English | 简体中文
自动加密/解密 Git 仓库中的敏感文件。 https://git-cryptx.201945.xyz
- 🔒 透明的文件加密/解密
- 🔄 无缝集成 Git 工作流
- 🎯 精确的文件匹配控制
- 👥 支持团队协作
- 💻 跨平台支持
要编译该项目,请使用以下命令:
cargo build --release编译完成后,请确保将可执行文件永久添加到系统的 PATH 中:
-
Linux/macOS: 将以下行添加到您的
~/.bashrc、~/.bash_profile或~/.zshrc文件中:export PATH="$PATH:/path/to/your/project/target/release"
然后运行:
source ~/.bashrc # 或 source ~/.bash_profile 或 source ~/.zshrc
-
Windows:
- 在开始菜单中搜索“环境变量”。
- 点击“环境变量”。
- 在“系统变量”下,找到
Path变量并点击“编辑”。 - 添加项目的
target/release目录路径。 - 点击“确定”以保存更改。
对于 macOS 用户,您可以使用 Homebrew 安装 git-cryptx:
brew tap ChrisHyperFunc/brew
brew install git-cryptx
brew upgrade git-cryptx-
初始化仓库: git-cryptx init
-
设置加密密钥: git-cryptx set-key
-
配置需要加密的文件(编辑 .gitattributes 并且该文件不得加密):
example.secret filter=git-cryptx diff=git-cryptx
*.secret filter=git-cryptx diff=git-cryptx
config/*.key filter=git-cryptx diff=git-cryptx
sensitive/* filter=git-cryptx diff=git-cryptx
sub_tree_directories/** filter=git-cryptx diff=git-cryptx
如有必要
.gitattributes !filter !diff
init: 初始化 git-cryptxset-key <key>: 添加加密密钥rm-key: 移除加密密钥status: 显示加密状态
git-cryptx 使用 Git 的过滤器机制实现文件的自动加密和解密:
- 当文件被添加到 Git 时,clean 过滤器自动加密内容
- 当文件被检出时,smudge 过滤器自动解密内容
- 工作目录中始终保持文件明文
- Git 仓库中始终保持文件密文
- 使用 AES-256-GCM 进行加密
- 密钥存储在 .git/cryptx 目录中
- 支持文件完整性验证
- 加密文件使用魔数标记
Q: 如何与团队成员共享密钥? A: 请通过安全渠道共享 .git/cryptx/keys/global_ase_key 文件。
Q: 如何查看加密文件的差异? A: git-cryptx 支持直接查看加密文件的明文差异,使用普通的 git diff 即可。
Q: git pull 时提示本地文件会被覆盖怎么办? A: 可以使用以下方法解决:
- 如果确定本地文件没有修改,只是解密状态不同:
git-cryptx reset <file_path>- 如果本地文件确实有修改:
# 存储本地修改
git stash
# 拉取更新
git pull
# 恢复本地修改
git stash pop- 如果发生冲突,需要手动解决冲突后再提交。
当新团队成员加入项目时,需要执行以下步骤:
- 克隆仓库:
git clone <repository-url>- 初始化 git-cryptx:
git-cryptx init-
从团队其他成员处获取密钥文件:
- 获取
.git/cryptx/keys/global_ase_key文件 - 将密钥文件放入本地仓库的相同位置
- 或执行 git-cryptx set-key
- 获取
-
重新检出文件:
# Clean working directory
git clean -fd
# Checkout files to trigger decryption
git checkout .- 验证文件状态:
git-cryptx status
cat your-encrypted-file # 检查文件是否正确解密注意事项:
- 确保密钥文件正确放置
- 如果文件仍然是加密状态,尝试删除文件后重新检出
- 检查 git-cryptx status 确保所有配置正确
欢迎提交 Pull Request 或创建 Issue。
MIT License