I have to push from first server to second (yeah, the names are great
:o) when ever someone pushes to first server. It should be done using
post-receive hook, for example. The problem is that I can not specify ssh
key, and even if I could, anything but 600 perm for the key is rejected.
What would be the best way to acomplish this? Thanx!
--
FreeB(eer)S(ex)D(rugs) are the real daemons
From: Andreas Ericsson <hidden> Date: 2016-06-15 22:48:52
On 05/28/2010 08:57 AM, Goran Mekić wrote:
I have to push from first server to second (yeah, the names are great
:o) when ever someone pushes to first server. It should be done using
post-receive hook, for example. The problem is that I can not specify ssh
key, and even if I could, anything but 600 perm for the key is rejected.
What would be the best way to acomplish this? Thanx!
Why can't you specify ssh key, and why can't you set the key to have perms
0600 and let it reside in a directory with perms 0700?
The post-receive hook is just a shell-script, basically.
--
Andreas Ericsson andreas.ericsson@op5.se
OP5 AB www.op5.se
Tel: +46 8-230225 Fax: +46 8-230231
Considering the successes of the wars on alcohol, poverty, drugs and
terror, I think we should give some serious thought to declaring war
on peace.
On Fri, 28 May 2010 11:15:17 +0200, Andreas Ericsson [off-list ref] wrote:
On 05/28/2010 08:57 AM, Goran Mekić wrote:
quoted
I have to push from first server to second (yeah, the names are
great
:o) when ever someone pushes to first server. It should be done using
post-receive hook, for example. The problem is that I can not specify
ssh
quoted
key, and even if I could, anything but 600 perm for the key is
rejected.
quoted
What would be the best way to acomplish this? Thanx!
Why can't you specify ssh key, and why can't you set the key to have
perms
0600 and let it reside in a directory with perms 0700?
The post-receive hook is just a shell-script, basically.
There's more then one developer and 600 is set to just one user.
Post-receive hook is executed as developer doing push. The accounts are in
LDAP, but I can't set all their UID number to same number because it's
used
for PAM. I was thinking about ACL. Is that even a solution? The dumb one
would be cron, but I wish I avoid pushing when there's no change.
--
FreeB(eer)S(ex)D(rugs) are the real daemons
There's more then one developer and 600 is set to just one user.
Post-receive hook is executed as developer doing push. The accounts are in
LDAP, but I can't set all their UID number to same number because it's
used
for PAM. I was thinking about ACL. Is that even a solution? The dumb one
would be cron, but I wish I avoid pushing when there's no change.
What about having a script which does the push have setuid to the owner of the key. Then the post-receive hook can invoke that script which will have access to the ssh key to do the push.
--
BJ
There's more then one developer and 600 is set to just one user.
Post-receive hook is executed as developer doing push. The accounts are in
LDAP, but I can't set all their UID number to same number because it's
used
for PAM. I was thinking about ACL. Is that even a solution? The dumb one
would be cron, but I wish I avoid pushing when there's no change.
What about having a script which does the push have setuid to the owner of the key. Then the post-receive hook can invoke that script which will have access to the ssh key to do the push.
That should work.
another option would be, that the post receive hook copies the ssh-key
file, changes its permission andcontinues only then to push.
If all users have ssh access to first server AND to second server and
all users use ssh-agent, then all users had just to make sure, that they
do agent forwarding in their .ssh/config script.