git.kamadorueda.com: a Git proxy to GitHub over SSH, for an allow list of repositories. Use it as a normal HTTPS Git remote at /github//. The token is the password (with any user name), or goes in an "Authorization: Bearer" header. # The token is in secrets/git.yaml in kamadorueda/apps: # sops decrypt --extract '["token"]' secrets/git.yaml export GIT_KAMADORUEDA_COM_TOKEN=... git ls-remote https://git:$GIT_KAMADORUEDA_COM_TOKEN@git.kamadorueda.com/github/kamadorueda/apps git clone https://git:$GIT_KAMADORUEDA_COM_TOKEN@git.kamadorueda.com/github/kamadorueda/apps # Or keep the token out of the saved remote URL: git -c http.extraHeader="Authorization: Bearer $GIT_KAMADORUEDA_COM_TOKEN" clone https://git.kamadorueda.com/github/kamadorueda/apps A repository that is not on the allow list answers 404, and a push to a read-only one answers 403. With the token, this page also lists the repositories.