fork of radicle with Git LFS support, backed by IPFS
Go to file
Lorenz Leutgeb ac572e64e5 node: Support systemd credential for passphrase
While it is possible to pass the passphrase via the environment, e.g.
`EnvironmentFile=<path to file that contains "RAD_PASSPHRASE=…">`
this is less secure than passing it via a file, because the environment
is inherited down the process tree.

Thus, allow using a systemd credential. The ID of the credential must be

    xyz.radicle.node.passphrase

and is not user-configurable.

Passing the passphrase via file is now possible with
`LoadCredential=xyz.radicle.node.passphrase:<path to file that contains passphrase>`

This requires just a bit of plumbing in `radicle-node`.

Because this mechanism is more secure than using the environment
variable `RAD_PASSPHRASE`, it takes priority. That is, if both the
systemd credential is available, *and* the environment variable
`RAD_PASSPHRASE` is set, the former is preferred.

Heads-up:
 1. The contents of the file must be valid UTF-8 (see documentation of
    `std::fs::read_to_string`). Assuming that the passphrase is at some
    point chosen by the user and typed on a keyboard, this does not
    seem like a severe restriction.
 2. The contents of the file are not processed otherwise, i.e. line
    breaks (notably at the end of the file) are not stripped.

The related `issue/8bd040e9de05e7fc27e373ebc1649ff4ad930e7a` asked for a
very similar feature: Passing the passphrase via a file named by the
value of the of the environment variable `RAD_PASSPHRASE_FILE`.
It was also briefly discussed at
<https://radicle.zulipchat.com/#narrow/channel/369277-heartwood/topic/.60RAD_PASSPHRASE_FILE.60/with/529104447>.
2025-10-09 10:03:21 +01:00
.cargo fetch: upgrade gix crates 2024-05-17 13:27:18 +02:00
.config nix: switch to use nix flakes 2023-12-13 12:25:12 +01:00
.github github/actions: Add a workflow to build 2025-09-04 15:43:36 +03:00
.radicle ci: Deny `cargo doc` warnings 2025-09-15 12:23:11 +02:00
build build/release: missed updating the symlink 2025-09-30 19:10:54 +02:00
crates node: Support systemd credential for passphrase 2025-10-09 10:03:21 +01:00
debian chore(debian/changelog): update package version to match upstream 2025-07-23 11:34:20 +02:00
scripts cli/self: Stop printing information about the node 2025-09-04 17:12:19 +03:00
systemd systemd: Clean up default service configurations 2025-08-26 20:25:08 +02:00
.dockerignore build: Add "upload" build step 2024-04-29 10:47:03 +02:00
.env.seed seed: Update default tracking policy for seed 2023-04-17 21:16:56 +02:00
.envrc chore: use watch_file in .envrc 2025-05-15 14:54:13 +02:00
.gitignore repo: Move workspace crates into `crates` subdirectory 2025-06-09 15:09:21 +02:00
.gitsigners Add Lorenz Leutgeb to `.gitsigners` 2025-04-17 14:33:36 +02:00
ARCHITECTURE.md docs: link to protocol guide 2024-04-03 15:32:26 +02:00
CHANGELOG.md node: Support systemd credential for passphrase 2025-10-09 10:03:21 +01:00
CONTRIBUTING.md doc: Mention handling of "radicle.xyz" 2025-09-04 16:44:05 +03:00
Cargo.lock crates: bump for release 2025-10-06 16:36:30 +01:00
Cargo.toml crates: bump for release 2025-10-06 16:36:30 +01:00
DCO Add licenses and contributor information 2022-11-16 12:26:12 +01:00
HACKING.md docs: Add a note on running isolated nodes 2024-09-12 17:56:21 +02:00
LICENSE-APACHE Add licenses and contributor information 2022-11-16 12:26:12 +01:00
LICENSE-MIT Add licenses and contributor information 2022-11-16 12:26:12 +01:00
README.md docs: fix installation instructions in README.md 2025-07-20 15:33:12 +00:00
VERSIONING.md build: Add "upload" build step 2024-04-29 10:47:03 +02:00
build.rs build: Update env vars for build process 2024-06-20 10:47:50 +02:00
deny.toml fetch: integrate the latest `gix-protocol` into `radicle-fetch` 2025-04-17 14:09:22 +02:00
flake.lock nix: Update nix packages to 25.05 2025-08-12 08:38:57 +01:00
flake.nix flake: Keep `crates/**/*.txt` files for build 2025-10-02 15:45:22 +01:00
git-remote-rad.1.adoc Add rudimentary Debian packaging for binaries 2023-11-01 12:56:35 +01:00
rad-id.1.adoc cli: test canonical tags 2025-07-16 16:54:43 +02:00
rad-patch.1.adoc remote-helper: Add patch.branch option 2025-09-19 07:57:44 +01:00
rad.1.adoc cli/self: Stop printing information about the node 2025-09-04 17:12:19 +03:00
radicle-node.1.adoc docs: Update manual pages to 1.0.0 2024-04-22 14:37:19 +02:00
rust-toolchain.toml rust-toolchain: 1.85 → 1.88 2025-07-24 17:43:12 +02:00

README.md

❤️🪵

Radicle Heartwood Protocol & Stack

Heartwood is the third iteration of the Radicle Protocol, a powerful peer-to-peer code collaboration and publishing stack. The repository contains a full implementation of Heartwood, complete with a user-friendly command-line interface (rad) and network daemon (radicle-node).

Radicle was designed to be a secure, decentralized and powerful alternative to code forges such as GitHub and GitLab that preserves user sovereignty and freedom.

See the Radicle home page for general information, and the Zulip chat to talk to the project.

See the Protocol Guide for an in-depth description of how Radicle works.

Installation

Requirements

  • Linux or Unix based operating system.
  • Git 2.34 or later
  • OpenSSH 9.1 or later with ssh-agent

📀 From binaries

Requires curl and tar.

Run the following command to install the latest binary release:

curl -sSf https://radicle.xyz/install | sh

Or visit our download page.

📦 From source

Requires the Rust toolchain.

You can install the Radicle stack from source, by running the following commands from inside this repository:

cargo install --path crates/radicle-cli --force --locked --root ~/.radicle
cargo install --path crates/radicle-node --force --locked --root ~/.radicle
cargo install --path crates/radicle-remote-helper --force --locked --root ~/.radicle

Or directly from our seed node:

cargo install --force --locked --root ~/.radicle \
    --git https://seed.radicle.xyz/z3gqcJUoA1n9HaHKufZs5FCSGazv5.git \
    crates/radicle-cli crates/radicle-node crates/radicle-remote-helper

Running

Systemd unit files are provided for the node under the /systemd folder. They can be used as a starting point for further customization.

For running in debug mode, see HACKING.md.

Feedback

If you have feedback, feel free to create issues using rad issue, join our Zulip, or email feedback@radicle.xyz. Emails sent to this address are automatically posted to our public #feedback channel on Zulip, revealing the From header (which usually contains your name and email address). This allows us to discuss your feedback on Zulip, and, if necessary, respond to you via email.

Contributing

See CONTRIBUTING.md and HACKING.md for an introduction to contributing to Radicle.

License

Radicle is distributed under the terms of both the MIT license and the Apache License (Version 2.0).

See LICENSE-APACHE and LICENSE-MIT for details.