# Install Git and Create Your First Repository: Commits, Branches and Remotes

> Install and configure Git, create a repository, make commits, work with branches and pull requests, connect to GitHub with SSH and avoid committing secrets.

- Source: https://www.itwonderlab.com/install-git-first-repository/
- Published: 2026-08-13
- Updated: 2026-08-13
- Author: Javier Ruiz Jiménez (https://www.javierruizjimenez.com/)
- Site: IT Wonder Lab (https://www.itwonderlab.com/)

---

## Why Git

[Git](https://www.itwonderlab.com/git/) keeps the history of your files. For infrastructure as code this means every change to [Terraform](https://www.itwonderlab.com/terraform/) or [Ansible](https://www.itwonderlab.com/ansible/) is reviewed, versioned and reversible, and a pipeline such as [GitHub Actions](https://www.itwonderlab.com/github-actions/) can run on every push.

## Install and configure

```bash
sudo apt update && sudo apt install -y git      # macOS: brew install git
git --version
git config --global user.name "Your Name"
git config --global user.email "you@example.com"
git config --global init.defaultBranch main
git config --global pull.rebase true
```

## First repository

```bash
mkdir infra && cd infra
git init
echo "# infra" > README.md
git status
git add README.md
git commit -m "Add README"
git log --oneline
```

A commit is a snapshot of the files you added with `git add` (the **staging area**). Write messages that say what changed and why.

## .gitignore: what must never be committed

```text title=".gitignore"
.terraform/
*.tfstate
*.tfstate.backup
*.tfvars
.env
*.pem
```

State files and credentials contain secrets. If one is committed, deleting it later does not remove it from the history: rotate the secret. See [Terraform secrets management](https://www.itwonderlab.com/terraform-secrets-management/).

## Branches

```bash
git switch -c add-vpc          # create and move to a branch
# edit files...
git add -A && git commit -m "Add VPC module"
git switch main
git merge add-vpc              # or open a pull request instead
git branch -d add-vpc
```

The usual flow is a short branch per change, a **pull request** for review and a merge into `main`.

## Connect to GitHub with SSH

```bash
ssh-keygen -t ed25519 -C "you@example.com"
cat ~/.ssh/id_ed25519.pub        # paste it in GitHub > Settings > SSH keys
ssh -T git@github.com
git remote add origin git@github.com:your-user/infra.git
git push -u origin main
```

This uses [public key authentication](https://www.itwonderlab.com/public-key-authentication/). Keys can also sign commits; see [GnuPG](https://www.itwonderlab.com/gnupg/).

## Everyday commands

```bash
git pull                       # update
git diff                       # unstaged changes; --staged for staged ones
git restore file.tf            # discard changes in a file
git commit --amend             # fix the last commit (not after pushing)
git stash / git stash pop      # park changes
git log --graph --oneline --all
git revert <commit>            # undo a pushed commit with a new commit
```

## Next steps

Use Git as the source of truth for a cluster with [Argo CD](https://www.itwonderlab.com/argocd-gitops-kubernetes/), or run Terraform from a pipeline with [GitHub Actions and AWS OIDC](https://www.itwonderlab.com/terraform-github-actions-aws-oidc/).
