threads / discuss / 23929

Git push from bare repo

Subject: Git push from bare repo

## tl;dr

5 messages between May 28, 2010 and May 29, 2010.

replies: 4people: 4as markdown or json

Goran Mekić· May 28, 2010, 06:57 UTC · lore
    I have to push from first server to second (yeah, the names are great
:o) when ever someone pushes to first server. It should be done using
post-receive hook, for example. The problem is that I can not specify ssh
key, and even if I could, anything but 600 perm for the key is rejected.
What would be the best way to acomplish this? Thanx!
-- 
FreeB(eer)S(ex)D(rugs) are the real daemons
Andreas Ericsson· May 28, 2010, 09:15 UTC · re: Goran Mekić · lore

Re: Git push from bare repo

On 05/28/2010 08:57 AM, Goran Mekić wrote:
Show 7 quoted lines
> 
>      I have to push from first server to second (yeah, the names are great
> :o) when ever someone pushes to first server. It should be done using
> post-receive hook, for example. The problem is that I can not specify ssh
> key, and even if I could, anything but 600 perm for the key is rejected.
> What would be the best way to acomplish this? Thanx!
> 

Why can't you specify ssh key, and why can't you set the key to have perms 0600 and let it reside in a directory with perms 0700?

The post-receive hook is just a shell-script, basically.
-- 
Andreas Ericsson                   andreas.ericsson@op5.se
OP5 AB                             www.op5.se
Tel: +46 8-230225                  Fax: +46 8-230231

Considering the successes of the wars on alcohol, poverty, drugs and
terror, I think we should give some serious thought to declaring war
on peace.
Goran Mekić· May 28, 2010, 12:28 UTC · re: Andreas Ericsson · lore

Re: Git push from bare repo

On Fri, 28 May 2010 11:15:17 +0200, Andreas Ericsson <ae@op5.se> wrote:
Show 6 quoted lines
> On 05/28/2010 08:57 AM, Goran Mekić wrote:
>> 
>>      I have to push from first server to second (yeah, the names are
>>      great
>> :o) when ever someone pushes to first server. It should be done using
>> post-receive hook, for example. The problem is that I can not specify
ssh
>> key, and even if I could, anything but 600 perm for the key is
rejected.
>> What would be the best way to acomplish this? Thanx!
>> 
> 
> Why can't you specify ssh key, and why can't you set the key to have
perms
> 0600 and let it reside in a directory with perms 0700?
> 
> The post-receive hook is just a shell-script, basically.
    There's more then one developer and 600 is set to just one user.
Post-receive hook is executed as developer doing push. The accounts are in
LDAP, but I can't set all their UID number to same number because it's
used
for PAM. I was thinking about ACL. Is that even a solution? The dumb one
would be cron, but I wish I avoid pushing when there's no change.
-- 
FreeB(eer)S(ex)D(rugs) are the real daemons
BJ Hargrave· May 28, 2010, 12:59 UTC · re: Goran Mekić · lore

Re: Git push from bare repo

On May 28, 2010, at 08:28 , Goran Mekić wrote:
Show 7 quoted lines
>    There's more then one developer and 600 is set to just one user.
> Post-receive hook is executed as developer doing push. The accounts are in
> LDAP, but I can't set all their UID number to same number because it's
> used
> for PAM. I was thinking about ACL. Is that even a solution? The dumb one
> would be cron, but I wish I avoid pushing when there's no change.
> 
What about having a script which does the push have setuid to the owner of the key. Then the post-receive hook can invoke that script which will have access to the ssh key to do the push.
-- 
BJ
Gelonida· May 29, 2010, 11:01 UTC · re: BJ Hargrave · lore

Re: Git push from bare repo

BJ Hargrave wrote:
Show 10 quoted lines
> On May 28, 2010, at 08:28 , Goran Mekić wrote:
>>    There's more then one developer and 600 is set to just one user.
>> Post-receive hook is executed as developer doing push. The accounts are in
>> LDAP, but I can't set all their UID number to same number because it's
>> used
>> for PAM. I was thinking about ACL. Is that even a solution? The dumb one
>> would be cron, but I wish I avoid pushing when there's no change.
>>
> 
> What about having a script which does the push have setuid to the owner of the key. Then the post-receive hook can invoke that script which will have access to the ssh key to do the push.
That should work.

another option would be, that the post receive hook copies the ssh-key file, changes its permission andcontinues only then to push.

If all users have ssh access to first server AND to second server and all users use ssh-agent, then all users had just to make sure, that they do agent forwarding in their .ssh/config script.

← back to recent threads