git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Use different ssh keys for different github repos (per-url sshCommand)

From
Ævar Arnfjörð Bjarmason <avarab@gmail.com>
Date
Jul 19, 2018, 12:50 UTC
Message-ID
<87zhynbd9z.fsf@evledraar.gmail.com>
In-Reply-To
<44d3c280-3fb2-2415-46b7-343983e76e0b@gmail.com>
On Thu, Jul 19 2018, Basin Ilya wrote:
Show 22 quoted lines
> Hi.
>
> I have two github accounts, one is for my organization and I want git to automatically choose the correct ssh `IdentityFile` based on the clone URL:
>
>     git@github.com:other/publicrepo.git
>        ~/.ssh/id_rsa
>     git@github.com:theorganization/privaterepo.git
>        ~/.ssh/id_rsa.theorganization
>
> Unfortunately, both URLs have same host name, therefore I can't configure this in the ssh client config. I could create a host alias there, but sometimes somebody else gives me the github URL and I want it to work out of the box.
>
> I thought I could add a per-URL `core` section similar to `user` and `http`, but this section is ignored by git (2.18):
>
>     [core "git@github.com:theorganization"]
>         sshCommand = /bin/false
>         #sshCommand = ssh -i ~/.ssh/id_rsa.theorganization
>
> I thought of writing a wrapper script to deduce the key from the arguments:
>
>     git@github.com git-upload-pack '/theorganization/privaterepo.git'
>
> Is this the only option?

Yes, I had a similar problem a while ago (which I sent an RFC patch for) which shows a script you can use: https://public-inbox.org/git/20180103102840.27897-1-avarab@gmail.com/

It would be nice if this were configurable. Instead of the way you suggested, it would be more general if we supported:

    [Include "remote:git@github.com:theorganization*"]
    path = theorganization.config

Although I'm sure we'd have some interesting chicken & egg problems there when it comes to bootstrapping the config parsing.

Previous: Basin IlyaNext: Jeff King
Message 2 of 7 in “Use different ssh keys for different github repos (per-url sshCommand)”
  1. Basin IlyaJul 19, 2018
  2. Ævar Arnfjörð BjarmasonJul 19, 2018
  3. Jeff KingJul 19, 2018
  4. Sitaram ChamartyJul 19, 2018
  5. Sitaram ChamartyJul 19, 2018
  6. Jeff KingJul 19, 2018
  7. Basin IlyaJul 19, 2018

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.