Commit 975f1af176

975f1af1761336421391d02fff1046fcdb0b24ee

parent: d45142ab0b

Verified · cmc

cmc <hello@cleberg.net> · 2026-09-02 01:04 UTC

Admin: document the admin repo overrides

Ref krz/gitbay#71

Layout: unified · split

Admin.org +15
@@ -169,6 +169,21 @@ Demotion is refused when it would leave no admin, over SSH and on the
169host alike, so the host-local =promote= is the way back in when the only 169host alike, so the host-local =promote= is the way back in when the only
170admin key is lost. 170admin key is lost.
171 171
172Instance admin carries no right on anyone's repository: policy does not
173consult it, and a private repository still answers not-found to an
174admin. Moderation goes through explicit overrides that skip the access
175check and write their own audit row:
176
177#+begin_src sh
178ssh git@<host> admin repo list [--owner o] [--visibility public|private] # size, last push
179ssh git@<host> admin repo archive|unarchive <owner/name>
180ssh git@<host> admin repo visibility <owner/name> public|private
181ssh git@<host> admin repo delete <owner/name> --yes
182#+end_src
183
184Each lands in the audit log as =admin repo.<action>= naming the
185repository, on top of the =cmd= row every mutating command gets.
186
172=limits.ssh_auth_rate= (10) throttles per-IP authentication *failures* 187=limits.ssh_auth_rate= (10) throttles per-IP authentication *failures*
173per minute — successful auths never count and clear the slate. 188per minute — successful auths never count and clear the slate.
174=limits.max_pack_bytes= is enforced as =receive.maxInputSize= on every 189=limits.max_pack_bytes= is enforced as =receive.maxInputSize= on every