PRIVATE GIT, SELF-HOSTED

Less to operate

A headless
Git host that
doesn’t
become a job.

Gith hosts private repositories on your own server using ordinary Git clients. One Go binary adds identity, access control, and an audit trail, then gets out of the way.

GO / SERVERgithone binary
OpenSSH+Gith+system Git
PRIVATE REPOSITORIESORDINARY GIT CLIENTSVERSIONED ACCESS POLICYAUDIT EVERY DECISION
01 / WHAT GITH ISA NARROWER KIND OF GIT HOST

Hosting, not a forge

The Git part.
On purpose.

Gith is server software for people who want to own their repositories and access policy, but do not need a GitHub-style product around them.

GITH GIVES YOU

Private repository hosting

  • Clone, fetch, archive, and push over SSH
  • Authenticated clone and fetch over smart HTTPS
  • Rules for repositories, people, groups, and Git references
  • A correlated, secret-free JSONL audit trail
GITH DOES NOT TRY TO BE

A collaboration platform

  • No browser dashboard, pull requests, issues, or CI
  • No Gith-specific desktop or command-line client
  • No database or always-running Gith service
  • No bundled SSH server or reimplementation of Git

A good fit when: Git transport and controlled access are the product you need—not the beginning of another platform.

02 / HOW A REQUEST WORKSONE REQUEST · ONE DECISION

A gate in front of Git

Check.Record.Run Git.

Your Git client connects over SSH, or over authenticated HTTPS for reads. OpenSSH or Apache starts Gith for that request. Gith identifies the principal, checks one immutable policy generation, records its decision, and hands the allowed operation to the server’s Git executable. Then the Gith process exits.

02 / GITH DECISION RECORDREQUEST / 8F2A
POLICY GENERATION / 71C2FIRST MATCHING RULE
  1. 01 / CLONE$ git clone git@host:org/apiPACK RECEIVED
  2. 02 / PUSH$ git push origin mainREQUEST / 8F2A
  1. 01identity bound
  2. 02policy matched
  3. 03intent recorded
AUTHORIZATION DECISION ALLOW

alice may push to org/api

IDENTITY
principal:alice
CAPABILITY
fast-forward
EVIDENCE
intent recorded
PROCESS RESULT / SUCCESSmain fast-forwardedexit 0 · 1096ms

DENY · NO MATCH · FAILED INTENT WRITESYSTEM GIT NEVER STARTS

03 / HOW ADMINISTRATION WORKSMAIN @ 71C2

No separate administration product

Change access
by pushing
a commit.

The special gith-admin repository is the control plane. An administrator clones it with Git, edits keys and conf/gith.conf, commits, and pushes main.

Gith validates the whole proposed state before activating it. A bad key, rule, or repository leaves the previous known-good generation active and returns a source-located error.

4fa171c2next
conf/gith.conf
01# identities and repository sets
02principal alice
03principal release-bot
04repository-set platform = repository:org/api repository:org/web
05
06allow read repository-set:platform principal:release-bot
07deny force-update repository:org/api all-principals
first matching rule decidesNO MATCH → DENY
06 PRECISE CAPABILITIES
  1. read
  2. create-repository
  3. create-reference
  4. fast-forward
  5. force-update
  6. delete-reference
04 / HOW REPOSITORIES BEGINPERSONAL NAMESPACE

No create-repository screen

First push in.
Private repo
out.

$ git push git@host:alice/sketch main
authorize→stage safely→alice/sketch.git PRIVATE

If Alice is allowed to create alice/sketch, that eligible first push stages and publishes a bare repository. Only Alice can access it until an administrator grants someone else a capability. A denied or interrupted push leaves no partial repository behind.

05 / WHAT FAILURE LOOKS LIKEAUDIT.JSONL

Evidence before action

No intent record?
No Git.

Every accepted or denied operation has a request ID that connects its intent and outcome. Gith writes the intent before it starts system Git. If that write fails, the operation does not begin.

request / 8f2aprincipal:aliceALLOW
09:41:08.021intentread · org/apirecorded
09:41:08.024git.upload-packchildstarted
09:41:09.117outcome1096mssuccess
SECRET-FREECORRELATEDAPPEND-ONLY
INVALID POLICY → PREVIOUS GENERATION STAYS ACTIVEFAILED FIRST PUSH → STAGING REMOVEDADMIN LOCKOUT → RECOVERY CREATES AN AUDITED COMMIT
06 / WHERE GITH COMES FROMGITOLITE v3.6.15 → GITH

Proven behavior, new implementation

Gitolite roots.
Go runtime.
Gith rules.

Gith is a behavioral port of a fixed Gitolite v3.6.15 release. It keeps a proven server-side model, but gives it an explicit Gith vocabulary and an implementation designed for Go.

THE ROOTS IT KEEPS

A known hosting model

Forced SSH commands, administration through a special Git repository, short-lived processes for each request, and ordered authorization behavior all come from the selected Gitolite baseline.

WHAT GITH MAKES ITS OWN

A smaller, typed surface

Gith uses its own names, six explicit capabilities, Go-native module boundaries, immutable policy generations, and no general extension system. It is not a drop-in Gitolite replacement.

HOW THAT CLAIM IS CHECKED

A fixed conformance oracle

Development tests compare observable behavior with Gitolite v3.6.15 at commit 782b05f. Gitolite and Perl are development references; neither is a Gith production dependency.

07 / GET STARTEDSUPPORTED HOST · UBUNTU 26.04 LTS · AMD64 / ARM64

The shape of a first installation

Empty host.
Admin key.
First push.

Gith runs under a dedicated Unix hosting account and composes with the host’s packaged Git and OpenSSH. The bootstrap guide covers installing the executable and wiring OpenSSH to the generated key file.

Once that host-level setup is complete, normal administration happens through Git.

  1. 01

    Bootstrap an administrator

    Run setup as the dedicated hosting account. The public-key filename becomes the first principal.

    $ gith setup --admin-key /path/to/alice.pub
  2. 02

    Check the gateway

    After OpenSSH uses Gith’s generated authorized_keys, connect with the administrator key.

    $ ssh git@host info
  3. 03

    Push policy, then code

    Clone gith-admin, add principals and rules, and push main. Eligible developers can then create private repositories with their first push.