Commit 32fb00e679

32fb00e6791aa36bff92e76111281e1f48c2aad5

parent: 4cf9a72907

Verified · cmc

cmc <hello@cleberg.net> · 2026-09-28 22:31 UTC

changelog: upgrade notes first, duplicates dropped, backup fixes; system-mode comment names the gitbay user

Ref #259

Layout: unified · split

CHANGELOG.org +41 −22
@@ -29,6 +29,29 @@ timeout (#256, #257, #276, #277).
29=--scope full=. A script that mints a token and then writes with it 29=--scope full=. A script that mints a token and then writes with it
30must add =--scope full=. Existing tokens keep their scope. 30must add =--scope full=. Existing tokens keep their scope.
31 31
32*Upgrade note.* Upgrade the instance before the CLI: an older server
33refuses the CLI's leading =--path== argument as an unknown command,
34for the eighteen commands whose CLI path differs from the registry's
35(the =gitbay auth ...= commands and =repo topics list=).
36
37*Upgrade note.* gitbayd needs =server.secret_key_file= (default
38=/etc/gitbay/secret.key=) and refuses to start without it. Before
39replacing the binary, run =gitbayd admin secrets init= as root and
40=chown gitbay:gitbay /etc/gitbay/secret.key= (=deploy/install.sh= does
41both when the file is missing). The first start seals the stored
42secrets. Back the key file up separately: =admin backup= archives do
43not carry it (see the Admin wiki, "Secret key"). Downgrading to an
44earlier release after values are sealed is not supported: an older
45gitbayd reads a sealed value's =gbs1:...= prefix as the literal
46secret.
47
48*Upgrade note.* Archives now carry a directory entry for every
49directory, so a bare repository whose refs are all packed restores as
50a repository. An archive written before this release lacks those
51entries; if extracting one leaves a repository's =refs/= directory
52missing, =gitbayd admin backup --verify <archive>= names it, and
53=mkdir -p <root>/repos/<owner>/<name>.git/refs= fixes it.
54
32- A token with a =--ttl= is refused on every command that creates a 55- A token with a =--ttl= is refused on every command that creates a
33 credential: tokens, keys, deploy keys, runner keys, login links, 56 credential: tokens, keys, deploy keys, runner keys, login links,
34 invites, accounts and verified addresses (#257). 57 invites, accounts and verified addresses (#257).
@@ -85,10 +108,6 @@ must add =--scope full=. Existing tokens keep their scope.
85 separately (#275). 108 separately (#275).
86- Audit retention deletes by id, up to the newest row older than the 109- Audit retention deletes by id, up to the newest row older than the
87 retention, so a clock step back cannot leave a gap in the chain (#275). 110 retention, so a clock step back cannot leave a gap in the chain (#275).
88*Upgrade note.* Upgrade the instance before the CLI: an older server
89refuses the CLI's leading =--path== argument as an unknown command,
90for the eighteen commands whose CLI path differs from the registry's
91(the =gitbay auth ...= commands and =repo topics list=).
92- =dashboard= and =feed= print activity as sentences 111- =dashboard= and =feed= print activity as sentences
93 (=cmc opened issue krz/gitbay#12=) instead of raw event payloads, 112 (=cmc opened issue krz/gitbay#12=) instead of raw event payloads,
94 and a labelled event names its labels there and on the web feed. An 113 and a labelled event names its labels there and on the web feed. An
@@ -137,18 +156,6 @@ for the eighteen commands whose CLI path differs from the registry's
137 previous" link on each revision after the first, so a reviewer whose 156 previous" link on each revision after the first, so a reviewer whose
138 approval a force-push staled can see what changed without leaving the 157 approval a force-push staled can see what changed without leaving the
139 browser (#269). 158 browser (#269).
140- Untrusted builds (merge requests from forks) get a fresh HOME removed after the build and no secrets; trusted builds keep a per-repository home under =<workdir>/trusted-home=. Deploy gitbayd before the runner; the old shared homes under the runner's workdir can be deleted. (#255)
141- =status set= refuses =ci/= contexts, which belong to the instance's builds. Build results are reused only from trusted builds on the same image. =repo settings require-contexts= names status contexts that must report green; setting any turns require-checks on, and one not yet reported counts as pending. (#258)
142*Upgrade note.* gitbayd needs =server.secret_key_file= (default
143=/etc/gitbay/secret.key=) and refuses to start without it. Before
144replacing the binary, run =gitbayd admin secrets init= as root and
145=chown gitbay:gitbay /etc/gitbay/secret.key= (=deploy/install.sh= does
146both when the file is missing). The first start seals the stored
147secrets. Back the key file up separately: =admin backup= archives do
148not carry it (see the Admin wiki, "Secret key"). Downgrading to an
149earlier release after values are sealed is not supported: an older
150gitbayd reads a sealed value's =gbs1:...= prefix as the literal
151secret.
152- CI secrets, webhook secrets, mirror tokens and push device tokens are 159- CI secrets, webhook secrets, mirror tokens and push device tokens are
153 stored sealed with AES-256-GCM (#273). =gitbayd admin secrets 160 stored sealed with AES-256-GCM (#273). =gitbayd admin secrets
154 init|rotate|check=. 161 init|rotate|check=.
@@ -186,12 +193,24 @@ secret.
186 backup is running" while it runs. =--verify= now also runs =git 193 backup is running" while it runs. =--verify= now also runs =git
187 fsck --connectivity-only= on each archived repository and names any 194 fsck --connectivity-only= on each archived repository and names any
188 that fail. (#259) 195 that fail. (#259)
189*Upgrade note.* Archives now carry a directory entry for every 196- A full backup archives each repository's HEAD, =packed-refs= and
190directory, so a bare repository whose refs are all packed restores as 197 =refs/= before its objects, so a push during the backup cannot leave
191a repository. An archive written before this release lacks those 198 an archived ref naming objects the archive lacks. (#259)
192entries; if extracting one leaves a repository's =refs/= directory 199- =gitbayd admin gc= and =admin mr prune= refuse with "a backup is
193missing, =gitbayd admin backup --verify <archive>= names it, and 200 running" during a full backup. A pack or loose object that git's
194=mkdir -p <root>/repos/<owner>/<name>.git/refs= fixes it. 201 automatic gc removes while the backup walks is skipped instead of
202 failing the run; =--verify= reports it if a ref needed it. (#259)
203- =gitbayd admin backup= and =--verify= no longer need the secret key
204 file: sealed values are copied as they are. A missing database is
205 refused instead of created. (#259)
206- =gitbayd admin backup= refuses an =--out= inside =server.root=, and
207 removes the snapshot directories and temporary archives a killed run
208 left beside its archive once they are a day old. (#259)
209- =gitbayd admin backup --verify= runs fsck with =--git-dir=, so a
210 directory that is not a repository fails instead of git checking an
211 enclosing one, and does not extract =objects/info/alternates=. (#259)
212- =gitbayd admin secrets init= and =rotate= hold an flock on =<key
213 file>.lock=, so two runs at once serialize. (#273)
195 214
196* v1.36.0 — 2026-09-23 215* v1.36.0 — 2026-09-23
197 216
cmd/gitbayd/system.go +2 −2
@@ -16,8 +16,8 @@ import (
16 16
17// authorizedKeysCmd backs sshd's AuthorizedKeysCommand in system mode: 17// authorizedKeysCmd backs sshd's AuthorizedKeysCommand in system mode:
18// 18//
19// AuthorizedKeysCommand /usr/bin/gitbayd --config /etc/gitbay/config.toml authorized-keys %t %k 19// AuthorizedKeysCommand /usr/local/bin/gitbayd --config /etc/gitbay/config.toml authorized-keys %t %k
20// AuthorizedKeysCommandUser git 20// AuthorizedKeysCommandUser gitbay
21// 21//
22// It prints a forced-command authorized_keys line for registered keys and 22// It prints a forced-command authorized_keys line for registered keys and
23// nothing for unknown ones — so unknown keys fail authentication inside 23// nothing for unknown ones — so unknown keys fail authentication inside