Commit 61d2f4d3f3
Verified · cmc
Layout: unified · split
Admin.org +9
| @@ -143,6 +143,8 @@ never in argv. | |||
| 143 | #+begin_src sh | 143 | #+begin_src sh |
| 144 | gitbayd admin audit [--limit n] # host-local | 144 | gitbayd admin audit [--limit n] # host-local |
| 145 | ssh git@<host> audit [--limit n] # instance admins, SSH only | 145 | ssh git@<host> audit [--limit n] # instance admins, SSH only |
| 146 | ssh git@<host> admin user list [--state active|pending|disabled|admin] | ||
| 147 | ssh git@<host> admin user show <name> # keys, emails, orgs, tokens, sessions | ||
| 146 | gitbayd admin user disable <name> # suspend: SSH, web, API all refused; | 148 | gitbayd admin user disable <name> # suspend: SSH, web, API all refused; |
| 147 | gitbayd admin user enable <name> # sessions dropped, nothing deleted | 149 | gitbayd admin user enable <name> # sessions dropped, nothing deleted |
| 148 | gitbayd admin user delete <name> --yes # only for accounts anchoring nothing: | 150 | gitbayd admin user delete <name> --yes # only for accounts anchoring nothing: |
| @@ -152,6 +154,13 @@ gitbayd admin user delete <name> --yes # only for accounts anchoring nothing: | |||
| 152 | # org's only admin | 154 | # org's only admin |
| 153 | #+end_src | 155 | #+end_src |
| 154 | 156 | ||
| 157 | =admin user list= pages by username (=--limit=, =--cursor=) and carries | ||
| 158 | each account's state and =last_seen=, the newest use of any of its SSH | ||
| 159 | keys or API tokens. =admin user show= adds the keys with their last use, | ||
| 160 | each address with how it was verified, PGP keys, org roles, the owned | ||
| 161 | repository count, API token names, and live browser sessions. Both are | ||
| 162 | SSH-only and refused to non-admins, like =audit=. | ||
| 163 | |||
| 155 | =limits.ssh_auth_rate= (10) throttles per-IP authentication *failures* | 164 | =limits.ssh_auth_rate= (10) throttles per-IP authentication *failures* |
| 156 | per minute — successful auths never count and clear the slate. | 165 | per minute — successful auths never count and clear the slate. |
| 157 | =limits.max_pack_bytes= is enforced as =receive.maxInputSize= on every | 166 | =limits.max_pack_bytes= is enforced as =receive.maxInputSize= on every |