Private repository hosting
- Clone, fetch, archive, and push over SSH
- Authenticated clone and fetch over smart HTTPS
- Rules for repositories, people, groups, and Git references
- A correlated, secret-free JSONL audit trail
Less to operate
Gith hosts private repositories on your own server using ordinary Git clients. One Go binary adds identity, access control, and an audit trail, then gets out of the way.
Hosting, not a forge
Gith is server software for people who want to own their repositories and access policy, but do not need a GitHub-style product around them.
A good fit when: Git transport and controlled access are the product you need—not the beginning of another platform.
A gate in front of Git
Your Git client connects over SSH, or over authenticated HTTPS for reads. OpenSSH or Apache starts Gith for that request. Gith identifies the principal, checks one immutable policy generation, records its decision, and hands the allowed operation to the server’s Git executable. Then the Gith process exits.
$ git clone git@host:org/apiPACK RECEIVED$ git push origin mainREQUEST / 8F2Aalice may push to org/api
DENY · NO MATCH · FAILED INTENT WRITESYSTEM GIT NEVER STARTS
No separate administration product
The special gith-admin repository is the control plane. An administrator clones it with Git, edits keys and conf/gith.conf, commits, and pushes main.
Gith validates the whole proposed state before activating it. A bad key, rule, or repository leaves the previous known-good generation active and returns a source-located error.
01# identities and repository sets
02principal alice
03principal release-bot
04repository-set platform = repository:org/api repository:org/web
05
06allow read repository-set:platform principal:release-bot
07deny force-update repository:org/api all-principals
No create-repository screen
$ git push git@host:alice/sketch main
If Alice is allowed to create alice/sketch, that eligible first push stages and publishes a bare repository. Only Alice can access it until an administrator grants someone else a capability. A denied or interrupted push leaves no partial repository behind.
Evidence before action
Every accepted or denied operation has a request ID that connects its intent and outcome. Gith writes the intent before it starts system Git. If that write fails, the operation does not begin.
Proven behavior, new implementation
Gith is a behavioral port of a fixed Gitolite v3.6.15 release. It keeps a proven server-side model, but gives it an explicit Gith vocabulary and an implementation designed for Go.
Forced SSH commands, administration through a special Git repository, short-lived processes for each request, and ordered authorization behavior all come from the selected Gitolite baseline.
Gith uses its own names, six explicit capabilities, Go-native module boundaries, immutable policy generations, and no general extension system. It is not a drop-in Gitolite replacement.
Development tests compare observable behavior with Gitolite v3.6.15 at commit 782b05f. Gitolite and Perl are development references; neither is a Gith production dependency.
The shape of a first installation
Gith runs under a dedicated Unix hosting account and composes with the host’s packaged Git and OpenSSH. The bootstrap guide covers installing the executable and wiring OpenSSH to the generated key file.
Once that host-level setup is complete, normal administration happens through Git.
Run setup as the dedicated hosting account. The public-key filename becomes the first principal.
$ gith setup --admin-key /path/to/alice.pubAfter OpenSSH uses Gith’s generated authorized_keys, connect with the administrator key.
$ ssh git@host infoClone gith-admin, add principals and rules, and push main. Eligible developers can then create private repositories with their first push.