Task # Transfer full Git history (all branches, tags, etc) to Bitbucket so that development can continue from there
User setup # List all keys in Gitolite must have access to Gitolite admin interface cd $ADMIN_HOME/pensieve/PRJ-admin/gitolite-admin ➜ gitolite-admin git:(master) ll keydir total 144K -rw-r--r-- 1 miro 401 Jun 29 2015 alter.pub -rw-r--r-- 1 miro 397 Jun 29 2015 codereview.pub -rw-r--r-- 1 miro 400 Apr 18 2016 hybris.pub -rw-r--r-- 1 miro 400 Apr 19 2016 hybris2.pub -rw-r----- 1 miro 398 Mar 30 2016 irae.pub ... DELETED ... -rw-r--r-- 1 miro 401 Jun 29 2015 miro.pub -rw-r--r-- 1 miro 411 Jun 29 2015 tkuser.jenkins0.pub -rw-r--r-- 1 miro 411 Jun 29 2015 tkuser.jenkins2.pub These will be split to 5 usergroups
This documents how to enforce the Gitolite permission to make LIVE branch writeable only by team leads
How gitolite works # Repository permission structure # This is general format of repo definition
REPO NAME rule line rule line for example
@staff = dilbert alice wally bob repo foo RW+ = dilbert # line 1 RW+ dev = alice # line 2 - = wally # line 3 RW temp/ = @staff # line 4 R = ashok # line 5 The Rule line has format:
How to setup new client # You need to be pensieve admin to do this. You will have to login as service user (non-host account) and su to root.
create new Linux user on pensieve setup gitolite: git clone <git://github.com/sitaramc/gitolite> mkdir bin; export PATH=$PATH:~/bin gitolite/install -ln add own public key to gitolite to get access to gilotile-admin repo (note the naming restrictions!!) gitolite setup -pk miro.pub get public key for the client account admin and add it (there can be multiple admins) clone the gitolite-admin repo from workstation whose pub key was added git clone <client@pensieve.thinkwrap>.[com:gitolite-admin.git](http://comgitolite-admin.git/) add the key to the repo cd gitolite-admin cp ~/mykey.pub keydir vim conf/gitolite conf add the newly added account admit to repos, create new repos if required All gitolite installs are independent so modification in one hosting user have zero impact on others.
General setup of code sharing host # The code sharing host (Pensieve) is dedicated Linux server in DMZ, accessible from external locations as well as from internal network (dual homed) - for the build server access.
Main features # multiple users each user represent a client: e.g. users client1 Users are separated by Unix permissions: # access rights to /home/USER are 0700 - no access except the dedicated user only ThinkWrap has root access or sudo access the access via ssh for the user is blocked - the user client1 cannot log in using ssh and get shell, only use git to pull or push changes Inside each user, there are multiple projects. # These projects will have multiple repositiories and will follow the naming convention: