]> dgit.raspbian.org Git - git-annex.git/commit
git-annex-shell: proxy nodes located beyond remote cluster gateways
authorJoey Hess <joeyh@joeyh.name>
Wed, 26 Jun 2024 16:56:16 +0000 (12:56 -0400)
committerJoey Hess <joeyh@joeyh.name>
Wed, 26 Jun 2024 16:56:16 +0000 (12:56 -0400)
commit07e899c9d316555a5615f272bacc8e734fef2f24
tree623d6accc3b301ce35cfb71d0a083f6c99db62b2
parent1ec2fecf3fb050df8de38b69bc14d9dcbf6b92c5
git-annex-shell: proxy nodes located beyond remote cluster gateways

Walking a tightrope between security and convenience here, because
git-annex-shell needs to only proxy for things when there has been
an explicit, local action to configure them.

In this case, the user has to have run `git-annex extendcluster`,
which now sets annex-cluster-gateway on the remote.

Note that any repositories that the gateway is recorded to
proxy for will be proxied onward. This is not limited to cluster nodes,
because checking the node log would not add any security; someone could
add any uuid to it. The gateway of course then does its own
checking to determine if it will allow proxying for the remote.
CmdLine/GitAnnexShell.hs
Command/ExtendCluster.hs
Command/UpdateCluster.hs
Command/UpdateProxy.hs
Remote.hs
Remote/Git.hs
Remote/Helper/Git.hs
Types/GitConfig.hs
doc/git-annex.mdwn
doc/todo/git-annex_proxies.mdwn