# Use different ssh keys for different github repos (per-url sshCommand)

7 messages from 2018-07-19 to 2018-07-19. Participants: Basin Ilya, Ævar Arnfjörð Bjarmason, Sitaram Chamarty, Jeff King.
Thread: https://gitlist.dev/t/48918

## Basin Ilya, 2018-07-19 12:24

Subject: Use different ssh keys for different github repos (per-url sshCommand)
Message-ID: <44d3c280-3fb2-2415-46b7-343983e76e0b@gmail.com>
URL: https://gitlist.dev/e/44d3c280-3fb2-2415-46b7-343983e76e0b%40gmail.com

```
Hi.

I have two github accounts, one is for my organization and I want git to automatically choose the correct ssh `IdentityFile` based on the clone URL:

    git@github.com:other/publicrepo.git
       ~/.ssh/id_rsa
    git@github.com:theorganization/privaterepo.git
       ~/.ssh/id_rsa.theorganization

Unfortunately, both URLs have same host name, therefore I can't configure this in the ssh client config. I could create a host alias there, but sometimes somebody else gives me the github URL and I want it to work out of the box.

I thought I could add a per-URL `core` section similar to `user` and `http`, but this section is ignored by git (2.18):

    [core "git@github.com:theorganization"]
        sshCommand = /bin/false
        #sshCommand = ssh -i ~/.ssh/id_rsa.theorganization

I thought of writing a wrapper script to deduce the key from the arguments:

    git@github.com git-upload-pack '/theorganization/privaterepo.git'

Is this the only option?

```

## Ævar Arnfjörð Bjarmason, 2018-07-19 12:50

Subject: Re: Use different ssh keys for different github repos (per-url sshCommand)
Message-ID: <87zhynbd9z.fsf@evledraar.gmail.com>
URL: https://gitlist.dev/e/87zhynbd9z.fsf%40evledraar.gmail.com
In-Reply-To: <44d3c280-3fb2-2415-46b7-343983e76e0b@gmail.com>

```

On Thu, Jul 19 2018, Basin Ilya wrote:

> Hi.
>
> I have two github accounts, one is for my organization and I want git to automatically choose the correct ssh `IdentityFile` based on the clone URL:
>
>     git@github.com:other/publicrepo.git
>        ~/.ssh/id_rsa
>     git@github.com:theorganization/privaterepo.git
>        ~/.ssh/id_rsa.theorganization
>
> Unfortunately, both URLs have same host name, therefore I can't configure this in the ssh client config. I could create a host alias there, but sometimes somebody else gives me the github URL and I want it to work out of the box.
>
> I thought I could add a per-URL `core` section similar to `user` and `http`, but this section is ignored by git (2.18):
>
>     [core "git@github.com:theorganization"]
>         sshCommand = /bin/false
>         #sshCommand = ssh -i ~/.ssh/id_rsa.theorganization
>
> I thought of writing a wrapper script to deduce the key from the arguments:
>
>     git@github.com git-upload-pack '/theorganization/privaterepo.git'
>
> Is this the only option?

Yes, I had a similar problem a while ago (which I sent an RFC patch for)
which shows a script you can use:
https://public-inbox.org/git/20180103102840.27897-1-avarab@gmail.com/

It would be nice if this were configurable. Instead of the way you
suggested, it would be more general if we supported:

    [Include "remote:git@github.com:theorganization*"]
    path = theorganization.config

Although I'm sure we'd have some interesting chicken & egg problems
there when it comes to bootstrapping the config parsing.

```

## Sitaram Chamarty, 2018-07-19 13:22

Subject: Re: Use different ssh keys for different github repos (per-url sshCommand)
Message-ID: <20180719132247.GA16497@sita-lt.atc.tcs.com>
URL: https://gitlist.dev/e/20180719132247.GA16497%40sita-lt.atc.tcs.com
In-Reply-To: <44d3c280-3fb2-2415-46b7-343983e76e0b@gmail.com>

```
On Thu, Jul 19, 2018 at 03:24:54PM +0300, Basin Ilya wrote:
> Hi.
> 
> I have two github accounts, one is for my organization and I want git to automatically choose the correct ssh `IdentityFile` based on the clone URL:
> 
>     git@github.com:other/publicrepo.git
>        ~/.ssh/id_rsa
>     git@github.com:theorganization/privaterepo.git
>        ~/.ssh/id_rsa.theorganization
> 
> Unfortunately, both URLs have same host name, therefore I can't configure this in the ssh client config. I could create a host alias there, but sometimes somebody else gives me the github URL and I want it to work out of the box.
> 
> I thought I could add a per-URL `core` section similar to `user` and `http`, but this section is ignored by git (2.18):
> 
>     [core "git@github.com:theorganization"]
>         sshCommand = /bin/false
>         #sshCommand = ssh -i ~/.ssh/id_rsa.theorganization
> 
> I thought of writing a wrapper script to deduce the key from the arguments:
> 
>     git@github.com git-upload-pack '/theorganization/privaterepo.git'
> 
> Is this the only option?

This is what I do (I don't have two accounts on github, but
elsewhere; same idea though)

    # this goes in ~/.ssh/config

    host gh1
        user                git
        hostname            github.com
        identityfile        ~/.ssh/id_rsa_1

    host gh2
        user                git
        hostname            github.com
        identityfile        ~/.ssh/id_rsa_2

Now use "gh1:username/reponame" and "gh2:username/reponame" as
URLs.  It all just works.

```

## Sitaram Chamarty, 2018-07-19 13:27

Subject: Re: Use different ssh keys for different github repos (per-url sshCommand)
Message-ID: <ff64d8b5-44f0-603e-fd87-5b8db86bd623@gmail.com>
URL: https://gitlist.dev/e/ff64d8b5-44f0-603e-fd87-5b8db86bd623%40gmail.com
In-Reply-To: <20180719132247.GA16497@sita-lt.atc.tcs.com>

```
On 07/19/2018 06:52 PM, Sitaram Chamarty wrote:
> On Thu, Jul 19, 2018 at 03:24:54PM +0300, Basin Ilya wrote:
>> Hi.
>>
>> I have two github accounts, one is for my organization and I want git to automatically choose the correct ssh `IdentityFile` based on the clone URL:
>>
>>     git@github.com:other/publicrepo.git
>>        ~/.ssh/id_rsa
>>     git@github.com:theorganization/privaterepo.git
>>        ~/.ssh/id_rsa.theorganization
>>
>> Unfortunately, both URLs have same host name, therefore I can't configure this in the ssh client config. I could create a host alias there, but sometimes somebody else gives me the github URL and I want it to work out of the box.
>>
>> I thought I could add a per-URL `core` section similar to `user` and `http`, but this section is ignored by git (2.18):
>>
>>     [core "git@github.com:theorganization"]
>>         sshCommand = /bin/false
>>         #sshCommand = ssh -i ~/.ssh/id_rsa.theorganization
>>
>> I thought of writing a wrapper script to deduce the key from the arguments:
>>
>>     git@github.com git-upload-pack '/theorganization/privaterepo.git'
>>
>> Is this the only option?
> 
> This is what I do (I don't have two accounts on github, but
> elsewhere; same idea though)

my apologies; I did not read your email fully and went off half-cocked!
Looks like you already tried host aliases and they don't work for you.

Sorry for the noise!

```

## Jeff King, 2018-07-19 16:42

Subject: Re: Use different ssh keys for different github repos (per-url sshCommand)
Message-ID: <20180719164251.GA4868@sigill.intra.peff.net>
URL: https://gitlist.dev/e/20180719164251.GA4868%40sigill.intra.peff.net
In-Reply-To: <44d3c280-3fb2-2415-46b7-343983e76e0b@gmail.com>

```
On Thu, Jul 19, 2018 at 03:24:54PM +0300, Basin Ilya wrote:

> I have two github accounts, one is for my organization and I want git
> to automatically choose the correct ssh `IdentityFile` based on the
> clone URL:
> 
>     git@github.com:other/publicrepo.git
>        ~/.ssh/id_rsa
>     git@github.com:theorganization/privaterepo.git
>        ~/.ssh/id_rsa.theorganization
> 
> Unfortunately, both URLs have same host name, therefore I can't
> configure this in the ssh client config. I could create a host alias
> there, but sometimes somebody else gives me the github URL and I want
> it to work out of the box.

I think you can hack around this using Git's URL rewriting.

For example, try this:

  git config --global \
    url.gh-other:other/.insteadOf \
    git@github.com:other/

  git config --global \
    url.gh-org:theorganization.insteadOf \
    git@github.com:theorganization/

And then:

  git clone git@github.com:other/publicrepo.git

will hit gh-other, which you can configure using an ssh host alias.

-Peff

```

## Jeff King, 2018-07-19 16:47

Subject: Re: Use different ssh keys for different github repos (per-url sshCommand)
Message-ID: <20180719164704.GB4868@sigill.intra.peff.net>
URL: https://gitlist.dev/e/20180719164704.GB4868%40sigill.intra.peff.net
In-Reply-To: <87zhynbd9z.fsf@evledraar.gmail.com>

```
On Thu, Jul 19, 2018 at 02:50:16PM +0200, Ævar Arnfjörð Bjarmason wrote:

> > I thought of writing a wrapper script to deduce the key from the arguments:
> >
> >     git@github.com git-upload-pack '/theorganization/privaterepo.git'
> >
> > Is this the only option?
> 
> Yes, I had a similar problem a while ago (which I sent an RFC patch for)
> which shows a script you can use:
> https://public-inbox.org/git/20180103102840.27897-1-avarab@gmail.com/
> 
> It would be nice if this were configurable. Instead of the way you
> suggested, it would be more general if we supported:
> 
>     [Include "remote:git@github.com:theorganization*"]
>     path = theorganization.config
> 
> Although I'm sure we'd have some interesting chicken & egg problems
> there when it comes to bootstrapping the config parsing.

I don't think we'd ever support this via the include mechanism. The
idea of "which remote are we looking at" is specific to a particular
part of an operation. Whereas config parsing is generally process-wide,
so it has to be based on a property of the whole process (like "which
directory are we in"). Maybe that's what you meant by chicken and egg.

If we were to make this more configurable, it would probably be more
like existing http.* config, which loads all the config, but then does
URL-specific matching when applying the config to a particular
operation.

-Peff

```

## Basin Ilya, 2018-07-19 19:01

Subject: Re: Use different ssh keys for different github repos (per-url sshCommand)
Message-ID: <966f577f-c4ca-46a4-d55d-817e84780324@gmail.com>
URL: https://gitlist.dev/e/966f577f-c4ca-46a4-d55d-817e84780324%40gmail.com
In-Reply-To: <20180719164251.GA4868@sigill.intra.peff.net>

```
Wow, thanks.

For me it was enough to configure just one rewrite, because my public github account is associated with my default key. Note that I added the missing slash and the username:

    git config --global \
      url.git@gh-org:theorganization/.insteadOf \
      git@github.com:theorganization/



19.07.2018 19:42, Jeff King пишет:
> On Thu, Jul 19, 2018 at 03:24:54PM +0300, Basin Ilya wrote:
> 
>> I have two github accounts, one is for my organization and I want git
>> to automatically choose the correct ssh `IdentityFile` based on the
>> clone URL:
>>
>>     git@github.com:other/publicrepo.git
>>        ~/.ssh/id_rsa
>>     git@github.com:theorganization/privaterepo.git
>>        ~/.ssh/id_rsa.theorganization
>>
>> Unfortunately, both URLs have same host name, therefore I can't
>> configure this in the ssh client config. I could create a host alias
>> there, but sometimes somebody else gives me the github URL and I want
>> it to work out of the box.
> 
> I think you can hack around this using Git's URL rewriting.
> 
> For example, try this:
> 
>   git config --global \
>     url.gh-other:other/.insteadOf \
>     git@github.com:other/
> 
>   git config --global \
>     url.gh-org:theorganization.insteadOf \
>     git@github.com:theorganization/
> 
> And then:
> 
>   git clone git@github.com:other/publicrepo.git
> 
> will hit gh-other, which you can configure using an ssh host alias.
> 
> -Peff
> 

```
