Compare commits
2 Commits
1f2d81984b
...
c1cbaffe42
Author | SHA1 | Date | |
---|---|---|---|
c1cbaffe42 | |||
99aac09f75 |
@ -159,7 +159,7 @@ update)
|
|||||||
case "${args[0]}" in
|
case "${args[0]}" in
|
||||||
containerfile) update 0 Containerfile . 500 ;;
|
containerfile) update 0 Containerfile . 500 ;;
|
||||||
access) update 2 access.yml . 400 ;;
|
access) update 2 access.yml . 400 ;;
|
||||||
authorized_keys) update 2 access.yml . 400 ;;
|
authorized_keys) update 2 authorized_keys . 400 ;;
|
||||||
ssh_router) update 1 ssh_router.sh .local/bin 500 ;;
|
ssh_router) update 1 ssh_router.sh .local/bin 500 ;;
|
||||||
gitops_router) update 1 gitops_router.sh .local/bin 500 ;;
|
gitops_router) update 1 gitops_router.sh .local/bin 500 ;;
|
||||||
validate_command) update 1 validate_command_access.sh .local/bin 500 ;;
|
validate_command) update 1 validate_command_access.sh .local/bin 500 ;;
|
||||||
|
@ -6,6 +6,7 @@ WORKSPACE="${SSH_ORIGINAL_COMMAND:-}"
|
|||||||
IMAGE="localhost/analytics-backend-workspace:latest"
|
IMAGE="localhost/analytics-backend-workspace:latest"
|
||||||
DEV_USER="devuser"
|
DEV_USER="devuser"
|
||||||
XDG_RUNTIME_DIR="/run/user/$(id -u)"
|
XDG_RUNTIME_DIR="/run/user/$(id -u)"
|
||||||
|
PODMAN_SOCKET="/run/user/$(id -u mypodmanuser)"
|
||||||
LOG_FILE="/tmp/.ssh-router-${PERSON}.log"
|
LOG_FILE="/tmp/.ssh-router-${PERSON}.log"
|
||||||
|
|
||||||
# ─────────────────────────────────────────────
|
# ─────────────────────────────────────────────
|
||||||
@ -124,6 +125,7 @@ start_container_if_needed() {
|
|||||||
--user "$DEV_USER" \
|
--user "$DEV_USER" \
|
||||||
--hostname "$WORKSPACE" \
|
--hostname "$WORKSPACE" \
|
||||||
--label auto-cleanup=true \
|
--label auto-cleanup=true \
|
||||||
|
-v "${PODMAN_SOCKET}/podman/podman.sock:/run/podman/podman.sock:z" \
|
||||||
-v "$HOME/data/$WORKSPACE:/app:Z" \
|
-v "$HOME/data/$WORKSPACE:/app:Z" \
|
||||||
-v "$HOME/secrets/$WORKSPACE/gitconfig:/home/$DEV_USER/.gitconfig:ro,Z" \
|
-v "$HOME/secrets/$WORKSPACE/gitconfig:/home/$DEV_USER/.gitconfig:ro,Z" \
|
||||||
-v "$HOME/secrets/$WORKSPACE/id_ed25519:/home/$DEV_USER/.ssh/id_ed25519:ro,Z" \
|
-v "$HOME/secrets/$WORKSPACE/id_ed25519:/home/$DEV_USER/.ssh/id_ed25519:ro,Z" \
|
||||||
|
Reference in New Issue
Block a user