git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Git Server Repository Security?

From
Kevin Daudt <me@ikke.info>
Date
May 18, 2015, 19:15 UTC
Message-ID
<20150518191555.GA27248@vps892.directvps.nl>
In-Reply-To
<CABQ4iYgauiENEv5ESbJTgUWVhRjt3NxmJfxTZTaa8U072atDEQ@mail.gmail.com>
On Mon, May 18, 2015 at 04:07:49PM +0100, John McIntyre wrote:
Show 9 quoted lines
> 2015-05-18 13:39 GMT+01:00 Heiko Voigt <hvoigt@hvoigt.net>:
> > On Mon, May 18, 2015 at 01:32:07PM +0100, John McIntyre wrote:
> >
> > I do not know, because I always used /home/git. In case not: How about
> > just using a symlink? And there is a lot of information on google ;-)
> 
> 
> I'm confused.   If I run the gitolite command again, in the /opt/git
> directory, will that set it up correctly?

It's recommended to put it inside /home/git/, but if you want, you can set $REPO_BASE inside /home/git/.gitolite.rc

> 
> And I thought that access was via key?  In the example config files
> I've seen, there is no mention of different keys in the config file.

Yes, but these keys are managed through a special repository called gitolite-admin.git. You can add the keys to this repository and change the config to give people access. When you commit and push this repository, those changes come into effect.

Show 5 quoted lines
> 
> Our users can currently ssh into the box.  I want to stop that, but
> since they all ssh in as the use 'git', if I change the shell of that
> user to /sbin/nologin or something similar, I'm effectively locking
> out the git user.

gitolite itself cares for that through the mechanism mentioned earlier. When you try to log in, gitolite takes over, lists the repositories you have access to, and then closes the connection, so no need to set login to /sbin/nologin.

Note that there is also git-shell, which is a shell which can only be used for git commands.

Previous: John McIntyreNext: Sitaram Chamarty
Message 8 of 11 in “Git Server Repository Security?”
  1. John McIntyreMay 18, 2015
  2. Heiko VoigtMay 18, 2015
  3. John McIntyreMay 18, 2015
  4. Heiko VoigtMay 18, 2015
  5. John McIntyreMay 18, 2015
  6. Heiko VoigtMay 18, 2015
  7. John McIntyreMay 18, 2015
  8. Kevin DaudtMay 18, 2015
  9. Sitaram ChamartyMay 19, 2015
  10. Jason CooperMay 18, 2015
  11. Sitaram ChamartyMay 19, 2015

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.