FerrisGitSecurity

Security and your data

The measures that protect an instance, described precisely. Data never leaves your server.

What the server sends back

The security headers, as an instance sends them.

$ curl -s -D - -o /dev/null http://localhost:8080/health
HTTP/1.1 200 OK
content-type: text/plain; charset=utf-8
content-security-policy: default-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; object-src 'none'; base-uri 'self'; frame-ancestors 'none'
x-frame-options: DENY
x-content-type-options: nosniff
referrer-policy: no-referrer
x-robots-tag: noindex, nofollow
content-length: 2
date: Sun, 04 Oct 2026 11:41:43 GMT
A local instance, version 0.1.2, asked for /health. The server adds the content policy, X-Frame-Options, X-Content-Type-Options and Referrer-Policy to every response: pages, API and Git.
Multi-factor authentication is mandatory
An account with no factor enrolled is forced through setup before it can do anything else. TOTP, passkeys and backup codes.
Passwords hashed with Argon2
One salt per password. An unknown username costs as much work as a wrong password, and gets the same answer.
Secrets encrypted with AES-256-GCM
CI variables, webhook secrets, the SMTP password and TOTP secrets, under SETTINGS_ENCRYPTION_KEY.
Tokens for Git, never passwords
Git over HTTPS authenticates with a personal access token, stored hashed: the server cannot read it back.
An audit log
Failed sign-ins, refused Git access, password resets, promotions and MFA resets by an administrator are recorded as events.
No cookies, strict headers
Sessions are JWTs. Every response carries a Content-Security-Policy, X-Frame-Options: DENY, and the sign-in routes are rate-limited per IP.
Your data, on your server
PostgreSQL and a directory of repositories, both yours to back up. The image runs as an unprivileged user on a read-only filesystem.

The security page of the documentation (in French)

Evaluate FerrisGit, then deploy your own instance.

The public instance lets you explore the product. Your own instance keeps your code.

Start the stack with Docker Compose
git clone https://github.com/Masmarino/FerrisGit.git
cd FerrisGit
cp .env.example .env
# set POSTGRES_PASSWORD, JWT_SECRET, SETTINGS_ENCRYPTION_KEY and the admin password in .env
docker compose up -d --build