Commit 11f3f93740

11f3f9374048a519b897b3d55f53747016090172

parent: bb2e8adadd

Verified · cmc

cmc <hello@cleberg.net> · 2026-08-26 02:38 UTC

parity: what each surface can do

Layout: unified · split

Home.org +1
@@ -9,6 +9,7 @@ CLI-first git forge: SSH is the API, the web is a rendering.
9- [[API][API and webhooks]] — the JSON API contract, tokens, payloads 9- [[API][API and webhooks]] — the JSON API contract, tokens, payloads
10- [[Roadmap][Roadmap]] — status, phases, decisions, what is not planned 10- [[Roadmap][Roadmap]] — status, phases, decisions, what is not planned
11- [[Threat-Model][Threat model]] — what the forge trusts and never does 11- [[Threat-Model][Threat model]] — what the forge trusts and never does
12- [[Parity][Parity]] — what each surface can do, and what stays SSH-only
12- [[Performance][Performance]] — stress-test numbers from importing git.git 13- [[Performance][Performance]] — stress-test numbers from importing git.git
13 14
14This wiki is a git repository: =git clone ssh://git@gitbay.org/krz/gitbay.wiki.git= 15This wiki is a git repository: =git clone ssh://git@gitbay.org/krz/gitbay.wiki.git=
Parity.org added +59
@@ -0,0 +1,59 @@
1#+title: Parity
2
3Which surface can do what. The CLI is the complete interface: every
4capability exists over SSH, and web writes call the same control
5commands, so the two cannot drift. This page is updated in the merge
6request that changes a row.
7
8* Rule
9
10A capability lands over SSH first. If it belongs to the
11triage/review/respond loop, it lands on the web in the same merge
12request. Anything whose input is a credential — secrets, mirror
13tokens, API tokens, session minting — stays SSH-only by design: the
14web dispatcher refuses =SSHOnly= commands outright.
15
16* Merge requests
17
18| capability | ssh/cli | web |
19|-----------------------+---------+-----|
20| read, diff, commits | yes | yes |
21| comment | yes | yes |
22| edit title and body | yes | yes |
23| review (approve etc.) | yes | yes |
24| resolve a thread | yes | yes |
25| merge (all strategies)| yes | yes |
26| close | yes | yes |
27| create | yes | no |
28| comment on a diff line| yes | no |
29| retarget | yes | no |
30
31* Issues
32
33| capability | ssh/cli | web |
34|---------------------+---------+-----|
35| read, list, filter | yes | yes |
36| create | yes | yes |
37| comment | yes | yes |
38| edit title and body | yes | yes |
39| close and reopen | yes | no |
40| labels, assignees | yes | no |
41| milestone | yes | no |
42
43* Repositories
44
45| capability | ssh/cli | web |
46|---------------------------+---------+-----|
47| browse, log, blame, search| yes | yes |
48| create | yes | yes |
49| edit a file | yes | yes |
50| pin | yes | yes |
51| settings, protection | yes | no |
52| topics, website | yes | no |
53| releases, builds | read | read|
54
55* SSH only, by design
56
57Build secrets, mirror configuration and tokens, custom domain claims,
58API token minting, web session minting, deploy keys, account and
59instance administration.