git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: I don't want the .git directory next to my code.

From
Martin Langhoff <martin.langhoff@gmail.com>
Date
Jan 17, 2008, 21:05 UTC
Message-ID
<46a038f90801171305t78fa1758l9ddf2d70890aea9f@mail.gmail.com>
In-Reply-To
<478EEAC4.2010006@talkingspider.com>
On Jan 17, 2008 6:42 PM, Mike <fromlists@talkingspider.com> wrote:
> With PHP, Python, and Ruby, the development is the deployment.  The
Plenty here use git for web apps.
> There's a fundamental "best practice" of web development being violated
> here- keep your docroots clean, only put stuff in them that should go
> live (or should eventually go live when ready).  Other files should not
> live under docroot.

*First* - people here have pointed out various ways of doing this with the GIT_DIR env variable. Nothing is being violated.

In terms of the best-practice you mention of publishing only the reachable files, your checkout is one directory higher. The top-level dir of your checkout should look like:

  .git
  htdocs # this is published
  conf # configuration files
  lib # libraries

if you publish the top of your checkout, your libraries sit in there. Along your .git and your config files.

> Among the reasons for that is security.  If one of those .git dirs does
> slip out and go live, it's a *huge* *gaping* *security* *hole*.  You

Well -- I routinely add .git CVS and .svn to http.conf with a directorymatch clause to prevent access to them. Just in case, belts-and-suspenders.

> If we end up having to write a special "publisher" app to move files
> from dev to live, then it will only be because of those damn .git
> directories.

Nah! It'll be because of a long list of things, including temp files, backup files that developers make, all sorts of things in your *work* dir that you really need there and you really should _not_ have in the production checkout.

BTW, I also add common patterns for those temp files to httpd.conf to restrict access to them.

> Maybe git just isn't intended to be used for anything besides compiled
> languages like c?  Or maybe just not for web app development?

C produces a ton of intermediary files that git never commits, and C projects usually get an "installer" too (debian's apt/dpkg, rpm, etc). Writing PHP/Ruby/Python produces less "intermediary" files, but it still creates some, so there's plenty of good reasons to have an "installer".

GIT does the SCM thing, but for handling your deployment you need something else. I normally use scripts that use git internally, written in make, perl or shell.

cheers,
martin
Previous: Russ DillNext: Andreas Ericsson
Message 31 of 65 in “I don't want the .git directory next to my code.”
  1. MikeJan 16, 2008
  2. Randal L. SchwartzJan 16, 2008
  3. MikeJan 16, 2008
  4. David SymondsJan 16, 2008
  5. MikeJan 16, 2008
  6. SeanJan 16, 2008
  7. MikeJan 16, 2008
  8. Neil MacnealeJan 16, 2008
  9. MikeJan 16, 2008
  10. Johannes SchindelinJan 16, 2008
  11. Linus TorvaldsJan 16, 2008
  12. Linus TorvaldsJan 16, 2008
  13. MikeJan 17, 2008
  14. Kris ShannonJan 17, 2008
  15. Wincent ColaiutaJan 17, 2008
  16. Jeff KingJan 17, 2008
  17. Linus TorvaldsJan 17, 2008
  18. Johannes SchindelinJan 17, 2008
  19. Linus TorvaldsJan 17, 2008
  20. Johannes SchindelinJan 17, 2008
  21. MikeJan 17, 2008
  22. Johannes SchindelinJan 17, 2008
  23. MikeJan 17, 2008
  24. Johannes SchindelinJan 17, 2008
  25. MikeJan 17, 2008
  26. Johannes SchindelinJan 17, 2008
  27. MikeJan 17, 2008
  28. Johannes SchindelinJan 17, 2008
  29. David SymondsJan 18, 2008
  30. Russ DillJan 22, 2008
  31. Martin LanghoffJan 17, 2008
  32. Andreas EricssonJan 18, 2008
  33. Junio C HamanoJan 16, 2008
  34. Ping YinJan 17, 2008
  35. Linus TorvaldsJan 17, 2008
  36. Dan McGeeJan 16, 2008
  37. MikeJan 16, 2008
  38. Mike KrierJan 16, 2008
  39. MikeJan 16, 2008
  40. Nguyen Thai Ngoc DuyJan 16, 2008
  41. David SymondsJan 16, 2008
  42. MikeJan 16, 2008
  43. Daniel BarkalowJan 16, 2008
  44. Luke LuJan 16, 2008
  45. MikeJan 16, 2008
  46. Sam VilainJan 17, 2008
  47. Daniel BarkalowJan 16, 2008
  48. MikeJan 16, 2008
  49. Johannes SchindelinJan 16, 2008
  50. Bert WesargJan 16, 2008
  51. Wayne DavisonJan 16, 2008
  52. Matthieu MoyJan 16, 2008
  53. Johannes SchindelinJan 16, 2008
  54. Bill LearJan 16, 2008
  55. Matthieu MoyJan 16, 2008
  56. Johannes SchindelinJan 16, 2008
  57. Junio C HamanoJan 16, 2008
  58. Johannes SchindelinJan 16, 2008
  59. Matthieu MoyJan 16, 2008
  60. Johannes SchindelinJan 16, 2008
  61. Jakub NarebskiJan 16, 2008
  62. Brian DowningJan 17, 2008
  63. Randal L. SchwartzJan 17, 2008
  64. Martin LanghoffJan 17, 2008
  65. Randal L. SchwartzJan 17, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.