git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: building git ; need suggestion

From
MBMagnus Bäck <baeck@google.com>
Date
Mar 15, 2013, 13:14 UTC
Message-ID
<20130315131403.GA27022@google.com>
In-Reply-To
<00107242-04EB-423F-90FE-A6DCDEE7E262@infoservices.in>
On Friday, March 15, 2013 at 08:52 EDT,
     Joydeep Bakshi <joydeep.bakshi@infoservices.in> wrote:
Show 21 quoted lines
> On 15-Mar-2013, at 6:14 PM, Fredrik Gustafsson <iveqy@iveqy.com> wrote:
> 
> > gitolite have a more fine ACL. Check it out. However it doesn't
> > really meet your needs with web-interface (and I'm not even sure
> > about the ACL thing is fine enough for you). You can read more about
> > ACL in the git book: http://git-scm.com/book/ch7-4.html
> > 
> > The webgui that's most populair is cgit and git-web. They don't do
> > ACL afaik.
> > 
> > Why would you need ACL? Why not don't share the branches that are
> > going to be secret? Or are you looking for some branches to be read
> > only?
> 
> Actually the branches have to be dedicated to a group of users.
>  developer branch ---> developers
> bug fixed branch --- > bug fixer
> 
> and specific group don't need to RW permission on other branch.
> Obviously the admin must have the full permission on all these branches
> and merge as per requirement.

Right, but that's R/W permissions. Almost any piece of Git hosting software supports restriction of pushes. Discriminating *read* access between developers and maintenance people sounds like a disaster if it's the same organization. Well, it sounds like a disaster even if there are two different organizations working on development and maintenance, but at least it's a reason.

Anyway, Gerrit supports per-branch read ACLs. As long as all changes go through code review, perhaps Gerrit web interface works sufficiently well as a repository viewer? Pushes that bypass code review won't show up there.

http://gerrit-documentation.googlecode.com/svn/Documentation/2.5/access-control.html#category_read
Show 5 quoted lines
> The web-interface is required for checking the history by the users
> themselves and for code review. I don't know any web interface which
> can show repo/branch based on authentication. I have tried gitweb but
> it can handle a single repo or multiple repo with single
> authentication. NO ACL

If you just have two levels of access you could have two separate Gitweb sites and use Gerrit to replicate a subset of the branches to each site. You could e.g. have gitweb-dev.example.com and gitweb-maint.example.com and grant access to those sites accordingly.

-- 
Magnus Bäck
baeck@google.com
Previous: Joydeep BakshiNext: Joydeep Bakshi
Message 5 of 10 in “building git ; need suggestion”
  1. Joydeep BakshiMar 15, 2013
  2. Joydeep BakshiMar 15, 2013
  3. Fredrik GustafssonMar 15, 2013
  4. Joydeep BakshiMar 15, 2013
  5. Magnus BäckMar 15, 2013
  6. Joydeep BakshiMar 18, 2013
  7. Joydeep BakshiMar 18, 2013
  8. David AguilarMar 19, 2013
  9. Paul CampbellMar 15, 2013
  10. Konstantin KhomoutovMar 15, 2013

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.