git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: how to restrict git to specific non-root superuser

From
NKNeal Kreitzinger <nkreitzinger@gmail.com>
Date
May 5, 2012, 03:29 UTC
Message-ID
<4FA49EA6.8030000@gmail.com>
In-Reply-To
<jo20t5$e8n$1@dough.gmane.org>
On 5/4/2012 8:48 PM, Neal Kreitzinger wrote:
Show 10 quoted lines
> I work on systems where 'everyone' has the root password (that problem
> is somewhat out of my hands). Is there a technique to setup git so that
> only a certain non-root superuser (ie, gittech) is allowed to run git
> commands? I don't want people logged in as root to mess up the git repos.
>
> I'm considering using git for deployment and some anonymous root user
> messing it up would be a very, very, bad thing. Maybe this proposition
> is theoretically impossible. Maybe someone has implemented this concept
> in practice.
>
I'm thinking a way to achieve this effect is:

install git under the home dir of the 'gittech' user and add that path only to the PATH of 'gittech'.

have the git repos under the 'gittech' home dir with worktree(s) assigned to deployment locations. If people mess with the worktrees I will be able to tell with git status via 'gittech'.

v/r, neal

Previous: Neal KreitzingerNext: Sitaram Chamarty
Message 2 of 3 in “how to restrict git to specific non-root superuser”
  1. Neal KreitzingerMay 5, 2012
  2. Neal KreitzingerMay 5, 2012
  3. Sitaram ChamartyMay 5, 2012

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.