Get started
From install to your first sealed push.
Install the tools, create an account, and push a repository the host can’t read. On macOS or Linux, with the git you already have.
01
What you install
One program, built for your system and processor. It runs as three command-line tools, and shub app starts the SealedGit app. You also need git.
curl -fsSL https://github.com/sealedgit/sealedgit/releases/latest/download/install.sh | sh
Hosting CLI
shub
The gh of SealedGit: accounts, repositories, invitations, admissions, issues, pull requests and releases. shub app starts the app.
Git, sealed
sgit
The git of SealedGit: clone, push, pull and fetch over encrypted sgit:// remotes. Every other command goes straight to your git.
Remote helper
git-remote-sgit
The helper git uses for sgit:// URLs. Git runs it for you.
The installer downloads only the build for this computer and checks its SHA-256. Every build, and how to verify a release
02
First steps
Seven steps, from an empty terminal to a repository your teammate can read and the host cannot. The CLI guide has every step in more depth.
-
Connect
shubto your serviceGive it the accounts address. It looks the host up from there.
shub config connect https://accounts.example.com -
Create your account
From the terminal, or on the web. Either way, confirm your address from the link in the email you receive.
shub auth signup --email you@example.com --password '…' --handle youYour handle is your username: lower-case letters, digits and hyphens, 2 to 39 characters. Passwords are at least 10 characters.
-
Sign in
Once your address is confirmed, sign the CLI in.
shub auth email-login --email you@example.com --password '…' -
Open the SealedGit app
The app runs on your computer and opens in your browser at a local address, with your repositories, profile and settings. Signing in there enrols this device, which is what lets a member admit it to a repository.
shub app -
Create a repository and push
Create it, clone it, commit as usual, and push through
sgit.shub repo create ledger --clone && cd ledger echo "opening balance 0" > BALANCES.md sgit add BALANCES.md && sgit commit -m "open the ledger" && sgit pushsgit addandsgit commitpass straight through to your git.sgit pushseals the commit before it leaves your machine. -
Invite a teammate
This records an invitation and emails them a link. It grants nothing on its own.
shub repo invite-email you/ledger --email teammate@example.com -
Admit their device
When they have accepted, compare the safety number with them, then admit their device. Admission is an MLS Add made by your device; the host cannot do it for you.
shub repo admissions --repo you/ledger --user <their handle> --key-package-digest <their digest>Admission pins their device key, so the host cannot substitute its own. How admission works
03
Everyday git
After the first clone you work with git as you always have. sgit handles the four commands that talk to the host, over encrypted sgit:// remotes.
| Command | What happens |
|---|---|
sgit clone | Fetches ciphertext from an sgit:// remote and decrypts it on your device. |
sgit push | Seals your commits into an encrypted git bundle, then uploads it. |
sgit pull | Fetches and decrypts what others pushed, then brings it into your branch, as git pull does. |
sgit fetch | Fetches and decrypts, without touching your working tree. |
sgit anything else | Passes straight through to your own git. |
Works as you’d expect
- branches
- tags
- force-with-lease
- submodules
- SHA-256 repositories
Large files: SealedGit does not speak the Git LFS wire protocol, which hands file contents to the server as they are. Use its sealed large-file store, shub lfs. Shallow and partial clones are not offered either; here is why.
04
Self-hosting
Run the whole stack yourself. Self-hosting changes who operates the host, not what the host can see: it still stores only ciphertext.
The ciphertext host
sealedgit-server
Stores and serves encrypted git bundles, opaque MLS framing and hash-chained RefHeads.
Identity
sealedgit-accounts
Email identity, invitations and OIDC.
In production, SealedGit runs on PostgreSQL plus S3-compatible object storage. Choose how to deploy it:
Containers
Docker Compose
Run SealedGit’s services as containers.
Kubernetes
Helm chart
Install SealedGit into the cluster you already run.
One machine
Single-box installer
For AWS or Hetzner, with automatic TLS.
Then connect the CLI to your own deployment by its accounts address:
shub config connect https://accounts.your-domain
For that to work, the accounts service names its host in ACCOUNTS_SEALEDGIT_HOST. Without it, set both by hand: shub config set-host and shub config set-accounts.
Ready
Your first sealed repository is a few commands away.
Create your account on the web, then continue in the terminal and the SealedGit app.