src/webhooks/dispatch.rs:48 Open
Review on the diff
A comment stays attached to its line. A reviewer can write a suggestion that the author applies in one click, as a commit. Approvals are counted, conflicts are detected.
Repositories, merge requests with inline review, issues, wikis, releases, signed webhooks and a CI/CD engine. One process, one PostgreSQL, on your own server.
$docker compose up -d --buildA single binary and a database. No account on a third-party service, no telemetry sent anywhere. See how it is made.
Illustration of one merge request in FerrisGit, from the push to the merge: a push over HTTPS creates the request, a reviewer suggests a change on a line, the author applies it in one click, the reviewer approves, the request is merged. The merge starts the pipeline of the repository: format and clippy run, then test, and all three succeed.
/api, each documentedEach tile is a piece of the real product. The interface is in French for now; five languages are planned for 0.2.
src/webhooks/dispatch.rs:48 Open
A comment stays attached to its line. A reviewer can write a suggestion that the author applies in one click, as a commit. Approvals are counted, conflicts are detected.
After every push, FerrisGit reads the file on the default branch and creates a pipeline. Stages are barriers, needs are dependencies; jobs run in Docker containers through a small runner, or as Kubernetes Pods.
Labels, milestones, assignees and four states. Drag a card to change its state, or use the card's menu from the keyboard.
| Action | Reader | Contrib. | Maint. |
|---|---|---|---|
| Browse, clone, read | |||
| Push, open issues and requests, review | |||
| Merge, release, settings, collaborators |
A role granted on a group applies to everything below it. The highest role wins.
Twelve events on merge requests, issues, pipelines and collaborators. Each delivery carries an HMAC-SHA256 signature of its raw body; the secret is encrypted at rest.
Visitors browse the catalogue, README, files, commits and releases of public repositories, and clone them. An administrator switch turns the public pages off.
No account can skip it. Authenticator apps (TOTP), passkeys (WebAuthn) and ten single-use backup codes.
Repositories, issues, merge requests and users, as you type. Notifications in the application tell you what concerns you.
Describe the jobs in .ferrisgit-ci.yml at the root of the repository. After every successful push, FerrisGit reads the file on the default branch and creates a pipeline. Flip the switch to see what the scheduler does when a job fails.
stages: [lint, test]
jobs:
format:
stage: lint
image: rust:1
script:
- rustup component add rustfmt
- cargo fmt --all -- --check
clippy:
stage: lint
image: rust:1
script:
- rustup component add clippy
- cargo clippy --all-targets -- -D warnings
test:
stage: test
image: rust:1
needs: [format, clippy]
script:
- cargo test --all-targets
Pipeline passed
lint
test
format and clippy start together; test declares needs: [format, clippy] and starts once both have succeeded.
ferrisgit-runner binary polls the server and runs each job in a container. Or Kubernetes: the server creates one Pod per job in your cluster.FerrisGit is one container image with PostgreSQL next to it. Try it with Docker Compose, install the Helm chart on Kubernetes, or run it from the sources.
git clone https://github.com/Masmarino/FerrisGit.git
cd FerrisGit
cp .env.example .env
# set POSTGRES_PASSWORD, JWT_SECRET, SETTINGS_ENCRYPTION_KEY and the admin password in .env
docker compose up -d --build
Compose builds the image from the sources. To use the published image instead, replace build: . by image: masmarino/ferrisgit:0.1.1 in docker-compose.yml.
git clone https://github.com/Masmarino/FerrisGit.git
cd FerrisGit
helm upgrade --install ferrisgit ./helm/ferrisgit \
--namespace ferrisgit --create-namespace \
--set image.tag=0.1.1 \
--set ingress.host=git.example.com \
--set-string ferrisgit.trustedProxyCidrs=10.42.0.0/16
kubectl -n ferrisgit rollout status deployment/ferrisgit
Left empty, the chart generates the database password, JWT_SECRET, SETTINGS_ENCRYPTION_KEY and the first administrator's password in the ferrisgit-secrets Secret. The release must be called ferrisgit.
git clone https://github.com/Masmarino/FerrisGit.git
cd FerrisGit
cp .env.example .env # then set real secrets
./scripts/dev.sh # PostgreSQL via Compose, cargo run on :8080, ng serve on :4201
Needs rustup, Node.js 26, Docker with Compose and git on the PATH. The script starts PostgreSQL, applies the migrations and runs the backend on port 8080 and the Angular dev server on port 4201.
One process, five crates, a hexagonal layout: the domain knows nothing of the database, the adapters know nothing of the use cases.
Fig. 1 One instance. The orange line follows a push from the client to the jobs it starts.
What protects an instance, named precisely. The data never leaves your server.
SETTINGS_ENCRYPTION_KEY.X-Frame-Options: DENY, and the sign-in routes are rate-limited per IP.Five versions, none shipped. Items are only ticked once they ship.
The public instance shows the product. Your instance keeps your code.
camille · 2 min
Exponential backoff, so a flapping endpoint stops being hammered.