From 0fa75ea8e374b39ac80d3a5e4bed51bb392ba752 Mon Sep 17 00:00:00 2001 From: Ahmed Abdelhalim Date: Sun, 26 Jul 2026 04:20:09 +0200 Subject: Give git user its own home, separate from /srv/git MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit authorized_keys lived under /srv/git (git's $HOME), the same tree restic backs up and restores. backup couldn't even read it (0700, unreadable by the backup user), and restore --delete treated it as extraneous and deleted it, breaking push access after every restore. git now gets a normal separate home; clone-prefix in cgitrc serves the repos dir by absolute path instead of the ~-relative form, since that relied on $HOME being the repos dir. Drops the sshd_config.d Include/ Match-block/AllowUsers approach tried first — it directly conflicted with pve-lxc-ssh's sshd_config push, which fully overwrites the file on every run and has no way to know about cgit's edits. Co-Authored-By: Claude.ai --- roles/cgit/tasks/main.yml | 25 ------------------------- 1 file changed, 25 deletions(-) (limited to 'roles/cgit/tasks') diff --git a/roles/cgit/tasks/main.yml b/roles/cgit/tasks/main.yml index 16a9ab61..93b7e4e9 100644 --- a/roles/cgit/tasks/main.yml +++ b/roles/cgit/tasks/main.yml @@ -20,7 +20,6 @@ name: "{{ cgit_ssh_user }}" group: "{{ cgit_ssh_user }}" shell: "/usr/bin/git-shell" - home: "{{ cgit_repos_dir }}" create_home: true system: true password: "*" @@ -32,38 +31,14 @@ scope: system value: main -- name: "Ensure sshd_config restricts login to expected users" - become: true - ansible.builtin.lineinfile: - path: "/etc/ssh/sshd_config" - regexp: "^AllowUsers " - line: "AllowUsers root {{ cgit_ssh_user }}" - validate: "sshd -T -f %s" - notify: "Restart sshd" - - name: "Deploy authorized_keys" become: true ansible.posix.authorized_key: user: "{{ cgit_ssh_user }}" key: "{{ item }}" - path: "/etc/ssh/authorized_keys/{{ cgit_ssh_user }}" state: present loop: "{{ user_public_keys }}" -- name: "Configure sshd AuthorizedKeysFile for {{ cgit_ssh_user }}" - become: true - ansible.builtin.blockinfile: - path: "/etc/ssh/sshd_config" - marker: "# {mark} ANSIBLE {{ cgit_ssh_user }} MATCH BLOCK" - validate: "sshd -T -f %s" - block: | - Match User {{ cgit_ssh_user }} - AuthorizedKeysFile /etc/ssh/authorized_keys/%u - AllowTcpForwarding no - AllowAgentForwarding no - PermitTTY no - notify: "Restart sshd" - - name: "Create repos directory" become: true ansible.builtin.file: -- cgit v1.2.3