Meeting agenda bot, website, git, ssh

Joerg Jaspert joerg at debian.org
Wed Jan 21 09:06:48 UTC 2009


>> > Is there one single access control setup for the whole thing, or are
>> > there several ?  It would be nice to be able to let people edit the
>> > website without giving them the power to run code on the server, for
>> > example.
>> Noone gets access to the server directly. :)
>> (Well, in case someone needs access to a server, we can certainly
>>  arrange things. But thats completly seperate from git access)
> If the code for something running on the server is kept in git then
> effectively everyone who can write to the git can run code on the
> server, because even if pushing to the running copy is manual no-one
> will review every diff.

Are we up to splitting hairs now? :)
So, for that:

Noone except us admins has shell access to the box the git repo is on.
Yes, of course, if you can commit stuff you can commit bad things too.
Somehow thats (technically) not avoidable. Unless you want one of us
admins play gatekeeper, and *I* sure not want to add such a
restriction.

-- 
bye, Joerg
[Kaffeemaschinen und Babies]
Funktioniert aber so ähnlich: Du füllst oben was rein und unten kommt's braun raus...
   -- Martin Würtele


More information about the Spi-general mailing list