Commit d45142ab0b

d45142ab0be0bda8c20c6267d57d6fceb23b8abc

parent: 61d2f4d3f3

Verified · cmc

cmc <hello@cleberg.net> · 2026-09-02 00:53 UTC

Admin: document admin user promote and demote

Ref krz/gitbay#70

Layout: unified · split

Admin.org +8
@@ -145,6 +145,9 @@ gitbayd admin audit [--limit n] # host-local
145145ssh git@<host> audit [--limit n] # instance admins, SSH only
146146ssh git@<host> admin user list [--state active|pending|disabled|admin]
147147ssh git@<host> admin user show <name> # keys, emails, orgs, tokens, sessions
148ssh git@<host> admin user promote <name> # grant instance admin
149ssh git@<host> admin user demote <name> # remove it; the last admin is refused
150gitbayd admin user promote <name> # host-local: recovery when no admin key is reachable
148151gitbayd admin user disable <name> # suspend: SSH, web, API all refused;
149152gitbayd admin user enable <name> # sessions dropped, nothing deleted
150153gitbayd admin user delete <name> --yes # only for accounts anchoring nothing:
@@ -161,6 +164,11 @@ each address with how it was verified, PGP keys, org roles, the owned
161164repository count, API token names, and live browser sessions. Both are
162165SSH-only and refused to non-admins, like =audit=.
163166
167Promotion needs an active account: a pending or disabled one is refused.
168Demotion is refused when it would leave no admin, over SSH and on the
169host alike, so the host-local =promote= is the way back in when the only
170admin key is lost.
171
164172=limits.ssh_auth_rate= (10) throttles per-IP authentication *failures*
165173per minute — successful auths never count and clear the slate.
166174=limits.max_pack_bytes= is enforced as =receive.maxInputSize= on every