Модуль 7 · Урок 28

Safe recovery, credentials і secrets

Recovery-команда правильна лише для конкретного state і scope. Unstage, discard uncommitted work, undo shared commit та move unpublished branch pointer — різні операції з різним ризиком. Secret incident починається з revoke/rotate, а не з косметичного видалення файла.

RestoreRevertReflogRotate first

Decision table перед дією

State/goalInspectТипове рішення
Прибрати path зі stagingstatus, staged diffrestore --staged PATH
Відкинути unstaged editsdiff -- PATH, backuprestore PATH лише усвідомлено
Скасувати shared commitshow, dependenciesrevert COMMIT
Знайти втрачений local tipreflogСтворити recovery branch на знайдений commit

Reflog локальний і expire/cleanup-bound; це evidence для recovery, не remote backup. Reset/rewrite shared history вимагає явної координації й не є базовим repair.

Remote authentication без секретів у коді

GitHub підтримує HTTPS credential flow і SSH. Пароль account для Git operations не використовується як старий password-based flow; credential manager, SSH key із passphrase або scoped token зберігаються у відповідному secure store. Не вставляйте token в remote URL, shell history, README, screenshot, issue чи support log.

Secret incident: invalidate, contain, remove, prevent

1 · Revoke/rotateСтаре значення має перестати працювати.
2 · ScopeRepo, paths, commits, branches, forks, time.
3 · CoordinateSecurity/repo owner і collaborators.
4 · RemoveCurrent tree та agreed history cleanup.
5 · VerifyRevocation, scan, no recontamination.
6 · PreventIgnore, push protection, least privilege.

.gitignore, delete latest file або private repository не відкликають credential і не стирають копії/history.

Лабораторна й acceptance

Для кожного recovery scenario заповніть state, inspect evidence, chosen action, irreversible risk і verification. Для synthetic incident створіть runbook без самого secret. Acceptance: жодного real credential, destructive automation або твердження, що history rewrite автоматично прибирає всі external copies.

Завантажити Git workflow lab →

Офіційні джерела

Практична перевірка · урок 28 з 60

Закріпіть матеріал уроку

Три сценарні питання. Для зарахування уроку потрібно дати щонайменше дві правильні відповіді.

1. Як прибрати path зі staging, зберігши working edit?
2. Що перевірити перед git restore PATH?
3. Як зазвичай скасувати shared bad commit без rewrite?