Skip to main content

ggshield machine setup

Description​

Set up ggshield protection on this machine.

ggshield machine setup [OPTIONS]

Configures every protection in one idempotent run: the ggshield AI hook for each detected AI coding assistant, the global git pre-commit/pre-push hooks, and a honeytoken to detect endpoint intrusion. Safe to re-run — it adds what is missing and leaves existing entries untouched.

Each protection is on by default; drop one with --no-ai-hooks, --no-git-hooks, or --no-honeytokens. --agent / --exclude-agent narrow which assistants get the AI hook. When run as root (or with --system), the git hooks are installed machine-wide for every user.

Options​

  • --no-ai-hooks: Do not configure the AI assistant hooks.
  • --no-git-hooks: Do not install the global git hooks.
  • --no-honeytokens: Do not plant a honeytoken on this machine.
  • --agent ASSISTANT: Only configure the AI hook for these assistants (repeatable). Defaults to every assistant detected on this machine.
  • --exclude-agent ASSISTANT: Skip these assistants when configuring the AI hook (repeatable).
  • --system: Install the git hooks machine-wide (all users) instead of for the current user. Implied when running as root, e.g. under an MDM.

This command supports all ggshield global options.