{"thread":{"id":"48918","subject":"Use different ssh keys for different github repos (per-url sshCommand)","startedAt":"2018-07-19T12:25:01Z","lastAt":"2018-07-19T19:01:36Z","messageCount":7,"participants":["Basin Ilya","Ævar Arnfjörð Bjarmason","Sitaram Chamarty","Jeff King"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"353024","messageId":"44d3c280-3fb2-2415-46b7-343983e76e0b@gmail.com","threadId":"48918","inReplyTo":null,"subject":"Use different ssh keys for different github repos (per-url sshCommand)","fromName":"Basin Ilya","fromEmail":"basinilya@gmail.com","sentAt":"2018-07-19T12:24:54Z","receivedAt":"2018-07-19T12:25:01Z","isPatch":false,"sender":{"key":"basinilya@gmail.com","avatar":null},"body":"Hi.\n\nI have two github accounts, one is for my organization and I want git to automatically choose the correct ssh `IdentityFile` based on the clone URL:\n\n    git@github.com:other/publicrepo.git\n       ~/.ssh/id_rsa\n    git@github.com:theorganization/privaterepo.git\n       ~/.ssh/id_rsa.theorganization\n\nUnfortunately, both URLs have same host name, therefore I can't configure this in the ssh client config. I could create a host alias there, but sometimes somebody else gives me the github URL and I want it to work out of the box.\n\nI thought I could add a per-URL `core` section similar to `user` and `http`, but this section is ignored by git (2.18):\n\n    [core \"git@github.com:theorganization\"]\n        sshCommand = /bin/false\n        #sshCommand = ssh -i ~/.ssh/id_rsa.theorganization\n\nI thought of writing a wrapper script to deduce the key from the arguments:\n\n    git@github.com git-upload-pack '/theorganization/privaterepo.git'\n\nIs this the only option?\n"},{"id":"353025","messageId":"87zhynbd9z.fsf@evledraar.gmail.com","threadId":"48918","inReplyTo":"44d3c280-3fb2-2415-46b7-343983e76e0b@gmail.com","subject":"Re: Use different ssh keys for different github repos (per-url sshCommand)","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2018-07-19T12:50:16Z","receivedAt":"2018-07-19T12:50:21Z","isPatch":false,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"\nOn Thu, Jul 19 2018, Basin Ilya wrote:\n\n> Hi.\n>\n> I have two github accounts, one is for my organization and I want git to automatically choose the correct ssh `IdentityFile` based on the clone URL:\n>\n>     git@github.com:other/publicrepo.git\n>        ~/.ssh/id_rsa\n>     git@github.com:theorganization/privaterepo.git\n>        ~/.ssh/id_rsa.theorganization\n>\n> Unfortunately, both URLs have same host name, therefore I can't configure this in the ssh client config. I could create a host alias there, but sometimes somebody else gives me the github URL and I want it to work out of the box.\n>\n> I thought I could add a per-URL `core` section similar to `user` and `http`, but this section is ignored by git (2.18):\n>\n>     [core \"git@github.com:theorganization\"]\n>         sshCommand = /bin/false\n>         #sshCommand = ssh -i ~/.ssh/id_rsa.theorganization\n>\n> I thought of writing a wrapper script to deduce the key from the arguments:\n>\n>     git@github.com git-upload-pack '/theorganization/privaterepo.git'\n>\n> Is this the only option?\n\nYes, I had a similar problem a while ago (which I sent an RFC patch for)\nwhich shows a script you can use:\nhttps://public-inbox.org/git/20180103102840.27897-1-avarab@gmail.com/\n\nIt would be nice if this were configurable. Instead of the way you\nsuggested, it would be more general if we supported:\n\n    [Include \"remote:git@github.com:theorganization*\"]\n    path = theorganization.config\n\nAlthough I'm sure we'd have some interesting chicken & egg problems\nthere when it comes to bootstrapping the config parsing.\n"},{"id":"353026","messageId":"20180719132247.GA16497@sita-lt.atc.tcs.com","threadId":"48918","inReplyTo":"44d3c280-3fb2-2415-46b7-343983e76e0b@gmail.com","subject":"Re: Use different ssh keys for different github repos (per-url sshCommand)","fromName":"Sitaram Chamarty","fromEmail":"sitaramc@gmail.com","sentAt":"2018-07-19T13:22:47Z","receivedAt":"2018-07-19T13:22:54Z","isPatch":false,"sender":{"key":"sitaramc@gmail.com","avatar":"https://avatars.githubusercontent.com/u/43316?v=4"},"body":"On Thu, Jul 19, 2018 at 03:24:54PM +0300, Basin Ilya wrote:\n> Hi.\n> \n> I have two github accounts, one is for my organization and I want git to automatically choose the correct ssh `IdentityFile` based on the clone URL:\n> \n>     git@github.com:other/publicrepo.git\n>        ~/.ssh/id_rsa\n>     git@github.com:theorganization/privaterepo.git\n>        ~/.ssh/id_rsa.theorganization\n> \n> Unfortunately, both URLs have same host name, therefore I can't configure this in the ssh client config. I could create a host alias there, but sometimes somebody else gives me the github URL and I want it to work out of the box.\n> \n> I thought I could add a per-URL `core` section similar to `user` and `http`, but this section is ignored by git (2.18):\n> \n>     [core \"git@github.com:theorganization\"]\n>         sshCommand = /bin/false\n>         #sshCommand = ssh -i ~/.ssh/id_rsa.theorganization\n> \n> I thought of writing a wrapper script to deduce the key from the arguments:\n> \n>     git@github.com git-upload-pack '/theorganization/privaterepo.git'\n> \n> Is this the only option?\n\nThis is what I do (I don't have two accounts on github, but\nelsewhere; same idea though)\n\n    # this goes in ~/.ssh/config\n\n    host gh1\n        user                git\n        hostname            github.com\n        identityfile        ~/.ssh/id_rsa_1\n\n    host gh2\n        user                git\n        hostname            github.com\n        identityfile        ~/.ssh/id_rsa_2\n\nNow use \"gh1:username/reponame\" and \"gh2:username/reponame\" as\nURLs.  It all just works.\n"},{"id":"353027","messageId":"ff64d8b5-44f0-603e-fd87-5b8db86bd623@gmail.com","threadId":"48918","inReplyTo":"20180719132247.GA16497@sita-lt.atc.tcs.com","subject":"Re: Use different ssh keys for different github repos (per-url sshCommand)","fromName":"Sitaram Chamarty","fromEmail":"sitaramc@gmail.com","sentAt":"2018-07-19T13:27:49Z","receivedAt":"2018-07-19T13:27:56Z","isPatch":false,"sender":{"key":"sitaramc@gmail.com","avatar":"https://avatars.githubusercontent.com/u/43316?v=4"},"body":"On 07/19/2018 06:52 PM, Sitaram Chamarty wrote:\n> On Thu, Jul 19, 2018 at 03:24:54PM +0300, Basin Ilya wrote:\n>> Hi.\n>>\n>> I have two github accounts, one is for my organization and I want git to automatically choose the correct ssh `IdentityFile` based on the clone URL:\n>>\n>>     git@github.com:other/publicrepo.git\n>>        ~/.ssh/id_rsa\n>>     git@github.com:theorganization/privaterepo.git\n>>        ~/.ssh/id_rsa.theorganization\n>>\n>> Unfortunately, both URLs have same host name, therefore I can't configure this in the ssh client config. I could create a host alias there, but sometimes somebody else gives me the github URL and I want it to work out of the box.\n>>\n>> I thought I could add a per-URL `core` section similar to `user` and `http`, but this section is ignored by git (2.18):\n>>\n>>     [core \"git@github.com:theorganization\"]\n>>         sshCommand = /bin/false\n>>         #sshCommand = ssh -i ~/.ssh/id_rsa.theorganization\n>>\n>> I thought of writing a wrapper script to deduce the key from the arguments:\n>>\n>>     git@github.com git-upload-pack '/theorganization/privaterepo.git'\n>>\n>> Is this the only option?\n> \n> This is what I do (I don't have two accounts on github, but\n> elsewhere; same idea though)\n\nmy apologies; I did not read your email fully and went off half-cocked!\nLooks like you already tried host aliases and they don't work for you.\n\nSorry for the noise!\n"},{"id":"353039","messageId":"20180719164251.GA4868@sigill.intra.peff.net","threadId":"48918","inReplyTo":"44d3c280-3fb2-2415-46b7-343983e76e0b@gmail.com","subject":"Re: Use different ssh keys for different github repos (per-url sshCommand)","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2018-07-19T16:42:52Z","receivedAt":"2018-07-19T16:42:55Z","isPatch":false,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Thu, Jul 19, 2018 at 03:24:54PM +0300, Basin Ilya wrote:\n\n> I have two github accounts, one is for my organization and I want git\n> to automatically choose the correct ssh `IdentityFile` based on the\n> clone URL:\n> \n>     git@github.com:other/publicrepo.git\n>        ~/.ssh/id_rsa\n>     git@github.com:theorganization/privaterepo.git\n>        ~/.ssh/id_rsa.theorganization\n> \n> Unfortunately, both URLs have same host name, therefore I can't\n> configure this in the ssh client config. I could create a host alias\n> there, but sometimes somebody else gives me the github URL and I want\n> it to work out of the box.\n\nI think you can hack around this using Git's URL rewriting.\n\nFor example, try this:\n\n  git config --global \\\n    url.gh-other:other/.insteadOf \\\n    git@github.com:other/\n\n  git config --global \\\n    url.gh-org:theorganization.insteadOf \\\n    git@github.com:theorganization/\n\nAnd then:\n\n  git clone git@github.com:other/publicrepo.git\n\nwill hit gh-other, which you can configure using an ssh host alias.\n\n-Peff\n"},{"id":"353041","messageId":"20180719164704.GB4868@sigill.intra.peff.net","threadId":"48918","inReplyTo":"87zhynbd9z.fsf@evledraar.gmail.com","subject":"Re: Use different ssh keys for different github repos (per-url sshCommand)","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2018-07-19T16:47:05Z","receivedAt":"2018-07-19T16:47:09Z","isPatch":false,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Thu, Jul 19, 2018 at 02:50:16PM +0200, Ævar Arnfjörð Bjarmason wrote:\n\n> > I thought of writing a wrapper script to deduce the key from the arguments:\n> >\n> >     git@github.com git-upload-pack '/theorganization/privaterepo.git'\n> >\n> > Is this the only option?\n> \n> Yes, I had a similar problem a while ago (which I sent an RFC patch for)\n> which shows a script you can use:\n> https://public-inbox.org/git/20180103102840.27897-1-avarab@gmail.com/\n> \n> It would be nice if this were configurable. Instead of the way you\n> suggested, it would be more general if we supported:\n> \n>     [Include \"remote:git@github.com:theorganization*\"]\n>     path = theorganization.config\n> \n> Although I'm sure we'd have some interesting chicken & egg problems\n> there when it comes to bootstrapping the config parsing.\n\nI don't think we'd ever support this via the include mechanism. The\nidea of \"which remote are we looking at\" is specific to a particular\npart of an operation. Whereas config parsing is generally process-wide,\nso it has to be based on a property of the whole process (like \"which\ndirectory are we in\"). Maybe that's what you meant by chicken and egg.\n\nIf we were to make this more configurable, it would probably be more\nlike existing http.* config, which loads all the config, but then does\nURL-specific matching when applying the config to a particular\noperation.\n\n-Peff\n"},{"id":"353066","messageId":"966f577f-c4ca-46a4-d55d-817e84780324@gmail.com","threadId":"48918","inReplyTo":"20180719164251.GA4868@sigill.intra.peff.net","subject":"Re: Use different ssh keys for different github repos (per-url sshCommand)","fromName":"Basin Ilya","fromEmail":"basinilya@gmail.com","sentAt":"2018-07-19T19:01:29Z","receivedAt":"2018-07-19T19:01:36Z","isPatch":false,"sender":{"key":"basinilya@gmail.com","avatar":null},"body":"Wow, thanks.\n\nFor me it was enough to configure just one rewrite, because my public github account is associated with my default key. Note that I added the missing slash and the username:\n\n    git config --global \\\n      url.git@gh-org:theorganization/.insteadOf \\\n      git@github.com:theorganization/\n\n\n\n19.07.2018 19:42, Jeff King пишет:\n> On Thu, Jul 19, 2018 at 03:24:54PM +0300, Basin Ilya wrote:\n> \n>> I have two github accounts, one is for my organization and I want git\n>> to automatically choose the correct ssh `IdentityFile` based on the\n>> clone URL:\n>>\n>>     git@github.com:other/publicrepo.git\n>>        ~/.ssh/id_rsa\n>>     git@github.com:theorganization/privaterepo.git\n>>        ~/.ssh/id_rsa.theorganization\n>>\n>> Unfortunately, both URLs have same host name, therefore I can't\n>> configure this in the ssh client config. I could create a host alias\n>> there, but sometimes somebody else gives me the github URL and I want\n>> it to work out of the box.\n> \n> I think you can hack around this using Git's URL rewriting.\n> \n> For example, try this:\n> \n>   git config --global \\\n>     url.gh-other:other/.insteadOf \\\n>     git@github.com:other/\n> \n>   git config --global \\\n>     url.gh-org:theorganization.insteadOf \\\n>     git@github.com:theorganization/\n> \n> And then:\n> \n>   git clone git@github.com:other/publicrepo.git\n> \n> will hit gh-other, which you can configure using an ssh host alias.\n> \n> -Peff\n> \n"}]}