irongit

Command line

ig

One static binary for x86_64 Linux. It signs you in, creates and manages repositories and images, and acts as the credential helper for both git and docker, so you never paste a token into either.

Install

curl -fsSL https://this-site/install.sh | sh

The script downloads the newest release, checks its SHA-256, installs it to ~/.local/bin/ig and adds the docker-credential-ig link docker needs. Prefer to do it by hand? Download /download/ig, make it executable and put it on your PATH. Later, ig upgrade keeps it current.

First login

$ ig login --host https://this-site
First copy your one-time code: BCDF-GHJK
Then open https://this-site/login/device?code=BCDF-GHJK and approve it.
Waiting for approval...
โœ“ Logged in to https://this-site as you
โœ“ git uses ig for https://this-site credentials
โœ“ docker uses ig for this-site

The browser page shows which machine is asking and what the token can do. After you approve, git clone, git push, docker push and docker pull against this server just work. On a machine without a browser, create a token in Settings and run ig login --with-token < token.txt.

Signing in

ig keeps one token per server in ~/.config/irongit/config.toml (mode 0600).

ig login --host URLSign in through the browser with a one-time code, save the token, and set up the git and docker credential helpers.
ig login --with-tokenRead an existing personal access token from stdin instead (for CI and servers without a browser).
ig login --skip-setupSign in without touching ~/.gitconfig or ~/.docker/config.json.
ig logoutForget the token for the current server and revoke it there.
ig auth statusWhich servers you are signed in to, as whom, with which scopes, and whether the helpers are set up.
ig auth tokenPrint the current token, e.g. for curl.
ig auth setup-gitMake git ask ig for credentials for this server (HTTPS clone, fetch, push).
ig auth setup-dockerPoint docker at docker-credential-ig for this server's registry.

Repositories

Wherever a repository is expected you can write owner/name, or just name for your own.

ig repo create NAME [--org ORG] [--public] [-d TEXT]Create a repository. Private unless you pass --public.
ig repo list [OWNER]Repositories of a user or organization that you can see (default: yours).
ig repo view REPOClone URLs, default branch, size, last push and your access level.
ig repo clone REPO [DIR] [--ssh]Clone over HTTPS with ig's credentials, or over SSH with your key.
ig repo visibility REPO public|privateChange who can see and clone the code. Images keep their own setting.
ig repo edit REPO [-d TEXT] [--default-branch B] [--archive|--unarchive]Change the description or default branch, or make the repository read-only.
ig repo delete REPO --yesDelete the repository and its history.
ig repo collab list REPOPeople with access besides the owner.
ig repo collab add REPO USER [--permission read|write|admin]Give someone access (default write).
ig repo collab remove REPO USERTake access away. Collaborators can also remove themselves.

Container images

Images are named owner/name or owner/path/name. A registry host prefix and :tag are accepted and ignored where they don't apply.

ig image list [OWNER]Images of a user or organization (default: yours) with tag and pull counts.
ig image tags IMAGETags with digests and sizes.
ig image visibility IMAGE public|privateAllow anonymous pulls, or require a token. Independent of any linked repository.
ig image delete IMAGE:TAG --yesDelete one tag.
ig image delete IMAGE --yesDelete the image and every tag. Unused layers are cleaned up afterwards.

SSH keys

ig ssh-key add [FILE] [--title T]Upload a public key (default ~/.ssh/id_ed25519.pub, then id_ecdsa.pub, id_rsa.pub).
ig ssh-key listYour keys with fingerprints and when each was last used.
ig ssh-key remove IDDelete a key.

Access tokens

Scopes: repo (git and repositories), packages (images), user (profile, keys, tokens, organizations), admin (site admins only). A token can only create tokens with scopes it has itself.

ig token create NAME [--scopes repo,packages] [--expires-days N]Create a token. The secret is printed once.
ig token listYour tokens, their scopes and last use.
ig token revoke IDRevoke a token immediately.

Organizations

Owners manage members and everything the organization owns; members can create and push to its repositories and images.

ig org create NAME [--display-name TEXT]Create an organization with you as its owner.
ig org listOrganizations you belong to and your role.
ig org members ORGWho is in it.
ig org add ORG USER [--role member|owner]Add someone or change their role.
ig org remove ORG USERRemove someone. You can always leave; the last owner cannot.

Everything else

ig api METHOD PATH [-d JSON|-]Call the JSON API directly, e.g. ig api GET user or ig api PATCH repos/you/app -d '{"description":"x"}'.
ig upgrade [--check] [--force]Replace ig with the newest release from the server, verified by SHA-256.
ig --json ...Machine-readable output for list and view commands.
ig --versionThe installed version.

Environment

IG_HOSTServer to use instead of the saved default (same as --host).
IG_TOKENToken to use instead of the saved one, handy in CI.
IG_CONFIG_DIRDirectory holding config.toml (default ~/.config/irongit).
IG_INSTALL_DIRWhere install.sh puts ig (default ~/.local/bin).
NO_COLORDisable colored output.

Every command exits non-zero on failure and prints the server's reason, so ig is safe to use in scripts. Add --json to get output you can pipe to jq.