{"thread":{"id":"21103","subject":"Git push over git protocol for corporate environment","startedAt":"2009-09-30T23:13:23Z","lastAt":"2009-10-04T16:26:27Z","messageCount":13,"participants":["Eugene Sajine","David Brown","Jakub Narebski","Michael Poole","Shawn O. Pearce","Marius Storm-Olsen","Ismael Luceno","Matthieu Moy"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"124054","messageId":"76c5b8580909301613m283c4bfdne8de449ca0fd0987@mail.gmail.com","threadId":"21103","inReplyTo":null,"subject":"Git push over git protocol for corporate environment","fromName":"Eugene Sajine","fromEmail":"euguess@gmail.com","sentAt":"2009-09-30T23:13:23Z","receivedAt":"2009-09-30T23:13:23Z","isPatch":false,"sender":{"key":"euguess@gmail.com","avatar":null},"body":"First of all thanks to everybody for an amazing tool! I’m a big fan of\nit, so I’m trying to get rid of CVS in my company and migrate to Git.\n\nWe are working in, I would say, standard corporate environment, so all\ndevelopment is in internal network. We have multiple offices in\ndifferent countries. Currently as I said we are using CVS (don’t\nask!;))\n\nMy problem is that I need the simplest, easiest and fastest solution\nfrom setup and maintenance point of view in a situation when we have a\nhuge CVS repo with hundreds of modules (projects) in it. My current\nunderstanding is that we are going to pull out project by project from\nCVS and create corresponding git repos.\nSo, this brings us to hundreds of git repos and over 200 hundred\ncommitters. In this circumstances we don’t want to manage each repo\nseparately as well as we don’t want to manage each person write access\nrights to each repo.\nAs I understand the best solution here is git protocol (one port only\non dedicated server and no security as we are in trusted network) with\nread and write access configured for all repos on a dedicated server.\nWhat do you think I should do? How to enable push over git protocol?\n\nI would appreciate any recommendation about such set up and any links\nto corresponding docs.\n\nThank you,\nEugene\n"},{"id":"124056","messageId":"20090930232309.GA20409@huya.quicinc.com","threadId":"21103","inReplyTo":"76c5b8580909301613m283c4bfdne8de449ca0fd0987@mail.gmail.com","subject":"Re: Git push over git protocol for corporate environment","fromName":"David Brown","fromEmail":"davidb@quicinc.com","sentAt":"2009-09-30T23:23:09Z","receivedAt":"2009-09-30T23:23:09Z","isPatch":false,"sender":{"key":"git@davidb.org","avatar":"https://gravatar.com/avatar/94c86a2938470a74c2eac5e2b69afc0871f79a660295c02219597aba8cb101c1?d=mp&s=160"},"body":"On Wed, Sep 30, 2009 at 04:13:23PM -0700, Eugene Sajine wrote:\n\n> As I understand the best solution here is git protocol (one port only\n> on dedicated server and no security as we are in trusted network) with\n> read and write access configured for all repos on a dedicated server.\n> What do you think I should do? How to enable push over git protocol?\n\nYou can pass --enable=receive-pack but it probably isn't what you\nwant.  Anybody can write anything, anywhere with that, and more\nimportantly, anybody can delete anything.\n\nWhen we started with git, we had a single machine that housed the\nrepos.  It ran a read-only git server, and people used ssh to\npush to it.  It doesn't require accounts on the machine, but you\ncan use git-shell to restrict access.  This is probably a good\nway to start out.\n\nEventually, it's possible to realize that there doesn't need to\nbe _the_ central server.  There can be several, and different\npeople in charge of different parts.  Here at least, people never\nreally adapted to this model.\n\nWe're now primarily using Gerrit, but that's a larger step from\nprocess change from CVS.\n\nDavid Brown\n"},{"id":"124057","messageId":"m3pr989eyt.fsf@localhost.localdomain","threadId":"21103","inReplyTo":"76c5b8580909301613m283c4bfdne8de449ca0fd0987@mail.gmail.com","subject":"Re: Git push over git protocol for corporate environment","fromName":"Jakub Narebski","fromEmail":"jnareb@gmail.com","sentAt":"2009-09-30T23:43:24Z","receivedAt":"2009-09-30T23:43:24Z","isPatch":false,"sender":{"key":"jnareb@gmail.com","avatar":"https://avatars.githubusercontent.com/u/2706?v=4"},"body":"Eugene Sajine <euguess@gmail.com> writes:\n\n> My problem is that I need the simplest, easiest and fastest solution\n> from setup and maintenance point of view in a situation when we have a\n> huge CVS repo with hundreds of modules (projects) in it. My current\n> understanding is that we are going to pull out project by project from\n> CVS and create corresponding git repos.\n>\n> So, this brings us to hundreds of git repos and over 200 hundred\n> committers. In this circumstances we don’t want to manage each repo\n> separately as well as we don’t want to manage each person write access\n> rights to each repo.\n>\n> As I understand the best solution here is git protocol (one port only\n> on dedicated server and no security as we are in trusted network) with\n> read and write access configured for all repos on a dedicated server.\n> What do you think I should do? How to enable push over git protocol?\n\nNo, I don't think it is a good solution, as git protocol is by design\nanonymous and unauthenticated.\n\nTo enable push via git protocol, you have to enable 'receive-pack'\nservice for git-daemon (the --enable=<service> option).\n\n> \n> I would appreciate any recommendation about such set up and any links\n> to corresponding docs.\n\nYou would probably want to use some tool to manage git repositories, \nlike\n * Gitosis (in Python, requires setuptools),\n * Gitolite (in Perl),\n * SCuMD (in Java),\nor even\n * ssh_acl\n\nI think Gitosis is most commonly used tool, see links in\nhttp://git.or.cz/gitwiki/InterfacesFrontendsAndTools and \nhttp://git.or.cz/gitwiki/BlogPosts pages on git wiki.\n\nThere are also full-fledged git hosting solutions, usually with web\ninterface to git repositories administration:\n * GitHub:FI (proprietary, non-free)\n * Gitorious (Ruby on Rails)\n * InDefero (PHP, clone of Google Code)\n * Girocco (Perl + bash, used by http://repo.or.cz)\n\n\nThere are also tools such as repo and Gerrit from Android project\n(Gerrit is a review board).\n\n\nAlso, depending on workflow used, you might not need for anyone beside\nproject maintainer to have push access to public repository;\nmaintainer would process pull requests from co-developers, from their\nper-developer forks.\n\n-- \nJakub Narebski\nPoland\nShadeHawk on #git\n"},{"id":"124058","messageId":"873a64gfa6.fsf@sanosuke.troilus.org","threadId":"21103","inReplyTo":"76c5b8580909301613m283c4bfdne8de449ca0fd0987@mail.gmail.com","subject":"Re: Git push over git protocol for corporate environment","fromName":"Michael Poole","fromEmail":"mdpoole@troilus.org","sentAt":"2009-09-30T23:54:09Z","receivedAt":"2009-09-30T23:54:09Z","isPatch":false,"sender":{"key":"mdpoole@troilus.org","avatar":null},"body":"Eugene Sajine writes:\n\n[snip]\n> My problem is that I need the simplest, easiest and fastest solution\n> from setup and maintenance point of view in a situation when we have a\n> huge CVS repo with hundreds of modules (projects) in it. My current\n> understanding is that we are going to pull out project by project from\n> CVS and create corresponding git repos.\n> So, this brings us to hundreds of git repos and over 200 hundred\n> committers. In this circumstances we don’t want to manage each repo\n> separately as well as we don’t want to manage each person write access\n> rights to each repo.\n> As I understand the best solution here is git protocol (one port only\n> on dedicated server and no security as we are in trusted network) with\n> read and write access configured for all repos on a dedicated server.\n> What do you think I should do? How to enable push over git protocol?\n\nHow do you manage permissions now?  How would you like to manage\nrights under the new system?\n\nI am a git amateur, but I would suggest using git+ssh (git over ssh)\nand use group or ACL permissions based on the SSH user account.  The\nstandard git-daemon does not provide authentication or authorization,\nso you would have to roll your own -- but git+ssh lets you leverage\nthe operating system's built-in access controls.\n\nFor example, some developers might belong to group A, and others\ndevelopers belong to group B.  With standard Unix permissions, you\ncould grant global read but only group-A commit rights to any number\nof permissions (by appropriate use of git init --shared).\n\nI have not tried using POSIX ACLs to grant more complicated access\nrights for git repositories, but setting default ACL entries on the\ndirectory before running \"git init\" *should* give good results.\n\n(Others have mentioned Gerrit.  I use that at work, and my only major\nwish is that it had per-branch rather than per-project access\ncontrols.  It is a vast improvement over the Subversion system we had\nbefore.)\n\nMichael Poole\n"},{"id":"124059","messageId":"20091001000620.GN14660@spearce.org","threadId":"21103","inReplyTo":"873a64gfa6.fsf@sanosuke.troilus.org","subject":"Re: Git push over git protocol for corporate environment","fromName":"Shawn O. Pearce","fromEmail":"spearce@spearce.org","sentAt":"2009-10-01T00:06:20Z","receivedAt":"2009-10-01T00:06:20Z","isPatch":false,"sender":{"key":"spearce@spearce.org","avatar":"https://avatars.githubusercontent.com/u/34844?v=4"},"body":"Michael Poole <mdpoole@troilus.org> wrote:\n> (Others have mentioned Gerrit.  I use that at work, and my only major\n> wish is that it had per-branch rather than per-project access\n> controls.  It is a vast improvement over the Subversion system we had\n> before.)\n\nYou'll be happy to hear _everyone_ is demanding per-branch controls,\nI have to do it before the end of the year, maybe even before the\nend of the month...\n\n-- \nShawn.\n"},{"id":"124065","messageId":"4AC44C55.6080807@gmail.com","threadId":"21103","inReplyTo":"20091001000620.GN14660@spearce.org","subject":"Re: Git push over git protocol for corporate environment","fromName":"Marius Storm-Olsen","fromEmail":"mstormo@gmail.com","sentAt":"2009-10-01T06:29:41Z","receivedAt":"2009-10-01T06:29:41Z","isPatch":false,"sender":{"key":"mstormo@gmail.com","avatar":"https://avatars.githubusercontent.com/u/1500?v=4"},"body":"Shawn O. Pearce said the following on 01.10.2009 02:06:\n> Michael Poole <mdpoole@troilus.org> wrote:\n>> (Others have mentioned Gerrit.  I use that at work, and my only\n>> major wish is that it had per-branch rather than per-project\n>> access controls.  It is a vast improvement over the Subversion\n>> system we had before.)\n> \n> You'll be happy to hear _everyone_ is demanding per-branch\n> controls, I have to do it before the end of the year, maybe even\n> before the end of the month...\n\nUgh, any pointers on this one? Does this mean that you're planning to \nadd this sort of control in git itself, or just some way to facilitate \nthe setting of owner/group on individual ref files? What about packed \nrefs?\n\n--\n.marius\n"},{"id":"124095","messageId":"20091001180628.GQ14660@spearce.org","threadId":"21103","inReplyTo":"4AC44C55.6080807@gmail.com","subject":"Re: Git push over git protocol for corporate environment","fromName":"Shawn O. Pearce","fromEmail":"spearce@spearce.org","sentAt":"2009-10-01T18:06:28Z","receivedAt":"2009-10-01T18:06:28Z","isPatch":false,"sender":{"key":"spearce@spearce.org","avatar":"https://avatars.githubusercontent.com/u/34844?v=4"},"body":"Marius Storm-Olsen <mstormo@gmail.com> wrote:\n> Shawn O. Pearce said the following on 01.10.2009 02:06:\n>> Michael Poole <mdpoole@troilus.org> wrote:\n>>> (Others have mentioned Gerrit.  I use that at work, and my only\n>>> major wish is that it had per-branch rather than per-project\n>>> access controls.  It is a vast improvement over the Subversion\n>>> system we had before.)\n>>\n>> You'll be happy to hear _everyone_ is demanding per-branch\n>> controls, I have to do it before the end of the year, maybe even\n>> before the end of the month...\n>\n> Ugh, any pointers on this one? Does this mean that you're planning to  \n> add this sort of control in git itself, or just some way to facilitate  \n> the setting of owner/group on individual ref files? What about packed  \n> refs?\n\nI guess you don't know how Gerrit Code Review works, or missed that\nI was talking about Gerrit and not git.\n\nGerrit behaves like Gitosis, it owns the repositories under its care,\nand (in general) nobody else is allowed to read or write to them\nexcept the Gerrit daemon process.  That process is running JGit,\nnot git.git, which means I have full control over the entire code\nthat serves that repository.\n\nWe already have write level control to branches in that JGit has\nper-ref hook support similar to what the update hook provides in git.\nIt doesn't actually use the update hook, its an interface API the\nserver implements and pushes down into the JGit library, and it has\nmore control over the response issued to the client, but we get the\nsame result.  I'm just missing a UI that allows an administrator to\nconfigure that implementation's decision making on a per-ref basis.\n\nWe don't yet have read level control to read branches, but this\nis fairly trivial to implement.  I just need an interface API\nthat can filter the refs before we advertise them to the client.\nGiven my expand refs protocal extension that I started working on\n(but have not yet finished) I'd need something like that in JGit\nanyway just to implement the expand refs behavior.  Teaching it to\nfurther filter refs by who can read what is then trivial.\n\n-- \nShawn.\n"},{"id":"124133","messageId":"76c5b8580910020741p2024f6c0w70be53338924e7e8@mail.gmail.com","threadId":"21103","inReplyTo":"00163623ac5d75929b0474e66b96@google.com","subject":"Re: Re: Git push over git protocol for corporate environment","fromName":"Eugene Sajine","fromEmail":"euguess@gmail.com","sentAt":"2009-10-02T14:41:59Z","receivedAt":"2009-10-02T14:41:59Z","isPatch":false,"sender":{"key":"euguess@gmail.com","avatar":null},"body":"I'm sorry if it will be a dup again... My first email got stuck or\ndeleted by server, although i didn't use any html...\n\nThanks to everybody for prompt answers!\n\nThere is one thing I’m still missing though. Do I understand correctly\nthat if a person has an ssh access (account) to the host in internal\nnetwork, then this won’t be enough for him to be able to push to the\nrepo? Should we still go through the hassle of managing the ssh keys\nfor each particular user who is supposed to have push access?\n\nI believe the answer is yes and that's why I'm leaning towards pulls\nand pushes over git protocol. There is no solution yet which would be\nas effective and simple to maintain. Using git protocol will not add\nsecurity, but it won't be worse than existing CVS or any other\ncentralized version control security model. As soon as security comes\ninto play, then we will need some other solution, but currently i\ndidn't see anything that would be easy to sell to the company.\n\nGithub is cool, but FI is way too expensive and very hard to sell.\n\nGitorious is even better!! for corporate use, i think, because of its\nteam oriented approach, but... man... I would kill for java\nimplementation or anything as simple as that!! As i see It is\nimpossible to install in network without internet access, and the\namount of dependencies which you have install/pre-install is enormous.\nI read somewhere ruby on rails is fun to develop with, but is a\nnightmare to deploy and maintain, and it seems to be true. Come on,\nguys!! Look at the Hudson CI - one war file containing everything you\nneed, application starts from command line \"java -jar hudson.war\" and\nruns on any port you specify. Time to start from download to having\nfirst build is less the 10 min!!! If there are gitorious guys -\nplease, think about it and don't forget to share the profit;)!\n\nI think Cgit can be something competitive - although i failed to run\nit yet, having some issues with build...and as all other web based\nstuff, you should implement something in order to create and set up\nbare repos on the server automatically (even probably edit the config\nfile via script) to avoid a mess and to avoid one guy spending his\ntime adding and configuring repos... Probably we will and up using\ngitweb as it at least knows to scan a folder for git repos...although\nit also gives me troubles installing... both with cgit and gitweb are\nconducted under cygwin, so probably this is the real problem with\nthem;)\n\nI think that this is what is missing right now in order for git to get\nrocket start and spread inside companies: secure and easy to maintain\nmainline hosting.\n\nProbably my lack of experience with git causes these thoughts - so,\nwhile i will continue to work on it, i would really appreciate any\nadvice, especially about experience using git not for open source and\nnot in 3 person's team.\n\nThanks a lot,\nEugene\n"},{"id":"124134","messageId":"20091002144727.GZ14660@spearce.org","threadId":"21103","inReplyTo":"76c5b8580910020741p2024f6c0w70be53338924e7e8@mail.gmail.com","subject":"Re: Re: Git push over git protocol for corporate environment","fromName":"Shawn O. Pearce","fromEmail":"spearce@spearce.org","sentAt":"2009-10-02T14:47:27Z","receivedAt":"2009-10-02T14:47:27Z","isPatch":false,"sender":{"key":"spearce@spearce.org","avatar":"https://avatars.githubusercontent.com/u/34844?v=4"},"body":"Eugene Sajine <euguess@gmail.com> wrote:\n> Gitorious is even better!! for corporate use, i think, because of its\n> team oriented approach, but... man... I would kill for java\n> implementation or anything as simple as that!!\n\nIf you want a Java based server, look at either:\n\n* SCuMD               http://github.com/gaffo/scumd\n* Gerrit Code Review  http://code.google.com/p/gerrit/\n\nI think SCuMD might be easier to install, I don't think it depends\nupon a database or a servlet container like Gerrit does.  But both\nare a SSH+Git implementation with some access control capabilities,\nand are implemented in Java.\n\nI don't think either is (yet) as easy to install as Hudson CI.\nBoth projects have a much smaller team of developers behind them,\nand are still focusing on basic functionality rather than ease of\nnew system setup.\n\n-- \nShawn.\n"},{"id":"124137","messageId":"76c5b8580910020858t16804f5cg96ebb067e3a69e82@mail.gmail.com","threadId":"21103","inReplyTo":"20091002144727.GZ14660@spearce.org","subject":"Re: Re: Git push over git protocol for corporate environment","fromName":"Eugene Sajine","fromEmail":"euguess@gmail.com","sentAt":"2009-10-02T15:58:59Z","receivedAt":"2009-10-02T15:58:59Z","isPatch":false,"sender":{"key":"euguess@gmail.com","avatar":null},"body":"Thanks Shawn!\n\nI saw info about Scumd and Gerrit in previous emails, but\nunfortunately haven't enough time to spend with those tools yet.\nReading about Gerrit right now.\n\n\nOn Fri, Oct 2, 2009 at 10:47 AM, Shawn O. Pearce <spearce@spearce.org> wrote:\n> Eugene Sajine <euguess@gmail.com> wrote:\n>> Gitorious is even better!! for corporate use, i think, because of its\n>> team oriented approach, but... man... I would kill for java\n>> implementation or anything as simple as that!!\n>\n> If you want a Java based server, look at either:\n>\n> * SCuMD               http://github.com/gaffo/scumd\n> * Gerrit Code Review  http://code.google.com/p/gerrit/\n>\n> I think SCuMD might be easier to install, I don't think it depends\n> upon a database or a servlet container like Gerrit does.  But both\n> are a SSH+Git implementation with some access control capabilities,\n> and are implemented in Java.\n>\n> I don't think either is (yet) as easy to install as Hudson CI.\n> Both projects have a much smaller team of developers behind them,\n> and are still focusing on basic functionality rather than ease of\n> new system setup.\n>\n> --\n> Shawn.\n>\n"},{"id":"124143","messageId":"4AC64C75.8090809@gmail.com","threadId":"21103","inReplyTo":"76c5b8580910020741p2024f6c0w70be53338924e7e8@mail.gmail.com","subject":"Re: Git push over git protocol for corporate environment","fromName":"Ismael Luceno","fromEmail":"ismael.luceno@gmail.com","sentAt":"2009-10-02T18:54:45Z","receivedAt":"2009-10-02T18:54:45Z","isPatch":false,"sender":{"key":"ismael.luceno@gmail.com","avatar":"https://gravatar.com/avatar/b0ee2c769d00610efaff4dc838a7d2f2bcaf253941fb5739d66b51bae47cbd5d?d=mp&s=160"},"body":"Eugene Sajine escribió:\n> I think that this is what is missing right now in order for git to get\n> rocket start and spread inside companies: secure and easy to maintain\n> mainline hosting.\n> \n\nIt looks like your problem is using cygwin. It's more complicated on a\nMS-Windows environment, and personally I think it's a _very bad idea_.\n\nGit is really easy to use in fact, you just set up the repo with:\n\n  mkdir repo.git\n  cd repo.git\n  git init --bare --shared=all\n\n--shared=all makes the repo readable to anyone, and ensures push rights\nto users under the same group as the user setting up the repo. You can\nchange the group with chmod of course.\n\nSSH access will be needed to push, unless the users can remotely mount\nthe repo via NFS or any other protocol.\n\nPulling is possible over http too, you just need to make\nhooks/post-update executable. To export via git protocol you must create\nan empty file named \"git-daemon-export-ok\".\n\nBesides setting a web repo browser and git-server there's nothing else\nspecific to git.\n\n-- \nIsmael Luceno\n\n"},{"id":"299138","messageId":"200910041725.39992.jnareb@gmail.com","threadId":"21103","inReplyTo":"00163623ac5d75929b0474e66b96@google.com","subject":"Re: Git push over git protocol for corporate environment","fromName":"Jakub Narebski","fromEmail":"jnareb@gmail.com","sentAt":"2009-10-04T15:25:39Z","receivedAt":"2009-10-04T15:25:39Z","isPatch":false,"sender":{"key":"jnareb@gmail.com","avatar":"https://avatars.githubusercontent.com/u/2706?v=4"},"body":"On Thu, 1 Oct 2009, Eugene Sajine wrote:\n\n> Thanks to everybody for prompt answers!\n\nYou are welcome!\n\n> There is one thing I'm still missing though. Do I understand correctly that  \n> if a person has an ssh access (account) to the host in internal network,  \n> then this won't be enough for him to be able to push to the repo? Should we  \n> still go through the hassle of managing the ssh keys for each particular  \n> user who is supposed to have push access?\n\nYes, it is enough to push (and fetch) via SSH protocol.\n\nNevertheless it is better to use key-based authentication, or to be more\nexact passwordless authentication, so that you are asked for ssh key\npassword (if there is one set for given key) only once when adding it\nto ssh agent (c.f. ssh-add, ssh-agent, and keychain).  Otherwise you \nwould need to give password over and over (well, I think git uses one\nor two connections for fetch / push, so it shouldn't be much of an \nissue).\n\nAlso you can have SSH key shared via networked filesystem...\n\n\nConversely, on the other hand side many git management tool require to\nsetup only single SSH account, and distinguish between users based on \nkeys they use.\n\n> \n> I believe the answer is yes and that's why I'm leaning towards pulls and  \n> pushes over git protocol. There is no solution yet which would be as  \n> effective and simple to maintain. Using git protocol will not add security,  \n> but it won't be worse than existing CVS or any other centralized version  \n> control security model. As soon as security comes into play, then we will  \n> need some other solution, but currently i didn't see anything that would be  \n> easy to sell to the company.\n\nGit protocol is anonymous and unauthenticated, so you can't (I think)\nmake any ACL with it.  CVS pserver was not secure, but CVS tunnelled over\nSSH, or used over SSH was.\n\n\nGitosis, Gitolite, SCuMD, repo are all git management tools.  \nGitHub:FI, Gitosis, Girocco (with github), InDefero are all git hosting\ntools (with web interface both for repo browsing and for administration).\nGerrit is git based review board.\n\n\n> Github is cool, but FI is way too expensive and very hard to sell.\n> \n> Gitorious is even better!! for corporate use, i think, because of its team  \n> oriented approach, but... man... I would kill for java implementation or  \n> anything as simple as that!!\n\nGitorious is roughly GitHub equivalent, as it is also git hosting\nsoftware (a web application).\n\nBoth SCuMD and (I think) Gerrit are in Java; SCuMD is SSH server and/or\ngit repository management tool in early stages of development,  Gerrit\nis multi-repo management web app and (mainly) review board.\n\n> As i see It is impossible to install in   \n> network without internet access, and the amount of dependencies which you  \n> have install/pre-install is enormous. I read somewhere ruby on rails is fun  \n> to develop with, but is a nightmare to deploy and maintain, and it seems to  \n> be true. Come on, guys!! Look at the Hudson CI - one war file containing  \n> everything you need, application starts from command line \"java -jar  \n> hudson.war\" and runs on any port you specify. Time to start from download  \n> to having first build is less the 10 min!!! If there are gitorious guys -  \n> please, think about it and don't forget to share the profit;)!\n\nI don't know what are tricks that Rubyists use to ease deployment, but\ntake a look at things such as Gems and Capistrano.\n\n> \n> I think Cgit can be something competitive - although i failed to run it  \n> yet, having some issues with build...and as all other web based stuff, you  \n> should implement something in order to create and set up bare repos on the  \n> server automatically (even probably edit the config file via script) to  \n> avoid a mess and to avoid one guy spending his time adding and configuring  \n> repos... Probably we will and up using gitweb as it at least knows to scan  \n> a folder for git repos...although it also gives me troubles installing...  \n> both with cgit and gitweb are conducted under cygwin, so probably this is  \n> the real problem with them;)\n\nBoth cgit (which is written in C) and gitweb (which is single Perl script,\nplus CSS and two images) are git web interfaces.  They do not have\nfeatures for managing repositories, nor for managing access to git \nrepositories.\n\nGirocco, which is git hosting software that http://repo.or.cz uses to\nmanage git repositories, uses (enhanced) gitweb for web interface.\n\n> \n> I think that this is what is missing right now in order for git to get  \n> rocket start and spread inside companies: secure and easy to maintain  \n> mainline hosting.\n\nParaphrasing known quote: Git development community have no plans for\nworld domination; it would be purely accidental side-effect ;-))\n\nSpread inside companies is not a goal; best possible tool for OSS\ndevelopment is.\n\n> \n> Probably all my frustration comes from lack of experience - so, while i  \n> will continue to work on it, i would really appreciate any advice,  \n> especially about experience using git not for open source and not in 3  \n> person's team.\n\nYou didn't mention trying Gitosis or Gitolite, which are I think most\ncommonly used tool for managing git repositories (well, Gitosis is \nanyway).  Gitosis is even mentioned in \"Pro Git\" book (http://progit.org).\n\nSee e.g. \"Hosting Git repositories, The Easy (and Secure) Way\"\nhttp://scie.nti.st/2007/11/14/hosting-git-repositories-the-easy-and-secure-way\n(from http://git.or.cz/gitwiki/BlogPosts)\n\n\n[cut rest of reply; please do not toppost, and remove parts of reply\nyou are not responding to].\n-- \nJakub Narebski\nPoland\n"},{"id":"298993","messageId":"vpqtyyf5dn0.fsf@bauges.imag.fr","threadId":"21103","inReplyTo":"200910041725.39992.jnareb@gmail.com","subject":"Re: Git push over git protocol for corporate environment","fromName":"Matthieu Moy","fromEmail":"matthieu.moy@grenoble-inp.fr","sentAt":"2009-10-04T16:26:27Z","receivedAt":"2009-10-04T16:26:27Z","isPatch":false,"sender":{"key":"matthieu.moy@grenoble-inp.fr","avatar":"https://gravatar.com/avatar/72c8a2705971a25dfaff23cece15130d405685845d911aedd5667ace277f3fc5?d=mp&s=160"},"body":"Jakub Narebski <jnareb@gmail.com> writes:\n\n> On Thu, 1 Oct 2009, Eugene Sajine wrote:\n>\n>> Thanks to everybody for prompt answers!\n>\n> You are welcome!\n>\n>> There is one thing I'm still missing though. Do I understand correctly that  \n>> if a person has an ssh access (account) to the host in internal network,  \n>> then this won't be enough for him to be able to push to the repo? Should we  \n>> still go through the hassle of managing the ssh keys for each particular  \n>> user who is supposed to have push access?\n>\n> Yes, it is enough to push (and fetch) via SSH protocol.\n\nTo be a bit more precise: roughly, there are two ways to manage access\nto a Git repo via SSH:\n\n* One unix user (typically called \"git\") managing the repository, and\n  eveybody connecting to the repo via ssh://git@.... Then, if you want\n  any access control within the owned repositories for this user, you\n  need a key-based authentication to be able to distinguish who's\n  connecting. This is what gitorious does.\n\n* Everyone has its own unix account, and the repository is shared (via\n  ACLs or simple group-based permissions, see git init --shared).\n  Then, each user can choose the way he prefers for authentication,\n  and if the user has an unrestricted account (i.e. can write\n  ~/.ssh/authorized_keys), then it's the job of the users to manage\n  this, not the one of the sysadmin.\n\n-- \nMatthieu Moy\nhttp://www-verimag.imag.fr/~moy/\n"}]}