quotas for organizations: orgs per user, repos and bytes per org #325

closed cmc opened this on 2026-10-02 15:07 UTC · security · milestone hosting

Discussion

cmc 2026-10-02 15:07 UTC

The per-account quotas from #82 cover only user-owned repositories. org create is open to every account with no cap (runOrgCreate), and checkRepoQuota runs only when the owner is a user, so an org bypasses max_repos_per_user and max_bytes_per_user as many times as anyone likes.

  • limits.max_orgs_per_user: organizations an account may create. Counted on creation, which needs a migration: orgs does not record who created it today; existing rows are backfilled from the earliest admin membership or left null and uncounted. Joining an org created by someone else does not count against it. Default in config 0 (unlimited); gitbay.org sets 5.
  • limits.max_repos_per_org and limits.max_bytes_per_org: same enforcement as the user caps (repo create, fork, import, transfer into the org; push, repo commit-file, mr apply-suggestion against the bytes left). Default 0; gitbay.org sets 250 and 5 GB.
  • Per-org override: admin org limits <org> [--repos n|default] [--bytes n|default], shown by org show to its admins and in admin stats. krz needs one before the gitbay.org limits are set (krz/gitbay alone is 5.5 GB).
  • A per-user override for the org count: admin user limits --orgs n|default.
  • Exit 4 messages give the numbers and what to do, like the user caps.
  • Admin wiki config reference: drop "Organizations are not capped."; Parity row for admin org limits.

Ref #82

closed by cmc in commit aaf2234b85: control: quotas for organizations

2026-10-02 15:17 UTC