> > on the files in those directories).\n\nTo control access via SSH protocol (which can be used both for\nfetching and for pushing), you can either configure accounts and\nuser/groups permissions on repository directories, or you can use\nexternal tool like ssh_acl or Gitosis.\n\nTo control access via HTTP you can employ authorization and\nauthentication from your web server; for push this would be matter of\nsetting up WebDAV.\n\nTo control access via anonymous git:// protocol, you can use whitelist\nand blacklist mechanism built in git-daemon; by default only\nrepositories with git-daemon-export-ok in them (in .git) are exported,\nif I understand correctly.\n\n\nAdditionally, if protocol is authenticated you can use hooks mechanism\nlike example contrib/hooks/update-paranoid to restrict access (and\nwith finer granularity too).\n\n> Do you now of a way to show public repos with gitweb to the public and\n> private repos to the staff with the same gitweb installation?\n\nYou can quite simply restrict access to some directories/repositories,\nor the fact that they are listed in list of all projects for _all_\nclients quite easily (see description of GITWEB_EXPORT_OK in\ngitweb/README and gitweb/INSTALL).\n\nIf you have something more fancy, check out newest gitweb and take a\nlook at gitweb/INSTALL: you can now, thanks to commit dd7f5f1 by\nAlexander Gavrilov, see\n  http://permalink.gmane.org/gmane.comp.version-control.git/99962\n\nHTH\n-- \nJakub Narebski\nPoland\nShadeHawk on #git\n"},{"id":"96493","messageId":"7vprkjjz79.fsf@gitster.siamese.dyndns.org","threadId":"16457","inReplyTo":"m3skpfk1mp.fsf@localhost.localdomain","subject":"Re: How to hide a git repository?","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2008-11-25T21:03:06Z","receivedAt":"2008-11-25T21:03:06Z","isPatch":false,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Jakub Narebski <jnareb@gmail.com> writes:\n\n> If you have something more fancy, check out newest gitweb and take a\n> look at gitweb/INSTALL: you can now, thanks to commit dd7f5f1 by\n> Alexander Gavrilov, see\n>   http://permalink.gmane.org/gmane.comp.version-control.git/99962\n\nSomehow I had an impression that you weren't enthused about that patch.\n"},{"id":"96495","messageId":"200811252219.38530.jnareb@gmail.com","threadId":"16457","inReplyTo":"7vprkjjz79.fsf@gitster.siamese.dyndns.org","subject":"Re: How to hide a git repository?","fromName":"Jakub Narebski","fromEmail":"jnareb@gmail.com","sentAt":"2008-11-25T21:19:35Z","receivedAt":"2008-11-25T21:19:35Z","isPatch":false,"sender":{"key":"jnareb@gmail.com","avatar":"https://avatars.githubusercontent.com/u/2706?v=4"},"body":"On Tue, 25 Nov 2008, Junio C Hamano wrote:\n> Jakub Narebski <jnareb@gmail.com> writes:\n> \n> > If you have something more fancy, check out newest gitweb and take a\n> > look at gitweb/INSTALL: you can now, thanks to commit dd7f5f1 by\n> > Alexander Gavrilov, see\n> >   http://permalink.gmane.org/gmane.comp.version-control.git/99962\n> \n> Somehow I had an impression that you weren't enthused about that\n> patch. \n\nI didn't like original version, but quite like the one that got in \ngit.git: very flexible and nonintrusive. I have acked it, haven't I?\n-- \nJakub Narebski\nPoland\n"},{"id":"96497","messageId":"7vljv7jx7h.fsf@gitster.siamese.dyndns.org","threadId":"16457","inReplyTo":"200811252219.38530.jnareb@gmail.com","subject":"Re: How to hide a git repository?","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2008-11-25T21:46:10Z","receivedAt":"2008-11-25T21:46:10Z","isPatch":false,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Jakub Narebski <jnareb@gmail.com> writes:\n\n> On Tue, 25 Nov 2008, Junio C Hamano wrote:\n>> Jakub Narebski <jnareb@gmail.com> writes:\n>> \n>> > If you have something more fancy, check out newest gitweb and take a\n>> > look at gitweb/INSTALL: you can now, thanks to commit dd7f5f1 by\n>> > Alexander Gavrilov, see\n>> >   http://permalink.gmane.org/gmane.comp.version-control.git/99962\n>> \n>> Somehow I had an impression that you weren't enthused about that\n>> patch. \n>\n> I didn't like original version, but quite like the one that got in \n> git.git: very flexible and nonintrusive. I have acked it, haven't I?\n\nYeah, indeed you did.  Thanks.\n"}]}