Compare commits

..

52 Commits

Author SHA1 Message Date
eba420cc81 chore: adapt tasks.json for gitops workflow 2025-05-17 08:18:11 +00:00
a9adb834e5 feat: move image cleanup function inside gitops router 2025-05-17 08:08:15 +00:00
f422da8d9e chore: add project local settings for lazyvim 2025-05-17 07:23:20 +00:00
079979292d fix: correct geturl spelling 2025-05-17 07:22:02 +00:00
14a96035b6 feat: add gitops function to copy home.tar.gz 2025-05-17 07:13:49 +00:00
1fc4153048 chore: start tracking home.tar.gz 2025-05-17 07:01:19 +00:00
dceda5fb53 feat: track home.tar.gz using Git LFS 2025-05-17 06:57:03 +00:00
b67af4b482 feat: add gitops function to remove podman containers 2025-05-17 06:34:26 +00:00
61902a8b5b feat: remove ability to copy directly using scp/sftp 2025-05-17 06:33:36 +00:00
5181a3c194 Revert "fix: avoid logging to stdout before running scp to copy tarball"
This reverts commit f8a09a135b.
2025-05-17 06:28:26 +00:00
0e2f89bde4 feat: add git lfs package 2025-05-17 06:11:42 +00:00
f09654160a fix: use evec instead of eval for running scp 2025-05-17 02:59:32 +00:00
f8a09a135b fix: avoid logging to stdout before running scp to copy tarball 2025-05-17 02:49:14 +00:00
80a3878295 fix: check for scp early to avoid shell ouput 2025-05-17 02:47:30 +00:00
54e2ec2374 feat: add gitops router script 2025-05-17 01:57:50 +00:00
156b47aded feat: use locally built image for starting a pod 2025-05-16 23:35:00 +00:00
422a962a85 feat: change owner to devuser for .ssh/*, .config and .config/fish 2025-05-16 23:31:41 +00:00
991478a0b0 feat: split images into 2 - base and workspace 2025-05-16 23:28:39 +00:00
8812bb4528 feat(build): add uid and guid to files in tarball 2025-05-16 23:03:15 +00:00
a45494c949 chore: untrack lazy-lock.json 2025-05-16 20:45:43 +00:00
502d44e06d feat(build): set group executable flag for all folders in .config 2025-05-16 16:23:17 +01:00
23870c3b24 feat(build): update project root file path to container home when creating tar 2025-05-16 15:52:31 +01:00
60eac985e6 feat: adapt strict directory permissions for container $HOME folder 2025-05-16 15:06:32 +01:00
ad7413a0ef fix: adapt build script to new folder convention 2025-05-16 14:22:27 +01:00
f2a947e5f1 chore: add task to delete files ignored by git 2025-05-16 14:15:20 +01:00
de522f78ca chore: untrack .local, .cache, .state .npm .config/fish directories 2025-05-16 14:15:20 +01:00
2123131ca5 chore: add a test task to run test-tmux.sh 2025-05-16 14:15:20 +01:00
6010c6a0ee feat(scripts): rewrite script to fire tmux and fish with project home 2025-05-16 14:15:20 +01:00
6df5d05cc5 refactor: rename nvim-workspace.sh to test-tmux.sh 2025-05-16 14:15:20 +01:00
54baa71622 refactor: move helper scripts into .bin folder and update tasks.json 2025-05-16 14:14:53 +01:00
a565ed4c33 chore: add a task to create a tarball of dot files for devuser 2025-05-16 14:11:52 +01:00
dfdf4fe738 fix: use correct XDG paths for launching neovim inside a tmux with project configs 2025-05-16 14:11:52 +01:00
397467d8a4 refactor: move .config and start.sh outside home/ folder 2025-05-16 14:11:52 +01:00
fcda25b36b fix(build): remove /opt/secure directory from image builder script 2025-05-16 14:11:52 +01:00
37892e4c0a fix: update location of ssh keys inside container 2025-05-16 14:04:35 +01:00
522713b5c2 refactor: migrate ssh config & keys from /opt/secure/ssh to ~/.ssh 2025-05-16 13:58:07 +01:00
cf3dde053d feat(buildah): add package buildah 2025-05-16 13:58:07 +01:00
bc0dbe12c6 chore(git): remove .gitmodules 2025-05-15 20:02:32 +00:00
a2cb37339c feat(buildah): remove headless lazyvim sync 2025-05-15 20:02:08 +00:00
50166b54a8 Revert "feat(nvim): do not install missing plugins in headless mode"
This reverts commit 7f2534a1fd.
2025-05-15 19:56:46 +00:00
b9ba8768b1 feat(nvim): run neovim with correct folder placement 2025-05-15 19:56:27 +00:00
010a4ff2a8 chore(git): ignore /home/.local and /home/.cache folders 2025-05-15 19:55:46 +00:00
0ea5f1a7e7 feat(nvim): integrate snacks with diffview.nvim 2025-05-15 16:50:27 +01:00
2e7b5c5fa3 feat(git): add configuration for git difftool 2025-05-15 16:49:32 +01:00
0a9d0a4ca0 feat(buildah): add less package 2025-05-15 16:48:52 +01:00
d425cca588 feat(nvim): remove fzf-lua extra
use snacks.nvim instead of fzf-lua
2025-05-15 16:48:03 +01:00
3c955ba097 chore(nvim): remove blame.nvim keymap 2025-05-15 16:46:53 +01:00
f7e7a7783e feat(access): give pallav rw access to palak's workspace 2025-05-15 05:40:03 +01:00
eba7f84bff feat(tasks): add task to copy access.yml 2025-05-15 05:39:25 +01:00
9abd983adf feat(zsh): replace zsh with fish 2025-05-15 05:37:56 +01:00
9398844e54 feat(nvim): enable copying to system clipboard directly 2025-05-14 10:04:12 +01:00
7f2534a1fd feat(nvim): do not install missing plugins in headless mode 2025-05-14 10:03:27 +01:00
41 changed files with 578 additions and 482 deletions

18
.bin/create-home-tarball.sh Executable file
View File

@ -0,0 +1,18 @@
#!/usr/bin/env bash
set -euo pipefail
if [ "$(basename "$(pwd -P)")" != "workspaces" ]; then
echo "Error: this script must be run from a directory named 'workspaces', not '$(basename "$(pwd -P)")'" >&2
exit 1
fi
replace_home() {
sed -i "s|$1|$2|g" .config/fish/fish_variables
find .local/share/nvim/mason/packages -type f -exec sed -i "s|$1|$2|g" {} +
}
find .config -type d -exec chmod g+x {} +
replace_home "$PWD" "/home/devuser"
tar -czf home.tar.gz --owner root:0 --group secproc:1002 --xform "s,$PWD,/home/devuser," .config .local .ssh start.sh
replace_home "/home/devuser" "$PWD"

9
.bin/gitops Executable file
View File

@ -0,0 +1,9 @@
#!/bin/bash
ssh -F /dev/null \
-o HostName=10.88.0.1 \
-o Port=22 \
-o User=infilytics \
-o IdentityFile=~/.ssh/id_ed25519 \
-o ProxyCommand=none \
gitops -- "$@"

30
.bin/test-tmux.sh Executable file
View File

@ -0,0 +1,30 @@
#!/usr/bin/env bash
set -euo pipefail
PWD="$(pwd -P)"
if [ "$(basename "$PWD")" != "workspaces" ]; then
echo "Error: this script must be run from a directory named 'workspaces', not '$(basename "$(pwd -P)")'" >&2
exit 1
fi
# Override PWD and HOME for this invocation
export PWD=$PWD
export HOME=$PWD
export TMUX=""
# Optionally adjust XDG_CONFIG_HOME if you use that
# export XDG_CONFIG_HOME="$HOME/.config"
# Start (or attach to) your dev session
SESSION="dev"
# If the session doesn't exist, create it
if ! tmux has-session -t "$SESSION" 2>/dev/null; then
tmux new-session -d -s "$SESSION" -n editor 'HOME='"$HOME"' XDG_STATE_HOME='"$HOME/.state"' /usr/bin/fish'
fi
tmux send-keys -t $SESSION:editor 'fisher install jorgebucaran/fisher pure-fish/pure patrickf1/fzf.fish jorgebucaran/autopair.fish gazorby/fish-abbreviation-tips jethrokuan/z' Enter
# Attach to it
exec tmux attach -t "$SESSION"

View File

View File

0
home/.config/nvim/LICENSE → .config/nvim/LICENSE Normal file → Executable file
View File

0
home/.config/nvim/README.md → .config/nvim/README.md Normal file → Executable file
View File

0
home/.config/nvim/init.lua → .config/nvim/init.lua Normal file → Executable file
View File

View File

@ -8,7 +8,6 @@
"lazyvim.plugins.extras.dap.core",
"lazyvim.plugins.extras.dap.nlua",
"lazyvim.plugins.extras.editor.dial",
"lazyvim.plugins.extras.editor.fzf",
"lazyvim.plugins.extras.editor.illuminate",
"lazyvim.plugins.extras.editor.inc-rename",
"lazyvim.plugins.extras.editor.mini-files",
@ -37,4 +36,3 @@
},
"version": 8
}

View File

@ -0,0 +1,15 @@
-- Keymaps are automatically loaded on the VeryLazy event
-- Default keymaps that are always set: https://github.com/LazyVim/LazyVim/blob/main/lua/lazyvim/config/keymaps.lua
vim.keymap.set(
"n",
"]<space>",
':<C-u>call append(line("."), repeat([""], v:count1))<CR>',
{ silent = true, desc = "Add line below" }
)
vim.keymap.set(
"n",
"[<space>",
':<C-u>call append(line(".")-1, repeat([""], v:count1))<CR>',
{ silent = true, desc = "Add line above" }
)

View File

@ -1,3 +1,4 @@
-- Options are automatically loaded before lazy.nvim startup
-- Default options that are always set: https://github.com/LazyVim/LazyVim/blob/main/lua/lazyvim/config/options.lua
-- Add any additional options here
vim.opt.clipboard = "unnamedplus"

View File

@ -0,0 +1,208 @@
return {
{
"folke/snacks.nvim",
dependencies = { "sindrets/diffview.nvim" },
---@type snacks.Config
opts = {
picker = {
sources = {
git_diff_any = {
finder = function()
local cmd = {
"git",
"log",
"--branches",
"--remotes",
"--oneline",
"--decorate=short",
"--color=never",
"--pretty=format:%h%x1f%D%x1f%s%x1f%ch",
}
local raw = vim.fn.systemlist(cmd)
if vim.v.shell_error ~= 0 then
vim.notify("Failed to load git log", vim.log.levels.ERROR)
return {}
end
local items = {}
for i, record in ipairs(raw) do
if record ~= "" then
-- split on our unitseparator
local parts = vim.split(record, "\x1f", { plain = true })
local sha = parts[1]
local decorate = parts[2]:gsub("^%s*(.-)%s*$", "%1") -- trim
local msg = parts[3]
local rel_date = parts[4]
-- rebuild a nice display string
local display = string.format("%s %s %s (%s)", sha, decorate ~= "" and decorate or "", msg, rel_date)
items[#items + 1] = {
idx = i, -- required
score = 0, -- required
text = display, -- shown in the list
commit = sha, -- for later Diffview use
branch = decorate,
msg = msg,
date = rel_date,
}
end
end
return items
end,
format = function(item, picker)
local util = Snacks.picker.util
local hl = Snacks.picker.highlight
local a = util.align
local ret = {}
-- 1) Commit icon + SHA
ret[#ret + 1] = { picker.opts.icons.git.commit, "SnacksPickerGitCommit" }
ret[#ret + 1] = { a(item.commit, 8, { truncate = true }), "SnacksPickerGitCommit" }
ret[#ret + 1] = { " " }
-- 2) Relative date
ret[#ret + 1] = { a(item.date, 16), "SnacksPickerGitDate" }
ret[#ret + 1] = { " " }
-- 3) Branch/Tag decorate info (if any)
if item.branch and item.branch ~= "" then
-- local truncated = a(item.branch, 20, { truncate = true })
local truncated = item.branch
ret[#ret + 1] = { "[" .. truncated .. "]", "SnacksPickerGitBranch" }
ret[#ret + 1] = { " " }
end
-- 4) Conventional-commit parsing: type, scope, breaking, and body
local msg = item.msg
local typ, scope, breaking, body = msg:match("^(%S+)%s*(%b())(!?):%s*(.*)$")
if not typ then
typ, breaking, body = msg:match("^(%S+)(!?):%s*(.*)$")
end
local msg_hl = "SnacksPickerGitMsg"
if typ and body then
local dimmed = vim.tbl_contains({ "chore", "bot", "build", "ci", "style", "test" }, typ)
msg_hl = dimmed and "SnacksPickerDimmed" or "SnacksPickerGitMsg"
-- type
local type_hl = breaking ~= "" and "SnacksPickerGitBreaking"
or dimmed and "SnacksPickerBold"
or "SnacksPickerGitType"
ret[#ret + 1] = { typ, type_hl }
-- scope
if scope and scope ~= "" then
ret[#ret + 1] = { scope, "SnacksPickerGitScope" }
end
-- breaking "!"
if breaking ~= "" then
ret[#ret + 1] = { "!", "SnacksPickerGitBreaking" }
end
-- delimiter
ret[#ret + 1] = { ": ", "SnacksPickerDelim" }
msg = body
end
-- 5) The rest of the message
ret[#ret + 1] = { msg, msg_hl }
-- 6) Markdown-style inline formatting & issue hyperlinked
hl.markdown(ret)
hl.highlight(ret, { ["#%d+"] = "SnacksPickerGitIssue" })
return ret
end,
preview = "git_show",
matcher = { fuzzy = true },
sort = { fields = { "idx" } },
title = "Select commits to diff",
confirm = function(picker)
local sel = picker:selected()
picker:close()
local function open_single(s)
local parents = vim.fn.systemlist("git rev-list --parents -n 1 " .. s)[1] or ""
if parents:find(" ") then
vim.cmd("DiffviewOpen " .. s .. "^.." .. s)
else
vim.cmd("DiffviewOpen " .. s)
end
end
if #sel == 1 then
open_single(sel[1].commit)
elseif #sel == 2 then
vim.cmd("DiffviewOpen " .. sel[2].commit .. ".." .. sel[1].commit)
else
vim.notify("Select maximum two commits", vim.log.levels.ERROR)
end
end,
},
git_diff_branches = {
finder = "git_branches",
format = "git_branch",
preview = "git_log",
matcher = { fuzzy = true },
sort = { fields = { "idx" } },
title = "Select branches to diff",
confirm = function(picker)
local sel = picker:selected()
picker:close()
local function open_single(s)
local parents = vim.fn.systemlist("git rev-list --parents -n 1 " .. s)[1] or ""
if parents:find(" ") then
vim.cmd("DiffviewOpen " .. s .. "^.." .. s)
else
vim.cmd("DiffviewOpen " .. s)
end
end
if #sel == 1 then
open_single(sel[1].branch)
elseif #sel == 2 then
vim.cmd("DiffviewOpen " .. sel[2].branch .. ".." .. sel[1].branch)
else
vim.notify("Select maximum two commits", vim.log.levels.ERROR)
end
end,
},
},
},
},
keys = {
{
"<leader>gD",
function()
---@diagnostic disable-next-line: undefined-field
Snacks.picker.git_diff_any()
end,
desc = "Snacks: Git Diff",
},
{
"<leader>gE",
function()
---@diagnostic disable-next-line: undefined-field
Snacks.picker.git_diff_branches()
end,
desc = "Snacks: Git Branch Diff",
},
},
},
{
"sindrets/diffview.nvim",
opts = {},
},
}

View File

0
home/.config/tmux/tmux.conf → .config/tmux/tmux.conf Normal file → Executable file
View File

View File

@ -4,7 +4,7 @@
# without any warranty.
# Copyright 2012— Gregory Pakosz (@gpakosz).
set -g default-shell /usr/bin/zsh
set -g default-shell /usr/bin/fish
# -- bindings ------------------------------------------------------------------

1
.gitattributes vendored Normal file
View File

@ -0,0 +1 @@
home.tar.gz filter=lfs diff=lfs merge=lfs -text

9
.gitignore vendored
View File

@ -1,4 +1,7 @@
local
logs
files/pallav
home/.config/nvim/lazy-lock.json
.local
.cache
.state
.config/fish
.npm
.config/nvim/lazy-lock.json

4
.gitmodules vendored
View File

@ -1,4 +0,0 @@
[submodule "home/.config/zsh/ohmyzsh"]
path = home/.config/zsh/ohmyzsh
url = https://github.com/ohmyzsh/ohmyzsh.git
ignore = all

24
.lazy.lua Normal file
View File

@ -0,0 +1,24 @@
return {
"folke/snacks.nvim",
opts = {
-- show hidden files in snacks.explorer
picker = {
sources = {
explorer = {
-- show hidden files like .env
hidden = true,
-- show files ignored by git like node_modules
ignored = false,
exclude = { ".git" },
},
files = {
-- show hidden files like .env
hidden = true,
-- show files ignored by git like node_modules
ignored = false,
exclude = { ".npm", ".git" },
},
},
},
},
}

4
00-allow-git.conf → .ssh/config Normal file → Executable file
View File

@ -1,7 +1,7 @@
Host alps
HostName 10.88.0.1
User git
IdentityFile /opt/secure/ssh/id_ed25519
IdentityFile ~/.ssh/id_ed25519
IdentitiesOnly yes
StrictHostKeyChecking yes
Port 2222
@ -10,7 +10,7 @@ Host alps
Host github
HostName github.com
User git
IdentityFile /opt/secure/ssh/id_ed25519
IdentityFile ~/.ssh/id_ed25519
IdentitiesOnly yes
StrictHostKeyChecking yes
ProxyCommand none

108
.vscode/tasks.json vendored
View File

@ -2,41 +2,121 @@
"version": "2.0.0",
"tasks": [
{
"label": "Build workspace image",
"label": "GitOps(Build): base image",
"type": "shell",
"command": "./build-workspace.sh",
"command": ".bin/gitops build base",
"group": "build",
"problemMatcher": [],
"detail": "build base image using buildah"
},
{
"label": "GitOps(Build): workspace image",
"type": "shell",
"command": ".bin/gitops build workspace",
"group": "build",
"problemMatcher": [],
"detail": "build podman image using buildah"
},
{
"label": "Clean dangling images",
"label": "GitOps: Clean dangling images",
"type": "shell",
"command": "./clean_dangling_images.sh",
"command": ".bin/gitops clean",
"problemMatcher": [],
"detail": "Clean podman images"
},
{
"label": "Tag image",
"label": "Gitops(Update): build-base.sh",
"type": "shell",
"command": "podman tag localhost/analytics-backend-workspace:latest localhost:5100/analytics-backend-workspace:latest",
"command": ".bin/gitops update base",
"group": "build",
"problemMatcher": [],
"detail": "Tag podman image to localhost 5100"
"detail": "Copy build-base.sh to /home/infilytics/.local/bin/"
},
{
"label": "Push image",
"label": "GitOps(Update): build-workspace.sh",
"type": "shell",
"command": "podman push --tls-verify=false localhost:5100/analytics-backend-workspace:latest",
"command": ".bin/gitops update workspace",
"group": "build",
"problemMatcher": [],
"detail": "Push podman image to localhost 5100"
"detail": "Copy build-workspace.sh to /home/infilytics/.local/bin/"
},
{
"label": "Copy ssh_router.sh",
"label": "GitOps(Update): ssh_router.sh",
"type": "shell",
"command": "sudo cp ssh_router.sh /home/infilytics/ && sudo chown -R infilytics:infilytics /home/infilytics/ssh_router.sh",
"command": ".bin/gitops update ssh_router",
"group": "build",
"problemMatcher": [],
"detail": "Copy ssh_router.sh to /home/infilytics"
"detail": "Copy ssh_router.sh to /home/infilytics/.local/bin/"
},
{
"label": "GitOps(Update): access.yml",
"type": "shell",
"command": ".bin/gitops update access",
"group": "build",
"problemMatcher": [],
"detail": "Copy access.yml to /home/infilytics/"
},
{
"label": "GitOps(Update): gitops_router.sh",
"type": "shell",
"command": ".bin/gitops update gitops_router",
"group": "build",
"problemMatcher": [],
"detail": "Copy gitops_router.sh to /home/infilytics/.local/bin"
},
{
"label": "GitOps(Update): home.tar.gz",
"type": "shell",
"command": ".bin/gitops update home_tar",
"group": "build",
"problemMatcher": [],
"detail": "Copy home.tar.gz to /home/infilytics/"
},
{
"label": "Create home tarball",
"type": "shell",
"command": "${workspaceFolder}/.bin/create-home-tarball.sh",
"group": "build",
"problemMatcher": [],
"detail": "create home.tar.gz from .config .local .ssh start.sh"
},
{
"label": "Test: start tmux session",
"type": "shell",
"command": "${workspaceFolder}/.bin/test-tmux.sh",
"group": "test",
"problemMatcher": [],
"detail": "run tmux with project room as home"
},
{
"label": "GitOps: Show image status",
"type": "shell",
"command": ".bin/gitops status",
"problemMatcher": [],
"detail": "run podman images on remote"
},
{
"label": "GitOps: Remove workspace container",
"type": "shell",
"command": ".bin/gitops remove ${input:container} -f",
"problemMatcher": [],
"detail": "run podman rm $args on remote"
},
{
"label": "Cleanup worktree",
"type": "shell",
"command": "git clean -Xfd",
"problemMatcher": [],
"detail": "delete all untracked files listed in .gitignore"
}
],
"inputs": []
"inputs": [
{
"id": "container",
"type": "pickString",
"description": "Pick a container",
"options": ["pallav", "palak", "param", "darshan"],
"default": "pallav"
}
]
}

View File

@ -4,6 +4,7 @@ pallav:
rw:
- darshan
- param
- palak
darshan:
name: Darshan Parmar

24
build-base.sh Executable file
View File

@ -0,0 +1,24 @@
#!/bin/bash
set -euo pipefail
BASE_IMG_NAME="analytics-backend-base"
DEV_USER=devuser
DEV_UID=1001
DEV_GID=1001
ctr=$(buildah from archlinux)
buildah run "$ctr" -- bash -c "
pacman -Sy --noconfirm && \
pacman -S --noconfirm --needed base-devel neovim git git-lfs fish tmux \
nodejs python podman fzf fd ripgrep jdk-openjdk fisher yazi less buildah \
lazygit luarocks python-pynvim npm bash-completion tree-sitter-cli kitty-terminfo \
lua51 openssh && \
pacman -Scc --noconfirm && \
groupadd -g $DEV_GID $DEV_USER && \
groupadd -g 1002 secproc && \
useradd -ms /bin/fish -G secproc -u $DEV_UID -g $DEV_GID $DEV_USER
"
buildah commit "$ctr" $BASE_IMG_NAME
echo "$BASE_IMG_NAME built."

View File

@ -1,56 +1,25 @@
#!/bin/bash
set -euo pipefail
BASE_IMG_NAME="analytics-backend-base"
IMG_NAME="analytics-backend-workspace"
DEV_USER=devuser
DEV_UID=1001
DEV_GID=1001
SECURE=/opt/secure
DEV_HOME=/home/$DEV_USER
ctr=$(buildah from archlinux)
ctr=$(buildah from "$BASE_IMG_NAME")
buildah run "$ctr" -- bash -c "\
pacman -Sy --noconfirm && pacman -S --noconfirm --needed base-devel neovim git zsh tmux \
nodejs python podman fzf fd ripgrep jdk-openjdk zsh-completions zsh-syntax-highlighting \
lazygit zsh-autosuggestions luarocks python-pynvim npm bash-completion tree-sitter-cli \
lua51 openssh && pacman -Scc --noconfirm && groupadd secproc && groupadd -g $DEV_GID $DEV_USER && \
useradd -ms /bin/zsh -G secproc -u $DEV_UID -g $DEV_GID $DEV_USER && mkdir -m 511 -p $SECURE
"
buildah add "$ctr" home.tar.gz $DEV_HOME
# copy start script, zshrc, neovim, tmux setup and ssh setup
buildah copy --chown $DEV_USER:$DEV_USER "$ctr" ./home/. $DEV_HOME
buildah copy "$ctr" 00-allow-git.conf /etc/ssh/ssh_config.d/
# configure lazyvim
buildah run --user $DEV_USER "$ctr" -- bash -c "\
nvim --headless \"+Lazy! sync\" +qa && sleep 1 && \
nvim --headless \"+Lazy! sync\" +qa && sleep 1 && \
nvim --headless \"+Lazy! sync\" +qa && \
mkdir -p $DEV_HOME/.ssh && ssh-keyscan -p 2222 10.88.0.1 >> ~/.ssh/known_hosts && \
ssh-keyscan -p 22 github.com >> ~/.ssh/known_hosts
"
# lock the files
buildah run "$ctr" -- bash -c "\
chmod 750 $DEV_HOME/start.sh \
$DEV_HOME/.config/lazygit/config.yml \
$DEV_HOME/.config/nvim/lua/config/lazy.lua \
$DEV_HOME/.config/nvim/init.lua \
$DEV_HOME/.config/nvim/README.md \
$DEV_HOME/.config/nvim/LICENSE \
$DEV_HOME/.config/tmux/tmux.conf \
$DEV_HOME/.config/zsh/fzf-git.sh && \
chown root:secproc $DEV_HOME/start.sh \
$DEV_HOME/.config/lazygit/config.yml \
$DEV_HOME/.config/nvim/lua/config/lazy.lua \
$DEV_HOME/.config/nvim/init.lua \
$DEV_HOME/.config/nvim/README.md \
$DEV_HOME/.config/nvim/LICENSE \
$DEV_HOME/.config/tmux/tmux.conf \
$DEV_HOME/.config/zsh/fzf-git.sh
"
# shellcheck disable=SC2016
buildah run "$ctr" -- fish -c '
set -gx HOME '"$DEV_HOME"';
ssh-keyscan -p 2222 10.88.0.1 >> $HOME/.ssh/known_hosts;
ssh-keyscan -p 22 github.com >> $HOME/.ssh/known_hosts;
chown -R '"$DEV_USER"':'"$DEV_USER"' $HOME/.local $HOME/.config/fish/completions \
$HOME/.config/fish/functions $HOME/.config/fish/fish_variables $HOME/.ssh;
chown '"$DEV_USER"':'"$DEV_USER"' $HOME/.config $HOME/.config/fish \
$HOME/.config/tmux;
'
buildah config \
--user $DEV_USER \
@ -60,5 +29,4 @@ buildah config \
"$ctr"
buildah commit "$ctr" $IMG_NAME
echo "$IMG_NAME built."
echo "$IMG_NAME built from $BASE_IMG_NAME."

View File

@ -1,12 +0,0 @@
#!/bin/bash
# Get list of image IDs with <none> tag (dangling images)
dangling_images=$(podman images -f "dangling=true" -q)
if [ -z "$dangling_images" ]; then
echo "✅ No dangling images to remove."
else
echo "⚠️ Removing dangling images..."
echo "$dangling_images" | xargs podman rmi -f
echo "🧹 Done!"
fi

View File

@ -2,6 +2,16 @@
name = ${GIT_NAME}
email = ${GIT_EMAIL}
[diff]
tool = nvimdiff
[difftool]
prompt = false # dont ask “launch nvim?” each time
[difftool "nvimdiff"]
cmd = nvim -d "$LOCAL" "$REMOTE"
trustExitCode = true
[alias]
co = checkout
st = status

114
gitops_router.sh Normal file
View File

@ -0,0 +1,114 @@
#!/usr/bin/env bash
set -euo pipefail
PERSON="$1"
HOST="alps:3222"
PROTOCOL="http"
REPO="babbarc/workspaces"
BRANCH="master"
LOG_FILE="/tmp/.gitops-router-${PERSON}.log"
log() {
local level="${1^^}" # convert to uppercase
shift
echo "[$(date '+%Y-%m-%d %H:%M:%S')] [$level] $*" | tee -a "$LOG_FILE"
}
log info "Received SSH_ORIGINAL_COMMAND: $SSH_ORIGINAL_COMMAND"
# Ensure the variable is set
if [[ -z "${SSH_ORIGINAL_COMMAND:-}" ]]; then
log error "No SSH_ORIGINAL_COMMAND provided."
exit 1
fi
geturl() {
echo "$PROTOCOL://$HOST/$REPO/$1/branch/$BRANCH/$2"
}
function run() {
"$HOME"/.local/bin/"$1"
}
function update() {
type=${4:-raw}
fname=$(basename "$1")
output_path="$HOME/$2/$fname"
url=$(geturl "$type" "$1")
[ -f "$output_path" ] && chmod 700 "$output_path"
curl -fsSL "$url" -o "$output_path" && log info "Downloaded $url to $output_path"
chmod "$3" "$output_path"
}
clean_images() {
# Get list of image IDs with <none> tag (dangling images)
dangling_images=$(podman images -f "dangling=true" -q)
if [ -z "$dangling_images" ]; then
echo "✅ No dangling images to remove."
else
echo "⚠️ Removing dangling images..."
echo "$dangling_images" | xargs podman rmi
echo "🧹 Done!"
fi
}
# Strip arguments and parse command
read -r command args <<<"$SSH_ORIGINAL_COMMAND"
# Define command routing
case "$command" in
build)
case "$args" in
base)
run build-base.sh
;;
workspace)
run build-workspace.sh
;;
*)
log error "Invalid arguments for build command: $args"
;;
esac
;;
update)
case "$args" in
workspace)
update build-workspace.sh .local/bin 500
;;
base)
update build-base.sh .local/bin 500
;;
access)
update access.yml . 400
;;
ssh_router)
update ssh_router.sh .local/bin 500
;;
gitops_router)
update gitops_router.sh .local/bin 500
;;
home_tar)
update home.tar.gz . 500 media
;;
*)
log error "Invalid arguments for update command: $args"
;;
esac
;;
clean)
clean_images
;;
status)
podman images
;;
remove)
podman rm "$args"
;;
*)
log error "Unknown command: $command"
exit 127
;;
esac

BIN
home.tar.gz (Stored with Git LFS) Normal file

Binary file not shown.

View File

@ -1,16 +0,0 @@
-- Keymaps are automatically loaded on the VeryLazy event
-- Default keymaps that are always set: https://github.com/LazyVim/LazyVim/blob/main/lua/lazyvim/config/keymaps.lua
vim.keymap.set(
"n",
"]<space>",
':<C-u>call append(line("."), repeat([""], v:count1))<CR>',
{ silent = true, desc = "Add line below" }
)
vim.keymap.set(
"n",
"[<space>",
':<C-u>call append(line(".")-1, repeat([""], v:count1))<CR>',
{ silent = true, desc = "Add line above" }
)
vim.keymap.set("n", "<leader>ghB", ":ToggleBlame virtual<Enter>", { silent = true, desc = "Toggle virtual blame" })-- Add any additional keymaps here

View File

@ -1,4 +0,0 @@
return {
"sindrets/diffview.nvim",
opts = {},
}

View File

@ -1,344 +0,0 @@
# The MIT License (MIT)
#
# Copyright (c) 2024 Junegunn Choi
#
# Permission is hereby granted, free of charge, to any person obtaining a copy
# of this software and associated documentation files (the "Software"), to deal
# in the Software without restriction, including without limitation the rights
# to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
# copies of the Software, and to permit persons to whom the Software is
# furnished to do so, subject to the following conditions:
#
# The above copyright notice and this permission notice shall be included in
# all copies or substantial portions of the Software.
#
# THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
# IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
# FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
# AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
# LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
# OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
# THE SOFTWARE.
# shellcheck disable=SC2039
[[ $0 = - ]] && return
__fzf_git_color() {
if [[ -n $NO_COLOR ]]; then
echo never
elif [[ $# -gt 0 ]] && [[ -n $FZF_GIT_PREVIEW_COLOR ]]; then
echo "$FZF_GIT_PREVIEW_COLOR"
else
echo "${FZF_GIT_COLOR:-always}"
fi
}
__fzf_git_cat() {
if [[ -n $FZF_GIT_CAT ]]; then
echo "$FZF_GIT_CAT"
return
fi
# Sometimes bat is installed as batcat
_fzf_git_bat_options="--style='${BAT_STYLE:-full}' --color=$(__fzf_git_color .) --pager=never"
if command -v batcat > /dev/null; then
echo "batcat $_fzf_git_bat_options"
elif command -v bat > /dev/null; then
echo "bat $_fzf_git_bat_options"
else
echo cat
fi
}
__fzf_git_pager() {
local pager
pager="${FZF_GIT_PAGER:-${GIT_PAGER:-$(git config --get core.pager 2>/dev/null)}}"
echo "${pager:-cat}"
}
if [[ $1 = --list ]]; then
shift
if [[ $# -eq 1 ]]; then
branches() {
git branch "$@" --sort=-committerdate --sort=-HEAD --format=$'%(HEAD) %(color:yellow)%(refname:short) %(color:green)(%(committerdate:relative))\t%(color:blue)%(subject)%(color:reset)' --color=$(__fzf_git_color) | column -ts$'\t'
}
refs() {
git for-each-ref "$@" --sort=-creatordate --sort=-HEAD --color=$(__fzf_git_color) --format=$'%(if:equals=refs/remotes)%(refname:rstrip=-2)%(then)%(color:magenta)remote-branch%(else)%(if:equals=refs/heads)%(refname:rstrip=-2)%(then)%(color:brightgreen)branch%(else)%(if:equals=refs/tags)%(refname:rstrip=-2)%(then)%(color:brightcyan)tag%(else)%(if:equals=refs/stash)%(refname:rstrip=-2)%(then)%(color:brightred)stash%(else)%(color:white)%(refname:rstrip=-2)%(end)%(end)%(end)%(end)\t%(color:yellow)%(refname:short) %(color:green)(%(creatordate:relative))\t%(color:blue)%(subject)%(color:reset)' | column -ts$'\t'
}
hashes() {
git log --date=short --format="%C(green)%C(bold)%cd %C(auto)%h%d %s (%an)" --graph --color=$(__fzf_git_color) "$@" $LIST_OPTS
}
case "$1" in
branches)
echo 'CTRL-O (open in browser) ALT-A (show all branches)'
echo 'ALT-H (list commit hashes)'
branches
;;
all-branches)
echo 'CTRL-O (open in browser) ALT-ENTER (accept without remote)'
echo 'ALT-H (list commit hashes)'
branches -a
;;
hashes)
echo 'CTRL-O (open in browser) CTRL-D (diff)'
echo 'CTRL-S (toggle sort) ALT-A (show all hashes)'
hashes
;;
all-hashes)
echo 'CTRL-O (open in browser) CTRL-D (diff)'
echo 'CTRL-S (toggle sort)'
hashes --all
;;
refs)
echo 'CTRL-O (open in browser) ALT-E (examine in editor) ALT-A (show all refs)'
refs --exclude='refs/remotes'
;;
all-refs)
echo 'CTRL-O (open in browser) ALT-E (examine in editor)'
refs
;;
*) exit 1 ;;
esac
elif [[ $# -gt 1 ]]; then
set -e
branch=$(git rev-parse --abbrev-ref HEAD 2> /dev/null)
if [[ $branch = HEAD ]]; then
branch=$(git describe --exact-match --tags 2> /dev/null || git rev-parse --short HEAD)
fi
# Only supports GitHub for now
case "$1" in
commit)
hash=$(grep -o "[a-f0-9]\{7,\}" <<< "$2")
path=/commit/$hash
;;
branch|remote-branch)
branch=$(sed 's/^[* ]*//' <<< "$2" | cut -d' ' -f1)
remote=$(git config branch."${branch}".remote || echo 'origin')
branch=${branch#$remote/}
path=/tree/$branch
;;
remote)
remote=$2
path=/tree/$branch
;;
file) path=/blob/$branch/$(git rev-parse --show-prefix)$2 ;;
tag) path=/releases/tag/$2 ;;
*) exit 1 ;;
esac
remote=${remote:-$(git config branch."${branch}".remote || echo 'origin')}
remote_url=$(git remote get-url "$remote" 2> /dev/null || echo "$remote")
if [[ $remote_url =~ ^git@ ]]; then
url=${remote_url%.git}
url=${url#git@}
url=https://${url/://}
elif [[ $remote_url =~ ^http ]]; then
url=${remote_url%.git}
fi
case "$(uname -s)" in
Darwin) open "$url$path" ;;
*) xdg-open "$url$path" ;;
esac
exit 0
fi
fi
if [[ $- =~ i ]] || [[ $1 = --run ]]; then # ----------------------------------
# Redefine this function to change the options
_fzf_git_fzf() {
fzf --height 50% --tmux 90%,70% \
--layout reverse --multi --min-height 20+ --border \
--no-separator --header-border horizontal \
--border-label-pos 2 \
--color 'label:blue' \
--preview-window 'right,50%' --preview-border line \
--bind 'ctrl-/:change-preview-window(down,50%|hidden|)' "$@"
}
_fzf_git_check() {
git rev-parse HEAD > /dev/null 2>&1 && return
[[ -n $TMUX ]] && tmux display-message "Not in a git repository"
return 1
}
__fzf_git=${BASH_SOURCE[0]:-${(%):-%x}}
__fzf_git=$(readlink -f "$__fzf_git" 2> /dev/null || /usr/bin/ruby --disable-gems -e 'puts File.expand_path(ARGV.first)' "$__fzf_git" 2> /dev/null)
_fzf_git_files() {
_fzf_git_check || return
local root query
root=$(git rev-parse --show-toplevel)
[[ $root != "$PWD" ]] && query='!../ '
(git -c color.status=$(__fzf_git_color) status --short --no-branch
git ls-files "$root" | grep -vxFf <(git status -s | grep '^[^?]' | cut -c4-; echo :) | sed 's/^/ /') |
_fzf_git_fzf -m --ansi --nth 2..,.. \
--border-label '📁 Files ' \
--header 'CTRL-O (open in browser) ALT-E (open in editor)' \
--bind "ctrl-o:execute-silent:bash \"$__fzf_git\" --list file {-1}" \
--bind "alt-e:execute:${EDITOR:-vim} {-1} > /dev/tty" \
--query "$query" \
--preview "git diff --no-ext-diff --color=$(__fzf_git_color .) -- {-1} | $(__fzf_git_pager); $(__fzf_git_cat) {-1}" "$@" |
cut -c4- | sed 's/.* -> //'
}
_fzf_git_branches() {
_fzf_git_check || return
bash "$__fzf_git" --list branches |
_fzf_git_fzf --ansi \
--border-label '🌲 Branches ' \
--header-lines 2 \
--tiebreak begin \
--preview-window down,border-top,40% \
--color hl:underline,hl+:underline \
--no-hscroll \
--bind 'ctrl-/:change-preview-window(down,70%|hidden|)' \
--bind "ctrl-o:execute-silent:bash \"$__fzf_git\" --list branch {}" \
--bind "alt-a:change-border-label(🌳 All branches)+reload:bash \"$__fzf_git\" --list all-branches" \
--bind "alt-h:become:LIST_OPTS=\$(cut -c3- <<< {} | cut -d' ' -f1) bash \"$__fzf_git\" --run hashes" \
--bind "alt-enter:become:printf '%s\n' {+} | cut -c3- | sed 's@[^/]*/@@'" \
--preview "git log --oneline --graph --date=short --color=$(__fzf_git_color .) --pretty='format:%C(auto)%cd %h%d %s' \$(cut -c3- <<< {} | cut -d' ' -f1) --" "$@" |
sed 's/^\* //' | awk '{print $1}' # Slightly modified to work with hashes as well
}
_fzf_git_tags() {
_fzf_git_check || return
git tag --sort -version:refname |
_fzf_git_fzf --preview-window right,70% \
--border-label '📛 Tags ' \
--header 'CTRL-O (open in browser)' \
--bind "ctrl-o:execute-silent:bash \"$__fzf_git\" --list tag {}" \
--preview "git show --color=$(__fzf_git_color .) {} | $(__fzf_git_pager)" "$@"
}
_fzf_git_hashes() {
_fzf_git_check || return
bash "$__fzf_git" --list hashes |
_fzf_git_fzf --ansi --no-sort --bind 'ctrl-s:toggle-sort' \
--border-label '🍡 Hashes ' \
--header-lines 2 \
--bind "ctrl-o:execute-silent:bash \"$__fzf_git\" --list commit {}" \
--bind "ctrl-d:execute:grep -o '[a-f0-9]\{7,\}' <<< {} | head -n 1 | xargs git diff --color=$(__fzf_git_color) > /dev/tty" \
--bind "alt-a:change-border-label(🍇 All hashes)+reload:bash \"$__fzf_git\" --list all-hashes" \
--color hl:underline,hl+:underline \
--preview "grep -o '[a-f0-9]\{7,\}' <<< {} | head -n 1 | xargs git show --color=$(__fzf_git_color .) | $(__fzf_git_pager)" "$@" |
awk 'match($0, /[a-f0-9][a-f0-9][a-f0-9][a-f0-9][a-f0-9][a-f0-9][a-f0-9][a-f0-9]*/) { print substr($0, RSTART, RLENGTH) }'
}
_fzf_git_remotes() {
_fzf_git_check || return
git remote -v | awk '{print $1 "\t" $2}' | uniq |
_fzf_git_fzf --tac \
--border-label '📡 Remotes ' \
--header 'CTRL-O (open in browser)' \
--bind "ctrl-o:execute-silent:bash \"$__fzf_git\" --list remote {1}" \
--preview-window right,70% \
--preview "git log --oneline --graph --date=short --color=$(__fzf_git_color .) --pretty='format:%C(auto)%cd %h%d %s' '{1}/$(git rev-parse --abbrev-ref HEAD)' --" "$@" |
cut -d$'\t' -f1
}
_fzf_git_stashes() {
_fzf_git_check || return
git stash list | _fzf_git_fzf \
--border-label '🥡 Stashes ' \
--header 'CTRL-X (drop stash)' \
--bind 'ctrl-x:reload(git stash drop -q {1}; git stash list)' \
-d: --preview "git show --color=$(__fzf_git_color .) {1} | $(__fzf_git_pager)" "$@" |
cut -d: -f1
}
_fzf_git_lreflogs() {
_fzf_git_check || return
git reflog --color=$(__fzf_git_color) --format="%C(blue)%gD %C(yellow)%h%C(auto)%d %gs" | _fzf_git_fzf --ansi \
--border-label '📒 Reflogs ' \
--preview "git show --color=$(__fzf_git_color .) {1} | $(__fzf_git_pager)" "$@" |
awk '{print $1}'
}
_fzf_git_each_ref() {
_fzf_git_check || return
bash "$__fzf_git" --list refs | _fzf_git_fzf --ansi \
--nth 2,2.. \
--tiebreak begin \
--border-label '☘️ Each ref ' \
--header-lines 1 \
--preview-window down,border-top,40% \
--color hl:underline,hl+:underline \
--no-hscroll \
--bind 'ctrl-/:change-preview-window(down,70%|hidden|)' \
--bind "ctrl-o:execute-silent:bash \"$__fzf_git\" --list {1} {2}" \
--bind "alt-e:execute:${EDITOR:-vim} <(git show {2}) > /dev/tty" \
--bind "alt-a:change-border-label(🍀 Every ref)+reload:bash \"$__fzf_git\" --list all-refs" \
--preview "git log --oneline --graph --date=short --color=$(__fzf_git_color .) --pretty='format:%C(auto)%cd %h%d %s' {2} --" "$@" |
awk '{print $2}'
}
_fzf_git_worktrees() {
_fzf_git_check || return
git worktree list | _fzf_git_fzf \
--border-label '🌴 Worktrees ' \
--header 'CTRL-X (remove worktree)' \
--bind 'ctrl-x:reload(git worktree remove {1} > /dev/null; git worktree list)' \
--preview "
git -c color.status=$(__fzf_git_color .) -C {1} status --short --branch
echo
git log --oneline --graph --date=short --color=$(__fzf_git_color .) --pretty='format:%C(auto)%cd %h%d %s' {2} --
" "$@" |
awk '{print $1}'
}
fi # --------------------------------------------------------------------------
if [[ $1 = --run ]]; then
shift
type=$1
shift
eval "_fzf_git_$type" "$@"
elif [[ $- =~ i ]]; then # ------------------------------------------------------
if [[ -n "${BASH_VERSION:-}" ]]; then
__fzf_git_init() {
bind -m emacs-standard '"\er": redraw-current-line'
bind -m emacs-standard '"\C-z": vi-editing-mode'
bind -m vi-command '"\C-z": emacs-editing-mode'
bind -m vi-insert '"\C-z": emacs-editing-mode'
local o c
for o in "$@"; do
c=${o:0:1}
bind -m emacs-standard '"\C-g\C-'$c'": " \C-u \C-a\C-k`_fzf_git_'$o'`\e\C-e\C-y\C-a\C-y\ey\C-h\C-e\er \C-h"'
bind -m vi-command '"\C-g\C-'$c'": "\C-z\C-g\C-'$c'\C-z"'
bind -m vi-insert '"\C-g\C-'$c'": "\C-z\C-g\C-'$c'\C-z"'
bind -m emacs-standard '"\C-g'$c'": " \C-u \C-a\C-k`_fzf_git_'$o'`\e\C-e\C-y\C-a\C-y\ey\C-h\C-e\er \C-h"'
bind -m vi-command '"\C-g'$c'": "\C-z\C-g'$c'\C-z"'
bind -m vi-insert '"\C-g'$c'": "\C-z\C-g'$c'\C-z"'
done
}
elif [[ -n "${ZSH_VERSION:-}" ]]; then
__fzf_git_join() {
local item
while read item; do
echo -n "${(q)item} "
done
}
__fzf_git_init() {
local m o
for o in "$@"; do
eval "fzf-git-$o-widget() { local result=\$(_fzf_git_$o | __fzf_git_join); zle reset-prompt; LBUFFER+=\$result }"
eval "zle -N fzf-git-$o-widget"
for m in emacs vicmd viins; do
eval "bindkey -M $m '^g^${o[1]}' fzf-git-$o-widget"
eval "bindkey -M $m '^g${o[1]}' fzf-git-$o-widget"
done
done
}
fi
__fzf_git_init files branches tags remotes hashes stashes lreflogs each_ref worktrees
fi # --------------------------------------------------------------------------

View File

@ -1,18 +0,0 @@
export ZSH=$HOME/.config/zsh/ohmyzsh
ZSH_THEME="robbyrussell"
plugins=(git fzf)
export FZF_CTRL_T_OPTS="--preview '(highlight -O ansi -l {} 2> /dev/null || cat {} || tree -C {}) 2> /dev/null | head -200'"
export FZF_ALT_C_OPTS="--preview 'tree -C {} | head -200'"
export FZF_DEFAULT_OPTS=" \
--color=bg+:#313244,bg:#1e1e2e,spinner:#f5e0dc,hl:#f38ba8 \
--color=fg:#cdd6f4,header:#f38ba8,info:#cba6f7,pointer:#f5e0dc \
--color=marker:#f5e0dc,fg+:#cdd6f4,prompt:#cba6f7,hl+:#f38ba8"
export FZF_TMUX=1
source $ZSH/oh-my-zsh.sh
source $HOME/.config/zsh/fzf-git.sh
source /usr/share/zsh/plugins/zsh-autosuggestions/zsh-autosuggestions.zsh
source /usr/share/zsh/plugins/zsh-syntax-highlighting/zsh-syntax-highlighting.zsh

View File

@ -1,7 +0,0 @@
#!/bin/bash
XDG_CONFIG_HOME="$PWD/home/.config" \
XDG_DATA_HOME="$PWD/local/share" \
XDG_STATE_HOME="$PWD/local/state" \
XDG_CACHE_HOME="$PWD/local/cache" \
nvim

View File

@ -1,5 +0,0 @@
#!/bin/bash
ln -s "$PWD"/zsh-autosuggestions "$PWD"/config/zsh/ohmyzsh/custom/plugins/zsh-autosuggestions
ln -s "$PWD"/zsh-syntax-highlighting "$PWD"/config/zsh/ohmyzsh/custom/plugins/zsh-syntax-highlighting
rm -rf local/state

View File

@ -2,7 +2,7 @@
PERSON="$1"
WORKSPACE="$SSH_ORIGINAL_COMMAND"
IMAGE="localhost:5100/analytics-backend-workspace:latest"
IMAGE="localhost/analytics-backend-workspace:latest"
DEV_USER="devuser"
XDG_RUNTIME_DIR="/run/user/$(id -u)"
@ -80,8 +80,8 @@ start_container_if_needed() {
-v "${XDG_RUNTIME_DIR}"/podman/podman.sock:/run/podman/podman.sock \
-v /home/infilytics/data/"$WORKSPACE":/app \
-v /home/infilytics/secrets/"$WORKSPACE"/gitconfig:/home/"$DEV_USER"/.gitconfig:ro \
-v /home/infilytics/secrets/"$WORKSPACE"/id_ed25519:/opt/secure/ssh/id_ed25519:ro \
-v /home/infilytics/secrets/"$WORKSPACE"/id_ed25519.pub:/opt/secure/ssh/id_ed25519.pub:ro \
-v /home/infilytics/secrets/"$WORKSPACE"/id_ed25519:/home/"$DEV_USER"/.ssh/id_ed25519:ro \
-v /home/infilytics/secrets/"$WORKSPACE"/id_ed25519.pub:/home/"$DEV_USER"/.ssh/id_ed25519.pub:ro \
--entrypoint "/home/$DEV_USER/start.sh" \
"$IMAGE" "${TMUX_SESSION}"
elif ! podman inspect -f '{{.State.Running}}' "$WORKSPACE" | grep -q true; then

0
home/start.sh → start.sh Normal file → Executable file
View File