Compare commits

..

93 Commits

Author SHA1 Message Date
95b6480323 Revert "feat: add ssh key into memory"
This reverts commit 2b19cccdbc.
2025-05-23 15:14:08 +00:00
2b19cccdbc feat: add ssh key into memory 2025-05-23 12:12:35 +00:00
5483cf71bd feat: remove secproc group and copy start.sh separately 2025-05-23 11:59:44 +00:00
b0c6750585 feat: remove default key paths 2025-05-23 11:59:16 +00:00
fce5d72b19 feat: set mode, remove secproc group and remove start.sh from tarball 2025-05-23 11:59:00 +00:00
bdac248845 chore: add task to update start.sh script in $HOME/ 2025-05-23 09:50:48 +00:00
1c7bc517dd feat: modify UID:GID to 1000:1000 for container 2025-05-22 16:49:48 +00:00
1e8bb0521c Revert "feat: add devuser to group appuser 1003"
This reverts commit d15950f86c.
2025-05-22 16:10:49 +00:00
9577707dd5 fix: add comma between groups 2025-05-21 15:13:20 +00:00
d15950f86c feat: add devuser to group appuser 1003 2025-05-21 15:07:04 +00:00
50907b9519 feat: remove sshd from openssh package 2025-05-21 10:36:38 +00:00
62d6833cdc feat: supress podman-compose warning 2025-05-20 20:59:24 +00:00
e5dc78049a chore: supress podman-compose warning 2025-05-20 20:53:45 +00:00
a3f393b844 feat: add packages podman-compose and podman-docker 2025-05-20 20:42:50 +00:00
fd7e83ccff feat: add environment var CONTAINER_CONNECTION to start up script 2025-05-20 19:54:19 +00:00
bc7d65a24b fix: run podman as user and correct default command 2025-05-20 18:37:17 +00:00
ed3dc4bb8f feat: add podman package and connection settings 2025-05-20 18:31:24 +00:00
9d0c18f94b Revert "feat: add package python-pip"
This reverts commit 1a9023b25f.
2025-05-20 09:14:08 +00:00
7f4913f942 feat: separate out .config installations into separate script 2025-05-20 09:10:09 +00:00
3c25755a27 chore: ignore home.tar.gz 2025-05-20 09:04:25 +00:00
1a9023b25f feat: add package python-pip 2025-05-20 09:03:47 +00:00
1652edccd0 Remove LFS-tracked file home.tar.gz 2025-05-20 09:01:59 +00:00
aa9dfca6c1 feat: add package rust-analyzer 2025-05-20 08:52:50 +00:00
2448ce6ab3 chore: build home.tar.gz
add rust lazy extra
2025-05-20 07:43:04 +00:00
c6503fa9dd feat: add lang.rust lazy extra plugin 2025-05-20 07:39:03 +00:00
1ced08a364 feat: add fish configuration files 2025-05-20 07:38:24 +00:00
44eff8fc7f feat: add continuum plugin to tmux 2025-05-20 06:53:06 +00:00
bfcb9175ec chore: build home.tar.gz 2025-05-20 06:52:29 +00:00
e319884921 feat: add packages rust startship and fortune-mod 2025-05-20 05:53:13 +00:00
7e4aaa2dec chore: correct task command to remove images 2025-05-17 19:33:18 +00:00
f0559a240f chore: update home.tar.gz 2025-05-17 19:30:21 +00:00
a2ea4e6344 feat: remove podman support 2025-05-17 19:27:01 +00:00
bc3db0abae chore: add task to remove images on remote 2025-05-17 18:41:11 +00:00
77435d3748 chore: remove redundant tasks 2025-05-17 16:11:11 +00:00
b7b09db4c5 chore: remove files related to workspace pipelines 2025-05-17 16:10:00 +00:00
1b88c80669 chore: update tasks 2025-05-17 15:16:11 +00:00
af579d1a7f chore: remove access and authorized_keys files from project 2025-05-17 15:15:51 +00:00
e6fff0c044 feat: add validate_command_access.sh with its tests 2025-05-17 15:12:18 +00:00
ba052d78d4 feat: add gitops ability to update authorized_keys 2025-05-17 15:10:44 +00:00
bc1cbfc772 chore: change repo for validate_command and gitconfig to workspaces 2025-05-17 15:10:08 +00:00
f8b38996df feat: add package go-yq to build image 2025-05-17 14:43:42 +00:00
d488a87dd4 feat: upgrade gitops ability to fetch files from different repos 2025-05-17 14:42:06 +00:00
3e361cd03c feat: separate access validation logic for gitops commands into a separate file 2025-05-17 14:38:56 +00:00
fd0c07e954 feat: remove buildah scripts and adapt project to use Containerfile 2025-05-17 13:21:36 +00:00
d3f5e93ad8 feat: add containerfile for our builds 2025-05-17 13:12:00 +00:00
c9460b8ebc chore: update command access for pallav 2025-05-17 11:37:50 +00:00
9629c3253e fix: validate commands, improve remove container logic, standardize logs in gitops router 2025-05-17 11:37:06 +00:00
6e11d19510 feat: update authorized_keys file 2025-05-17 10:04:00 +00:00
a4bfe5a5c0 feat: use %h instead of hard coded paths in authorized_keys 2025-05-17 09:44:31 +00:00
54a42ad4d5 fix: use $HOME variable in place of hard coded path values 2025-05-17 09:39:07 +00:00
21eee8c3ec feat: remove access to host podman socket 2025-05-17 09:35:48 +00:00
ff72c95012 style: beatify and optimize ssh router with chatgpt 2025-05-17 09:21:48 +00:00
3576bf93c2 style: beautify and optimize gitops router with chatgpt 2025-05-17 09:15:50 +00:00
d7c7686a9e feat: generate gitconfig on the fly before creating container 2025-05-17 09:04:26 +00:00
a179a3ad23 chore: add task to copy gitconfig.template 2025-05-17 09:02:58 +00:00
56744155cb feat: add gitops function to update gitconfig template 2025-05-17 08:59:58 +00:00
eba420cc81 chore: adapt tasks.json for gitops workflow 2025-05-17 08:18:11 +00:00
a9adb834e5 feat: move image cleanup function inside gitops router 2025-05-17 08:08:15 +00:00
f422da8d9e chore: add project local settings for lazyvim 2025-05-17 07:23:20 +00:00
079979292d fix: correct geturl spelling 2025-05-17 07:22:02 +00:00
14a96035b6 feat: add gitops function to copy home.tar.gz 2025-05-17 07:13:49 +00:00
1fc4153048 chore: start tracking home.tar.gz 2025-05-17 07:01:19 +00:00
dceda5fb53 feat: track home.tar.gz using Git LFS 2025-05-17 06:57:03 +00:00
b67af4b482 feat: add gitops function to remove podman containers 2025-05-17 06:34:26 +00:00
61902a8b5b feat: remove ability to copy directly using scp/sftp 2025-05-17 06:33:36 +00:00
5181a3c194 Revert "fix: avoid logging to stdout before running scp to copy tarball"
This reverts commit f8a09a135b.
2025-05-17 06:28:26 +00:00
0e2f89bde4 feat: add git lfs package 2025-05-17 06:11:42 +00:00
f09654160a fix: use evec instead of eval for running scp 2025-05-17 02:59:32 +00:00
f8a09a135b fix: avoid logging to stdout before running scp to copy tarball 2025-05-17 02:49:14 +00:00
80a3878295 fix: check for scp early to avoid shell ouput 2025-05-17 02:47:30 +00:00
54e2ec2374 feat: add gitops router script 2025-05-17 01:57:50 +00:00
156b47aded feat: use locally built image for starting a pod 2025-05-16 23:35:00 +00:00
422a962a85 feat: change owner to devuser for .ssh/*, .config and .config/fish 2025-05-16 23:31:41 +00:00
991478a0b0 feat: split images into 2 - base and workspace 2025-05-16 23:28:39 +00:00
8812bb4528 feat(build): add uid and guid to files in tarball 2025-05-16 23:03:15 +00:00
a45494c949 chore: untrack lazy-lock.json 2025-05-16 20:45:43 +00:00
502d44e06d feat(build): set group executable flag for all folders in .config 2025-05-16 16:23:17 +01:00
23870c3b24 feat(build): update project root file path to container home when creating tar 2025-05-16 15:52:31 +01:00
60eac985e6 feat: adapt strict directory permissions for container $HOME folder 2025-05-16 15:06:32 +01:00
ad7413a0ef fix: adapt build script to new folder convention 2025-05-16 14:22:27 +01:00
f2a947e5f1 chore: add task to delete files ignored by git 2025-05-16 14:15:20 +01:00
de522f78ca chore: untrack .local, .cache, .state .npm .config/fish directories 2025-05-16 14:15:20 +01:00
2123131ca5 chore: add a test task to run test-tmux.sh 2025-05-16 14:15:20 +01:00
6010c6a0ee feat(scripts): rewrite script to fire tmux and fish with project home 2025-05-16 14:15:20 +01:00
6df5d05cc5 refactor: rename nvim-workspace.sh to test-tmux.sh 2025-05-16 14:15:20 +01:00
54baa71622 refactor: move helper scripts into .bin folder and update tasks.json 2025-05-16 14:14:53 +01:00
a565ed4c33 chore: add a task to create a tarball of dot files for devuser 2025-05-16 14:11:52 +01:00
dfdf4fe738 fix: use correct XDG paths for launching neovim inside a tmux with project configs 2025-05-16 14:11:52 +01:00
397467d8a4 refactor: move .config and start.sh outside home/ folder 2025-05-16 14:11:52 +01:00
fcda25b36b fix(build): remove /opt/secure directory from image builder script 2025-05-16 14:11:52 +01:00
37892e4c0a fix: update location of ssh keys inside container 2025-05-16 14:04:35 +01:00
522713b5c2 refactor: migrate ssh config & keys from /opt/secure/ssh to ~/.ssh 2025-05-16 13:58:07 +01:00
cf3dde053d feat(buildah): add package buildah 2025-05-16 13:58:07 +01:00
38 changed files with 270 additions and 379 deletions

18
.bin/create-home-tarball.sh Executable file
View File

@ -0,0 +1,18 @@
#!/usr/bin/env bash
set -euo pipefail
if [ "$(basename "$(pwd -P)")" != "workspaces" ]; then
echo "Error: this script must be run from a directory named 'workspaces', not '$(basename "$(pwd -P)")'" >&2
exit 1
fi
replace_home() {
sed -i "s|$1|$2|g" .config/fish/fish_variables
find .local/share/nvim/mason/packages -type f -exec sed -i "s|$1|$2|g" {} +
}
find .config -type d -exec chmod g+x {} +
replace_home "$PWD" "/home/devuser"
tar --mode=a=r,u+w,a+x -czf home.tar.gz --owner root:0 --group root:0 --xform "s,$PWD,/home/devuser," .config .local .ssh
replace_home "/home/devuser" "$PWD"

9
.bin/gitops Executable file
View File

@ -0,0 +1,9 @@
#!/bin/bash
ssh -F /dev/null \
-o HostName=10.88.0.1 \
-o Port=22 \
-o User=infilytics \
-o IdentityFile=~/.ssh/id_ed25519 \
-o ProxyCommand=none \
gitops -- "$@"

5
.bin/install-config.sh Executable file
View File

@ -0,0 +1,5 @@
#!/usr/bin/env fish
fisher install patrickf1/fzf.fish jorgebucaran/autopair.fish gazorby/fish-abbreviation-tips jethrokuan/z
echo 'function fish_greeting; fortune; end' >"$HOME"/.config/fish/functions/fish_greeting.fish
echo 'starship init fish | source' >"$HOME"/.config/fish/config.fish

28
.bin/test-tmux.sh Executable file
View File

@ -0,0 +1,28 @@
#!/usr/bin/env bash
set -euo pipefail
PWD="$(pwd -P)"
if [ "$(basename "$PWD")" != "workspaces" ]; then
echo "Error: this script must be run from a directory named 'workspaces', not '$(basename "$(pwd -P)")'" >&2
exit 1
fi
# Override PWD and HOME for this invocation
export PWD=$PWD
export HOME=$PWD
export TMUX=""
# Optionally adjust XDG_CONFIG_HOME if you use that
# export XDG_CONFIG_HOME="$HOME/.config"
# Start (or attach to) your dev session
SESSION="dev"
# If the session doesn't exist, create it
if ! tmux has-session -t "$SESSION" 2>/dev/null; then
tmux new-session -d -s "$SESSION" -n editor 'HOME='"$HOME"' XDG_STATE_HOME='"$HOME/.state"' /usr/bin/fish'
fi
# Attach to it
exec tmux attach -t "$SESSION"

1
.config/fish/config.fish Normal file
View File

@ -0,0 +1 @@
starship init fish | source

View File

@ -0,0 +1,4 @@
patrickf1/fzf.fish
jorgebucaran/autopair.fish
gazorby/fish-abbreviation-tips
jethrokuan/z

View File

@ -0,0 +1 @@
function fish_greeting; fortune; end

View File

View File

0
home/.config/nvim/LICENSE → .config/nvim/LICENSE Normal file → Executable file
View File

0
home/.config/nvim/README.md → .config/nvim/README.md Normal file → Executable file
View File

0
home/.config/nvim/init.lua → .config/nvim/init.lua Normal file → Executable file
View File

View File

@ -21,6 +21,7 @@
"lazyvim.plugins.extras.lang.json", "lazyvim.plugins.extras.lang.json",
"lazyvim.plugins.extras.lang.markdown", "lazyvim.plugins.extras.lang.markdown",
"lazyvim.plugins.extras.lang.python", "lazyvim.plugins.extras.lang.python",
"lazyvim.plugins.extras.lang.rust",
"lazyvim.plugins.extras.lang.scala", "lazyvim.plugins.extras.lang.scala",
"lazyvim.plugins.extras.lang.sql", "lazyvim.plugins.extras.lang.sql",
"lazyvim.plugins.extras.lang.toml", "lazyvim.plugins.extras.lang.toml",
@ -35,4 +36,4 @@
"NEWS.md": "10960" "NEWS.md": "10960"
}, },
"version": 8 "version": 8
} }

View File

0
home/.config/tmux/tmux.conf → .config/tmux/tmux.conf Normal file → Executable file
View File

View File

@ -431,9 +431,9 @@ tmux_conf_uninstall_plugins_on_reload=true
# visit https://github.com/tmux-plugins for available plugins # visit https://github.com/tmux-plugins for available plugins
#set -g @plugin 'tmux-plugins/tmux-copycat' #set -g @plugin 'tmux-plugins/tmux-copycat'
#set -g @plugin 'tmux-plugins/tmux-cpu' #set -g @plugin 'tmux-plugins/tmux-cpu'
#set -g @plugin 'tmux-plugins/tmux-resurrect' set -g @plugin 'tmux-plugins/tmux-resurrect'
#set -g @plugin 'tmux-plugins/tmux-continuum' set -g @plugin 'tmux-plugins/tmux-continuum'
#set -g @continuum-restore 'on' set -g @continuum-restore 'on'
set -g @plugin 'catppuccin/tmux' set -g @plugin 'catppuccin/tmux'

1
.gitattributes vendored Normal file
View File

@ -0,0 +1 @@
home.tar.gz filter=lfs diff=lfs merge=lfs -text

15
.gitignore vendored
View File

@ -1,5 +1,12 @@
logs logs
files/pallav .local
home/.config/nvim/lazy-lock.json .cache
home/.local .state
home/.cache .config/fish/*/*
.config/fish/fish_variables
!.config/fish/config.fish
!.config/fish/fish_plugins
!.config/fish/functions/fish_greeting.fish
.npm
.config/nvim/lazy-lock.json
home.tar.gz

24
.lazy.lua Normal file
View File

@ -0,0 +1,24 @@
return {
"folke/snacks.nvim",
opts = {
-- show hidden files in snacks.explorer
picker = {
sources = {
explorer = {
-- show hidden files like .env
hidden = true,
-- show files ignored by git like node_modules
ignored = false,
exclude = { ".git" },
},
files = {
-- show hidden files like .env
hidden = true,
-- show files ignored by git like node_modules
ignored = false,
exclude = { ".npm", ".git" },
},
},
},
},
}

2
00-allow-git.conf → .ssh/config Normal file → Executable file
View File

@ -1,7 +1,6 @@
Host alps Host alps
HostName 10.88.0.1 HostName 10.88.0.1
User git User git
IdentityFile /opt/secure/ssh/id_ed25519
IdentitiesOnly yes IdentitiesOnly yes
StrictHostKeyChecking yes StrictHostKeyChecking yes
Port 2222 Port 2222
@ -10,7 +9,6 @@ Host alps
Host github Host github
HostName github.com HostName github.com
User git User git
IdentityFile /opt/secure/ssh/id_ed25519
IdentitiesOnly yes IdentitiesOnly yes
StrictHostKeyChecking yes StrictHostKeyChecking yes
ProxyCommand none ProxyCommand none

112
.vscode/tasks.json vendored
View File

@ -2,48 +2,126 @@
"version": "2.0.0", "version": "2.0.0",
"tasks": [ "tasks": [
{ {
"label": "Build workspace image", "label": "GitOps(Build): base image",
"type": "shell", "type": "shell",
"command": "./build-workspace.sh", "command": ".bin/gitops build base",
"group": "build",
"problemMatcher": [],
"detail": "build base image using buildah"
},
{
"label": "GitOps(Build): workspace image",
"type": "shell",
"command": ".bin/gitops build workspace",
"group": "build", "group": "build",
"problemMatcher": [], "problemMatcher": [],
"detail": "build podman image using buildah" "detail": "build podman image using buildah"
}, },
{ {
"label": "Clean dangling images", "label": "GitOps(Build): all images",
"type": "shell", "type": "shell",
"command": "./clean_dangling_images.sh", "command": ".bin/gitops build all",
"group": "build",
"problemMatcher": [],
"detail": "build podman image using buildah"
},
{
"label": "GitOps: Clean dangling images",
"type": "shell",
"command": ".bin/gitops clean",
"problemMatcher": [], "problemMatcher": [],
"detail": "Clean podman images" "detail": "Clean podman images"
}, },
{ {
"label": "Tag image", "label": "GitOps(Update): Containerfile",
"type": "shell", "type": "shell",
"command": "podman tag localhost/analytics-backend-workspace:latest localhost:5100/analytics-backend-workspace:latest", "command": ".bin/gitops update containerfile",
"group": "build",
"problemMatcher": [], "problemMatcher": [],
"detail": "Tag podman image to localhost 5100" "detail": "Copy Containerfile to $HOME/"
}, },
{ {
"label": "Push image", "label": "GitOps(Update): home.tar.gz",
"type": "shell", "type": "shell",
"command": "podman push --tls-verify=false localhost:5100/analytics-backend-workspace:latest", "command": ".bin/gitops update home_tar",
"group": "build",
"problemMatcher": [], "problemMatcher": [],
"detail": "Push podman image to localhost 5100" "detail": "Copy home.tar.gz to $HOME/"
}, },
{ {
"label": "Copy ssh_router.sh", "label": "GitOps(Update): gitconfig.template",
"type": "shell", "type": "shell",
"command": "sudo cp ssh_router.sh /home/infilytics/ && sudo chown -R infilytics:infilytics /home/infilytics/ssh_router.sh", "command": ".bin/gitops update gitconfig",
"group": "build",
"problemMatcher": [], "problemMatcher": [],
"detail": "Copy ssh_router.sh to /home/infilytics" "detail": "Copy gitconfig.template to $HOME/"
}, },
{ {
"label": "Copy access.yml", "label": "GitOps(Update): start.sh",
"type": "shell", "type": "shell",
"command": "sudo cp access.yml /home/infilytics/ && sudo chown -R infilytics:infilytics /home/infilytics/access.yml", "command": ".bin/gitops update start.sh",
"group": "build",
"problemMatcher": [], "problemMatcher": [],
"detail": "Copy access.yml to /home/infilytics" "detail": "Copy start.sh to $HOME/"
},
{
"label": "Create home tarball",
"type": "shell",
"command": "${workspaceFolder}/.bin/create-home-tarball.sh",
"group": "build",
"problemMatcher": [],
"detail": "create home.tar.gz from .config .local .ssh start.sh"
},
{
"label": "Test: start tmux session",
"type": "shell",
"command": "${workspaceFolder}/.bin/test-tmux.sh",
"group": "test",
"problemMatcher": [],
"detail": "run tmux with project room as home"
},
{
"label": "GitOps: Show image status",
"type": "shell",
"command": ".bin/gitops status",
"problemMatcher": [],
"detail": "run podman images on remote"
},
{
"label": "GitOps: Remove workspace container",
"type": "shell",
"command": ".bin/gitops remove ${input:container} -f",
"problemMatcher": [],
"detail": "run podman rm $args on remote"
},
{
"label": "GitOps: Remove workspace image",
"type": "shell",
"command": ".bin/gitops rmi ${input:images}",
"problemMatcher": [],
"detail": "run podman rmi $args on remote"
},
{
"label": "Cleanup worktree",
"type": "shell",
"command": "git clean -Xfd",
"problemMatcher": [],
"detail": "delete all untracked files listed in .gitignore"
} }
], ],
"inputs": [] "inputs": [
{
"id": "container",
"type": "pickString",
"description": "Pick a container",
"options": ["pallav", "palak", "param", "darshan"],
"default": "pallav"
},
{
"id": "images",
"type": "promptString",
"description": "space separated list of images",
"default": ""
}
]
} }

66
Containerfile Normal file
View File

@ -0,0 +1,66 @@
# ───────────────────
# Stage 1: Base Image
# ───────────────────
FROM archlinux:base-devel-20250511.0.348143 as base
ARG DEV_USER=devuser
ARG DEV_UID=1000
ARG DEV_GID=1000
# Install all necessary packages and clean up cache
RUN pacman -Sy --noconfirm && \
pacman -S --noconfirm --needed \
base-devel neovim git git-lfs fish tmux go-yq rust starship podman \
nodejs python fzf fd ripgrep jdk-openjdk fisher yazi less rust-analyzer \
lazygit luarocks python-pynvim npm bash-completion tree-sitter-cli kitty-terminfo \
lua51 openssh fortune-mod podman-compose podman-docker && \
pacman -Scc --noconfirm && \
rm -rf /var/cache/pacman/pkg/* /usr/bin/sshd /usr/lib/systemd/system/sshd.service
# Create user/groups as per your script, with -l to avoid system user quirks
RUN groupadd -g $DEV_GID $DEV_USER && \
useradd -l -ms /bin/fish -u $DEV_UID -g $DEV_GID $DEV_USER
# ────────────────────────
# Stage 2: Workspace Image
# ────────────────────────
FROM base as workspace
ARG DEV_USER=devuser
ARG DEV_UID=1000
ARG DEV_GID=1000
ARG DEV_HOME=/home/$DEV_USER
ARG POD_USER=mypodmanuser
ARG POD_UID=1002
# Use ADD for extracting archives
ADD home.tar.gz $DEV_HOME
COPY --chmod=755 start.sh $DEV_HOME/
# Prepare .ssh and known_hosts, and fix permissions only if dirs exist
RUN mkdir -p $DEV_HOME/.ssh && \
touch /etc/containers/nodocker && \
ssh-keyscan -p 2222 10.88.0.1 >> $DEV_HOME/.ssh/known_hosts && \
ssh-keyscan -p 22 github.com >> $DEV_HOME/.ssh/known_hosts && \
for d in $DEV_HOME/.local \
$DEV_HOME/.config/fish/completions \
$DEV_HOME/.config/fish/functions \
$DEV_HOME/.config/fish/fish_variables \
$DEV_HOME/.ssh; do \
if [ -e "$d" ]; then chown -R $DEV_USER:$DEV_USER "$d"; fi; \
done && \
for d in $DEV_HOME/.local \
$DEV_HOME/.config \
$DEV_HOME/.config/fish \
$DEV_HOME/.config/tmux; do \
if [ -e "$d" ]; then chown $DEV_USER:$DEV_USER "$d"; fi; \
done
WORKDIR /app
USER $DEV_USER
RUN podman system connection add my-remote --identity $DEV_HOME/.ssh/id_ed25519 \
ssh://$POD_USER@10.88.0.1/run/user/${POD_UID}/podman/podman.sock && \
podman system connection default my-remote
CMD ["/home/devuser/start.sh"]

View File

@ -1,30 +0,0 @@
pallav:
name: Pallav Vasa
email: pallav@infilytics.in
rw:
- darshan
- param
- palak
darshan:
name: Darshan Parmar
email: darshan@infilytics.in
rw:
- param
ro:
- pallav
param:
name: Param Makawana
email: param@infilytics.in
ro:
- pallav
- darshan
palak:
name: Palak Vasa
email: pakak@infilytics.in
ro:
- pallav
- param
- darshan

View File

@ -1 +0,0 @@
command="/home/infilytics/ssh_router.sh pallav",no-port-forwarding,no-agent-forwarding,no-X11-forwarding ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIK0il/OJiXygyPWYBt05+OQYjJPxgGuP3kP9hLsD/C7x phoenix@sphinx

View File

@ -1,69 +0,0 @@
#!/bin/bash
set -euo pipefail
IMG_NAME="analytics-backend-workspace"
DEV_USER=devuser
DEV_UID=1001
DEV_GID=1001
SECURE=/opt/secure
DEV_HOME=/home/$DEV_USER
ctr=$(buildah from archlinux)
buildah run "$ctr" -- bash -c "\
pacman -Sy --noconfirm && pacman -S --noconfirm --needed base-devel neovim git fish tmux \
nodejs python podman fzf fd ripgrep jdk-openjdk fisher yazi less buildah \
lazygit luarocks python-pynvim npm bash-completion tree-sitter-cli kitty-terminfo \
lua51 openssh && pacman -Scc --noconfirm && groupadd secproc && groupadd -g $DEV_GID $DEV_USER && \
useradd -ms /bin/fish -G secproc -u $DEV_UID -g $DEV_GID $DEV_USER && mkdir -m 511 -p $SECURE
"
# copy start script, neovim, tmux setup and ssh setup
buildah copy --chown $DEV_USER:$DEV_USER "$ctr" ./home/. $DEV_HOME
buildah copy "$ctr" 00-allow-git.conf /etc/ssh/ssh_config.d/
# configure lazyvim
# shellcheck disable=SC2016
buildah run --user "$DEV_USER" "$ctr" -- fish -c '
set -gx HOME '"$DEV_HOME"';
mkdir -p $HOME/.ssh;
ssh-keyscan -p 2222 10.88.0.1 >> $HOME/.ssh/known_hosts;
ssh-keyscan -p 22 github.com >> $HOME/.ssh/known_hosts;
fisher install \
jorgebucaran/fisher \
pure-fish/pure \
patrickf1/fzf.fish \
jorgebucaran/autopair.fish \
gazorby/fish-abbreviation-tips \
jethrokuan/z;
'
# lock the files
buildah run "$ctr" -- bash -c "\
chmod 750 $DEV_HOME/start.sh \
$DEV_HOME/.config/lazygit/config.yml \
$DEV_HOME/.config/nvim/lua/config/lazy.lua \
$DEV_HOME/.config/nvim/init.lua \
$DEV_HOME/.config/nvim/README.md \
$DEV_HOME/.config/nvim/LICENSE \
$DEV_HOME/.config/tmux/tmux.conf && \
chown root:secproc $DEV_HOME/start.sh \
$DEV_HOME/.config/lazygit/config.yml \
$DEV_HOME/.config/nvim/lua/config/lazy.lua \
$DEV_HOME/.config/nvim/init.lua \
$DEV_HOME/.config/nvim/README.md \
$DEV_HOME/.config/nvim/LICENSE \
$DEV_HOME/.config/tmux/tmux.conf
"
buildah config \
--user $DEV_USER \
--workingdir /app \
--env CONTAINER_HOST=unix:///run/podman/podman.sock \
--cmd "[\"$DEV_HOME/start.sh\"]" \
"$ctr"
buildah commit "$ctr" $IMG_NAME
echo "$IMG_NAME built."

View File

@ -1,12 +0,0 @@
#!/bin/bash
# Get list of image IDs with <none> tag (dangling images)
dangling_images=$(podman images -f "dangling=true" -q)
if [ -z "$dangling_images" ]; then
echo "✅ No dangling images to remove."
else
echo "⚠️ Removing dangling images..."
echo "$dangling_images" | xargs podman rmi -f
echo "🧹 Done!"
fi

View File

@ -1,39 +0,0 @@
#!/bin/bash
set -euo pipefail
YAML_FILE="access.yml"
TEMPLATE_FILE="gitconfig.template"
USER="$1"
# Extract user fields from YAML
GIT_NAME=$(yq ".\"$USER\".name" "$YAML_FILE")
GIT_EMAIL=$(yq ".\"$USER\".email" "$YAML_FILE")
# Ensure fields are not empty
if [[ -z "$GIT_NAME" || -z "$GIT_EMAIL" ]]; then
echo "❌ Error: User '$USER' not found or missing name/email in $YAML_FILE"
exit 1
fi
# Create output directory
USER_DIR="files/$USER"
mkdir -p "$USER_DIR"
# Generate .gitconfig
env GIT_NAME="$GIT_NAME" GIT_EMAIL="$GIT_EMAIL" \
envsubst <"$TEMPLATE_FILE" >"$USER_DIR/gitconfig"
echo "✅ .gitconfig created at $USER_DIR/gitconfig"
# Generate SSH keypair if it doesn't exist
KEYFILE="$USER_DIR/id_ed25519"
if [[ -f "$KEYFILE" ]]; then
echo "🔑 SSH key already exists for $USER at $KEYFILE"
else
ssh-keygen -t ed25519 -N "" -C "$GIT_EMAIL" -f "$KEYFILE"
echo "✅ SSH keypair generated at:"
echo " 🔐 Private: $KEYFILE"
echo " 🔓 Public : $KEYFILE.pub"
fi

View File

@ -1,2 +0,0 @@
#!/bin/bash
EDITOR=nvim tmux new-session -s "$1"

View File

@ -1,7 +0,0 @@
#!/bin/bash
XDG_CONFIG_HOME="$PWD/home/.config" \
XDG_DATA_HOME="$PWD/home/.local/share" \
XDG_STATE_HOME="$PWD/home/.local/state" \
XDG_CACHE_HOME="$PWD/home/.cache" \
nvim

View File

@ -1,5 +0,0 @@
#!/bin/bash
ln -s "$PWD"/zsh-autosuggestions "$PWD"/config/zsh/ohmyzsh/custom/plugins/zsh-autosuggestions
ln -s "$PWD"/zsh-syntax-highlighting "$PWD"/config/zsh/ohmyzsh/custom/plugins/zsh-syntax-highlighting
rm -rf local/state

View File

@ -1,187 +0,0 @@
#!/bin/bash
PERSON="$1"
WORKSPACE="$SSH_ORIGINAL_COMMAND"
IMAGE="localhost:5100/analytics-backend-workspace:latest"
DEV_USER="devuser"
XDG_RUNTIME_DIR="/run/user/$(id -u)"
LOG_FILE="/tmp/.ssh-router-${PERSON}.log"
log() {
echo "[$(date '+%Y-%m-%d %H:%M:%S')] $*" >>"$LOG_FILE"
}
if [[ ! -t 0 ]]; then
log "❌ No TTY allocated — refusing to run tmux without an interactive terminal"
echo "Error: No TTY. Use 'ssh -t'" >&2
exit 1
fi
# log "🧩 IMAGE = '$IMAGE'"
# log "🧩 WORKSPACE = '$WORKSPACE'"
# log "🧩 PERSON = '$PERSON'"
# Fallbacks
if [[ -z "${WORKSPACE:-}" ]]; then
WORKSPACE="$PERSON"
log " Defaulted WORKSPACE to $WORKSPACE"
fi
TMUX_SESSION="$WORKSPACE|analytics-backend"
# Start podman socket service if it's not running
if [[ ! -S "$XDG_RUNTIME_DIR/podman/podman.sock" ]]; then
log "🔄 Starting Podman socket service for user $USER"
systemctl --user start podman.socket || {
log "❌ Failed to start podman.socket via systemd"
exit 1
}
# Wait briefly for socket to appear
sleep 1
fi
if [[ ! -S "$XDG_RUNTIME_DIR/podman/podman.sock" ]]; then
log "❌ Podman socket still missing after startup attempt"
exit 1
fi
# Check if image exists locally
if ! podman image exists "$IMAGE"; then
log "📦 Image $IMAGE not found locally. Pulling from registry..."
# Attempt to pull the image from the local registry (insecure HTTP)
if ! podman pull --tls-verify=false "$IMAGE"; then
log "❌ Failed to pull image from $IMAGE"
exit 1
fi
log "✅ Successfully pulled $IMAGE"
fi
case "$SSH_ORIGINAL_COMMAND" in
*scp* | *sftp* | *rsync* | *tar*)
log "❌ File transfers are disabled"
exit 1
;;
esac
# Function to start the container if not running
start_container_if_needed() {
if ! podman container exists "$WORKSPACE"; then
log "🚀 Creating container $WORKSPACE..."
podman run -dit \
--userns=keep-id \
--name "$WORKSPACE" \
--user "$DEV_USER" \
--hostname "$WORKSPACE" \
--label auto-cleanup=true \
-v "${XDG_RUNTIME_DIR}"/podman/podman.sock:/run/podman/podman.sock \
-v /home/infilytics/data/"$WORKSPACE":/app \
-v /home/infilytics/secrets/"$WORKSPACE"/gitconfig:/home/"$DEV_USER"/.gitconfig:ro \
-v /home/infilytics/secrets/"$WORKSPACE"/id_ed25519:/opt/secure/ssh/id_ed25519:ro \
-v /home/infilytics/secrets/"$WORKSPACE"/id_ed25519.pub:/opt/secure/ssh/id_ed25519.pub:ro \
--entrypoint "/home/$DEV_USER/start.sh" \
"$IMAGE" "${TMUX_SESSION}"
elif ! podman inspect -f '{{.State.Running}}' "$WORKSPACE" | grep -q true; then
log "⚡ Starting existing container $WORKSPACE..."
podman start "$WORKSPACE" >/dev/null 2>&1
fi
sleep 1
}
# After devuser exits...
check_devuser_attached() {
# Get list of clients
client_users=$(podman exec "$WORKSPACE" tmux list-clients -t "$TMUX_SESSION" -F "#{client_user}" 2>/dev/null)
if echo "$client_users" | grep -q "$DEV_USER"; then
log "💡 devuser still attached — container stays running"
return 0
else
log "🏃 $PERSON has logged out — stopping container"
podman stop "$WORKSPACE" >/dev/null 2>&1
return 1
fi
}
get_access_mode() {
local yaml_file="access.yml"
local workspace="$1"
local person="$2"
if [[ ! "$workspace" =~ ^[a-zA-Z0-9._-]+$ ]]; then
log "❌ Invalid container name: $WORKSPACE"
exit 1
fi
# Special case: user accessing their own workspace
if [[ "$workspace" == "$person" ]]; then
echo "access=rw"
return 0
fi
# Check rw
if yq '.["'"$person"'"].rw // []' "$yaml_file" | grep -q "\b$workspace\b"; then
echo "access=rw"
return 0
fi
# Check ro
if yq '.["'"$person"'"].ro // []' "$yaml_file" | grep -q "\b$workspace\b"; then
echo "access=ro"
return 0
fi
# No access → exit with error
log "$person has no access to $workspace" >&2
exit 1
}
# === Main ===
read -r access_line < <(get_access_mode "$WORKSPACE" "$PERSON") || exit 1
MODE="${access_line#access=}"
case "$MODE" in
rw)
start_container_if_needed
# Run tmux session inside the container
if ! podman exec -it --user "$DEV_USER" "$WORKSPACE" tmux has-session -t "$TMUX_SESSION" >/dev/null 2>&1; then
if ! podman exec -it -e EDITOR=nvim --user "$DEV_USER" "$WORKSPACE" tmux new-session -d -s "$TMUX_SESSION" >/dev/null 2>&1; then
log "❌ Could not create new tmux session. Please contact admin or try again later."
exit 1
fi
fi
log "$PERSON is working on $WORKSPACE's workspace"
if ! podman exec -it -e TERM="$TERM" --user "$DEV_USER" "$WORKSPACE" tmux attach -t "$TMUX_SESSION"; then
log "❌ Could not attach to tmux session. Please contact admin or try again later."
exit 1
fi
log "$PERSON finished working on $WORKSPACE's worksapce"
check_devuser_attached
exit 0
;;
ro)
if (podman container exists "$WORKSPACE" && podman inspect -f '{{.State.Running}}' "$WORKSPACE" | grep -q true) >/dev/null 2>&1; then
log "📜 $PERSON is viewing $WORKSPACE's workspace"
if ! podman exec -it -e TERM="$TERM" --user "$DEV_USER" "$WORKSPACE" tmux attach -r -t "$TMUX_SESSION"; then
log "❌ Could not attach to tmux session. Please contact admin or try again later."
exit 1
fi
log "🏃 $PERSON stopped viewing $WORKSPACE's workspace"
exit 0
else
log "❌ Workspace for $WORKSPACE does not exist."
exit 1
fi
;;
*)
log "❌ Invalid access mode: $MODE"
exit 1
;;
esac

2
start.sh Executable file
View File

@ -0,0 +1,2 @@
#!/bin/bash
PODMAN_COMPOSE_WARNING_LOGS=false EDITOR=nvim CONTAINER_CONNECTION=my-remote tmux new-session -s "$1"