git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Git and securing a repository

From
FBFelipe Balbi <felipebalbi@users.sourceforge.net>
Date
Jan 2, 2008, 06:34 UTC
Message-ID
<31e679430801012234x20bbebe7vb496a338bf2699d5@mail.gmail.com>
In-Reply-To
<477B39B5.5010107@advancedsl.com.ar>
On Jan 2, 2008 2:13 AM, Gonzalo Garramuño <ggarra@advancedsl.com.ar> wrote:
Show 14 quoted lines
>
> I've been using git for some time and love it.  For open source projects
> there's clearly nothing currently better.
>
> However, I am now using git for proprietary elements, which in the
> future I may need or want to partially restrict access to.  The idea
> being that at my company some (junior) developers should not be given
> access to some elements.  That means either that some full git
> repository should be password protected or even portions of the same
> repository.
>
> Another desirable way to protect elements might be only giving
> clone/pull access to a repository (or portion of it) but not permissions
> to push in changes.

push access is only available through ssh, so if your developer doesn't have a ssh account on the server, he can't push code to it

>
> I have not seen or read much about how git deals with accesses and
> permissions.  Can anyone point me to some documentation if some or all
> of this is possible?

it's easy on the full repository case, create different groups and share git repositories by groups, after that chmod o-rwx -R /path/to/repository.git.

If a user is not the owner nor is part of that group in particular, it wouldn't be able to push any code to the repository.

btw, if you don't start git-daemon you could use ssh to pull code as well.

thinking on the partial repository access, maybe git submodule would help, but i've never used it.

-- 
Best Regards,

Felipe Balbi
felipebalbi@users.sourceforge.net
Previous: Gonzalo GarramuñoNext: Gonzalo Garramuño
Message 2 of 18 in “Git and securing a repository”
  1. Gonzalo GarramuñoJan 2, 2008
  2. Felipe BalbiJan 2, 2008
  3. Gonzalo GarramuñoJan 2, 2008
  4. David SymondsJan 2, 2008
  5. Gonzalo GarramuñoJan 2, 2008
  6. Jakub NarebskiJan 2, 2008
  7. Shawn O. PearceJan 3, 2008
  8. Bruno Cesar RibasJan 3, 2008
  9. Gonzalo GarramuñoJan 3, 2008
  10. Shawn O. PearceJan 3, 2008
  11. Gonzalo GarramuñoJan 3, 2008
  12. Shawn O. PearceJan 3, 2008
  13. Jakub NarebskiJan 3, 2008
  14. Junio C HamanoJan 3, 2008
  15. Jan HudecJan 2, 2008
  16. Gregory JefferisJan 2, 2008
  17. Linus TorvaldsJan 2, 2008
  18. Daniel BarkalowJan 2, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.