Docs menu
Docs / Start

Quick start: your first blocked push in 10 minutes

On this page

Run the gateway in Docker, point one repo at it, and watch it stop a leaked key. Need bare metal, a LAN setup or TLS? The full setup guide covers every option.

You need: a machine with Docker (the gateway), your dev machine with git and an SSH key, and a personal access token that can write to your repo on GitHub, GitLab or Gitea.

Start the gateway#

On the gateway machine:

curl -O https://raw.githubusercontent.com/nimblegate/nimblegate/main/compose.yaml
docker compose up -d

Claim your admin login#

Print the one-time setup token:

docker logs nimblegate | grep nbg-setup

Open http://localhost:7900/setup, paste the token and choose a password. Gateway on another machine? Tunnel to it first, then open the same address:

ssh -L 7900:127.0.0.1:7900 <user>@<gateway-host>

Add your SSH key#

On your dev machine, print your public key:

cat ~/.ssh/id_ed25519.pub

In the dashboard: Keys → Add a key, paste the line, save. No key yet? Run ssh-keygen -t ed25519 first.

Register your repo#

In the dashboard: Repos → Add a repo.

  • Name: what you’ll push to, e.g. my-app
  • Upstream URL: your real repo over HTTPS, e.g. https://github.com/you/my-app.git
  • Upstream credential: an access token that can push to the repo (which scopes)

Click Register. Existing history is mirrored down, and the core rule kit is applied.

Push through the gateway#

On your dev machine, in your clone of the repo:

git remote set-url origin ssh://git@<gateway-host>:2222/~/my-app.git
git push

A clean push is checked and forwarded to your real repo in about a second. Keep the ~/ in the URL; it’s required on the Docker image.

Watch it block a leaked key#

Commit a random fake AWS key and push:

echo "AWS_KEY=AKIA$(LC_ALL=C tr -dc 'A-Z0-9' < /dev/urandom | head -c 16)" > leak-test.env
git add leak-test.env && git commit -m "test: leak a fake key"
git push

The push is rejected, and nothing reaches your real repo:

remote:   refs/heads/main: BLOCK [security/no-hardcoded-credentials] credentials detected (raw bytes redacted): leak-test.env:1 - AWS access key
 ! [remote rejected] main -> main (pre-receive hook declined)

Undo the test commit with git reset --hard HEAD~1. Open Feed in the dashboard to see both pushes and why each was decided.

Next#

Live demo How it works Questions: contact@nimblegate.com