git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Git Server Repository Security?

From
JMJohn McIntyre <joh98.mac@gmail.com>
Date
May 18, 2015, 10:58 UTC
Message-ID
<CABQ4iYgjtdw46Psow_e7uGLqx0ZiFt+TQOgXvCmP1-W10LGEmg@mail.gmail.com>
In-Reply-To
<20150518102633.GA15186@book.hvoigt.net>
2015-05-18 11:26 GMT+01:00 Heiko Voigt <hvoigt@hvoigt.net>:
Show 18 quoted lines
> Hi,
>
> On Mon, May 18, 2015 at 11:07:02AM +0100, John McIntyre wrote:
>> Hi,
>> I've been asked to set up a git repository for a few projects.  So I
>> have a Linux CentOS server running git.   I place the repositories
>> under /opt and I use the .ssh/authorized_keys of the git user, to
>> grant access. The user sends me his private key, and I paste it into
>> the end of the file.
>>
>> And now, I realise that there's a problem.  If I have /opt/repo1.git
>> and /opt/repo2.git, then all users can access both repositories.
>>
>> Is there a way to prevent this?
>
> If you want a simple tool using ssh-keys have a look at gitolite[1].
> It quite simple to setup and with it you can specify all kinds of access
> rights.
That's adding a separate level of complexity.

I looked into filesystem-level permissions. I don't see any means of doing so, because everyone accesses the repositories using the 'git' user. So even if I add a group like 'devClient1' and then change the group ownership of a repo to that user, they'll still be able to access all repos..?

John.
Previous: Heiko VoigtNext: Heiko Voigt
Message 3 of 11 in “Git Server Repository Security?”
  1. John McIntyreMay 18, 2015
  2. Heiko VoigtMay 18, 2015
  3. John McIntyreMay 18, 2015
  4. Heiko VoigtMay 18, 2015
  5. John McIntyreMay 18, 2015
  6. Heiko VoigtMay 18, 2015
  7. John McIntyreMay 18, 2015
  8. Kevin DaudtMay 18, 2015
  9. Sitaram ChamartyMay 19, 2015
  10. Jason CooperMay 18, 2015
  11. Sitaram ChamartyMay 19, 2015

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.