21 ms·
Organizing multiple Git identities
- DistractionRect 3y agoI've seen a similar trick on HN, with some basic bash aliases: https://news.ycombinator.com/item?id=25070300 https://news.ycombinator.com/item?id=25070300
- syntaxing 3y agoHow do you store the tokens? This seems to work if it’s password based?
- rkangel 3y agoI have the email address problem, but that's the only paramter that needs to vary. I use the simplest way of handling this, which is this in my .config/git/config: [user] name = "My Name" useConfigOnly = true Then, the first time you commit in each repo, you'll get an "Author Identity Unknown" message. Then just run `git config --local user.email hello@example.com` to set the config for that repo.
- Tmpod 3y agoDidn't know about that, neat! I use multiple addresses as well and sometimes I forget to change when starting smth new. Not anymore :p
- simonkagedal 3y agoThis is what I’ve been doing for years, with some aliases to set work or personal. But honestly, I’ve started to find it annoying enough (for those first commits) to start wanting something else; yet still not annoying enough for me to research a different solution. Seeing this post, I’ll probably switch to the ”includeIf” way!
- jomar 3y agoThat is a nice trick. I've had my main email address in .config/git/config, added an override in ./.git/config for projects that need it, and checked who I am from time to time with [alias] whoami = "!f() { echo $(git config --get user.name)' <'$(git config --get user.email)'>'; }; f" but I might switch to your less error-prone approach.
- l72 3y agoHow do people handle multiple git identities with github+ssh? Since you always log in as the `git` user, you can't reuse keys. I end up with an ~/.ssh/config like: Host github-client1 Hostname github.com User git IdentityFile ~/.ssh/id_rsa-client1 Host github-client2 Hostname github.com User git IdentityFile ~/.ssh/id_rsa-client2 Then clone using `git clone git@github-client1:username/repo.git` Is there a better way?
- Macha 3y agoThis is what I do. If you wanted to have it all in your git config, you could set core.sshCommand to "ssh -i ~/.ssh/id_rsa-client", maybe combined with includeIf as in the article (since it's a glob match, you could match on the github org name).
- qntmfred 3y agoI used to do it that way. Recently learned this approach put this in your ~/.gitconfig-personal [core] sshCommand = "ssh -i ~/.ssh/github_personal_ed25519" and this in your ~/.gitconfig-work [core] sshCommand = "ssh -i ~/.ssh/github_work_ed25519"
- deleted 3y ago[deleted]
- nickjj 3y agoThis is what I do too, I've written about it in detail at: https://nickjanetakis.com/blog/using-a-custom-ssh-key-to-access-a-private-git-repo https://nickjanetakis.com/blog/using-a-custom-ssh-key-to-acc... You can also set that in your `.git/config` file on a per repo basis. Additionally you can set `GIT_SSH_COMMAND="ssh -i /tmp/custom_key_ed25519 -o IdentitiesOnly=yes" git pull` to override whatever is in your global or repo config for 1 off pulls / clones as a different user.
- nine_k 3y agoThis is indispensable when you have to clone a repo, so no config settings based on being inside a repo do not apply.
- perdjesk 3y agoCheck the following comment in previous discussion about git capabilities to manage multiple identities to commit, authenticate and sign based on directories or remote repository URL. https://news.ycombinator.com/item?id=36800853 https://news.ycombinator.com/item?id=36800853
- javier_e06 3y agoI use podman containers with lazydocker. https://github.com/jesseduffield/lazydocker https://github.com/jesseduffield/lazydocker That way my work is a bit more separated. Good tips.
- firloop 3y ago> This trick has simplified my project onboarding quite a bit. No more "You forgot to update your Email Address" requests from clients! Does this happen in practice? Most commits on professional git repos that I work on are of the form <username>@users.noreply.github.com.
- avgcorrection 3y agoI think the noreply email behavior on Github is a bit strange. I commit with my newer email. Then it gets merged to the upstream I was making a pull request in. Then it seems that the committer's (me) email is that noreply email. And then my author email gets rewritten to my old email (the one registered on GitHub first—but both are registered on GitHub). (Why does it much with my emails... I'm just wondering out loud.)
- jomar 3y agoProbably the older email address is still the primary one for the GitHub account. GitHub took it upon themselves to change email addresses and author names when merging via the UI buttons like "Squash and Merge" in 2018 and then again in 2019. See <https://github.com/isaacs/github/issues/1368 https://github.com/isaacs/github/issues/1368> for the tedious details. Essentially the post-2019 behaviour seems to be that where possible with "Squash and Merge" they will set noreply@github as the committer so that they can sign the merged commit themselves, and set author name & email to what they have recorded for the GH account involved (and the signature is then a record that GH have verified that account's involvement). Personally I think it is shocking that they ignore the name and email address that the actual author of the commit has selected. This is both a violation of the author's intentions -- for example, you may set work and personal email addresses in different repositories as discussed here, but GitHub will rewrite them all to the same thing when other people press "Squash and Merge" on your pull requests -- and potentially a doxxing security risk. I have considered re-reporting this to GitHub via the newer community discussions or via support again, but given the extent to which they've ignored all such reports over the last five years it is hard to find the motivation to do so.
- 3y ago
- ruined 3y agothat conditional include is nice, didn't know about that. i've been using direnv to set env vars, but i'll probably switch to the conditional include.
- lsaferite 3y agoI find the usage of the .envrc files better because it allows for more than just git config. I use it for loading all manner of org-specific information. I'm sure there's a way to configure the ssh keys using this approach as well, but I've yet to take the time to figure it out.
- pyrolistical 3y agoAnd here I am modifying each .git/config by hand like a pleb
- simpaticoder 3y agoI don't see what's wrong with .git/config. If anything, it's better because it keeps data close to where it is used. The only benefit to centralized config is that every git identity is in one place. But that may not be desirable, e.g. in the case you have MANY repos and identities.
- chungy 3y agoThat's also where the `git config` command gets/sets things by default when you don't pass --global.
- dmarinus 3y agoNice git feature, I just configure my identities in .git/config (per repository).
- vindex10 3y agoI find one disadvantage of SSH key auth, in case of GitHub in particular, that SSH key grants access to all the repos independently on the organization, etc, which becomes a bigger problem when sharing the machine with other people. One can set a password on the ssh key, but I still felt a bit paranoid about it. I found a way out with fine-grained personal access tokens which allow you to choose the repositories this token will have access to [1]. My setup consists of two ingredients: 1. GPG encrypted fine-grained PAT: `gpg -c --no-symkey-cache --pinentry-mode loopback my_name` ends up into `my_name.gpg` secret. 2. A git credential configuration which is generic across git repositories: [credential "https://oauth2@github.com"] helper = "!f() { test \"$1\" = get && echo \"password=$(gpg -d --pinentry-mode loopback --no-symkey-cache $_GITHUB_TOKEN)\"; }; f" Now switching identities results into setting the env var `$_GITHUB_TOKEN` to the path to my gpg encrypted token, which will be decrypted by git on the fly. You can figure out a suitable way to alias this for yourself :) And it only activates for git urls of the from "oauth2@github.com" which allows you to clone public repos without questions. Another advantage is that you can share the same repo with other people, no need to maintain a copy. Disadvantage is that you have to enter password each time you push/pull. [1] https://github.blog/2022-10-18-introducing-fine-grained-personal-access-tokens-for-github/ https://github.blog/2022-10-18-introducing-fine-grained-pers...
- tjoff 3y ago> I find one disadvantage of SSH key auth, in case of GitHub in particular, that SSH key grants access to all the repos independently on the organization, etc. Doesn't the article fix exactly that?
- vindex10 3y agomy concern is not the configuration of gitconfig, but keeping the "escalated" ssh keys on the shared machine if I understood correctly, the article suggests the way how to choose ssh key among those already stored on the server
- atoav 3y ago> Disadvantage is that you have to enter password each time you push/pull. Run ssh-add in your terminal session before doing your push/pull dance — this way you only have to enter the password once. This gives you the security of the password protected key without bothering you too much in practise. If you need to pull on a remote that doesn't have your private keys (as is good and proper) you can run ssh -A foo@bar.com to take that identity with you onto that remote (e.g. so you are able to pus/pull from there).
- mlegendre 3y agoBeware that the trailing slash in the string after `gitdir` is significant! This string is a globbing pattern (it is not obvious at first sight, and seldom mentioned), and the trailing slash implies `**` [1]. So if you type "gitdir:~/work" instead of "gitdir:~/work/", you will lose some time wondering why your configuration is ignored. [1]: https://git-scm.com/docs/git-config#_conditional_includes https://git-scm.com/docs/git-config#_conditional_includes
- cquintana92 3y agoShameless plug of a tool I wrote for managing multiple git identities: https://github.com/cquintana92/git-switch-user https://github.com/cquintana92/git-switch-user
- dolmen 3y agoSee also https://github.com/dolmen/github-keygen https://github.com/dolmen/github-keygen
- psnehanshu 3y agoRecently I tried to work on two projects that required different git credentials for push/pull. I ended up using basic auth with HTTPS with one repo, and the other on SSH.
- thamer 3y agoI use conditional includes for this, but I also add a single letter describing which Git identity I'm currently using to my PS1 so that it appears before $ in my shell prompt. This prevents me from committing code with the wrong identity, in case I'm using a git checkout that's anywhere not covered by the conditional include rules. I use Starship (https://starship.rs https://starship.rs) to manage my prompt, and wrote a short script that only runs if I'm somewhere in a git repo, and if so finds my Git user's email and looks up the corresponding letter in an associative array declared in my ~/.config/starship-zsh/.zshenv: git_email=$(git config --get user.email | perl -pe 'chomp if eof') letter=$STARSHIP_GIT_USERS[$git_email] echo -n $letter It's installed like this: [custom.git_user] command = "ZDOTDIR=~/.config/starship-zsh /path/to/the-script-above.sh" # set ZDOTDIR, makes zsh load the .zshenv file when = "git rev-parse --git-dir >/dev/null 2>/dev/null" # only run if we're in a git repo format = ' $output' The .zshenv file contains the STARSHIP_GIT_USERS variable and its values, with a `declare -A` since it's an associative array.
- alana314 3y agois there something similar for aws identities?
- hk1337 3y agoI normally just use aws profiles and the aws plugin in oh-my-zsh. I can easily run "acp <profile_name>" to authenticate me on a particular profile. https://github.com/ohmyzsh/ohmyzsh/tree/master/plugins/aws https://github.com/ohmyzsh/ohmyzsh/tree/master/plugins/aws
- dolmen 3y agoRelated: my own project to handle SSH keys for GitHub: https://github.com/dolmen/github-keygen https://github.com/dolmen/github-keygen The project might not look active, but that's because it just works. 12 years old now.
- joaquincabezas 3y agoI found this a few years ago at https://stackoverflow.com/questions/14754762/can-gitconfig-options-be-set-conditionally/59184292#59184292 https://stackoverflow.com/questions/14754762/can-gitconfig-o... and has been my preferred setup.
- dlahoda 3y agonixos solves private keys and tools switch easy. for folders, i ended up with overlays. just follow origin upstream remote locally so that http and file united. i mean if remote is https github com slash dzmitry lahoda slash web3.nix than local is /home/dz/github com slash dzmitry lahoda slash web3.nix navigation is easy. forks easy. no project1 or client 1. just navigation overlay. same works for consumption of knowledge and learning. one may do codespace with nix easy too or many local homes. nix and path overlays is superior and easy to maintain. nix makes remote, local, ci, codespace, user switch, depending on dlmany versions of same repo super easy. even by unix idiots like me. that not full schema so. there are tags and data properties (security, size, files count, uniquiness of copy). so decide if store local or remo only, git and syncthing same time, torrent and syncthing, gdrive and git, keepass and syncthing, what devices, ipfs. any combo. tags when overlays (forced hierarchy fail). when git forks, than many remotes with overlay following most active fork. that approach partially fixes some of my mental issue i guess. oh, i want to install zfs to fix duplication. hardware keys for security i use also. thesd days can mix same key, but held ssh, crypto, aws creds on same device.
- stevefan1999 3y agoI also want this, but on a folder level I have a github.com folder with all the repos I cloned from GH but I always have to type git config user.name/email before committing. It's so annoying at this point.
- dataflow 3y agoYou could try overriding 'git' in your PATH with a shell script wrapper that prepends something like -c user.name=yourname before the rest of the command, or that runs git config if it hasn't been run yet, etc. (whatever makes sense for your case)