Commit 32fb00e679
Verified · cmc
Layout: unified · split
CHANGELOG.org +41 −22
| @@ -29,6 +29,29 @@ timeout (#256, #257, #276, #277). | ||
| 29 | 29 | =--scope full=. A script that mints a token and then writes with it |
| 30 | 30 | must add =--scope full=. Existing tokens keep their scope. |
| 31 | 31 | |
| 32 | *Upgrade note.* Upgrade the instance before the CLI: an older server | |
| 33 | refuses the CLI's leading =--path== argument as an unknown command, | |
| 34 | for the eighteen commands whose CLI path differs from the registry's | |
| 35 | (the =gitbay auth ...= commands and =repo topics list=). | |
| 36 | ||
| 37 | *Upgrade note.* gitbayd needs =server.secret_key_file= (default | |
| 38 | =/etc/gitbay/secret.key=) and refuses to start without it. Before | |
| 39 | replacing the binary, run =gitbayd admin secrets init= as root and | |
| 40 | =chown gitbay:gitbay /etc/gitbay/secret.key= (=deploy/install.sh= does | |
| 41 | both when the file is missing). The first start seals the stored | |
| 42 | secrets. Back the key file up separately: =admin backup= archives do | |
| 43 | not carry it (see the Admin wiki, "Secret key"). Downgrading to an | |
| 44 | earlier release after values are sealed is not supported: an older | |
| 45 | gitbayd reads a sealed value's =gbs1:...= prefix as the literal | |
| 46 | secret. | |
| 47 | ||
| 48 | *Upgrade note.* Archives now carry a directory entry for every | |
| 49 | directory, so a bare repository whose refs are all packed restores as | |
| 50 | a repository. An archive written before this release lacks those | |
| 51 | entries; if extracting one leaves a repository's =refs/= directory | |
| 52 | missing, =gitbayd admin backup --verify <archive>= names it, and | |
| 53 | =mkdir -p <root>/repos/<owner>/<name>.git/refs= fixes it. | |
| 54 | ||
| 32 | 55 | - A token with a =--ttl= is refused on every command that creates a |
| 33 | 56 | credential: tokens, keys, deploy keys, runner keys, login links, |
| 34 | 57 | invites, accounts and verified addresses (#257). |
| @@ -85,10 +108,6 @@ must add =--scope full=. Existing tokens keep their scope. | ||
| 85 | 108 | separately (#275). |
| 86 | 109 | - Audit retention deletes by id, up to the newest row older than the |
| 87 | 110 | retention, so a clock step back cannot leave a gap in the chain (#275). |
| 88 | *Upgrade note.* Upgrade the instance before the CLI: an older server | |
| 89 | refuses the CLI's leading =--path== argument as an unknown command, | |
| 90 | for the eighteen commands whose CLI path differs from the registry's | |
| 91 | (the =gitbay auth ...= commands and =repo topics list=). | |
| 92 | 111 | - =dashboard= and =feed= print activity as sentences |
| 93 | 112 | (=cmc opened issue krz/gitbay#12=) instead of raw event payloads, |
| 94 | 113 | and a labelled event names its labels there and on the web feed. An |
| @@ -137,18 +156,6 @@ for the eighteen commands whose CLI path differs from the registry's | ||
| 137 | 156 | previous" link on each revision after the first, so a reviewer whose |
| 138 | 157 | approval a force-push staled can see what changed without leaving the |
| 139 | 158 | browser (#269). |
| 140 | - Untrusted builds (merge requests from forks) get a fresh HOME removed after the build and no secrets; trusted builds keep a per-repository home under =<workdir>/trusted-home=. Deploy gitbayd before the runner; the old shared homes under the runner's workdir can be deleted. (#255) | |
| 141 | - =status set= refuses =ci/= contexts, which belong to the instance's builds. Build results are reused only from trusted builds on the same image. =repo settings require-contexts= names status contexts that must report green; setting any turns require-checks on, and one not yet reported counts as pending. (#258) | |
| 142 | *Upgrade note.* gitbayd needs =server.secret_key_file= (default | |
| 143 | =/etc/gitbay/secret.key=) and refuses to start without it. Before | |
| 144 | replacing the binary, run =gitbayd admin secrets init= as root and | |
| 145 | =chown gitbay:gitbay /etc/gitbay/secret.key= (=deploy/install.sh= does | |
| 146 | both when the file is missing). The first start seals the stored | |
| 147 | secrets. Back the key file up separately: =admin backup= archives do | |
| 148 | not carry it (see the Admin wiki, "Secret key"). Downgrading to an | |
| 149 | earlier release after values are sealed is not supported: an older | |
| 150 | gitbayd reads a sealed value's =gbs1:...= prefix as the literal | |
| 151 | secret. | |
| 152 | 159 | - CI secrets, webhook secrets, mirror tokens and push device tokens are |
| 153 | 160 | stored sealed with AES-256-GCM (#273). =gitbayd admin secrets |
| 154 | 161 | init|rotate|check=. |
| @@ -186,12 +193,24 @@ secret. | ||
| 186 | 193 | backup is running" while it runs. =--verify= now also runs =git |
| 187 | 194 | fsck --connectivity-only= on each archived repository and names any |
| 188 | 195 | that fail. (#259) |
| 189 | *Upgrade note.* Archives now carry a directory entry for every | |
| 190 | directory, so a bare repository whose refs are all packed restores as | |
| 191 | a repository. An archive written before this release lacks those | |
| 192 | entries; if extracting one leaves a repository's =refs/= directory | |
| 193 | missing, =gitbayd admin backup --verify <archive>= names it, and | |
| 194 | =mkdir -p <root>/repos/<owner>/<name>.git/refs= fixes it. | |
| 196 | - A full backup archives each repository's HEAD, =packed-refs= and | |
| 197 | =refs/= before its objects, so a push during the backup cannot leave | |
| 198 | an archived ref naming objects the archive lacks. (#259) | |
| 199 | - =gitbayd admin gc= and =admin mr prune= refuse with "a backup is | |
| 200 | running" during a full backup. A pack or loose object that git's | |
| 201 | automatic gc removes while the backup walks is skipped instead of | |
| 202 | failing the run; =--verify= reports it if a ref needed it. (#259) | |
| 203 | - =gitbayd admin backup= and =--verify= no longer need the secret key | |
| 204 | file: sealed values are copied as they are. A missing database is | |
| 205 | refused instead of created. (#259) | |
| 206 | - =gitbayd admin backup= refuses an =--out= inside =server.root=, and | |
| 207 | removes the snapshot directories and temporary archives a killed run | |
| 208 | left beside its archive once they are a day old. (#259) | |
| 209 | - =gitbayd admin backup --verify= runs fsck with =--git-dir=, so a | |
| 210 | directory that is not a repository fails instead of git checking an | |
| 211 | enclosing one, and does not extract =objects/info/alternates=. (#259) | |
| 212 | - =gitbayd admin secrets init= and =rotate= hold an flock on =<key | |
| 213 | file>.lock=, so two runs at once serialize. (#273) | |
| 195 | 214 | |
| 196 | 215 | * v1.36.0 — 2026-09-23 |
| 197 | 216 | |
cmd/gitbayd/system.go +2 −2
| @@ -16,8 +16,8 @@ import ( | ||
| 16 | 16 | |
| 17 | 17 | // authorizedKeysCmd backs sshd's AuthorizedKeysCommand in system mode: |
| 18 | 18 | // |
| 19 | // AuthorizedKeysCommand /usr/bin/gitbayd --config /etc/gitbay/config.toml authorized-keys %t %k | |
| 20 | // AuthorizedKeysCommandUser git | |
| 19 | // AuthorizedKeysCommand /usr/local/bin/gitbayd --config /etc/gitbay/config.toml authorized-keys %t %k | |
| 20 | // AuthorizedKeysCommandUser gitbay | |
| 21 | 21 | // |
| 22 | 22 | // It prints a forced-command authorized_keys line for registered keys and |
| 23 | 23 | // nothing for unknown ones — so unknown keys fail authentication inside |