git submodule add <url> <path> clones the library into a folder and records it. A relative URL is resolved against the superproject's own remote, so ../booknest-ui.git means the repository next to BookNest's on the server. Then a fresh clone of BookNest fetches it:
git submodule add ../booknest-ui.git public/vendor/ui
git submodule add ssh://dev@localhost:32022/home/dev/v5-ch2/server/booknest-ui.git \
public/vendor/ui
git -C public/vendor/ui switch -q --detach v1.0.0
# Edit public/index.html: link vendor/ui/book-card.css
git add -A && git commit -qm "Add the booknest-ui library as a submodule at v1.0.0"
cat .gitmodules
git push -q
git clone -q ../server/booknest.git ../fresh && cd ../fresh
git submodule update -q --init
git submodule status
cd ../booknestCloning into '/home/dev/v5-ch2/booknest/public/vendor/ui'...
fatal: transport 'file' not allowed
...
Cloning into '/home/dev/v5-ch2/booknest/public/vendor/ui'...
[submodule "public/vendor/ui"]
path = public/vendor/ui
url = ssh://dev@localhost:32022/home/dev/v5-ch2/server/booknest-ui.git
25b55abf390cc82fec78cfc385135222baa1ba6d public/vendor/ui (v1.0.0)The first attempt failed on purpose: since the security releases of October 2022 (Git 2.38.1 1,932 , CVE-2022-39253), submodules may not be cloned over the local file transport unless protocol.file.allow is always, so a malicious repository cannot point one at files on your disk. The second attempt uses the SSH server of Git's Transport Protocols. The URL goes into .gitmodules, a tracked file; the commit goes into BookNest's tree. A plain git clone leaves the folder empty until git submodule update --init, or clone with --recurse-submodules.