Commit 4395ff1dd8

4395ff1dd87e98476a0047194486d6571efafa8d

parent: 1702a17ef1

Verified · cmc

cmc <hello@cleberg.net> · 2026-09-02 04:38 UTC

Admin, Users: quotas, pending expiry, browser sessions

Ref krz/gitbay#82 #83

Layout: unified · split

Admin.org +10
@@ -86,6 +86,10 @@ validation still prints, followed by the contradiction.
86- =mode= — =closed= (default) | =invite= | =open=. invite/open require 86- =mode= — =closed= (default) | =invite= | =open=. invite/open require
87 [mail]. See the user guide for the flows. 87 [mail]. See the user guide for the flows.
88 88
89- =pending_expiry= (empty, never) — a duration such as ="168h"=; a
90 self-registered account still unverified after that long is removed,
91 hourly and at start, audited as =pending.expired=.
92
89** [mail] 93** [mail]
90- =smtp_host= (host:port, 587 assumed), =from=, optional =smtp_user= / 94- =smtp_host= (host:port, 587 assumed), =from=, optional =smtp_user= /
91 =smtp_pass=. STARTTLS when offered. Required for invite/open 95 =smtp_pass=. STARTTLS when offered. Required for invite/open
@@ -104,6 +108,11 @@ validation still prints, followed by the contradiction.
104- =clone_timeout= (3600s) — cap on =repo import= fetches. 108- =clone_timeout= (3600s) — cap on =repo import= fetches.
105- =max_blob_bytes= (100MB) — cap on raw file serving over the web. 109- =max_blob_bytes= (100MB) — cap on raw file serving over the web.
106- =max_asset_bytes= (512MB) — cap per uploaded release asset. 110- =max_asset_bytes= (512MB) — cap per uploaded release asset.
111- =max_repos_per_user= (0, unlimited) — repositories an account may own
112 directly; =repo create=, =fork= and =import= refuse past it.
113 Organizations are not capped.
114- =max_bytes_per_user= (0, unlimited) — disk the account's own
115 repositories may take; a push may be no larger than what is left.
107- =max_pack_bytes=, =ssh_auth_rate= — reserved, not yet enforced. 116- =max_pack_bytes=, =ssh_auth_rate= — reserved, not yet enforced.
108 117
109** [git_daemon] 118** [git_daemon]
@@ -156,6 +165,7 @@ gitbayd admin audit [--actor u|-] [--action prefix] [--since 24h|7d|date] [--lim
156ssh git@<host> audit ... # the same, from an admin session (SSH only) 165ssh git@<host> audit ... # the same, from an admin session (SSH only)
157ssh git@<host> admin user list [--state active|pending|disabled|admin] 166ssh git@<host> admin user list [--state active|pending|disabled|admin]
158ssh git@<host> admin user show <name> # keys, emails, orgs, tokens, sessions 167ssh git@<host> admin user show <name> # keys, emails, orgs, tokens, sessions
168ssh git@<host> admin user limits <name> [--repos n|default] [--bytes n|default] # per-account caps
159ssh git@<host> admin user promote <name> # grant instance admin 169ssh git@<host> admin user promote <name> # grant instance admin
160ssh git@<host> admin user demote <name> # remove it; the last admin is refused 170ssh git@<host> admin user demote <name> # remove it; the last admin is refused
161gitbayd admin user promote <name> # host-local: recovery when no admin key is reachable 171gitbayd admin user promote <name> # host-local: recovery when no admin key is reachable
Users.org +8
@@ -415,6 +415,14 @@ instance issues its own certificates). Claims are exclusive per
415instance; unverified claims serve nothing and expire after 7 days. 415instance; unverified claims serve nothing and expire after 7 days.
416=repo domain list= reports pending/verified/expired. 416=repo domain list= reports pending/verified/expired.
417 417
418* Browser sessions
419
420=gitbay web login= mints a one-time URL; the session it opens lasts
421seven days. =gitbay web sessions list= shows each of yours by a short
422id with its creation and expiry, and =gitbay web sessions revoke <id>=
423or =--all= ends them from the terminal, which is where a lost laptop is
424handled.
425
418* Notifications 426* Notifications
419 427
420When the instance has SMTP configured, activity mails you: someone 428When the instance has SMTP configured, activity mails you: someone