future CVS setup
"Gregor J. Rothfuss" <[email protected]>
| Newsgroups | gmane.comp.cms.wyona.devel |
|---|---|
| Message-ID | <142101c2d067$cdd3e4a0$3b00000a@kpmg> |
i wonder what i should do about cvs permissions. currently our cvs does not support our needs very well. it is especially lacking in these regards: - clear policy for customer projects - ways to keep customer projects in sync with the tree - granular access control - secure cvs while reducing admin overhead pending the refactoring of wyona cms, i hope to have all project-specific files in one directory. this would allow to make individual repositories out of various publications, with their own ACLs. these can still reside within pubs/ to allow for checkouts of the complete source tree. i have set up cvs with custom ACLs and all kinds of niceties before, but considering that we are moving to apache soon im hesitant to patch cvs etc. it remains to be seen how we are gonna split up our cvs between apache and wyona anyway. it would certainly be a bit problematic to keep our projects at apache, even though they are fully open-sourced and are nice example sites :) re: security, we are currently running cvs in a jail which presents severe limitations. while it is secure, it means we have to do a lot of admin work to add new accounts, and niceties like syncmail dont work. my goal is to move to a setup where cvs users do not have a shell (ideally authenticated through PAM / LDAP). just some more sunday evening ramblings. -gregor -- Gregor J. Rothfuss [email protected] http://greg.abstrakt.ch