{"thread":{"id":"33190","subject":"building git ; need suggestion","startedAt":"2013-03-15T12:24:05Z","lastAt":"2013-03-19T02:11:50Z","messageCount":10,"participants":["Joydeep Bakshi","Fredrik Gustafsson","Magnus Bäck","Konstantin Khomoutov","Paul Campbell","David Aguilar"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"211394","messageId":"868B103B-690E-477B-BF75-8F954F893E6F@infoservices.in","threadId":"33190","inReplyTo":null,"subject":"building git ; need suggestion","fromName":"Joydeep Bakshi","fromEmail":"joydeep.bakshi@infoservices.in","sentAt":"2013-03-15T12:24:05Z","receivedAt":"2013-03-15T12:24:05Z","isPatch":false,"sender":{"key":"joydeep.bakshi@infoservices.in","avatar":null},"body":"Hello list,\n\nGreetings !!!\n\nI'm building a git repo on a dedicated server; hence need some kind guidelines from you.\n\n[1] the server will have different git repo with branches\n[2] there will be a web-based GUI which must be flexible to show just a specific branch of a repo based on user authentication\n[3] the web-based GUI should also have the flexibility to show a single repo based on the authentication\n[4] the web-based GUI should have an admin account to supervise and configure all repos along with their branches\n[3] there must be a control mechanism in the repo/web based GUI which have ACL on branches i.e.\nsome specific users should see some specific/ or just a branch and able to commit there only.\n\nbased on the above scenario could anyone suggest the best available solution ?\nThere are many like gitolike/github etc…. but don't know whig one has much finer granular\ncontrol/ACL/web-based GUI…\n\nThanks in advanced for your kind response.\n"},{"id":"211397","messageId":"FB013A89-A4A5-431B-A288-D0C922F156A4@infoservices.in","threadId":"33190","inReplyTo":"868B103B-690E-477B-BF75-8F954F893E6F@infoservices.in","subject":"Re: building git ; need suggestion","fromName":"Joydeep Bakshi","fromEmail":"joydeep.bakshi@infoservices.in","sentAt":"2013-03-15T12:43:28Z","receivedAt":"2013-03-15T12:43:28Z","isPatch":false,"sender":{"key":"joydeep.bakshi@infoservices.in","avatar":null},"body":"\nforgot to mention:\n------------------------\n\na code review system like gerrit is also helpful, but don't know if gerrit\nhas such fine control mechanism.\n\n\n\n\nOn 15-Mar-2013, at 5:54 PM, Joydeep Bakshi <joydeep.bakshi@infoservices.in> wrote:\n\n> Hello list,\n> \n> Greetings !!!\n> \n> I'm building a git repo on a dedicated server; hence need some kind guidelines from you.\n> \n> [1] the server will have different git repo with branches\n> [2] there will be a web-based GUI which must be flexible to show just a specific branch of a repo based on user authentication\n> [3] the web-based GUI should also have the flexibility to show a single repo based on the authentication\n> [4] the web-based GUI should have an admin account to supervise and configure all repos along with their branches\n> [3] there must be a control mechanism in the repo/web based GUI which have ACL on branches i.e.\n> some specific users should see some specific/ or just a branch and able to commit there only.\n> \n> based on the above scenario could anyone suggest the best available solution ?\n> There are many like gitolike/github etc…. but don't know whig one has much finer granular\n> control/ACL/web-based GUI…\n> \n> Thanks in advanced for your kind response.\n> \n> --\n> To unsubscribe from this list: send the line \"unsubscribe git\" in\n> the body of a message to majordomo@vger.kernel.org\n> More majordomo info at  http://vger.kernel.org/majordomo-info.html\n"},{"id":"211396","messageId":"20130315124415.GA23122@paksenarrion.iveqy.com","threadId":"33190","inReplyTo":"868B103B-690E-477B-BF75-8F954F893E6F@infoservices.in","subject":"Re: building git ; need suggestion","fromName":"Fredrik Gustafsson","fromEmail":"iveqy@iveqy.com","sentAt":"2013-03-15T12:44:15Z","receivedAt":"2013-03-15T12:44:15Z","isPatch":false,"sender":{"key":"iveqy@iveqy.com","avatar":"https://avatars.githubusercontent.com/u/761743?v=4"},"body":"On Fri, Mar 15, 2013 at 05:54:05PM +0530, Joydeep Bakshi wrote:\n> [1] the server will have different git repo with branches\n> [2] there will be a web-based GUI which must be flexible to show just a specific branch of a repo based on user authentication\n> [3] the web-based GUI should also have the flexibility to show a single repo based on the authentication\n> [4] the web-based GUI should have an admin account to supervise and configure all repos along with their branches\n> [3] there must be a control mechanism in the repo/web based GUI which have ACL on branches i.e.\n> some specific users should see some specific/ or just a branch and able to commit there only.\n> \n> based on the above scenario could anyone suggest the best available solution ?\n> There are many like gitolike/github etc…. but don't know whig one has much finer granular\n> control/ACL/web-based GUI…\n\ngitolite have a more fine ACL. Check it out. However it doesn't really\nmeet your needs with web-interface (and I'm not even sure about the ACL\nthing is fine enough for you). You can read more about ACL in the git\nbook: http://git-scm.com/book/ch7-4.html\n\nThe webgui that's most populair is cgit and git-web. They don't do ACL\nafaik.\n\nWhy would you need ACL? Why not don't share the branches that are going\nto be secret? Or are you looking for some branches to be read only?\n\nWhen we did this, we did a simple gitolite implementation ourself and\nintegrated cgit on our website wich already had ACL. It works well.\nHowerver we do ACL on repo-level, not on branch level.\n\nYou can also look into git-submodules which will make it possible for\nyou to do repo-wide ACL.\n\nHowever I'm not sure you will be using git in the way git is designed\ntoo and even if it will work, maybe an other solution is better for you.\n\n-- \nMed vänliga hälsningar\nFredrik Gustafsson\n\ntel: 0733-608274\ne-post: iveqy@iveqy.com\n"},{"id":"211398","messageId":"00107242-04EB-423F-90FE-A6DCDEE7E262@infoservices.in","threadId":"33190","inReplyTo":"20130315124415.GA23122@paksenarrion.iveqy.com","subject":"Re: building git ; need suggestion","fromName":"Joydeep Bakshi","fromEmail":"joydeep.bakshi@infoservices.in","sentAt":"2013-03-15T12:52:47Z","receivedAt":"2013-03-15T12:52:47Z","isPatch":false,"sender":{"key":"joydeep.bakshi@infoservices.in","avatar":null},"body":"\nOn 15-Mar-2013, at 6:14 PM, Fredrik Gustafsson <iveqy@iveqy.com> wrote:\n\n> On Fri, Mar 15, 2013 at 05:54:05PM +0530, Joydeep Bakshi wrote:\n>> [1] the server will have different git repo with branches\n>> [2] there will be a web-based GUI which must be flexible to show just a specific branch of a repo based on user authentication\n>> [3] the web-based GUI should also have the flexibility to show a single repo based on the authentication\n>> [4] the web-based GUI should have an admin account to supervise and configure all repos along with their branches\n>> [3] there must be a control mechanism in the repo/web based GUI which have ACL on branches i.e.\n>> some specific users should see some specific/ or just a branch and able to commit there only.\n>> \n>> based on the above scenario could anyone suggest the best available solution ?\n>> There are many like gitolike/github etc…. but don't know whig one has much finer granular\n>> control/ACL/web-based GUI…\n> \n> gitolite have a more fine ACL. Check it out. However it doesn't really\n> meet your needs with web-interface (and I'm not even sure about the ACL\n> thing is fine enough for you). You can read more about ACL in the git\n> book: http://git-scm.com/book/ch7-4.html\n> \n> The webgui that's most populair is cgit and git-web. They don't do ACL\n> afaik.\n> \n> Why would you need ACL? Why not don't share the branches that are going\n> to be secret? Or are you looking for some branches to be read only?\n\nActually the branches have to be dedicated to a group of users.\n developer branch ---> developers\nbug fixed branch --- > bug fixer \n\nand specific group don't need to RW permission on other branch.\nObviously the admin must have the full permission on all these branches\nand merge as per requirement.\n\nThe web-interface is required for checking the history by the users themselves\nand for code review. I don't know any web interface which can show repo/branch \nbased on authentication. I have tried gitweb but it can handle a single repo or multiple\nrepo with single authentication. NO ACL\n "},{"id":"211399","messageId":"20130315131403.GA27022@google.com","threadId":"33190","inReplyTo":"00107242-04EB-423F-90FE-A6DCDEE7E262@infoservices.in","subject":"Re: building git ; need suggestion","fromName":"Magnus Bäck","fromEmail":"baeck@google.com","sentAt":"2013-03-15T13:14:05Z","receivedAt":"2013-03-15T13:14:05Z","isPatch":false,"sender":{"key":"baeck@google.com","avatar":null},"body":"On Friday, March 15, 2013 at 08:52 EDT,\n     Joydeep Bakshi <joydeep.bakshi@infoservices.in> wrote:\n\n> On 15-Mar-2013, at 6:14 PM, Fredrik Gustafsson <iveqy@iveqy.com> wrote:\n> \n> > gitolite have a more fine ACL. Check it out. However it doesn't\n> > really meet your needs with web-interface (and I'm not even sure\n> > about the ACL thing is fine enough for you). You can read more about\n> > ACL in the git book: http://git-scm.com/book/ch7-4.html\n> > \n> > The webgui that's most populair is cgit and git-web. They don't do\n> > ACL afaik.\n> > \n> > Why would you need ACL? Why not don't share the branches that are\n> > going to be secret? Or are you looking for some branches to be read\n> > only?\n> \n> Actually the branches have to be dedicated to a group of users.\n>  developer branch ---> developers\n> bug fixed branch --- > bug fixer\n> \n> and specific group don't need to RW permission on other branch.\n> Obviously the admin must have the full permission on all these branches\n> and merge as per requirement.\n\nRight, but that's R/W permissions. Almost any piece of Git hosting\nsoftware supports restriction of pushes. Discriminating *read* access\nbetween developers and maintenance people sounds like a disaster if it's\nthe same organization. Well, it sounds like a disaster even if there are\ntwo different organizations working on development and maintenance, but\nat least it's a reason.\n\nAnyway, Gerrit supports per-branch read ACLs. As long as all changes go\nthrough code review, perhaps Gerrit web interface works sufficiently\nwell as a repository viewer? Pushes that bypass code review won't show\nup there.\n\nhttp://gerrit-documentation.googlecode.com/svn/Documentation/2.5/access-control.html#category_read\n\n> The web-interface is required for checking the history by the users\n> themselves and for code review. I don't know any web interface which\n> can show repo/branch based on authentication. I have tried gitweb but\n> it can handle a single repo or multiple repo with single\n> authentication. NO ACL\n\nIf you just have two levels of access you could have two separate\nGitweb sites and use Gerrit to replicate a subset of the branches\nto each site. You could e.g. have gitweb-dev.example.com and\ngitweb-maint.example.com and grant access to those sites accordingly.\n\n-- \nMagnus Bäck\nbaeck@google.com\n"},{"id":"211400","messageId":"20130315175615.0759deab3f313479eb24fb84@domain007.com","threadId":"33190","inReplyTo":"20130315124415.GA23122@paksenarrion.iveqy.com","subject":"Re: building git ; need suggestion","fromName":"Konstantin Khomoutov","fromEmail":"kostix+git@007spb.ru","sentAt":"2013-03-15T13:56:15Z","receivedAt":"2013-03-15T13:56:15Z","isPatch":false,"sender":{"key":"kostix+git@007spb.ru","avatar":null},"body":"On Fri, 15 Mar 2013 13:44:15 +0100\nFredrik Gustafsson <iveqy@iveqy.com> wrote:\n\n[...]\n> The webgui that's most populair is cgit and git-web. They don't do ACL\n> afaik.\n\ngitweb passes around branch names using a specific parameter in the\nGET queries it operates on, like\nhttp://gitweb.domain.local/?p=repo.git;a=shortlog;h=refs/heads/master\n\nSo I think it should be possible to somehow implement different\naccess rules in the front-end web server based on the qieries.\n"},{"id":"211409","messageId":"CALeLG_mSkHfpBkfDu_MCe_rQBxGa_1i==mf9cBSwurYgv3EbfQ@mail.gmail.com","threadId":"33190","inReplyTo":"00107242-04EB-423F-90FE-A6DCDEE7E262@infoservices.in","subject":"Re: building git ; need suggestion","fromName":"Paul Campbell","fromEmail":"pcampbell@kemitix.net","sentAt":"2013-03-15T17:25:26Z","receivedAt":"2013-03-15T17:25:26Z","isPatch":false,"sender":{"key":"pcampbell@kemitix.net","avatar":"https://gravatar.com/avatar/57584e05501b694929004e43fcd7308f4ad64df2eb0474cd8c7e5f93662bb0f1?d=mp&s=160"},"body":"On Fri, Mar 15, 2013 at 12:52 PM, Joydeep Bakshi\n<joydeep.bakshi@infoservices.in> wrote:\n>\n> On 15-Mar-2013, at 6:14 PM, Fredrik Gustafsson <iveqy@iveqy.com> wrote:\n>\n>> On Fri, Mar 15, 2013 at 05:54:05PM +0530, Joydeep Bakshi wrote:\n>>> [1] the server will have different git repo with branches\n>>> [2] there will be a web-based GUI which must be flexible to show just a specific branch of a repo based on user authentication\n>>> [3] the web-based GUI should also have the flexibility to show a single repo based on the authentication\n>>> [4] the web-based GUI should have an admin account to supervise and configure all repos along with their branches\n>>> [3] there must be a control mechanism in the repo/web based GUI which have ACL on branches i.e.\n>>> some specific users should see some specific/ or just a branch and able to commit there only.\n>>>\n>>> based on the above scenario could anyone suggest the best available solution ?\n>>> There are many like gitolike/github etc…. but don't know whig one has much finer granular\n>>> control/ACL/web-based GUI…\n>>\n>> gitolite have a more fine ACL. Check it out. However it doesn't really\n>> meet your needs with web-interface (and I'm not even sure about the ACL\n>> thing is fine enough for you). You can read more about ACL in the git\n>> book: http://git-scm.com/book/ch7-4.html\n>>\n>> The webgui that's most populair is cgit and git-web. They don't do ACL\n>> afaik.\n>>\n>> Why would you need ACL? Why not don't share the branches that are going\n>> to be secret? Or are you looking for some branches to be read only?\n>\n> Actually the branches have to be dedicated to a group of users.\n>  developer branch ---> developers\n> bug fixed branch --- > bug fixer\n>\n> and specific group don't need to RW permission on other branch.\n> Obviously the admin must have the full permission on all these branches\n> and merge as per requirement.\n>\n> The web-interface is required for checking the history by the users themselves\n> and for code review. I don't know any web interface which can show repo/branch\n> based on authentication. I have tried gitweb but it can handle a single repo or multiple\n> repo with single authentication. NO ACL\n\nI think you would need to have a separate repo for each group. Then\nonly push the appropriate branches to each repo.\n\n-- \nPaul [W] Campbell\n"},{"id":"211547","messageId":"C8080BF5-DC87-421D-97A1-DF5CF403A03A@infoservices.in","threadId":"33190","inReplyTo":"20130315131403.GA27022@google.com","subject":"Re: building git ; need suggestion","fromName":"Joydeep Bakshi","fromEmail":"joydeep.bakshi@infoservices.in","sentAt":"2013-03-18T05:44:05Z","receivedAt":"2013-03-18T05:44:05Z","isPatch":false,"sender":{"key":"joydeep.bakshi@infoservices.in","avatar":null},"body":"\nOn 15-Mar-2013, at 6:44 PM, Magnus Bäck <baeck@google.com> wrote:\n>> \n> \n> Right, but that's R/W permissions. Almost any piece of Git hosting\n> software supports restriction of pushes. Discriminating *read* access\n> between developers and maintenance people sounds like a disaster if it's\n> the same organisation. \n\nJust restriction on push access is what required.\n"},{"id":"211562","messageId":"9E0367AC-617A-440B-925E-5796CF2E1ADF@infoservices.in","threadId":"33190","inReplyTo":"C8080BF5-DC87-421D-97A1-DF5CF403A03A@infoservices.in","subject":"Re: building git ; need suggestion","fromName":"Joydeep Bakshi","fromEmail":"joydeep.bakshi@infoservices.in","sentAt":"2013-03-18T12:24:26Z","receivedAt":"2013-03-18T12:24:26Z","isPatch":false,"sender":{"key":"joydeep.bakshi@infoservices.in","avatar":null},"body":"I'm closer to my requirement. I have found gitweb simply provide a GUI  for history check\nand code comparison. And the git itself is good enough to do the ACL stuff with hooks.\n\nI already have the following code to deploy the push into its work-tree\n\n===========================\n#!/bin/bash\n\nwhile read oldrev newrev ref\ndo\n  branch=`echo $ref | cut -d/ -f3`\n\n  if [ \"master\" == \"$branch\" ]; then\n    git --work-tree=/path/under/root/dir/live-site/ checkout -f $branch\n    echo 'Changes pushed live.'\n  fi\n\n  if [ \"dev\" == \"$branch\" ]; then\n    git --work-tree=/path/under/root/dir/dev-site/ checkout -f $branch\n    echo 'Changes pushed to dev.'\n  fi\ndone\n=========================\n\nThis code can be extended for as many branches as you have.\n\nI now need a mechanism to restrict the user to it's own branch so that user can't push into\nany other branch in mistake.\n\nSay I have\n\nmaster branch -> only admin user can push here.\ndev branch -> only user dev1 , dev2  and master can push here. \ntesting branch -> only user test1 and test2 can push here.\n\nI think this can also be done with pre-receive hook. Any suggestion on the hook design is\nwelcome. Also this can be implemented on the above hook or in a separate hook.\nA separate hook is better due to maintainability and then I need to call multiple\npre-receive hook. Please suggest.\n\nThanks\n\n\n\nOn 18-Mar-2013, at 11:14 AM, Joydeep Bakshi <joydeep.bakshi@infoservices.in> wrote:\n\n> \n> On 15-Mar-2013, at 6:44 PM, Magnus Bäck <baeck@google.com> wrote:\n>>> \n>> \n>> Right, but that's R/W permissions. Almost any piece of Git hosting\n>> software supports restriction of pushes. Discriminating *read* access\n>> between developers and maintenance people sounds like a disaster if it's\n>> the same organisation. \n> \n> Just restriction on push access is what required.\n> \n> --\n> To unsubscribe from this list: send the line \"unsubscribe git\" in\n> the body of a message to majordomo@vger.kernel.org\n> More majordomo info at  http://vger.kernel.org/majordomo-info.html\n"},{"id":"211626","messageId":"CAJDDKr6bmH6gDSBPN+U6LbSNrFw-adsfv0ZESDAOG7H2nuZapg@mail.gmail.com","threadId":"33190","inReplyTo":"9E0367AC-617A-440B-925E-5796CF2E1ADF@infoservices.in","subject":"Re: building git ; need suggestion","fromName":"David Aguilar","fromEmail":"davvid@gmail.com","sentAt":"2013-03-19T02:11:50Z","receivedAt":"2013-03-19T02:11:50Z","isPatch":false,"sender":{"key":"davvid@gmail.com","avatar":"https://avatars.githubusercontent.com/u/13196?v=4"},"body":"On Mon, Mar 18, 2013 at 5:24 AM, Joydeep Bakshi\n<joydeep.bakshi@infoservices.in> wrote:\n> I'm closer to my requirement. I have found gitweb simply provide a GUI  for history check\n> and code comparison. And the git itself is good enough to do the ACL stuff with hooks.\n>\n> I already have the following code to deploy the push into its work-tree\n\nYou should try gitolite.  It has very flexible rules,\nand it's already been implemented for you ;-)\n\nhttps://github.com/sitaramc/gitolite\n\n\n\n> ===========================\n> #!/bin/bash\n>\n> while read oldrev newrev ref\n> do\n>   branch=`echo $ref | cut -d/ -f3`\n>\n>   if [ \"master\" == \"$branch\" ]; then\n>     git --work-tree=/path/under/root/dir/live-site/ checkout -f $branch\n>     echo 'Changes pushed live.'\n>   fi\n>\n>   if [ \"dev\" == \"$branch\" ]; then\n>     git --work-tree=/path/under/root/dir/dev-site/ checkout -f $branch\n>     echo 'Changes pushed to dev.'\n>   fi\n> done\n> =========================\n>\n> This code can be extended for as many branches as you have.\n>\n> I now need a mechanism to restrict the user to it's own branch so that user can't push into\n> any other branch in mistake.\n>\n> Say I have\n>\n> master branch -> only admin user can push here.\n> dev branch -> only user dev1 , dev2  and master can push here.\n> testing branch -> only user test1 and test2 can push here.\n>\n> I think this can also be done with pre-receive hook. Any suggestion on the hook design is\n> welcome. Also this can be implemented on the above hook or in a separate hook.\n> A separate hook is better due to maintainability and then I need to call multiple\n> pre-receive hook. Please suggest.\n>\n> Thanks\n>\n>\n>\n> On 18-Mar-2013, at 11:14 AM, Joydeep Bakshi <joydeep.bakshi@infoservices.in> wrote:\n>\n>>\n>> On 15-Mar-2013, at 6:44 PM, Magnus Bäck <baeck@google.com> wrote:\n>>>>\n>>>\n>>> Right, but that's R/W permissions. Almost any piece of Git hosting\n>>> software supports restriction of pushes. Discriminating *read* access\n>>> between developers and maintenance people sounds like a disaster if it's\n>>> the same organisation.\n>>\n>> Just restriction on push access is what required.\n>>\n>> --\n>> To unsubscribe from this list: send the line \"unsubscribe git\" in\n>> the body of a message to majordomo@vger.kernel.org\n>> More majordomo info at  http://vger.kernel.org/majordomo-info.html\n>\n> --\n> To unsubscribe from this list: send the line \"unsubscribe git\" in\n> the body of a message to majordomo@vger.kernel.org\n> More majordomo info at  http://vger.kernel.org/majordomo-info.html\n\n\n\n-- \nDavid\n"}]}