#157: rewrite SSH origin to HTTPS in the worktree #183

Merged
ltms merged 1 commits from worker/fleetd-157-https-in-worktree-a75e0a-1 into main 2026-08-28 01:22:57 +02:00
Member

Follow-up to #177. The per-worktree environment credential helper (configureEnvironmentCredentialHelper in GitWorktrees) only applies to HTTPS remotes -- Git never consults credential.helper for an SSH transport. This repo's origin is ssh://git@git.ltms.dev:2224/fleet/fleetd.git, so members push over SSH and the helper is never consulted. Once memberCredentials.policy: allow-list blocks SSH_AUTH_SOCK, an SSH-origin member cannot authenticate at all (no private key files on this host, only an ssh-agent socket).

Adds configureHttpsUrlRewriteForSshOrigin: derives the host (and port, for the SSH-side match) from the parent's own origin URL (never hardcoded), and sets a worktree-scoped git config --worktree url.<https-base>.insteadOf <ssh-base>. Uses insteadOf, not pushInsteadOf, so fetch/rebase also work. An already-HTTPS origin is left alone (the credential helper already covers it). A non-ssh/non-https origin (including the scp-like git@host:path shorthand) is left untouched deliberately, since that shorthand's host:path split depends on the user's ssh_config aliases rather than URI syntax.

Tests: aProvisionedWorktreeRewritesAnSshOriginToHttpsWorktreeScoped (worktree resolves https for both fetch and push; parent still resolves the original ssh:// for both; uses a synthetic host/port to prove no hardcoding) and aProvisionedWorktreeLeavesAnHttpsOriginAlone.

mvn clean install: Tests run: 986, Failures: 0, Errors: 0, Skipped: 0 -- BUILD SUCCESS.

Follow-up to #177. The per-worktree environment credential helper (configureEnvironmentCredentialHelper in GitWorktrees) only applies to HTTPS remotes -- Git never consults credential.helper for an SSH transport. This repo's origin is ssh://git@git.ltms.dev:2224/fleet/fleetd.git, so members push over SSH and the helper is never consulted. Once memberCredentials.policy: allow-list blocks SSH_AUTH_SOCK, an SSH-origin member cannot authenticate at all (no private key files on this host, only an ssh-agent socket). Adds configureHttpsUrlRewriteForSshOrigin: derives the host (and port, for the SSH-side match) from the parent's own origin URL (never hardcoded), and sets a worktree-scoped `git config --worktree url.<https-base>.insteadOf <ssh-base>`. Uses insteadOf, not pushInsteadOf, so fetch/rebase also work. An already-HTTPS origin is left alone (the credential helper already covers it). A non-ssh/non-https origin (including the scp-like `git@host:path` shorthand) is left untouched deliberately, since that shorthand's host:path split depends on the user's ssh_config aliases rather than URI syntax. Tests: aProvisionedWorktreeRewritesAnSshOriginToHttpsWorktreeScoped (worktree resolves https for both fetch and push; parent still resolves the original ssh:// for both; uses a synthetic host/port to prove no hardcoding) and aProvisionedWorktreeLeavesAnHttpsOriginAlone. mvn clean install: Tests run: 986, Failures: 0, Errors: 0, Skipped: 0 -- BUILD SUCCESS.
agent added 1 commit 2026-08-28 01:20:50 +02:00
#157: rewrite SSH origin to HTTPS in the worktree so the credential helper is reachable
CI / build (pull_request) Successful in 1m10s
CI / contract (pull_request) Successful in 1m16s
4accc746bd
ltms merged commit 85417d5215 into main 2026-08-28 01:22:57 +02:00
ltms deleted branch worker/fleetd-157-https-in-worktree-a75e0a-1 2026-08-28 01:22:57 +02:00
Sign in to join this conversation.