Reuse local credentials
Devsy makes some of your local credentials available inside the dev container, so you do not configure them in each workspace. It supports git credentials, Docker registry credentials, and GPG keys.
Only use with trusted repositories
Code that runs in the container, including lifecycle commands and features from devcontainer.json, can use these credentials. Do not enable them for repositories or devcontainer.json files you have not reviewed.
SSH agent forwarding never exposes your private key. It does let anything in the container request signatures, and so act as you against any service the key can access, for as long as the workspace runs.
Git
Devsy provides HTTPS credentials through a git credential helper. SSH credentials work through agent forwarding, which Devsy sets up in the workspace's SSH config. To turn injection off for all workspaces:
devsy context set default -o SSH_INJECT_GIT_CREDENTIALS=falseDocker
Devsy provides registry credentials through a Docker credential helper, so you can pull and push private images from the container. To turn it off for all workspaces:
devsy context set default -o SSH_INJECT_DOCKER_CREDENTIALS=falseGPG
Devsy can forward your GPG keys into the container over the SSH tunnel, so you can sign commits there. To turn it on for all workspaces:
devsy context set default -o GPG_AGENT_FORWARDING=trueOr for one workspace:
devsy workspace up --ssh-gpg-forwarding my-workspace