2.6 KiB
2.6 KiB
2026-09-11 — Forgejo/ht gitleaks + *enc.git Klartext-Sperre (TODO320)
Status: live on koopa Forgejo (koopa-forgejo / git.hacktivism.ch)
Freigabe: Auftrag TODO=320 this session (host mutation ht)
Analog: firefly/taler admin-log/firefly/28-gitolite-enc-gitleaks.md + hooks/common/pre-receive.d-gitleaks
Tip: k stays 319 (no tip-advance)
What
- gitleaks pre-receive on non-
*enc.git— reject pushes with detected secrets. - Skip
*enc.gitfor gitleaks (ciphertext / FP). git-crypt-enforceon*enc.git— require.gitattributes+.git-crypt/; reject blobs underfilter=git-cryptmissing\0GITCRYPT(9-byte header).
Live paths (koopa)
| Item | Path |
|---|---|
| Data root | ~/koopa-forgejo/data → container /var/lib/gitea |
| Binary | data/custom/bin/gitleaks (v8.21.2 linux_x64) |
| Shared hooks | data/custom/hooks/pre-receive.d/{gitleaks,git-crypt-enforce} |
| Smoke | data/custom/bin/smoke-todo320.sh (run inside container) |
| Per-repo | data/git/repositories/*/*.git/hooks/pre-receive.d/ → symlinks to shared hooks (container paths) |
| Staging / installer SoT | laptop PATH[llm-configs]/bin/forgejo-hooks/ + koopa ~/koopa-forgejo/hooks-staging/ |
Installer: install-hooks-ht.sh (idempotent; podman; does not restart container).
After install: ~32 repos linked. New repos: re-run installer (custom/hooks alone not relied on for auto-sync into every bare repo).
Smoke (Done-when a/b/c) — PASSED 2026-09-11
podman exec koopa-forgejo /var/lib/gitea/custom/bin/smoke-todo320.sh
# ALL SMOKES PASSED
# (a) secret push denied — private-key fixture (not AWS EXAMPLE keys)
# (b) enc ciphertext allowed
# (c) enc plaintext denied
Fixes needed during smoke: park incoming objects on refs/tmp/* (not refs/heads/*, else rev-list tip --not --branches is empty); magic check head -c 9 for \0GITCRYPT.
Rollback
# Per repo or all: remove custom hooks from pre-receive.d (keep Forgejo `gitea` hook)
rm -f ~/koopa-forgejo/data/git/repositories/*/*.git/hooks/pre-receive.d/gitleaks
rm -f ~/koopa-forgejo/data/git/repositories/*/*.git/hooks/pre-receive.d/git-crypt-enforce
# Optional: remove shared copies under data/custom/hooks/pre-receive.d/
Ops notes
- Use podman (not docker sock) for
koopa-forgejo. - Symlink targets must be container paths (
/var/lib/gitea/custom/...). - Hook logs redact via gitleaks
--redact; do not echo secrets. - Laptop SSH:
Host git.hacktivism.chProxyJump koopa, Port 9200, User git. - Local SoT scripts:
$HOME/git/llm/llm-configs/bin/forgejo-hooks/.