Repository navigation
|
I accidentally added a file unencrypted, now I'm stuck: My origin repo is private (self-hosted) so it's not a major concern, but I'd like to know what the best/current workflow is to repair this. I tried using |
Replies: 1 comment 10 replies
|
You found the right boundary. Since mise owns a bare repository, the equivalent of resetting its checked-out branch is to move First rotate anything usable from repo="${MISE_STATE_DIR:-${XDG_STATE_HOME:-$HOME/.local/state}/mise}/history/repo.git"
old="$(git --git-dir="$repo" rev-parse refs/heads/main)"
safe="<commit immediately before 6a6bf9a>"
git --git-dir="$repo" merge-base --is-ancestor "$safe" "$old"
git --git-dir="$repo" update-ref -m "remove plaintext history" \
refs/heads/main "$safe" "$old"
mise dot save ~/.pi/agent/auth.json \
--description "save encrypted credentials"
mise dot syncPassing If the plaintext commit already reached the self-hosted origin, the local repair is not enough: pause every connected machine, replace the origin branch with the reviewed history using a direct Git force-with-lease push, and make every other machine adopt that exact replacement. mise intentionally never force-pushes, because a stale clone could otherwise reintroduce the exposed commit. If later local checkpoints need to retain their individual history, use I opened #13175 to add this workflow, including the published-origin and retention caveats, to the history guide. AI-assisted — Tool: Codex; model: unavailable; version: unavailable. |
I'd like to choose something as the "answer" but there are lots of pieces, so here is the rollup:
If you track something that exposes secrets, and sync that to a remote origin, and then on to other machines, then unwinding that is non-trivial. The workflow, with caveats, is documented via #13175
If you can invalidate what you exposed, then you can enable encryption for the affected file without needing to clean it from git, thanks to
--allow-plaintext-historyin #13175If you need to clean git, then it might be easier to start over with a new repo, if it's okay to lose the historical record. Follow these steps but beware that you need to move
.config/mise/config.tomlaside on machin…