Git on a server: tracking /etc
Almost everything that makes a Linux server yours lives in /etc: users, SSH settings, the web server's config, the firewall. When something breaks after “someone changed something”, the first questions are always what changed, when, and who did it. etckeeper turns /etc into a git repository, so git can answer all three.
You will learn
- Install and start etckeeper on Rocky and on Ubuntu (they differ!)
- Commit your own config changes with a message that says why
- See what a package install changed, committed for you automatically
- Find and undo a bad edit with
git diffandgit restore - Why
/etc's repository must stay private
Installing etckeeper
This is where the two families really differ. Ubuntu's package does everything as it installs. On Rocky, etckeeper comes from EPEL, you start the repository yourself, and the part that hooks into dnf is a separate package.
| Step | Rocky / RHEL | Ubuntu / Debian |
|---|---|---|
| Install | sudo dnf install epel-releasesudo dnf install git etckeeper etckeeper-dnf | sudo apt updatesudo apt install etckeeper |
| Start tracking /etc | sudo etckeeper initsudo etckeeper commit "Initial commit" | done for you during the install |
| Commits around every package install | the etckeeper-dnf plugin | built in (an apt hook) |
| Commit message after an install | committing changes in /etc after dnf run | committing changes in /etc made by "apt install …" |
| Daily commit of anything left over | sudo systemctl enable --now etckeeper.timer | on by default |
| See the history | sudo git -C /etc log --oneline same on both | |
The daily commit catches changes nobody committed by hand, so they still show up in the history, one day at a time.
Everyday use
After etckeeper is set up, it's a normal git repository that belongs to root. Use sudo git -C /etc … from anywhere, or cd /etc and sudo git ….
sudo git -C /etc status # what changed since the last commit? sudo git -C /etc diff # exactly which lines sudo etckeeper commit "SSH: at most 3 password tries" # commit everything, with a why sudo git -C /etc log --oneline -- ssh/sshd_config # history of one file sudo git -C /etc restore hosts # undo an uncommitted edit
Use etckeeper commit rather than git commit. It adds every change for you, records the file owners and permissions that git can't store (in /etc/.etckeeper), and puts your name on the commit, even though you ran it with sudo.
Run sudo git -C /etc status before changing a config file. If it's not clean, someone else changed something and didn't commit it. Find out what first, so you don't mix their change into yours.
Keep it private
/etc holds password hashes (/etc/shadow), private keys and service passwords, so the repository is locked down: /etc/.git is mode 700, and only root can read it. Never push it to GitHub or any public place. If you want a copy somewhere else, push only to a private server you control, over SSH.
etckeeper or Ansible?
etckeeper records what happened on one server, including changes made by hand. Configuration management tools like Ansible describe how many servers should be, and make them that way. Teams that use Ansible still often run etckeeper, because it catches the change someone made by hand at 2 a.m.
Try it: a server with a memory 🗂️
Set up etckeeper on the practice server, change the SSH settings properly, install a web server, then recover from a bad edit to /etc/hosts.
Quick check
1. You installed etckeeper on Rocky, but sudo git -C /etc log says “not a git repository”. What's missing?
✓ On Rocky you start the repository yourself. Ubuntu's package does it during the install.
2. Why should /etc's repository never be pushed to a public GitHub repo?
✓ That's why /etc/.git is readable by root only.
3. A config file was edited by hand and now a service won't start. Nobody has committed since. What shows you the edit?
✓ diff shows uncommitted changes, line by line. log only shows what was committed.
Next up: Linux DevOps · Ship it, automate it, starting with “Containers: build & ship your own image”.