git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [Q] Encrypted GIT?

From
Johannes Schindelin <johannes.schindelin@gmx.de>
Date
Mar 13, 2008, 11:55 UTC
Message-ID
<alpine.LSU.1.00.0803131254580.1656@racer.site>
In-Reply-To
<20080313114738.GC2414@genesis.frugalware.org>
Hi,
On Thu, 13 Mar 2008, Miklos Vajna wrote:
Show 12 quoted lines
> On Thu, Mar 13, 2008 at 11:48:53AM +0300, Alexander Gladysh <agladysh@gmail.com> wrote:
> > I want to create a private GIT repo (without working copy) on a 
> > machine in external data-center. While I do not actually believe that 
> > it is possible that someone who has physical access to a machine would 
> > be interested in peeking into my repo, I'd like to play safe and to 
> > have this issue covered.
> > 
> > Please advise what is the best way to do it. Are there any existing 
> > solutions?
> 
> i don't think but you can write a wrapper around git receive/upload-pack 
> and use (for example) tar+gpg to keep your repo encrypted on the disc.

The problem is: you cannot decrypt on the remote side, otherwise you will lose all the security.

But if you do not decrypt on the remote side, you cannot store deltified objects (you lose all the benefits of Git's efficient storage), neither can you update incrementally (you lose all the benefits of Git's efficient transport).

The latter can be remedied (somewhat) by encrypting each object individually. In that case, .gitattributes can help (you should be able to find a mail to that extent, which I sent no more than 2 weeks ago). However, you must make sure that the encryption is repeatable, i.e. two different encryption runs _must_ result in _identical_ output.

If it is only a single file containing all your secrets, it can also make sense to just encrypt it, and track the _encrypted_ file directly (without clean/smudge filters).

Hth, Dscho

Previous: Miklos VajnaNext: Miklos Vajna
Message 3 of 17 in “[Q] Encrypted GIT?”
  1. Alexander GladyshMar 13, 2008
  2. Miklos VajnaMar 13, 2008
  3. Johannes SchindelinMar 13, 2008
  4. Miklos VajnaMar 13, 2008
  5. Theodore TsoMar 13, 2008
  6. Alexander GladyshMar 13, 2008
  7. Johannes SchindelinMar 13, 2008
  8. Jeff KingMar 13, 2008
  9. Jeff KingMar 13, 2008
  10. Jeff KingMar 13, 2008
  11. Theodore TsoMar 13, 2008
  12. Jeff KingMar 13, 2008
  13. David BrownMar 13, 2008
  14. Thomas HarningMar 13, 2008
  15. Luke LuMar 13, 2008
  16. Thomas HarningMar 13, 2008
  17. Luke LuMar 13, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.