git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Git Server Repository Security?

From
Sitaram Chamarty <sitaramc@gmail.com>
Date
May 19, 2015, 00:41 UTC
Message-ID
<555A86C8.2020006@gmail.com>
In-Reply-To
<CABQ4iYgjtdw46Psow_e7uGLqx0ZiFt+TQOgXvCmP1-W10LGEmg@mail.gmail.com>
On 05/18/2015 04:28 PM, John McIntyre wrote:
> 2015-05-18 11:26 GMT+01:00 Heiko Voigt <hvoigt@hvoigt.net>:
Show 11 quoted lines
>> If you want a simple tool using ssh-keys have a look at gitolite[1].
>> It quite simple to setup and with it you can specify all kinds of access
>> rights.
> 
> That's adding a separate level of complexity.
> 
> I looked into filesystem-level permissions.  I don't see any means of
> doing so, because everyone accesses the repositories using the 'git'
> user.  So even if I add a group like 'devClient1' and then change the
> group ownership of a repo to that user, they'll still be able to
> access all repos..?
My usual answer to this is http://gitolite.com/gitolite/overview.html#basic-use-case

The first example is doable with file system permissions if you give everyone a separate userid, but it's a nightmare. The second one is not even possible.

Previous: Jason Cooper
Message 11 of 11 in “Git Server Repository Security?”
  1. John McIntyreMay 18, 2015
  2. Heiko VoigtMay 18, 2015
  3. John McIntyreMay 18, 2015
  4. Heiko VoigtMay 18, 2015
  5. John McIntyreMay 18, 2015
  6. Heiko VoigtMay 18, 2015
  7. John McIntyreMay 18, 2015
  8. Kevin DaudtMay 18, 2015
  9. Sitaram ChamartyMay 19, 2015
  10. Jason CooperMay 18, 2015
  11. Sitaram ChamartyMay 19, 2015

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.