Commit d45142ab0b
Verified · cmc
Layout: unified · split
Admin.org +8
| @@ -145,6 +145,9 @@ gitbayd admin audit [--limit n] # host-local | ||
| 145 | 145 | ssh git@<host> audit [--limit n] # instance admins, SSH only |
| 146 | 146 | ssh git@<host> admin user list [--state active|pending|disabled|admin] |
| 147 | 147 | ssh git@<host> admin user show <name> # keys, emails, orgs, tokens, sessions |
| 148 | ssh git@<host> admin user promote <name> # grant instance admin | |
| 149 | ssh git@<host> admin user demote <name> # remove it; the last admin is refused | |
| 150 | gitbayd admin user promote <name> # host-local: recovery when no admin key is reachable | |
| 148 | 151 | gitbayd admin user disable <name> # suspend: SSH, web, API all refused; |
| 149 | 152 | gitbayd admin user enable <name> # sessions dropped, nothing deleted |
| 150 | 153 | gitbayd admin user delete <name> --yes # only for accounts anchoring nothing: |
| @@ -161,6 +164,11 @@ each address with how it was verified, PGP keys, org roles, the owned | ||
| 161 | 164 | repository count, API token names, and live browser sessions. Both are |
| 162 | 165 | SSH-only and refused to non-admins, like =audit=. |
| 163 | 166 | |
| 167 | Promotion needs an active account: a pending or disabled one is refused. | |
| 168 | Demotion is refused when it would leave no admin, over SSH and on the | |
| 169 | host alike, so the host-local =promote= is the way back in when the only | |
| 170 | admin key is lost. | |
| 171 | ||
| 164 | 172 | =limits.ssh_auth_rate= (10) throttles per-IP authentication *failures* |
| 165 | 173 | per minute — successful auths never count and clear the slate. |
| 166 | 174 | =limits.max_pack_bytes= is enforced as =receive.maxInputSize= on every |