2核2G CentOS7.6.1810



[root@VM-0-17-centos ~]# dnf -y install git-all



[root@VM-0-17-centos ~]# dnf -y install dh-autoreconf curl-devel expat-devel gettext-devel openssl-devel perl-devel zlib-devel
[root@VM-0-17-centos ~]# dnf -y install asciidoc xmlto docbook2X


[root@VM-0-17-centos ~]# tar xvf git-2.9.5.tar.xz
[root@VM-0-17-centos ~]# cd git-2.9.5/
[root@VM-0-17-centos git-2.9.5]# make configure
GIT_VERSION = 2.9.5GEN configure
[root@VM-0-17-centos git-2.9.5]# ./configure --prefix=/usr
[root@VM-0-17-centos git-2.9.5]# echo $?    #检查上一个命令是否有异常
[root@VM-0-17-centos git-2.9.5]# make all doc info
make[1]: Leaving directory `/root/git-2.9.5/Documentation'
make -C Documentation info
make[1]: Entering directory `/root/git-2.9.5/Documentation'
GEN doc.dep
make[2]: Entering directory `/root/git-2.9.5'
make[2]: `GIT-VERSION-FILE' is up to date.
make[2]: Leaving directory `/root/git-2.9.5'
make[1]: Leaving directory `/root/git-2.9.5/Documentation'
make[1]: Entering directory `/root/git-2.9.5/Documentation'
make[2]: Entering directory `/root/git-2.9.5'
make[2]: `GIT-VERSION-FILE' is up to date.
make[2]: Leaving directory `/root/git-2.9.5'
DB2TEXI user-manual.texi
/bin/sh: line 1: docbook2x-texi: command not found
make[1]: *** [user-manual.texi] Error 127
make[1]: Leaving directory `/root/git-2.9.5/Documentation'
make: *** [info] Error 2

  此时可以看到会报错"docbook2x-texi: command not found",我查了一圈发现,实际上已经安装(docbook2X),这里只需要设置一个软链接。

[root@VM-0-17-centos git-2.9.5]# ln -s /usr/bin/db2x_docbook2texi /usr/bin/docbook2x-texi

  之后,重新执行"make all doc info",并继续安装

[root@VM-0-17-centos git-2.9.5]# make all doc info
[root@VM-0-17-centos git-2.9.5]# echo $?
[root@VM-0-17-centos git-2.9.5]# make install install-doc install-html install-info
[root@VM-0-17-centos git-2.9.5]# echo $?





[root@VM-0-17-centos ~]# groupadd git
[root@VM-0-17-centos ~]# useradd git -g git
[root@VM-0-17-centos ~]# passwd git
Changing password for user git.
New password: 
Retype new password: 
passwd: all authentication tokens updated successfully.


    目录空白位置右键,点击”Open Git Bash Here“,打开命令行工具。然后执行如下命令:

$ git init  #初始化仓库
Initialized empty Git repository in C:/Users/admin/Desktop/my_project/.git/admin@DESKTOP-4CERLUK MINGW64 ~/Desktop/my_project (master)
$ ll -a
total 14
drwxr-xr-x 1 admin 197121  0 Sep 28 22:23 ./
drwxr-xr-x 1 admin 197121  0 Sep 28 22:10 ../
drwxr-xr-x 1 admin 197121  0 Sep 28 22:23 .git/  #初始化成功
-rw-r--r-- 1 admin 197121 13 Sep 28 22:20 test1.txt
-rw-r--r-- 1 admin 197121 13 Sep 28 22:20 test2.sqladmin@DESKTOP-4CERLUK MINGW64 ~/Desktop/my_project (master)
$ git status    #查看状态
On branch masterNo commits yetUntracked files:    #未跟踪的文件(use "git add <file>..." to include in what will be committed)test1.txttest2.sqlnothing added to commit but untracked files present (use "git add" to track)admin@DESKTOP-4CERLUK MINGW64 ~/Desktop/my_project (master)
$ git add .  #将当前目录下所有文件进行跟踪,也可以跟随文件名进行单点添加admin@DESKTOP-4CERLUK MINGW64 ~/Desktop/my_project (master)
$ git status
On branch masterNo commits yetChanges to be committed:    #要提交的更改(use "git rm --cached <file>..." to unstage)new file:   test1.txtnew file:   test2.sqladmin@DESKTOP-4CERLUK MINGW64 ~/Desktop/my_project (master)
$ git commit -m 'initial project version'  #提交并备注
[master (root-commit) 59a2071] initial project version2 files changed, 2 insertions(+)create mode 100644 test1.txtcreate mode 100644 test2.sqladmin@DESKTOP-4CERLUK MINGW64 ~/Desktop/my_project (master)
$ cd ..  #返回上一层admin@DESKTOP-4CERLUK MINGW64 ~/Desktop
$ git clone --bare my_project my_project.git  #克隆一个裸仓
Cloning into bare repository 'my_project.git'...
done.admin@DESKTOP-4CERLUK MINGW64 ~/Desktop
$ scp -r my_project.git git@[服务器地址]:/home/git/my_project.git  #将裸仓上传至服务器端
The authenticity of host ' [服务器地址]([服务器地址])' can't be established.
ED25519 key fingerprint is SHA256:ZIPLdZAeqo7YVJ3qpwbt+Rw+ymtMWdOq1d1lR3gZ9Uk.
This key is not known by any other names.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Warning: Permanently added '[服务器地址]' (ED25519) to the list of known hosts.
git@[服务器地址]'s password:
config 100% 164 9.1KB/s 00:00
description 100% 73 4.1KB/s 00:00
HEAD 100% 23 1.3KB/s 00:00
applypatch-msg.sample 100% 478 26.8KB/s 00:00
commit-msg.sample 100% 896 51.0KB/s 00:00
fsmonitor-watchman.sample 100% 4726 243.7KB/s 00:00
post-update.sample 100% 189 11.1KB/s 00:00
pre-applypatch.sample 100% 424 24.4KB/s 00:00
pre-commit.sample 100% 1649 93.1KB/s 00:00
pre-merge-commit.sample 100% 416 24.2KB/s 00:00
pre-push.sample 100% 1374 79.1KB/s 00:00
pre-rebase.sample 100% 4898 263.4KB/s 00:00
pre-receive.sample 100% 544 31.2KB/s 00:00
prepare-commit-msg.sample 100% 1492 84.5KB/s 00:00
push-to-checkout.sample 100% 2783 158.6KB/s 00:00
sendemail-validate.sample 100% 2308 125.5KB/s 00:00
update.sample 100% 3650 192.5KB/s 00:00
exclude 100% 240 13.6KB/s 00:00
9f7cb32c94b4023186abd39e4b26f7988079f2 100% 29 1.7KB/s 00:00
a207135e033a0df9364b34c256403ca36acf96 100% 132 7.7KB/s 00:00
7e2bcac3de881816c992429389a8b2b4d8e3b9 100% 63 3.6KB/s 00:00
packed-refs 100% 105 6.0KB/s 00:00admin@DESKTOP-4CERLUK MINGW64 ~/Desktop


[root@VM-0-17-centos ~]# su git
[git@VM-0-17-centos root]$ cd
[git@VM-0-17-centos ~]$ ll
total 4
drwxr-xr-x 6 git git 4096 Sep 28 22:48 my_project.git
[git@VM-0-17-centos ~]$ ls my_project.git/
config  description  HEAD  hooks  info  objects  packed-refs  refs


$ git clone git@[服务器地址]:my_project.git
Cloning into 'my_project'...
git@[服务器地址]'s password:
remote: Counting objects: 3, done.
remote: Compressing objects: 100% (2/2), done.
remote: Total 3 (delta 0), reused 0 (delta 0)
Receiving objects: 100% (3/3), done.admin@DESKTOP-4CERLUK MINGW64 ~/Desktop
$ cd my_project/admin@DESKTOP-4CERLUK MINGW64 ~/Desktop/my_project (master)
$ ls -a
./ ../ .git/ test1.txt test2.sqladmin@DESKTOP-4CERLUK MINGW64 ~/Desktop/my_project (master)




[git@VM-0-17-centos ~]$ pwd
[git@VM-0-17-centos ~]$ git init --bare my_project2.git
Initialized empty Git repository in /home/git/my_project2.git/
[git@VM-0-17-centos ~]$ ls
my_project2.git  my_project.git
[git@VM-0-17-centos ~]$ ls my_project2.git/
branches  config  description  HEAD  hooks  info  objects  refs


$ git clone git@[服务器地址]:my_project2.git
Cloning into 'my_project2'...
git@[服务器地址]'s password:
warning: You appear to have cloned an empty repository.admin@DESKTOP-4CERLUK MINGW64 ~/Desktop
$ cd my_project2/admin@DESKTOP-4CERLUK MINGW64 ~/Desktop/my_project2 (master)
$ ll -a
total 12
drwxr-xr-x 1 admin 197121 0 Sep 29 21:56 ./
drwxr-xr-x 1 admin 197121 0 Sep 29 21:56 ../
drwxr-xr-x 1 admin 197121 0 Sep 29 21:56 .git/admin@DESKTOP-4CERLUK MINGW64 ~/Desktop/my_project2 (master)


  Git可以使用四种不同的协议来传输资料:本地协议(Local),HTTP 协议,SSH(Secure Shell)协议及 Git 协议。 它们各有优缺点,但据我所知多数情况下采用SSH协议或HTTP协议。优缺点详见官方文档:


    首先,你需要确认个人是否已经拥有密钥。 默认情况下,用户的 SSH 密钥存储在其 ~/.ssh 目录下。 进入该目录并列出其中内容,你便可以快速确认自己是否已拥有密钥:

$ cd ~/.ssh/admin@DESKTOP-4CERLUK MINGW64 ~/.ssh
$ ls -a
./  ../  id_ed25519  known_hosts  known_hosts.old

    其中id_ed25529和id_ed25519.pub就是一对公私钥对,.pub文件为本地的公钥,对应的另一个为私钥。 如果找不到这样的文件(或者根本没有 .ssh 目录),你可以通过运行 ssh-keygen 程序来创建它们。 在 Linux/macOS 系统中,ssh-keygen 随 SSH 软件包提供;在 Windows 上,该程序包含于 MSysGit 软件包中。我这里使用的是Windows系统,git的命令行:

$ ssh-keygen.exe -o
Generating public/private ed25519 key pair.
Enter file in which to save the key (/c/Users/admin/.ssh/id_ed25519):
Enter passphrase for "/c/Users/admin/.ssh/id_ed25519" (empty for no passphrase):
Enter same passphrase again:
Your identification has been saved in /c/Users/admin/.ssh/id_ed25519
Your public key has been saved in /c/Users/admin/.ssh/
The key fingerprint is:
SHA256:cUJipY/OfsEfq25aCOh+34O1KT79Ya/3KG4eTe883SQ admin@DESKTOP-4CERLUK
The key's randomart image is:
+--[ED25519 256]--+
|      o.o        |
|     . +         |
|      . o .      |
|   .   o +       |
|  . . ..S   .    |
| .   + .+ .o .E .|
|  .   ++.=+o. .+.|
| .  ..+oB.=+.+. o|
|  .. o=B+B=+o.+. |
admin@DESKTOP-4CERLUK MINGW64 ~/Desktop/my_project2 (master)

    ssh-keygen 会确认密钥的存储位置(默认是 .ssh/id_rsa),然后它会要求你输入两次密钥口令。 如果你不想在使用密钥时输入口令,将其留空即可。 然而,如果你使用了密码,那么请确保添加了 -o 选项,它会以比默认格式更能抗暴力破解的格式保存私钥。 你也可以用 ssh-agent 工具来避免每次都要输入密码。

    接着将公钥配置到服务器上。注意:我们在原本的公钥前面添加 no-port-forwarding,no-X11-forwarding,no-agent-forwarding,no-pty 用来限制ssh端口转发访问服务器

[git@VM-0-17-centos ~]$ mkdir .ssh
[git@VM-0-17-centos ~]$ chmod 700 .ssh
[git@VM-0-17-centos ~]$ touch .ssh/authorized_keys
[git@VM-0-17-centos ~]$ chmod 600 .ssh/authorized_keys
[git@VM-0-17-centos ~]$ vim .ssh/authorized_keys
no-port-forwarding,no-X11-forwarding,no-agent-forwarding,no-pty [公钥内容]


$ git clone git@[服务器地址]:my_project
Cloning into 'my_project'...
remote: Counting objects: 3, done.  #可以看到直接开始clone,不需要输入密码了
remote: Compressing objects: 100% (2/2), done.
remote: Total 3 (delta 0), reused 0 (delta 0)
Receiving objects: 100% (3/3), done.admin@DESKTOP-4CERLUK MINGW64 ~/Desktop


    借助一个名为 git-shell 的受限 shell 工具,你可以方便地将用户 git 的活动限制在与 Git 相关的范围内。 该工具随 Git 软件包一同提供。如果将 git-shell 设置为用户 git 的登录 shell(login shell), 那么该用户便不能获得此服务器的普通 shell 访问权限。 若要使用 git-shell,需要用它替换掉 bash 或 csh,使其成为该用户的登录 shell。为进行上述操作,首先你必须确保 git-shell 的完整路径名已存在于 /etc/shells 文件中。

[root@VM-0-17-centos ~]# cat /etc/shells
[root@VM-0-17-centos ~]# which git-shell

    确认没有问题后才可以使用 chsh <username> -s <shell> 命令修改系统用户的 默认登录shell。或者直接vim /etc/passwd,将git用户登录模式改为/usr/bin/git-shell。

[root@VM-0-17-centos ~]# chsh git -s $(which git-shell)    #我这里与chsh git -s /usr/bin/git-shell等价
Changing shell for git.
chsh: Warning: "/usr/bin/git-shell" is not listed in /etc/shells.
Shell changed.


$ ssh git@[服务器地址]
Last login: Mon Sep 30 19:16:21 2024 from
fatal: Interactive git shell is not enabled.
hint: ~/git-shell-commands should exist and have read and execute access.
Connection to [服务器地址] closed.admin@DESKTOP-4CERLUK MINGW64 ~/Desktop


    我们一般通过SSH进行授权访问,通过git://进行无授权访问,但HTTP协议可以同时实现以上两种方式的访问。而配置一个轻量级http服务器一般只需要在服务器上启动Git自带的名为git-http-backend的CGI脚本。该 CGI 脚本将会读取由 git fetch 或 git push 命令向 HTTP URL 发送的请求路径和头部信息, 来判断该客户端是否支持 HTTP 通信(不低于 1.6.6 版本的客户端支持此特性)。如果 CGI 发现该客户端支持智能(Smart)模式,它将会以智能模式与它进行通信, 否则它将会回落到哑(Dumb)模式下(因此它可以对某些老的客户端实现向下兼容)。


[root@VM-0-17-centos ~]# dnf -y install httpd httpd-tools
[root@VM-0-17-centos ~]# httpd -M | grep -E 'cgi|alias|env'  #查看Apache启用模块
AH00558: httpd: Could not reliably determine the server's fully qualified domain name, using ::1. Set the 'ServerName' directive globally to suppress this messagealias_module (shared)env_module (shared)setenvif_module (shared)vhost_alias_module (shared)proxy_fcgi_module (shared)proxy_scgi_module (shared)cgi_module (shared)
[root@VM-0-17-centos ~]# dnf -y install cgi_module alias_module env_module

    该操作将会启用 cgi_module, alias_module 和 env_module 等 Apache 模块, 这些模块都是使该功能正常工作所必须的。

    还要将裸仓的上级目录(例如上文中的/home/git)的用户组设置为apache(注意:这里是apache的用户组,不同系统可能不一样),这样 Web 服务器才能读写该仓库, 因为运行 CGI 脚本的 Apache 实例默认会以该用户的权限运行。因为这里不用ssh认证,所以我将裸仓的上级目录改到/srv/git,操作如下:

[root@VM-0-17-centos ~]# mkdir -p /srv/git

    接着修改Apache的配置文件,我这里直接新增一个配置文件到/etc/httpd/conf.d/目录下,因为/etc/httpd/conf/httpd.conf中存在"IncludeOptional conf.d/*.conf"(IncludeOptional引用的路径有问题时会被忽略,不会报错)引用了/etc/httpd/conf.d/目录下所有.conf文件。命令如下:

[root@VM-0-17-centos ~]# vim /etc/httpd/conf.d/git.conf
# 监听8989端口
Listen 8989
<VirtualHost *:8989># git库的存放目录SetEnv GIT_PROJECT_ROOT /srv/git#如果没有下面这一行,那么无授权客户端只能访问带 git-daemon-export-ok 文件的版本库;如果有Git将会公开服务器上所有的仓库SetEnv GIT_HTTP_EXPORT_ALL# 将以/git/开头的请求映射到git-http-backend这个CGI脚本ScriptAlias /git/ /usr/libexec/git-core/git-http-backend/#匹配目录<Directory "/usr/libexec/git-core"># 匹配文件名<Files "git-http-backend"># 用户认证类型AuthType Basic# 设置授权领域的名称AuthName "Git Access"# 设置用于身份验证的用户的账号密码地址AuthUserFile /srv/git/.htpasswdRequire expr !(%{QUERY_STRING} -strmatch '*service=git-receive-pack*' || %{REQUEST_URI} =~ m#/git-receive-pack$#)# 强制用户必须身份验证才能访问受保护的资源Require valid-user</Files></Directory><Directory "/srv/git">#启用 CGI 脚本的执行权限Options +ExecCGI#忽略.htaccess 文件AllowOverride None#授权所有用户访问当前目录下的所有文件Require all granted</Directory>
[root@VM-0-17-centos ~]# systemctl restart httpd


    Require expr !(%{QUERY_STRING} -strmatch '*service=git-receive-pack*' || %{REQUEST_URI} =~ m#/git-receive-pack$#) 配置说明:

      %{QUERY_STRING} 这是HTTP请求的查询字符串部分,即URL中问号后面的参数部分;

      %{QUERY_STRING} -strmatch '*service=git-receive-pack*' 这部分表示查询字符串中是否包含`service=git-receive-pack`。`-strmatch`表示字符串匹配,`*service=git-receive-pack*`表示允许前后有任意字符的匹配条件;

      || 这是逻辑或操作符,表示两个条件中的任意一个满足即可;

      %{REQUEST_URI} =~ m#/git-receive-pack$# 这部分检查请求的URI(路径部分)是否以`/git-receive-pack`结尾。`=~`表示正则表达式匹配,`m#...#`是正则表达式的模式,而`$`表示匹配字符串的末尾。

      因此,整个 Require 表达式的含义是:仅当查询字符串包含`service=git-receive-pack`或URI以`/git-receive-pack`结尾时,这部分规则才会被触发。(即在上传时需要进行身份验证



[root@VM-0-17-centos ~]# htpasswd -c /srv/git/.htpasswd testuser
New password: 
Re-type new password: 
Adding password for user testuser
[root@VM-0-17-centos ~]# chgrp apache /srv/git/.htpasswd


[root@VM-0-17-centos conf]# cd /srv/git/
[root@VM-0-17-centos git]# git init --bare my_project3.git  #创建裸仓
Initialized empty Git repository in /srv/git/my_project3.git/
[root@VM-0-17-centos git]# git init --bare my_project4.git  #创建无授权客户可以访问的裸仓
Initialized empty Git repository in /srv/git/my_project4.git/
[root@VM-0-17-centos git]# touch my_project4.git/git-daemon-export-ok
#也可以chown -R apache:apache /srv/git将个人与组都改为apache
[root@VM-0-17-centos git]# chgrp -R apache /srv/git
[root@VM-0-17-centos git]# chmod -R g+w /srv/git/
[root@VM-0-17-centos git]# ll
total 4
drwxrwxr-x 7 root apache 4096 Oct 12 16:06 my_project3.git
drwxrwxr-x 7 root apache 4096 Oct 14 18:30 my_project4.git

    将服务器端 /etc/httpd/conf.d/git.conf 配置文件中的 "SetEnv GIT_HTTP_EXPORT_ALL"删除或注释,之后进行clone测试(Windows客户端):

$ git clone http://[服务器地址]:8989/git/my_project3.git
Cloning into 'my_project3'...
fatal: repository 'http://[服务器地址]:8989/git/my_project3.git/' not foundadmin@DESKTOP-4CERLUK MINGW64 ~/Desktop
$ git clone http://[服务器地址]:8989/git/my_project4.git
Cloning into 'my_project4'...
warning: You appear to have cloned an empty repository.admin@DESKTOP-4CERLUK MINGW64 ~/Desktop


$ rm -rf my_project4/admin@DESKTOP-4CERLUK MINGW64 ~/Desktop
$ rm -rf my_project3/admin@DESKTOP-4CERLUK MINGW64 ~/Desktop
$ git clone http://[服务器地址]:8989/git/my_project3.git
Cloning into 'my_project3'...
warning: You appear to have cloned an empty repository.admin@DESKTOP-4CERLUK MINGW64 ~/Desktop
$ git clone http://[服务器地址]:8989/git/my_project4.git
Cloning into 'my_project4'...
warning: You appear to have cloned an empty repository.admin@DESKTOP-4CERLUK MINGW64 ~/Desktop

    再进行push测试,git push时会从弹出输入账号密码的界面,如下图:

$ echo "my_project3" > my_project3/file.txtadmin@DESKTOP-4CERLUK MINGW64 ~/Desktop/my_project3 (master)
$ cd my_project3/admin@DESKTOP-4CERLUK MINGW64 ~/Desktop/my_project3 (master)
$ git add .
warning: in the working copy of 'file.txt', LF will be replaced by CRLF the next time Git touches itadmin@DESKTOP-4CERLUK MINGW64 ~/Desktop/my_project3 (master)
$ git commit -m "Initial commit"
[master (root-commit) f1c23cd] Initial commit1 file changed, 1 insertion(+)create mode 100644 file.txtadmin@DESKTOP-4CERLUK MINGW64 ~/Desktop/my_project3 (master)
Enumerating objects: 3, done.
Counting objects: 100% (3/3), done.
Writing objects: 100% (3/3), 219 bytes | 219.00 KiB/s, done.
Total 3 (delta 0), reused 0 (delta 0), pack-reused 0 (from 0)
To http://[服务器地址]:8989/git/my_project3.git* [new branch]      master -> masteradmin@DESKTOP-4CERLUK MINGW64 ~/Desktop/my_project3 (master)











