Expand description
Fetching an app’s git source on the host, hardened for an untrusted repository.
The daemon runs git itself (the checkout is what a build reads), so git is held to what a fetch and a checkout need:
- no hooks (
core.hooksPath=/dev/null), nofile://orext::transports, no local paths, no submodules unless the app asks; - no system or global config, no terminal prompts, a bounded run time, and an environment cleared down to what git and ssh need;
- credentials never in argv: a token travels as an
http.extraHeaderscoped to the repository’s origin, set throughGIT_CONFIG_*in the environment; an SSH key is a 0600 file that exists for one git call, with a per-appknown_hosts.
Structs§
Enums§
- Credentials
- Credentials resolved for one fetch.
- GitAuth
- Credentials for a git source, by the name of an org secret holding them.
- Transport
- How a URL reaches its repository.
Constants§
- GIT_
TIMEOUT - How long one git command may run.
Functions§
- fetch
- Fetch
srcintodir(<sources>/<app>) and check out the exact commit its ref names now. - generate_
deploy_ key - A new ed25519 deploy key:
(private OpenSSH key, public key line), made byssh-keygenin a 0700 directory that is removed afterwards. - is_sha
- redact
- The URL without any userinfo, for logs.
- ssh_
command sshwith exactly this key and this known_hosts, never prompting.- transport
- The transport of an allowed URL. Local paths,
file://,ext::and anything that could read as an option are refused. - validate_
ref - A branch, tag or SHA, as git’s check-ref-format would take it, minus anything that could read as an option.
- validate_
subdir - A relative path inside the checkout, never escaping it.