| 1 | --- |
| 2 | title: Go modules |
| 3 | description: go get a workspace's Go modules straight from its repositories on g1t.sh, public and private. |
| 4 | --- |
| 5 | |
| 6 | A repository on g1t.sh is a Go module at its own address. `go get` finds |
| 7 | its code from the address, and fetches it with git: |
| 8 | |
| 9 | ```sh |
| 10 | go get g1t.sh/acme/tools |
| 11 | go get g1t.sh/acme/tools/cmd/lint@v1.4.0 |
| 12 | ``` |
| 13 | |
| 14 | The repository's `go.mod` names the module: |
| 15 | |
| 16 | ```text |
| 17 | module g1t.sh/acme/tools |
| 18 | ``` |
| 19 | |
| 20 | Versions are its tags (`v1.4.0`); a pseudo-version names any other commit. |
| 21 | Packages in subdirectories are imported by their path, as above. |
| 22 | |
| 23 | ## Public modules |
| 24 | |
| 25 | Public repositories need nothing: `go get` works as is, and the public Go |
| 26 | module proxy and checksum database serve them like any other public module. |
| 27 | |
| 28 | ## Private modules |
| 29 | |
| 30 | Tell Go which modules are private, so it fetches them from g1t.sh directly |
| 31 | and does not ask the public proxy or checksum database about them: |
| 32 | |
| 33 | ```sh |
| 34 | go env -w GOPRIVATE=g1t.sh/acme |
| 35 | ``` |
| 36 | |
| 37 | Then give git credentials for g1t.sh: your username and an |
| 38 | [access token](https://g1t.sh/settings/tokens) (full access, or with |
| 39 | `code:read`) in `~/.netrc` (`_netrc` on Windows): |
| 40 | |
| 41 | ```text |
| 42 | machine g1t.sh |
| 43 | login <you> |
| 44 | password <token> |
| 45 | ``` |
| 46 | |
| 47 | or with a git credential helper, as for any clone (see |
| 48 | [Git](/guides/git/#authentication)). Reading a private module needs the |
| 49 | Read role on its repository. |
| 50 | |
| 51 | Keep `GOINSECURE` and `GOFLAGS=-insecure` unset: g1t.sh is served over |
| 52 | HTTPS, and neither is ever needed. |
| 53 | |
| 54 | ## In workflows |
| 55 | |
| 56 | ```yaml |
| 57 | jobs: |
| 58 | build: |
| 59 | runs-on: ubuntu-latest |
| 60 | env: |
| 61 | GOPRIVATE: g1t.sh/acme |
| 62 | steps: |
| 63 | - uses: actions/checkout@v4 |
| 64 | - uses: actions/setup-go@v5 |
| 65 | with: |
| 66 | go-version: stable |
| 67 | - run: git config --global url."https://g1t:${G1T_TOKEN}@g1t.sh/".insteadOf "https://g1t.sh/" |
| 68 | env: |
| 69 | G1T_TOKEN: ${{ secrets.G1T_TOKEN }} |
| 70 | - run: go build ./... |
| 71 | ``` |
| 72 | |
| 73 | ## How it works |
| 74 | |
| 75 | Go asks `https://g1t.sh/<workspace>/<repo>?go-get=1` and reads a |
| 76 | `go-import` tag pointing at `https://g1t.sh/<workspace>/<repo>.git`. Every |
| 77 | repository address answers, private ones included, and the answer names |
| 78 | nothing but that address; whether anything can be fetched is up to git and |
| 79 | your credentials. |