The Dangerous Convenience of Implicit Ownership
Authorization systems often become complicated one convenience at a time. Everlock ran into a good example of this while working on repository permissions. The original rule sounded harmless:
Documentation
Authorization systems often become complicated one convenience at a time. Everlock ran into a good example of this while working on repository permissions. The original rule sounded harmless:
Repositories are served over HTTPS as well as SSH, using git's standard smart HTTP protocol. Clone, fetch and push work with an unmodified git client. One backend serves three things on one host: the
The host that serves [git over HTTP](/docs/git/http) also serves a browser surface over every hosted repository — one interface for the instance, not one per repository. It comes up with the backend:
A push can start a build. Everlock speaks the runner protocol itself, so a stock [`forgejo-runner`](https://code.forgejo.org/forgejo/runner) registers against it and takes work — there is no separate
This guide runs a build on a push, locally: - start Everlock with git over HTTP, which serves the runner protocol too - create a repository and clone it over HTTP - register a `forgejo-runner` against
Pull requests look simple when a forge is doing the work for you. A contributor creates an account, forks a repository, pushes a branch, and clicks a button. The forge connects all of those pieces and
"Everything is Git" describes the architectural rule behind Everlock. This article is the more mechanical version of that idea. What does it actually mean to build application storage on top of bare G
The 0.9.0 release makes Everlock a git host: repositories are served over HTTP, browsed in a web UI, and built by CI runs that a push starts. It also replaces the two embedded AI models with one that
On most Git forges, a pull request is not really a Git object. It is an application object that happens to point at Git commits. There is usually a database row with an integer id, an author, a state,
Everlock starts with a fairly unreasonable constraint: > Everything that matters should live in Git. Not just the source code for Everlock. The data managed by Everlock. Photos. Calendars. Configurati
The 0.8.0 release adds file shares: a versioned store mounted as a network drive over WebDAV, from Finder, Windows Explorer, a Linux file manager, or `rclone`. Every change is a commit, so a share's h
A repository that collects build artifacts, uploads, or generated data grows forever, and a large file committed once keeps costing disk long after it was deleted. Everlock can bound that: a repositor