Commit d45142ab0b

d45142ab0be0bda8c20c6267d57d6fceb23b8abc

parent: 61d2f4d3f3

Verified · cmc

cmc <hello@cleberg.net> · 2026-09-02 00:53 UTC

Admin: document admin user promote and demote

Ref krz/gitbay#70

Layout: unified · split

Admin.org +8
@@ -145,6 +145,9 @@ gitbayd admin audit [--limit n] # host-local
145ssh git@<host> audit [--limit n] # instance admins, SSH only 145ssh git@<host> audit [--limit n] # instance admins, SSH only
146ssh git@<host> admin user list [--state active|pending|disabled|admin] 146ssh git@<host> admin user list [--state active|pending|disabled|admin]
147ssh git@<host> admin user show <name> # keys, emails, orgs, tokens, sessions 147ssh git@<host> admin user show <name> # keys, emails, orgs, tokens, sessions
148ssh git@<host> admin user promote <name> # grant instance admin
149ssh git@<host> admin user demote <name> # remove it; the last admin is refused
150gitbayd admin user promote <name> # host-local: recovery when no admin key is reachable
148gitbayd admin user disable <name> # suspend: SSH, web, API all refused; 151gitbayd admin user disable <name> # suspend: SSH, web, API all refused;
149gitbayd admin user enable <name> # sessions dropped, nothing deleted 152gitbayd admin user enable <name> # sessions dropped, nothing deleted
150gitbayd admin user delete <name> --yes # only for accounts anchoring nothing: 153gitbayd admin user delete <name> --yes # only for accounts anchoring nothing:
@@ -161,6 +164,11 @@ each address with how it was verified, PGP keys, org roles, the owned
161repository count, API token names, and live browser sessions. Both are 164repository count, API token names, and live browser sessions. Both are
162SSH-only and refused to non-admins, like =audit=. 165SSH-only and refused to non-admins, like =audit=.
163 166
167Promotion needs an active account: a pending or disabled one is refused.
168Demotion is refused when it would leave no admin, over SSH and on the
169host alike, so the host-local =promote= is the way back in when the only
170admin key is lost.
171
164=limits.ssh_auth_rate= (10) throttles per-IP authentication *failures* 172=limits.ssh_auth_rate= (10) throttles per-IP authentication *failures*
165per minute — successful auths never count and clear the slate. 173per minute — successful auths never count and clear the slate.
166=limits.max_pack_bytes= is enforced as =receive.maxInputSize= on every 174=limits.max_pack_bytes= is enforced as =receive.maxInputSize= on every