Commit d45142ab0b
Verified · cmc
Layout: unified · split
Admin.org +8
| @@ -145,6 +145,9 @@ gitbayd admin audit [--limit n] # host-local | |||
| 145 | ssh git@<host> audit [--limit n] # instance admins, SSH only | 145 | ssh git@<host> audit [--limit n] # instance admins, SSH only |
| 146 | ssh git@<host> admin user list [--state active|pending|disabled|admin] | 146 | ssh git@<host> admin user list [--state active|pending|disabled|admin] |
| 147 | ssh git@<host> admin user show <name> # keys, emails, orgs, tokens, sessions | 147 | ssh git@<host> admin user show <name> # keys, emails, orgs, tokens, sessions |
| 148 | ssh git@<host> admin user promote <name> # grant instance admin | ||
| 149 | ssh git@<host> admin user demote <name> # remove it; the last admin is refused | ||
| 150 | gitbayd admin user promote <name> # host-local: recovery when no admin key is reachable | ||
| 148 | gitbayd admin user disable <name> # suspend: SSH, web, API all refused; | 151 | gitbayd admin user disable <name> # suspend: SSH, web, API all refused; |
| 149 | gitbayd admin user enable <name> # sessions dropped, nothing deleted | 152 | gitbayd admin user enable <name> # sessions dropped, nothing deleted |
| 150 | gitbayd admin user delete <name> --yes # only for accounts anchoring nothing: | 153 | gitbayd admin user delete <name> --yes # only for accounts anchoring nothing: |
| @@ -161,6 +164,11 @@ each address with how it was verified, PGP keys, org roles, the owned | |||
| 161 | repository count, API token names, and live browser sessions. Both are | 164 | repository count, API token names, and live browser sessions. Both are |
| 162 | SSH-only and refused to non-admins, like =audit=. | 165 | SSH-only and refused to non-admins, like =audit=. |
| 163 | 166 | ||
| 167 | Promotion needs an active account: a pending or disabled one is refused. | ||
| 168 | Demotion is refused when it would leave no admin, over SSH and on the | ||
| 169 | host alike, so the host-local =promote= is the way back in when the only | ||
| 170 | admin key is lost. | ||
| 171 | |||
| 164 | =limits.ssh_auth_rate= (10) throttles per-IP authentication *failures* | 172 | =limits.ssh_auth_rate= (10) throttles per-IP authentication *failures* |
| 165 | per minute — successful auths never count and clear the slate. | 173 | per minute — successful auths never count and clear the slate. |
| 166 | =limits.max_pack_bytes= is enforced as =receive.maxInputSize= on every | 174 | =limits.max_pack_bytes= is enforced as =receive.maxInputSize= on every |