Headless by design
The headless
Git host.
One Go binary between identity and Git. No dashboard to tend, no custom client to install, and no resident service waiting around.
git push git@host:alice/project main$ gith setup --admin-key alice.pubOne job, done completely
You bring the connection.
Gith holds the boundary.
Every request follows the same narrow path: establish who is asking, decide whether that exact Git operation is allowed, record the intent, and hand it to system Git.
alice@laptop
- 01bind principal
- 02read one policy
- 03record intent
- 04execute Git
fast-forward
The control plane is a Git repository
Policy moves
the way code does.
Keys, principals, groups, repository sets, and authorization rules live in gith-admin. Review a diff. Push a commit. Activate one complete generation.
01# people and automation are principals
02principal alice
03principal release-bot
04
05allow read repository-set:platform
06 principal:alice
07
08allow fast-forward repository:org/api
09 principal:release-bot reference:^refs/heads/release$
10
11deny force-update repository:org/api
12 all-principals reference:^refs/heads/main$
- 01readclone · fetch · archive
- 02create-repositoryfirst eligible push
- 03create-referencenew branch or tag
- 04fast-forwardadvance history
- 05force-updaterewrite history
- 06delete-referenceremove branch or tag
Fail closed
If Gith cannot prove the request is allowed and record its intent, the operation stops.
People, CI, or AI
An agent is just another principal. Give it a key or credential, narrow its repository and reference capabilities, and keep the same audit trail.
Same Git.Smaller blast radius.
The whole stack
OpenSSH / Apache+Gith+system Git
One binary. Ordinary protocols. Explicit policy.