|
| name | last commit | updated |
| Containerfile.ci |
deploy: Containerfile.ci comment stages the file before podman build |
28 days ago |
| audit.sh |
Security hardening: fuzzing, headers, threat model, host sandbox |
1 month ago |
| clonebench.sh |
gitbayd: one pack-generation limit for SSH, HTTP and git:// |
10 days ago |
| cloud-init.yaml |
docs: restore puts the secret key file back before starting gitbayd |
10 days ago |
| copy.sh |
deploy: one copy helper, so neither target assumes rsync |
1 month ago |
| gitbay-runner-builds.nft |
runner host: build egress by cgroup, narrower for untrusted builds |
9 days ago |
| gitbay-runner-egress.nft |
runner host: build egress by cgroup, narrower for untrusted builds |
9 days ago |
| gitbay-runner-egress.service |
runner host: flood test asserts the table's effect; exact rollback of the builds table |
9 days ago |
| gitbay-runner-prune.service |
deploy: install the image prune timer with the runner |
1 month ago |
| gitbay-runner-prune.timer |
deploy, wiki: prepare a runner host for rootless podman |
1 month ago |
| gitbay-runner.override.conf |
runner host: build egress by cgroup, narrower for untrusted builds |
9 days ago |
| install.sh |
deploy, wiki: provision and document the secret key file |
10 days ago |
| release.sh |
deploy: the bay1 runner claims untrusted builds; release ships gitbay-runner |
29 days ago |
| runner-auth-flood-test.sh |
deploy: the flood test adds and removes its key with gitbay auth keys |
9 days ago |
| runner-egress-check.sh |
runner egress: remove the rule when it blocks the runner's poll |
10 days ago |
| runner-podman-setup.sh |
runner host: builds reach only the forge's public ports on it |
10 days ago |