Commit 975f1af176
Verified · cmc
Layout: unified · split
Admin.org +15
| @@ -169,6 +169,21 @@ Demotion is refused when it would leave no admin, over SSH and on the | |||
| 169 | host alike, so the host-local =promote= is the way back in when the only | 169 | host alike, so the host-local =promote= is the way back in when the only |
| 170 | admin key is lost. | 170 | admin key is lost. |
| 171 | 171 | ||
| 172 | Instance admin carries no right on anyone's repository: policy does not | ||
| 173 | consult it, and a private repository still answers not-found to an | ||
| 174 | admin. Moderation goes through explicit overrides that skip the access | ||
| 175 | check and write their own audit row: | ||
| 176 | |||
| 177 | #+begin_src sh | ||
| 178 | ssh git@<host> admin repo list [--owner o] [--visibility public|private] # size, last push | ||
| 179 | ssh git@<host> admin repo archive|unarchive <owner/name> | ||
| 180 | ssh git@<host> admin repo visibility <owner/name> public|private | ||
| 181 | ssh git@<host> admin repo delete <owner/name> --yes | ||
| 182 | #+end_src | ||
| 183 | |||
| 184 | Each lands in the audit log as =admin repo.<action>= naming the | ||
| 185 | repository, on top of the =cmd= row every mutating command gets. | ||
| 186 | |||
| 172 | =limits.ssh_auth_rate= (10) throttles per-IP authentication *failures* | 187 | =limits.ssh_auth_rate= (10) throttles per-IP authentication *failures* |
| 173 | per minute — successful auths never count and clear the slate. | 188 | per minute — successful auths never count and clear the slate. |
| 174 | =limits.max_pack_bytes= is enforced as =receive.maxInputSize= on every | 189 | =limits.max_pack_bytes= is enforced as =receive.maxInputSize= on every |