Commit 32fb00e679
Verified · cmc
Layout: unified · split
CHANGELOG.org +41 −22
| @@ -29,6 +29,29 @@ timeout (#256, #257, #276, #277). | |||
| 29 | =--scope full=. A script that mints a token and then writes with it | 29 | =--scope full=. A script that mints a token and then writes with it |
| 30 | must add =--scope full=. Existing tokens keep their scope. | 30 | must add =--scope full=. Existing tokens keep their scope. |
| 31 | 31 | ||
| 32 | *Upgrade note.* Upgrade the instance before the CLI: an older server | ||
| 33 | refuses the CLI's leading =--path== argument as an unknown command, | ||
| 34 | for the eighteen commands whose CLI path differs from the registry's | ||
| 35 | (the =gitbay auth ...= commands and =repo topics list=). | ||
| 36 | |||
| 37 | *Upgrade note.* gitbayd needs =server.secret_key_file= (default | ||
| 38 | =/etc/gitbay/secret.key=) and refuses to start without it. Before | ||
| 39 | replacing the binary, run =gitbayd admin secrets init= as root and | ||
| 40 | =chown gitbay:gitbay /etc/gitbay/secret.key= (=deploy/install.sh= does | ||
| 41 | both when the file is missing). The first start seals the stored | ||
| 42 | secrets. Back the key file up separately: =admin backup= archives do | ||
| 43 | not carry it (see the Admin wiki, "Secret key"). Downgrading to an | ||
| 44 | earlier release after values are sealed is not supported: an older | ||
| 45 | gitbayd reads a sealed value's =gbs1:...= prefix as the literal | ||
| 46 | secret. | ||
| 47 | |||
| 48 | *Upgrade note.* Archives now carry a directory entry for every | ||
| 49 | directory, so a bare repository whose refs are all packed restores as | ||
| 50 | a repository. An archive written before this release lacks those | ||
| 51 | entries; if extracting one leaves a repository's =refs/= directory | ||
| 52 | missing, =gitbayd admin backup --verify <archive>= names it, and | ||
| 53 | =mkdir -p <root>/repos/<owner>/<name>.git/refs= fixes it. | ||
| 54 | |||
| 32 | - A token with a =--ttl= is refused on every command that creates a | 55 | - A token with a =--ttl= is refused on every command that creates a |
| 33 | credential: tokens, keys, deploy keys, runner keys, login links, | 56 | credential: tokens, keys, deploy keys, runner keys, login links, |
| 34 | invites, accounts and verified addresses (#257). | 57 | invites, accounts and verified addresses (#257). |
| @@ -85,10 +108,6 @@ must add =--scope full=. Existing tokens keep their scope. | |||
| 85 | separately (#275). | 108 | separately (#275). |
| 86 | - Audit retention deletes by id, up to the newest row older than the | 109 | - Audit retention deletes by id, up to the newest row older than the |
| 87 | retention, so a clock step back cannot leave a gap in the chain (#275). | 110 | retention, so a clock step back cannot leave a gap in the chain (#275). |
| 88 | *Upgrade note.* Upgrade the instance before the CLI: an older server | ||
| 89 | refuses the CLI's leading =--path== argument as an unknown command, | ||
| 90 | for the eighteen commands whose CLI path differs from the registry's | ||
| 91 | (the =gitbay auth ...= commands and =repo topics list=). | ||
| 92 | - =dashboard= and =feed= print activity as sentences | 111 | - =dashboard= and =feed= print activity as sentences |
| 93 | (=cmc opened issue krz/gitbay#12=) instead of raw event payloads, | 112 | (=cmc opened issue krz/gitbay#12=) instead of raw event payloads, |
| 94 | and a labelled event names its labels there and on the web feed. An | 113 | and a labelled event names its labels there and on the web feed. An |
| @@ -137,18 +156,6 @@ for the eighteen commands whose CLI path differs from the registry's | |||
| 137 | previous" link on each revision after the first, so a reviewer whose | 156 | previous" link on each revision after the first, so a reviewer whose |
| 138 | approval a force-push staled can see what changed without leaving the | 157 | approval a force-push staled can see what changed without leaving the |
| 139 | browser (#269). | 158 | browser (#269). |
| 140 | - Untrusted builds (merge requests from forks) get a fresh HOME removed after the build and no secrets; trusted builds keep a per-repository home under =<workdir>/trusted-home=. Deploy gitbayd before the runner; the old shared homes under the runner's workdir can be deleted. (#255) | ||
| 141 | - =status set= refuses =ci/= contexts, which belong to the instance's builds. Build results are reused only from trusted builds on the same image. =repo settings require-contexts= names status contexts that must report green; setting any turns require-checks on, and one not yet reported counts as pending. (#258) | ||
| 142 | *Upgrade note.* gitbayd needs =server.secret_key_file= (default | ||
| 143 | =/etc/gitbay/secret.key=) and refuses to start without it. Before | ||
| 144 | replacing the binary, run =gitbayd admin secrets init= as root and | ||
| 145 | =chown gitbay:gitbay /etc/gitbay/secret.key= (=deploy/install.sh= does | ||
| 146 | both when the file is missing). The first start seals the stored | ||
| 147 | secrets. Back the key file up separately: =admin backup= archives do | ||
| 148 | not carry it (see the Admin wiki, "Secret key"). Downgrading to an | ||
| 149 | earlier release after values are sealed is not supported: an older | ||
| 150 | gitbayd reads a sealed value's =gbs1:...= prefix as the literal | ||
| 151 | secret. | ||
| 152 | - CI secrets, webhook secrets, mirror tokens and push device tokens are | 159 | - CI secrets, webhook secrets, mirror tokens and push device tokens are |
| 153 | stored sealed with AES-256-GCM (#273). =gitbayd admin secrets | 160 | stored sealed with AES-256-GCM (#273). =gitbayd admin secrets |
| 154 | init|rotate|check=. | 161 | init|rotate|check=. |
| @@ -186,12 +193,24 @@ secret. | |||
| 186 | backup is running" while it runs. =--verify= now also runs =git | 193 | backup is running" while it runs. =--verify= now also runs =git |
| 187 | fsck --connectivity-only= on each archived repository and names any | 194 | fsck --connectivity-only= on each archived repository and names any |
| 188 | that fail. (#259) | 195 | that fail. (#259) |
| 189 | *Upgrade note.* Archives now carry a directory entry for every | 196 | - A full backup archives each repository's HEAD, =packed-refs= and |
| 190 | directory, so a bare repository whose refs are all packed restores as | 197 | =refs/= before its objects, so a push during the backup cannot leave |
| 191 | a repository. An archive written before this release lacks those | 198 | an archived ref naming objects the archive lacks. (#259) |
| 192 | entries; if extracting one leaves a repository's =refs/= directory | 199 | - =gitbayd admin gc= and =admin mr prune= refuse with "a backup is |
| 193 | missing, =gitbayd admin backup --verify <archive>= names it, and | 200 | running" during a full backup. A pack or loose object that git's |
| 194 | =mkdir -p <root>/repos/<owner>/<name>.git/refs= fixes it. | 201 | automatic gc removes while the backup walks is skipped instead of |
| 202 | failing the run; =--verify= reports it if a ref needed it. (#259) | ||
| 203 | - =gitbayd admin backup= and =--verify= no longer need the secret key | ||
| 204 | file: sealed values are copied as they are. A missing database is | ||
| 205 | refused instead of created. (#259) | ||
| 206 | - =gitbayd admin backup= refuses an =--out= inside =server.root=, and | ||
| 207 | removes the snapshot directories and temporary archives a killed run | ||
| 208 | left beside its archive once they are a day old. (#259) | ||
| 209 | - =gitbayd admin backup --verify= runs fsck with =--git-dir=, so a | ||
| 210 | directory that is not a repository fails instead of git checking an | ||
| 211 | enclosing one, and does not extract =objects/info/alternates=. (#259) | ||
| 212 | - =gitbayd admin secrets init= and =rotate= hold an flock on =<key | ||
| 213 | file>.lock=, so two runs at once serialize. (#273) | ||
| 195 | 214 | ||
| 196 | * v1.36.0 — 2026-09-23 | 215 | * v1.36.0 — 2026-09-23 |
| 197 | 216 | ||
cmd/gitbayd/system.go +2 −2
| @@ -16,8 +16,8 @@ import ( | |||
| 16 | 16 | ||
| 17 | // authorizedKeysCmd backs sshd's AuthorizedKeysCommand in system mode: | 17 | // authorizedKeysCmd backs sshd's AuthorizedKeysCommand in system mode: |
| 18 | // | 18 | // |
| 19 | // AuthorizedKeysCommand /usr/bin/gitbayd --config /etc/gitbay/config.toml authorized-keys %t %k | 19 | // AuthorizedKeysCommand /usr/local/bin/gitbayd --config /etc/gitbay/config.toml authorized-keys %t %k |
| 20 | // AuthorizedKeysCommandUser git | 20 | // AuthorizedKeysCommandUser gitbay |
| 21 | // | 21 | // |
| 22 | // It prints a forced-command authorized_keys line for registered keys and | 22 | // It prints a forced-command authorized_keys line for registered keys and |
| 23 | // nothing for unknown ones — so unknown keys fail authentication inside | 23 | // nothing for unknown ones — so unknown keys fail authentication inside |