{"thread":{"id":"23929","subject":"Git push from bare repo","startedAt":"2010-05-28T06:57:13Z","lastAt":"2010-05-29T11:01:57Z","messageCount":5,"participants":["Goran Mekić","Andreas Ericsson","BJ Hargrave","Gelonida"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"142486","messageId":"3197051701046e645c8ff2ae7dca872a@ns-linux.org","threadId":"23929","inReplyTo":null,"subject":"Git push from bare repo","fromName":"Goran Mekić","fromEmail":"meka@ns-linux.org","sentAt":"2010-05-28T06:57:13Z","receivedAt":"2010-05-28T06:57:13Z","isPatch":false,"sender":{"key":"meka@ns-linux.org","avatar":null},"body":"\n    I have to push from first server to second (yeah, the names are great\n\n:o) when ever someone pushes to first server. It should be done using\n\npost-receive hook, for example. The problem is that I can not specify ssh\n\nkey, and even if I could, anything but 600 perm for the key is rejected.\n\nWhat would be the best way to acomplish this? Thanx!\n\n\n\n-- \n\nFreeB(eer)S(ex)D(rugs) are the real daemons\n"},{"id":"142488","messageId":"4BFF89A5.7020802@op5.se","threadId":"23929","inReplyTo":"3197051701046e645c8ff2ae7dca872a@ns-linux.org","subject":"Re: Git push from bare repo","fromName":"Andreas Ericsson","fromEmail":"ae@op5.se","sentAt":"2010-05-28T09:15:17Z","receivedAt":"2010-05-28T09:15:17Z","isPatch":false,"sender":{"key":"ae@op5.se","avatar":"https://gravatar.com/avatar/426e89595c75a8f5252dd0c989e5fabe5bcac616e68557427ad9aef6b0ca342a?d=mp&s=160"},"body":"On 05/28/2010 08:57 AM, Goran Mekić wrote:\n> \n>      I have to push from first server to second (yeah, the names are great\n> :o) when ever someone pushes to first server. It should be done using\n> post-receive hook, for example. The problem is that I can not specify ssh\n> key, and even if I could, anything but 600 perm for the key is rejected.\n> What would be the best way to acomplish this? Thanx!\n> \n\nWhy can't you specify ssh key, and why can't you set the key to have perms\n0600 and let it reside in a directory with perms 0700?\n\nThe post-receive hook is just a shell-script, basically.\n\n-- \nAndreas Ericsson                   andreas.ericsson@op5.se\nOP5 AB                             www.op5.se\nTel: +46 8-230225                  Fax: +46 8-230231\n\nConsidering the successes of the wars on alcohol, poverty, drugs and\nterror, I think we should give some serious thought to declaring war\non peace.\n"},{"id":"142495","messageId":"3529f1c81d1062a941056914c612d8c2@ns-linux.org","threadId":"23929","inReplyTo":"4BFF89A5.7020802@op5.se","subject":"Re: Git push from bare repo","fromName":"Goran Mekić","fromEmail":"meka@ns-linux.org","sentAt":"2010-05-28T12:28:27Z","receivedAt":"2010-05-28T12:28:27Z","isPatch":false,"sender":{"key":"meka@ns-linux.org","avatar":null},"body":"\nOn Fri, 28 May 2010 11:15:17 +0200, Andreas Ericsson <ae@op5.se> wrote:\n> On 05/28/2010 08:57 AM, Goran Mekić wrote:\n>> \n>>      I have to push from first server to second (yeah, the names are\n>>      great\n>> :o) when ever someone pushes to first server. It should be done using\n>> post-receive hook, for example. The problem is that I can not specify\nssh\n>> key, and even if I could, anything but 600 perm for the key is\nrejected.\n>> What would be the best way to acomplish this? Thanx!\n>> \n> \n> Why can't you specify ssh key, and why can't you set the key to have\nperms\n> 0600 and let it reside in a directory with perms 0700?\n> \n> The post-receive hook is just a shell-script, basically.\n    There's more then one developer and 600 is set to just one user.\nPost-receive hook is executed as developer doing push. The accounts are in\nLDAP, but I can't set all their UID number to same number because it's\nused\nfor PAM. I was thinking about ACL. Is that even a solution? The dumb one\nwould be cron, but I wish I avoid pushing when there's no change.\n\n-- \nFreeB(eer)S(ex)D(rugs) are the real daemons\n"},{"id":"142496","messageId":"36AD1DE8-9E28-4373-94CF-72E88ABBB309@bjhargrave.com","threadId":"23929","inReplyTo":"3529f1c81d1062a941056914c612d8c2@ns-linux.org","subject":"Re: Git push from bare repo","fromName":"BJ Hargrave","fromEmail":"bj@bjhargrave.com","sentAt":"2010-05-28T12:59:37Z","receivedAt":"2010-05-28T12:59:37Z","isPatch":false,"sender":{"key":"bj@bjhargrave.com","avatar":"https://gravatar.com/avatar/48e60c01177c0e8d3e60c996d54fbe36cf70058efcdd020375b4055e34fc05d7?d=mp&s=160"},"body":"\nOn May 28, 2010, at 08:28 , Goran Mekić wrote:\n>    There's more then one developer and 600 is set to just one user.\n> Post-receive hook is executed as developer doing push. The accounts are in\n> LDAP, but I can't set all their UID number to same number because it's\n> used\n> for PAM. I was thinking about ACL. Is that even a solution? The dumb one\n> would be cron, but I wish I avoid pushing when there's no change.\n> \n\nWhat about having a script which does the push have setuid to the owner of the key. Then the post-receive hook can invoke that script which will have access to the ssh key to do the push.\n-- \n\nBJ\n"},{"id":"142531","messageId":"htqs75$tco$1@dough.gmane.org","threadId":"23929","inReplyTo":"36AD1DE8-9E28-4373-94CF-72E88ABBB309@bjhargrave.com","subject":"Re: Git push from bare repo","fromName":"Gelonida","fromEmail":"gelonida@gmail.com","sentAt":"2010-05-29T11:01:57Z","receivedAt":"2010-05-29T11:01:57Z","isPatch":false,"sender":{"key":"gelonida@gmail.com","avatar":null},"body":"BJ Hargrave wrote:\n> On May 28, 2010, at 08:28 , Goran Mekić wrote:\n>>    There's more then one developer and 600 is set to just one user.\n>> Post-receive hook is executed as developer doing push. The accounts are in\n>> LDAP, but I can't set all their UID number to same number because it's\n>> used\n>> for PAM. I was thinking about ACL. Is that even a solution? The dumb one\n>> would be cron, but I wish I avoid pushing when there's no change.\n>>\n> \n> What about having a script which does the push have setuid to the owner of the key. Then the post-receive hook can invoke that script which will have access to the ssh key to do the push.\nThat should work.\n\n\nanother option would be, that the post receive hook copies the ssh-key\nfile, changes its permission andcontinues only then to push.\n\n\nIf all users have ssh access to first server AND to second server and\nall users use ssh-agent, then all users had just to make sure, that they\ndo agent forwarding in their .ssh/config script.\n"}]}