Server-Side Git Hooks
Explore server-side hooks such as `pre-receive` and `update` for repository-wide policy enforcement and automation.
Server-Side Git Hooks is a free Git Advanced: Monorepo, Submodules & Workflows lesson on CoddyKit — lesson 2 of 4. You can read the complete lesson below for free — then practise it hands-on in the browser with a built-in code editor and a 24/7 AI tutor. It is part of the Git Advanced: Monorepo, Submodules & Workflows learning path, one of 4 lessons in the course, and your progress syncs across the web and the CoddyKit app.
Welcome to Server-Side Hooks
In the previous lesson, we learned about client-side Git hooks. Now, let's explore server-side hooks, which operate on the Git server itself.
These hooks are powerful tools for enforcing repository-wide policies and automating tasks before or after changes are accepted into the central repository.
Client vs. Server Hooks
The key difference between client-side and server-side hooks is where they run:
- Client-side hooks: Run on your local machine before actions like committing or pushing. They help enforce local best practices.
- Server-side hooks: Run on the central Git server after you push changes, but before they're fully integrated. They ensure repository-wide rules are met by everyone.
Server-side hooks provide a stronger guarantee that rules are followed by all contributors.
Where Server Hooks Live
Server-side hooks reside in the hooks directory of your bare repository on the server.
A bare repository is one that doesn't have a working directory – it only contains the Git metadata. When you push to a remote, you're pushing to a bare repository.
Just like client-side hooks, they are executable scripts that Git runs at specific points in the workflow.
The 'pre-receive' Hook
The pre-receive hook is one of the most commonly used server-side hooks. It executes once per push, before any references (like branches or tags) are updated.
It receives a list of all references being pushed and their old/new commit IDs. If this script exits with a non-zero status, the entire push is rejected, and no references are updated.
This makes it ideal for enforcing global policies.
'pre-receive' in Action
The pre-receive hook is perfect for:
- Enforcing branch naming conventions: E.g., all new branches must start with "feature/", "bugfix/", etc.
- Validating commit messages: Ensuring every commit message includes a ticket ID or follows a specific format.
- Preventing pushes to protected branches: Blocking direct pushes to
mainordevelop. - Checking code for sensitive information: Basic credential scanning.
Example: Block Direct Main Push
Here's a conceptual example of a pre-receive script that prevents direct pushes to the main branch. If someone tries to push to main, the push will be rejected.
This script would be placed as pre-receive in the server's bare repository hooks directory and made executable.
#!/bin/sh
while read oldrev newrev refname
do
if [ "$refname" = "refs/heads/main" ]; then
echo "ERROR: Direct pushes to 'main' branch are forbidden."
echo "Please use a pull request workflow."
exit 1
fi
done
exit 0The 'update' Hook
The update hook is similar to pre-receive but runs once for each reference being updated by a push.
It takes three arguments: the name of the reference, the old object name, and the new object name. If any update script exits with a non-zero status, only that specific reference update is rejected.
This allows for more granular control over individual branch updates.
'update' in Action
The update hook is useful for:
- Enforcing fast-forward merges: Preventing non-fast-forward pushes to specific branches, ensuring a linear history.
- Implementing fine-grained access control: Allowing certain users to push to specific branches only.
- Logging updates: Recording every branch update for auditing purposes.
- Preventing force pushes: Ensuring history isn't rewritten on critical branches.
Setting Up Server Hooks
To implement server-side hooks:
- Access the server: You need SSH access or similar to the Git server's repository.
- Locate the hooks directory: Navigate to the
.git/hooksdirectory within your bare repository. - Create/Modify scripts: Write your hook script (e.g.,
pre-receiveorupdate). - Make executable: Ensure the script has execute permissions (e.g.,
chmod +x pre-receive).
Remember, these changes affect everyone interacting with that repository.
Best Practices & Security
When working with server-side hooks:
- Keep them simple: Complex logic can be hard to debug and maintain.
- Version control hooks: Consider storing your hook scripts in a separate repository and deploying them to your Git servers for consistency.
- Test thoroughly: Ensure your hooks don't accidentally block legitimate workflows.
- Consider performance: Hooks run on every push, so avoid resource-intensive operations.
They are powerful, so use them wisely!
Quick Check
Which of the following scenarios would be best handled by a pre-receive hook rather than an update hook?
Recap: Server-Side Hooks
You've explored the power of server-side Git hooks! We learned:
- Server-side hooks enforce policies on the central Git server.
pre-receiveruns once per push, good for global checks.updateruns once per reference, good for granular control.- Implementing them involves placing executable scripts in the bare repository's
hooksdirectory.
These hooks are crucial for maintaining code quality and workflow consistency in team environments. Keep practicing!
Frequently asked questions
Is the “Server-Side Git Hooks” lesson free?
Yes — the full text of “Server-Side Git Hooks” is free to read here on the web, and the Git Advanced: Monorepo, Submodules & Workflows course includes 4 lessons in total. To practise it interactively (a built-in code editor and a 24/7 AI tutor) and unlock the rest of the Git Advanced: Monorepo, Submodules & Workflows course, upgrade to CoddyKit PRO.
What will I learn in “Server-Side Git Hooks”?
Explore server-side hooks such as `pre-receive` and `update` for repository-wide policy enforcement and automation. You practise Git Advanced: Monorepo, Submodules & Workflows with hands-on code you run directly in the browser, and a 24/7 AI tutor answers your questions as you work through the lesson.
Do I need any experience to start Git Advanced: Monorepo, Submodules & Workflows?
No prior experience is required. Git Advanced: Monorepo, Submodules & Workflows on CoddyKit is structured for beginners through advanced learners; this is — lesson 2 of 4, so you can start here or from the beginning and move at your own pace.
How long does the “Server-Side Git Hooks” lesson take?
Most CoddyKit lessons take about 5–10 minutes. Each one is bite-sized and interactive, so you make steady progress and pick up exactly where you left off across the web and the app.
Can I write and run code in this Git Advanced: Monorepo, Submodules & Workflows lesson?
Yes. Every Git Advanced: Monorepo, Submodules & Workflows lesson includes a built-in code editor, so you write and run real code right in your browser and get instant AI feedback — no local setup required.