Commit 983b55e5da

983b55e5daa115bc3cded4f60ce43e5ae35f1d61

parent: e977337c14

Verified · cmc

cmc <hello@cleberg.net> · 2026-09-03 21:43 UTC

Users: the runner key scope, and CLI connection sharing

Layout: unified · split

Users.org +9 −4
@@ -53,9 +53,11 @@ gitbay auth keys add --scope git < ~/.ssh/ci_key.pub # key on stdin
5353gitbay auth keys remove SHA256:...
5454#+end_src
5555
56Scopes: =full= (default; git plus every control command) or =git= (git
57transport only — right for CI and automation keys, which then cannot
58touch issues, settings, or your account).
56Scopes: =full= (default; git plus every control command), =git= (git
57transport only — right for automation keys, which then cannot touch
58issues, settings, or your account), or =runner= (the CI runner's
59protocol plus read-only git, for the key a =gitbay-runner= host holds;
60see [[Admin]]).
5961
6062A key belongs to exactly one account instance-wide. Registering a key
6163someone else already holds is refused without telling you whose it is.
@@ -467,5 +469,8 @@ gitbay init [name] [--private] # git init + repo create + origin, in one step
467469
468470Configuration lives at =~/.config/gitbay/config.toml=. The CLI shells
469471out to your real =ssh=, so =~/.ssh/config=, the agent, and hardware keys
470all apply. Man pages: =gitbay man --dir <dir>=; completions:
472all apply. It shares one connection per instance through a control
473socket under =~/.ssh=: the first command in five minutes pays the
474handshake and the rest ride it. =no_multiplex = true= on an instance in
475the config turns that off. Man pages: =gitbay man --dir <dir>=; completions:
471476=gitbay completion bash|zsh|fish=.