Skip to content

docs: explain git identity and credentials in shared workspaces #30278

Description

@coder

Problem

Shared workspaces covers roles, app routing, and sharing policies, but doesn't explain whose git identity and credentials are used when multiple users connect to the same workspace. In practice, everything resolves to the workspace owner:

  • Commit author/committer: templates typically set GIT_AUTHOR_* / GIT_COMMITTER_* on the agent from data.coder_workspace_owner.me (e.g. examples/templates/docker/main.tf). These are set at build time, so commits from any shared user are attributed to the owner.
  • Git over SSH: agentGitSSHKey returns the owner's key via GetGitSSHKey(ctx, workspace.OwnerID) (coderd/gitsshkey.go).
  • External auth: workspaceAgentsExternalAuth resolves tokens with UserID: workspace.OwnerID (coderd/workspaceagents.go), so HTTPS git / gh operations act as the owner.

A user with the use role gets SSH/terminal access, which is enough to push with the owner's SCM permissions. Owners sharing a personal workspace may not realize this.

Proposed docs changes

Add a section to docs/user-guides/shared-workspaces.md (and link it from docs/tutorials/persistent-shared-workspaces.md) that covers:

  1. Git identity, the git SSH key, and external auth tokens all belong to the workspace owner, for every connected user.
  2. Security implications of sharing a personally owned workspace (shared users can act with the owner's SCM credentials).
  3. Recommendation: use a service-account-owned workspace for shared or long-lived use cases, and note that activity will be attributed to the service account.
  4. How shared users can commit/push as themselves, e.g. overriding GIT_AUTHOR_* / GIT_COMMITTER_* in their session (template env vars take precedence over git config), or git -c user.name=... -c user.email=..., plus authenticating with their own credentials (e.g. gh auth login). Mention the trade-offs: credentials written to disk can be seen by other users of the workspace.

Created on behalf of @ericpaulsen

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions