FerryDocs
ArchitectureSecurity model

Repository credentials

Ferry hides a token that is in a repository URL. git sends it only to the host of the repository.

Edit on GitHub
environmentFerrygitRepository hostgets the tokenAnother hostgets no token

Ferry gives the credentials to git through its environment, never on its command line.

1 / 3

A repository URL can contain a token. Ferry it: it writes *** in its place.

You giveFerry writes
https://user:token@github.com/…https://***@github.com/…

Where Ferry redacts the token

  • deploy logs
  • error messages
  • the change lists of a
  • webhook answers

What to do

Ferry keeps a repository URL with its credentials in the data directory. Protect that directory and its backups.

A connected git account is another way to read a private repository.

On this page