koopa-admin-log/2026/2026-09-11--forgejo-gitleaks-enc-gate.md

2.6 KiB

2026-09-11 — Forgejo/ht gitleaks + *enc.git Klartext-Sperre (TODO320)

Status: live on koopa Forgejo (koopa-forgejo / git.hacktivism.ch)
Freigabe: Auftrag TODO=320 this session (host mutation ht)
Analog: firefly/taler admin-log/firefly/28-gitolite-enc-gitleaks.md + hooks/common/pre-receive.d-gitleaks
Tip: k stays 319 (no tip-advance)

What

  1. gitleaks pre-receive on non-*enc.git — reject pushes with detected secrets.
  2. Skip *enc.git for gitleaks (ciphertext / FP).
  3. git-crypt-enforce on *enc.git — require .gitattributes + .git-crypt/; reject blobs under filter=git-crypt missing \0GITCRYPT (9-byte header).

Live paths (koopa)

Item Path
Data root ~/koopa-forgejo/data → container /var/lib/gitea
Binary data/custom/bin/gitleaks (v8.21.2 linux_x64)
Shared hooks data/custom/hooks/pre-receive.d/{gitleaks,git-crypt-enforce}
Smoke data/custom/bin/smoke-todo320.sh (run inside container)
Per-repo data/git/repositories/*/*.git/hooks/pre-receive.d/ → symlinks to shared hooks (container paths)
Staging / installer SoT laptop PATH[llm-configs]/bin/forgejo-hooks/ + koopa ~/koopa-forgejo/hooks-staging/

Installer: install-hooks-ht.sh (idempotent; podman; does not restart container).
After install: ~32 repos linked. New repos: re-run installer (custom/hooks alone not relied on for auto-sync into every bare repo).

Smoke (Done-when a/b/c) — PASSED 2026-09-11

podman exec koopa-forgejo /var/lib/gitea/custom/bin/smoke-todo320.sh
# ALL SMOKES PASSED
# (a) secret push denied — private-key fixture (not AWS EXAMPLE keys)
# (b) enc ciphertext allowed
# (c) enc plaintext denied

Fixes needed during smoke: park incoming objects on refs/tmp/* (not refs/heads/*, else rev-list tip --not --branches is empty); magic check head -c 9 for \0GITCRYPT.

Rollback

# Per repo or all: remove custom hooks from pre-receive.d (keep Forgejo `gitea` hook)
rm -f ~/koopa-forgejo/data/git/repositories/*/*.git/hooks/pre-receive.d/gitleaks
rm -f ~/koopa-forgejo/data/git/repositories/*/*.git/hooks/pre-receive.d/git-crypt-enforce
# Optional: remove shared copies under data/custom/hooks/pre-receive.d/

Ops notes

  • Use podman (not docker sock) for koopa-forgejo.
  • Symlink targets must be container paths (/var/lib/gitea/custom/...).
  • Hook logs redact via gitleaks --redact; do not echo secrets.
  • Laptop SSH: Host git.hacktivism.ch ProxyJump koopa, Port 9200, User git.
  • Local SoT scripts: $HOME/git/llm/llm-configs/bin/forgejo-hooks/.