Get started

From install to your first sealed push.

Install the tools, create an account, and push a repository the host can’t read. On macOS or Linux, with the git you already have.

01

What you install

One program, built for your system and processor. It runs as three command-line tools, and shub app starts the SealedGit app. You also need git.

shell
curl -fsSL https://github.com/sealedgit/sealedgit/releases/latest/download/install.sh | sh

Hosting CLI

shub

The gh of SealedGit: accounts, repositories, invitations, admissions, issues, pull requests and releases. shub app starts the app.

Git, sealed

sgit

The git of SealedGit: clone, push, pull and fetch over encrypted sgit:// remotes. Every other command goes straight to your git.

Remote helper

git-remote-sgit

The helper git uses for sgit:// URLs. Git runs it for you.

The installer downloads only the build for this computer and checks its SHA-256. Every build, and how to verify a release

02

First steps

Seven steps, from an empty terminal to a repository your teammate can read and the host cannot. The CLI guide has every step in more depth.

  1. Connect shub to your service

    Give it the accounts address. It looks the host up from there.

    shell
    shub config connect https://accounts.example.com
  2. Create your account

    From the terminal, or on the web. Either way, confirm your address from the link in the email you receive.

    shell
    shub auth signup --email you@example.com --password '…' --handle you

    Your handle is your username: lower-case letters, digits and hyphens, 2 to 39 characters. Passwords are at least 10 characters.

  3. Sign in

    Once your address is confirmed, sign the CLI in.

    shell
    shub auth email-login --email you@example.com --password '…'
  4. Open the SealedGit app

    The app runs on your computer and opens in your browser at a local address, with your repositories, profile and settings. Signing in there enrols this device, which is what lets a member admit it to a repository.

    shell
    shub app
  5. Create a repository and push

    Create it, clone it, commit as usual, and push through sgit.

    shell
    shub repo create ledger --clone && cd ledger
    echo "opening balance 0" > BALANCES.md
    sgit add BALANCES.md && sgit commit -m "open the ledger" && sgit push

    sgit add and sgit commit pass straight through to your git. sgit push seals the commit before it leaves your machine.

  6. Invite a teammate

    This records an invitation and emails them a link. It grants nothing on its own.

    shell
    shub repo invite-email you/ledger --email teammate@example.com
  7. Admit their device

    When they have accepted, compare the safety number with them, then admit their device. Admission is an MLS Add made by your device; the host cannot do it for you.

    shell
    shub repo admissions --repo you/ledger --user <their handle> --key-package-digest <their digest>

    Admission pins their device key, so the host cannot substitute its own. How admission works

03

Everyday git

After the first clone you work with git as you always have. sgit handles the four commands that talk to the host, over encrypted sgit:// remotes.

CommandWhat happens
sgit cloneFetches ciphertext from an sgit:// remote and decrypts it on your device.
sgit pushSeals your commits into an encrypted git bundle, then uploads it.
sgit pullFetches and decrypts what others pushed, then brings it into your branch, as git pull does.
sgit fetchFetches and decrypts, without touching your working tree.
sgit anything elsePasses straight through to your own git.

Works as you’d expect

  • branches
  • tags
  • force-with-lease
  • submodules
  • SHA-256 repositories

Large files: SealedGit does not speak the Git LFS wire protocol, which hands file contents to the server as they are. Use its sealed large-file store, shub lfs. Shallow and partial clones are not offered either; here is why.

04

Self-hosting

Run the whole stack yourself. Self-hosting changes who operates the host, not what the host can see: it still stores only ciphertext.

The ciphertext host

sealedgit-server

Stores and serves encrypted git bundles, opaque MLS framing and hash-chained RefHeads.

Identity

sealedgit-accounts

Email identity, invitations and OIDC.

In production, SealedGit runs on PostgreSQL plus S3-compatible object storage. Choose how to deploy it:

Containers

Docker Compose

Run SealedGit’s services as containers.

Kubernetes

Helm chart

Install SealedGit into the cluster you already run.

One machine

Single-box installer

For AWS or Hetzner, with automatic TLS.

Then connect the CLI to your own deployment by its accounts address:

shell
shub config connect https://accounts.your-domain

For that to work, the accounts service names its host in ACCOUNTS_SEALEDGIT_HOST. Without it, set both by hand: shub config set-host and shub config set-accounts.

Ready

Your first sealed repository is a few commands away.

Create your account on the web, then continue in the terminal and the SealedGit app.