GuidesConnect GitHub or GitLab
What Ferry stores
Ferry keeps the secrets of a connection in its database and asks for read access only.
For a GitHub App, Ferry stores the id of the app and its private key.
1 / 3
What Ferry keeps
| Method | Ferry stores | How Ferry uses it |
|---|---|---|
| GitHub App | The id of the app and its private key | The key signs a request for a token. The token reads the chosen repositories for one hour. Ferry keeps it in memory and never stores it. |
| GitLab application | The id and the secret of the application, the access token and its refresh token | The access token lasts two hours. Ferry renews it a short time before it expires. |
| Access token | The token | As it is |
Where the secrets go
- All of it is in the database of the server, in the data directory (mode
0700). Datastore passwords and env values are there too. See Security model. - The API never returns a secret. For a personal access token, it shows
token_hint: the last characters. - Ferry sends a token only to its own provider. The API of the provider lists repositories. Its git server clones a repository or lists its branches.
- Ferry never sends a token to a different host, even if the provider answers with a redirect.
- A token never shows on a command line, in the git cache, in a deploy log or in an error message.
Read access only
| Provider | Ferry asks for |
|---|---|
| GitHub App | contents: read and metadata: read |
| GitLab | read_api and read_repository |