Skip to lesson
supraj.dev THE ENGINEERING HANDBOOKS
LEARN / BUILD / VERIFY2026 edition · checked 06 Oct

CHAPTER 11 / 30 · Capabilities

Git and GitHub without hidden authority

Separate transport authentication, repository permissions and approval to publish a change.

4 min readWorked exerciseInterview practice

What you will build

An authentication and publication checklist for a disposable repository. You will inspect local Git state and plan a read-only remote operation before permitting writes.

The mechanism at a glance
  1. Select repository and revision
  2. Choose auth capability
  3. Read and create local commits
  4. Review before remote publication

Conceptual flow. Follow the lesson for prerequisites, exact commands and verification limits.

Read the mechanism

Git transport, GitHub’s API, package registries and commit signing are distinct services. A token that reads a repository over HTTPS does not necessarily authenticate to every GitHub Packages hostname. A Git commit can exist locally without a push; a push can exist without a pull request.

Docker’s GitHub integration can resolve the host’s authenticated gh credential dynamically. That is convenient but makes the host account’s existing scope relevant. The test question is not just “does authentication work?” It is “which repositories and actions does this identity authorize?”

SSH agent forwarding keeps private keys on the host but exposes signing/authentication operations to guest processes. Non-extractability is not absence of authority. A forwarded agent may allow access that a narrowly scoped HTTPS test credential would not.

Worked lab · review before publishing

Start with the synthetic repository from chapter 6 and its fetched teaching commit. On the host:

git status --short --untracked-files=all
git remote -v
git log --oneline -5
git diff --check

Inspect remote URLs before retaining them in shareable logs; a misconfigured remote can embed a credential. If one does, redact it and repair it through your normal credential-management procedure rather than printing it repeatedly.

Build an action matrix:

OperationNeeded authorityReview gate
Read public sourcePublic read/network accessConfirm exact source revision
Read private test sourceRepository readConfirm test account and repository
Commit locallyLocal repository writeInspect staged diff
Push branchRemote repository writeConfirm destination and branch
Open PRGitHub API writeReview title, body and diff
Merge/deployIntegration/deployment authoritySeparate release decision

For a live extension, select one disposable remote you own and test a read with your already approved authentication. Do not create a token with broad scopes simply to make the lesson work. Avoid commands that retrieve or print token values.

Expected observations

The local commit remains useful even without remote authentication. A denied push does not mean clone mode failed; it may mean the identity correctly lacks publication authority. A successful repository read does not establish write permission.

A pull request should carry evidence: input revision, test command and result, known limitations and any generated files. Do not paste a complete agent transcript if it contains prompts, proprietary code or credentials.

Troubleshooting

When HTTPS works but SSH fails, check the selected transport and forwarded capability. When repository access works but a package pull fails, investigate the package service’s separate auth requirements. Never solve either by exposing private keys or mounting the whole host configuration directory.

Interview practice

Why should an agent that can create a commit still need a publication gate?

A local commit changes a reviewable artifact. Publishing shares that artifact and may trigger automation. The destination, content and downstream deployment effects need their own decision.

Is an SSH agent socket safer than a copied private key?

It can reduce raw-key exposure, but still delegates signing capability. Assess reachable identities, destinations and duration instead of treating forwarding as harmless.

Completion check

Trace one change from local edit to potential deployment. Identify the credential and approval boundary at each transition without retrieving any credential value.

Sources and version notes

Checked 6 October 2026; current baseline: sbx v0.46.0. Manage credentials · Use Git with sandboxes

YOUR NEXT STEP

Make the understanding yours.

Use the completion check above. Mark this chapter when you can explain the mechanism and its limits.

Self-assessed reading progress. This does not certify that a lab ran or a system is secure.