# /etc/apache2/sites-available/git.christianimmanuel.de-common.conf # Shared part of the git.christianimmanuel.de vhosts. Included by the :80 and the :443 (certbot) vhost. # needs: a2enmod rewrite cgi env (and php module) DocumentRoot /var/www/html/git.christianimmanuel.de # --- clone via smart HTTP (read-only: no receive-pack is exposed), with or without .git --- SetEnv GIT_PROJECT_ROOT /var/www/html/git.christianimmanuel.de/repos SetEnv GIT_HTTP_EXPORT_ALL 1 SetEnv GIT_CONFIG_COUNT 1 SetEnv GIT_CONFIG_KEY_0 safe.directory SetEnv GIT_CONFIG_VALUE_0 * ScriptAliasMatch \ "(?x)^/([^/]+/[^/]+?)(?:\.git)?/(HEAD|info/refs|objects/(info/[^/]+|[0-9a-f]{2}/[0-9a-f]{38,62}|pack/pack-[0-9a-f]{40,64}\.(pack|idx))|git-upload-pack)$" \ /usr/lib/git-core/git-http-backend/$1.git/$2 ScriptAliasMatch \ "(?x)^/private/([^/]+/[^/]+?)(?:\.git)?/(HEAD|info/refs|objects/(info/[^/]+|[0-9a-f]{2}/[0-9a-f]{38,62}|pack/pack-[0-9a-f]{40,64}\.(pack|idx))|git-upload-pack)$" \ /usr/lib/git-core/git-http-backend/.private/$1.git/$2 Options +ExecCGI Require all granted # --- private area: everything below /private needs a password (browse, raw, tarball, clone) --- # users: htpasswd -cB /var/www/html/git.christianimmanuel.de/.htpasswd NAME (-c only the first time) AuthType Basic AuthName "private" AuthUserFile /var/www/html/git.christianimmanuel.de/.htpasswd Require valid-user # --- browser --- Options -Indexes AllowOverride None Require all granted RewriteEngine On RewriteCond %{REQUEST_FILENAME} !-f RewriteRule ^ index.php [L] Require all denied # repos are only reachable through git-http-backend or index.php Require all denied ErrorLog ${APACHE_LOG_DIR}/git.christianimmanuel.de-error.log CustomLog ${APACHE_LOG_DIR}/git.christianimmanuel.de-access.log combined