Skip to main content

Module git

Module git 

Source
Expand description

Fetching an app’s git source on the host, hardened for an untrusted repository.

The daemon runs git itself (the checkout is what a build reads), so git is held to what a fetch and a checkout need:

  • no hooks (core.hooksPath=/dev/null), no file:// or ext:: transports, no local paths, no submodules unless the app asks;
  • no system or global config, no terminal prompts, a bounded run time, and an environment cleared down to what git and ssh need;
  • credentials never in argv: a token travels as an http.extraHeader scoped to the repository’s origin, set through GIT_CONFIG_* in the environment; an SSH key is a 0600 file that exists for one git call, with a per-app known_hosts.

Structs§

Checkout
What a fetch checked out.
GitSource
A git source.

Enums§

Credentials
Credentials resolved for one fetch.
GitAuth
Credentials for a git source, by the name of an org secret holding them.
Transport
How a URL reaches its repository.

Constants§

GIT_TIMEOUT
How long one git command may run.

Functions§

fetch
Fetch src into dir (<sources>/<app>) and check out the exact commit its ref names now.
generate_deploy_key
A new ed25519 deploy key: (private OpenSSH key, public key line), made by ssh-keygen in a 0700 directory that is removed afterwards.
is_sha
redact
The URL without any userinfo, for logs.
ssh_command
ssh with exactly this key and this known_hosts, never prompting.
transport
The transport of an allowed URL. Local paths, file://, ext:: and anything that could read as an option are refused.
validate_ref
A branch, tag or SHA, as git’s check-ref-format would take it, minus anything that could read as an option.
validate_subdir
A relative path inside the checkout, never escaping it.