服务器端 Git 钩子
探索 `pre-receive` 和 `update` 等服务器端钩子,在整个仓库范围内强制执行策略并实现自动化
服务器端 Git 钩子 是 CoddyKit 上的免费 Git Advanced: Monorepo, Submodules & Workflows 课时。 这是第 2 节课,共 4 节。 你可以在下方免费阅读本课时的完整内容 — 然后在浏览器中使用内置代码编辑器和全天候 AI 导师进行实践。 这是 Git Advanced: Monorepo, Submodules & Workflows 学习路径的一部分,你的进度在网页和 CoddyKit 应用中同步。 Git Advanced: Monorepo, Submodules & Workflows 课程共包含 4 节课。
本课时的部分内容尚未翻译,以英文显示。
Welcome to Server-Side Hooks
In the previous lesson, we learned about client-side Git hooks. Now, let's explore server-side hooks, which operate on the Git server itself.
These hooks are powerful tools for enforcing repository-wide policies and automating tasks before or after changes are accepted into the central repository.
Client vs. Server Hooks
The key difference between client-side and server-side hooks is where they run:
- Client-side hooks: Run on your local machine before actions like committing or pushing. They help enforce local best practices.
- Server-side hooks: Run on the central Git server after you push changes, but before they're fully integrated. They ensure repository-wide rules are met by everyone.
Server-side hooks provide a stronger guarantee that rules are followed by all contributors.
Where Server Hooks Live
Server-side hooks reside in the hooks directory of your bare repository on the server.
A bare repository is one that doesn't have a working directory – it only contains the Git metadata. When you push to a remote, you're pushing to a bare repository.
Just like client-side hooks, they are executable scripts that Git runs at specific points in the workflow.
The 'pre-receive' Hook
The pre-receive hook is one of the most commonly used server-side hooks. It executes once per push, before any references (like branches or tags) are updated.
It receives a list of all references being pushed and their old/new commit IDs. If this script exits with a non-zero status, the entire push is rejected, and no references are updated.
This makes it ideal for enforcing global policies.
'pre-receive' in Action
The pre-receive hook is perfect for:
- Enforcing branch naming conventions: E.g., all new branches must start with "feature/", "bugfix/", etc.
- Validating commit messages: Ensuring every commit message includes a ticket ID or follows a specific format.
- Preventing pushes to protected branches: Blocking direct pushes to
mainordevelop. - Checking code for sensitive information: Basic credential scanning.
Example: Block Direct Main Push
Here's a conceptual example of a pre-receive script that prevents direct pushes to the main branch. If someone tries to push to main, the push will be rejected.
This script would be placed as pre-receive in the server's bare repository hooks directory and made executable.
#!/bin/sh
while read oldrev newrev refname
do
if [ "$refname" = "refs/heads/main" ]; then
echo "ERROR: Direct pushes to 'main' branch are forbidden."
echo "Please use a pull request workflow."
exit 1
fi
done
exit 0The 'update' Hook
The update hook is similar to pre-receive but runs once for each reference being updated by a push.
It takes three arguments: the name of the reference, the old object name, and the new object name. If any update script exits with a non-zero status, only that specific reference update is rejected.
This allows for more granular control over individual branch updates.
'update' in Action
The update hook is useful for:
- Enforcing fast-forward merges: Preventing non-fast-forward pushes to specific branches, ensuring a linear history.
- Implementing fine-grained access control: Allowing certain users to push to specific branches only.
- Logging updates: Recording every branch update for auditing purposes.
- Preventing force pushes: Ensuring history isn't rewritten on critical branches.
Setting Up Server Hooks
To implement server-side hooks:
- Access the server: You need SSH access or similar to the Git server's repository.
- Locate the hooks directory: Navigate to the
.git/hooksdirectory within your bare repository. - Create/Modify scripts: Write your hook script (e.g.,
pre-receiveorupdate). - Make executable: Ensure the script has execute permissions (e.g.,
chmod +x pre-receive).
Remember, these changes affect everyone interacting with that repository.
Best Practices & Security
When working with server-side hooks:
- Keep them simple: Complex logic can be hard to debug and maintain.
- Version control hooks: Consider storing your hook scripts in a separate repository and deploying them to your Git servers for consistency.
- Test thoroughly: Ensure your hooks don't accidentally block legitimate workflows.
- Consider performance: Hooks run on every push, so avoid resource-intensive operations.
They are powerful, so use them wisely!
Quick Check
Which of the following scenarios would be best handled by a pre-receive hook rather than an update hook?
Recap: Server-Side Hooks
You've explored the power of server-side Git hooks! We learned:
- Server-side hooks enforce policies on the central Git server.
pre-receiveruns once per push, good for global checks.updateruns once per reference, good for granular control.- Implementing them involves placing executable scripts in the bare repository's
hooksdirectory.
These hooks are crucial for maintaining code quality and workflow consistency in team environments. Keep practicing!
用 AI 导师学习 Git Advanced: Monorepo, Submodules & Workflows — 免费
在浏览器中编写并运行真实代码,获得全天候 AI 导师的即时帮助,并在网页或应用中继续学习。
- 课程
- 12
- 课程
- 48
常见问题解答
「服务器端 Git 钩子」课时是免费的吗?
是的 — 「服务器端 Git 钩子」的完整文本可在网页上免费阅读。要进行交互式练习(内置代码编辑器和全天候 AI 导师)并解锁 Git Advanced: Monorepo, Submodules & Workflows 课程的其余内容,请升级到 CoddyKit PRO。 Git Advanced: Monorepo, Submodules & Workflows 课程共包含 4 节课。
「服务器端 Git 钩子」这节课中我会学到什么?
探索 `pre-receive` 和 `update` 等服务器端钩子,在整个仓库范围内强制执行策略并实现自动化 你通过在浏览器中直接运行的动手代码来练习 Git Advanced: Monorepo, Submodules & Workflows,全天候 AI 导师会在你学习这节课的过程中回答你的问题。
学习 Git Advanced: Monorepo, Submodules & Workflows 需要有经验吗?
无需任何先前经验。CoddyKit 上的 Git Advanced: Monorepo, Submodules & Workflows 课程适合初学者到高级学习者,你可以从这里开始或从头开始,按照自己的节奏学习。 这是第 2 节课,共 4 节。
「服务器端 Git 钩子」课时需要多长时间?
大多数 CoddyKit 课程大约需要 5–10 分钟。每节课都很精短且互动,所以你能稳步进步,并在网页和应用中从离开的地方继续。
我能在这节 Git Advanced: Monorepo, Submodules & Workflows 课中编写并运行代码吗?
能。每节 Git Advanced: Monorepo, Submodules & Workflows 课都包含内置代码编辑器,你可以在浏览器中直接编写并运行真实代码,并获得即时 AI 反馈 — 无需本地设置。
此课程中的所有课时
- 客户端 Git 钩子
- 服务器端 Git 钩子
- Git 配置与别名
- 使用 Husky 与团队共享钩子