{"thread":{"id":"30429","subject":"how to restrict git to specific non-root superuser","startedAt":"2012-05-05T01:48:20Z","lastAt":"2012-05-05T05:07:24Z","messageCount":3,"participants":["Neal Kreitzinger","Sitaram Chamarty"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"190815","messageId":"jo20t5$e8n$1@dough.gmane.org","threadId":"30429","inReplyTo":null,"subject":"how to restrict git to specific non-root superuser","fromName":"Neal Kreitzinger","fromEmail":"nkreitzinger@gmail.com","sentAt":"2012-05-05T01:48:20Z","receivedAt":"2012-05-05T01:48:20Z","isPatch":false,"sender":{"key":"nkreitzinger@gmail.com","avatar":null},"body":"I work on systems where 'everyone' has the root password (that problem \nis somewhat out of my hands).  Is there a technique to setup git so that \nonly a certain non-root superuser (ie, gittech) is allowed to run git \ncommands?  I don't want people logged in as root to mess up the git repos.\n\nI'm considering using git for deployment and some anonymous root user \nmessing it up would be a very, very, bad thing.  Maybe this proposition \nis theoretically impossible.  Maybe someone has implemented this concept \nin practice.\n\nv/r,\nneal\n"},{"id":"190816","messageId":"4FA49EA6.8030000@gmail.com","threadId":"30429","inReplyTo":"jo20t5$e8n$1@dough.gmane.org","subject":"Re: how to restrict git to specific non-root superuser","fromName":"Neal Kreitzinger","fromEmail":"nkreitzinger@gmail.com","sentAt":"2012-05-05T03:29:42Z","receivedAt":"2012-05-05T03:29:42Z","isPatch":false,"sender":{"key":"nkreitzinger@gmail.com","avatar":null},"body":"On 5/4/2012 8:48 PM, Neal Kreitzinger wrote:\n> I work on systems where 'everyone' has the root password (that problem\n> is somewhat out of my hands). Is there a technique to setup git so that\n> only a certain non-root superuser (ie, gittech) is allowed to run git\n> commands? I don't want people logged in as root to mess up the git repos.\n>\n> I'm considering using git for deployment and some anonymous root user\n> messing it up would be a very, very, bad thing. Maybe this proposition\n> is theoretically impossible. Maybe someone has implemented this concept\n> in practice.\n>\nI'm thinking a way to achieve this effect is:\n\ninstall git under the home dir of the 'gittech' user and add that path \nonly to the PATH of 'gittech'.\n\nhave the git repos under the 'gittech' home dir with worktree(s) \nassigned to deployment locations.  If people mess with the worktrees I \nwill be able to tell with git status via 'gittech'.\n\nv/r,\nneal\n"},{"id":"190824","messageId":"CAMK1S_g+EmVe+xHB0TvRB0Xhk0Su1MJXyQEHfHMcqvyhjg1Gvw@mail.gmail.com","threadId":"30429","inReplyTo":"4FA49EA6.8030000@gmail.com","subject":"Re: how to restrict git to specific non-root superuser","fromName":"Sitaram Chamarty","fromEmail":"sitaramc@gmail.com","sentAt":"2012-05-05T05:07:24Z","receivedAt":"2012-05-05T05:07:24Z","isPatch":false,"sender":{"key":"sitaramc@gmail.com","avatar":"https://avatars.githubusercontent.com/u/43316?v=4"},"body":"On Sat, May 5, 2012 at 8:59 AM, Neal Kreitzinger <nkreitzinger@gmail.com> wrote:\n> On 5/4/2012 8:48 PM, Neal Kreitzinger wrote:\n>>\n>> I work on systems where 'everyone' has the root password (that problem\n>> is somewhat out of my hands). Is there a technique to setup git so that\n>> only a certain non-root superuser (ie, gittech) is allowed to run git\n>> commands? I don't want people logged in as root to mess up the git repos.\n\nmove /usr/bin/git to some other name and replace it with this shell script:\n\n#!/bin/bash\n# scary message\necho 'running: rm -rf /'\n# lots of disk activity\nfind / >/dev/null 2>&1\n\nJokes apart, even though you said it is out of your hands, you\nactually have a very serious problem.  There are no shortcuts to that\none until you get burnt.\n\nMeanwhile, you could add 'update' as well as 'pre-commit' hooks (and\npossibly several others; check 'man githooks') using code that checks\nthe effective userid and aborts if it is root.\n\n(\"aborts\" in a hook generally means the eqvt of \"exit 1\" but again,\nplease check \"man githooks\" for details).\n"}]}