{{define "footleft"}}{{.Account}} / keys{{end}} {{define "body" -}} {{template "topbar" .}}
{{.Account}} / keys
the only state the server owns
{{if .Error}}
{{.Error}}
{{end}} {{if .NewToken}}
{{.NewTokenLabel}}
{{.NewToken}}
this is the only time it is shown. only its hash is kept.
{{end}}
ssh keys
{{range .Keys}}
{{.Algo}} {{.Fingerprint}} added {{.Added}}
{{if .Comment}}{{.Comment}} · {{end}}{{.LastUsed}} ·
{{end}}
public key
cat ~/.ssh/id_ed25519.pub
signing keys
{{range .GPGKeys}}
{{.Fingerprint}} added {{.Added}}
{{if .UID}}{{.UID}} · {{end}}
{{end}}
signing key
gpg --armor --export you@example.com
tokens
{{range .Tokens}}
{{.Name}} created {{.Created}}
{{.Detail}} ·
{{end}}
 
a token is shown once, inside the command that uses it. only its hash is kept, so it cannot be shown again. lost one? revoke it and make another.
a key signs you in and pushes. a signing key is only ever read, and names you on a commit you signed. a git token clones and pushes over https. a runner token attaches one machine to one repository, and is made on that repository's runners page. a feed token reads one feed and can write nothing.
everything else is in .barerepo/config, in the repository it belongs to.
{{- end}}