git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Git and securing a repository

From
Linus Torvalds <torvalds@linux-foundation.org>
Date
Jan 2, 2008, 22:17 UTC
Message-ID
<alpine.LFD.1.00.0801021406020.3010@woody.linux-foundation.org>
In-Reply-To
<477B6199.6070601@advancedsl.com.ar>
On Wed, 2 Jan 2008, Gonzalo Garramu?o wrote:
> 
> I was really looking for a permission based system that was part of git itself
> (and thus more portable and easier to admin), and not the OS. Something akin
> to what perforce or even CVS can do.
Well, git by design doesn't do that. 

That doesn't mean that it has to be OS-level permissions (in fact, it generally shouldn't), it just means that git wasn't really meant to care about permissions itself, and you the user management and permissions should come from "outside".

That outside *can* be OS-level things like just permissions on files, but more commonly it's things like SSH keys and using the git hooks. In other words, pretty much by design, git is meant to be the *core* SCM infrastructure, and then you layer your user management on top of it as a *separate* layer.

An example of that would probably be gitosis, but I haven't used it myself. For the kernel, people literally tend to just use SSH accounts, and not any central repository at all (ie the kind of crazy "central repo access control rules" that centralized repos need are just not necessary at all in a more distributed usage model).

See 
	http://eagain.net/gitweb/?p=gitosis.git
	http://scie.nti.st/2007/11/14/hosting-git-repositories-the-easy-and-secure-way

for a quick starting point on gitosis, if that suits your needs (there's more, google is your friend).

			Linus
Previous: Gregory JefferisNext: Daniel Barkalow
Message 17 of 18 in “Git and securing a repository”
  1. Gonzalo GarramuñoJan 2, 2008
  2. Felipe BalbiJan 2, 2008
  3. Gonzalo GarramuñoJan 2, 2008
  4. David SymondsJan 2, 2008
  5. Gonzalo GarramuñoJan 2, 2008
  6. Jakub NarebskiJan 2, 2008
  7. Shawn O. PearceJan 3, 2008
  8. Bruno Cesar RibasJan 3, 2008
  9. Gonzalo GarramuñoJan 3, 2008
  10. Shawn O. PearceJan 3, 2008
  11. Gonzalo GarramuñoJan 3, 2008
  12. Shawn O. PearceJan 3, 2008
  13. Jakub NarebskiJan 3, 2008
  14. Junio C HamanoJan 3, 2008
  15. Jan HudecJan 2, 2008
  16. Gregory JefferisJan 2, 2008
  17. Linus TorvaldsJan 2, 2008
  18. Daniel BarkalowJan 2, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.