Git · Lesson 7 · 25 min

Git on a server: tracking /etc

Almost everything that makes a Linux server yours lives in /etc: users, SSH settings, the web server's config, the firewall. When something breaks after “someone changed something”, the first questions are always what changed, when, and who did it. etckeeper turns /etc into a git repository, so git can answer all three.

You will learn

  • Install and start etckeeper on Rocky and on Ubuntu (they differ!)
  • Commit your own config changes with a message that says why
  • See what a package install changed, committed for you automatically
  • Find and undo a bad edit with git diff and git restore
  • Why /etc's repository must stay private

Installing etckeeper

This is where the two families really differ. Ubuntu's package does everything as it installs. On Rocky, etckeeper comes from EPEL, you start the repository yourself, and the part that hooks into dnf is a separate package.

StepRocky / RHELUbuntu / Debian
Installsudo dnf install epel-release
sudo dnf install git etckeeper etckeeper-dnf
sudo apt update
sudo apt install etckeeper
Start tracking /etcsudo etckeeper init
sudo etckeeper commit "Initial commit"
done for you during the install
Commits around every package installthe etckeeper-dnf pluginbuilt in (an apt hook)
Commit message after an installcommitting changes in /etc after dnf runcommitting changes in /etc made by "apt install …"
Daily commit of anything left oversudo systemctl enable --now etckeeper.timeron by default
See the historysudo git -C /etc log --oneline same on both

The daily commit catches changes nobody committed by hand, so they still show up in the history, one day at a time.

Everyday use

After etckeeper is set up, it's a normal git repository that belongs to root. Use sudo git -C /etc … from anywhere, or cd /etc and sudo git ….

Same on both
sudo git -C /etc status                      # what changed since the last commit?
sudo git -C /etc diff                        # exactly which lines
sudo etckeeper commit "SSH: at most 3 password tries"   # commit everything, with a why
sudo git -C /etc log --oneline -- ssh/sshd_config      # history of one file
sudo git -C /etc restore hosts               # undo an uncommitted edit

Use etckeeper commit rather than git commit. It adds every change for you, records the file owners and permissions that git can't store (in /etc/.etckeeper), and puts your name on the commit, even though you ran it with sudo.

Before you edit, look

Run sudo git -C /etc status before changing a config file. If it's not clean, someone else changed something and didn't commit it. Find out what first, so you don't mix their change into yours.

Keep it private

/etc holds password hashes (/etc/shadow), private keys and service passwords, so the repository is locked down: /etc/.git is mode 700, and only root can read it. Never push it to GitHub or any public place. If you want a copy somewhere else, push only to a private server you control, over SSH.

etckeeper or Ansible?

etckeeper records what happened on one server, including changes made by hand. Configuration management tools like Ansible describe how many servers should be, and make them that way. Teams that use Ansible still often run etckeeper, because it catches the change someone made by hand at 2 a.m.

Try it: a server with a memory 🗂️

Set up etckeeper on the practice server, change the SSH settings properly, install a web server, then recover from a bad edit to /etc/hosts.

Quick check

1. You installed etckeeper on Rocky, but sudo git -C /etc log says “not a git repository”. What's missing?

2. Why should /etc's repository never be pushed to a public GitHub repo?

3. A config file was edited by hand and now a service won't start. Nobody has committed since. What shows you the edit?

Finished the missions and the quiz? Mark it done to track your progress.

Next up: Linux DevOps · Ship it, automate it, starting with “Containers: build & ship your own image”.