Compare commits
1 Commits
master
...
44b1e63a1b
Author | SHA1 | Date | |
---|---|---|---|
44b1e63a1b |
@ -1,18 +0,0 @@
|
|||||||
#!/usr/bin/env bash
|
|
||||||
set -euo pipefail
|
|
||||||
|
|
||||||
if [ "$(basename "$(pwd -P)")" != "workspaces" ]; then
|
|
||||||
echo "Error: this script must be run from a directory named 'workspaces', not '$(basename "$(pwd -P)")'" >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
replace_home() {
|
|
||||||
sed -i "s|$1|$2|g" .config/fish/fish_variables
|
|
||||||
find .local/share/nvim/mason/packages -type f -exec sed -i "s|$1|$2|g" {} +
|
|
||||||
}
|
|
||||||
|
|
||||||
find .config -type d -exec chmod g+x {} +
|
|
||||||
|
|
||||||
replace_home "$PWD" "/home/devuser"
|
|
||||||
tar --mode=a=r,u+w,a+x -czf home.tar.gz --owner root:0 --group root:0 --xform "s,$PWD,/home/devuser," .config .local .ssh
|
|
||||||
replace_home "/home/devuser" "$PWD"
|
|
@ -1,9 +0,0 @@
|
|||||||
#!/bin/bash
|
|
||||||
|
|
||||||
ssh -F /dev/null \
|
|
||||||
-o HostName=10.88.0.1 \
|
|
||||||
-o Port=22 \
|
|
||||||
-o User=infilytics \
|
|
||||||
-o IdentityFile=~/.ssh/id_ed25519 \
|
|
||||||
-o ProxyCommand=none \
|
|
||||||
gitops -- "$@"
|
|
@ -1,5 +0,0 @@
|
|||||||
#!/usr/bin/env fish
|
|
||||||
|
|
||||||
fisher install patrickf1/fzf.fish jorgebucaran/autopair.fish gazorby/fish-abbreviation-tips jethrokuan/z
|
|
||||||
echo 'function fish_greeting; fortune; end' >"$HOME"/.config/fish/functions/fish_greeting.fish
|
|
||||||
echo 'starship init fish | source' >"$HOME"/.config/fish/config.fish
|
|
@ -1,28 +0,0 @@
|
|||||||
#!/usr/bin/env bash
|
|
||||||
set -euo pipefail
|
|
||||||
|
|
||||||
PWD="$(pwd -P)"
|
|
||||||
|
|
||||||
if [ "$(basename "$PWD")" != "workspaces" ]; then
|
|
||||||
echo "Error: this script must be run from a directory named 'workspaces', not '$(basename "$(pwd -P)")'" >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
# Override PWD and HOME for this invocation
|
|
||||||
export PWD=$PWD
|
|
||||||
export HOME=$PWD
|
|
||||||
export TMUX=""
|
|
||||||
|
|
||||||
# Optionally adjust XDG_CONFIG_HOME if you use that
|
|
||||||
# export XDG_CONFIG_HOME="$HOME/.config"
|
|
||||||
|
|
||||||
# Start (or attach to) your dev session
|
|
||||||
SESSION="dev"
|
|
||||||
|
|
||||||
# If the session doesn't exist, create it
|
|
||||||
if ! tmux has-session -t "$SESSION" 2>/dev/null; then
|
|
||||||
tmux new-session -d -s "$SESSION" -n editor 'HOME='"$HOME"' XDG_STATE_HOME='"$HOME/.state"' /usr/bin/fish'
|
|
||||||
fi
|
|
||||||
|
|
||||||
# Attach to it
|
|
||||||
exec tmux attach -t "$SESSION"
|
|
@ -1 +0,0 @@
|
|||||||
starship init fish | source
|
|
@ -1,4 +0,0 @@
|
|||||||
patrickf1/fzf.fish
|
|
||||||
jorgebucaran/autopair.fish
|
|
||||||
gazorby/fish-abbreviation-tips
|
|
||||||
jethrokuan/z
|
|
@ -1 +0,0 @@
|
|||||||
function fish_greeting; fortune; end
|
|
1
.gitattributes
vendored
1
.gitattributes
vendored
@ -1 +0,0 @@
|
|||||||
home.tar.gz filter=lfs diff=lfs merge=lfs -text
|
|
15
.gitignore
vendored
15
.gitignore
vendored
@ -1,12 +1,5 @@
|
|||||||
logs
|
logs
|
||||||
.local
|
files/pallav
|
||||||
.cache
|
home/.config/nvim/lazy-lock.json
|
||||||
.state
|
home/.local
|
||||||
.config/fish/*/*
|
home/.cache
|
||||||
.config/fish/fish_variables
|
|
||||||
!.config/fish/config.fish
|
|
||||||
!.config/fish/fish_plugins
|
|
||||||
!.config/fish/functions/fish_greeting.fish
|
|
||||||
.npm
|
|
||||||
.config/nvim/lazy-lock.json
|
|
||||||
home.tar.gz
|
|
||||||
|
24
.lazy.lua
24
.lazy.lua
@ -1,24 +0,0 @@
|
|||||||
return {
|
|
||||||
"folke/snacks.nvim",
|
|
||||||
opts = {
|
|
||||||
-- show hidden files in snacks.explorer
|
|
||||||
picker = {
|
|
||||||
sources = {
|
|
||||||
explorer = {
|
|
||||||
-- show hidden files like .env
|
|
||||||
hidden = true,
|
|
||||||
-- show files ignored by git like node_modules
|
|
||||||
ignored = false,
|
|
||||||
exclude = { ".git" },
|
|
||||||
},
|
|
||||||
files = {
|
|
||||||
-- show hidden files like .env
|
|
||||||
hidden = true,
|
|
||||||
-- show files ignored by git like node_modules
|
|
||||||
ignored = false,
|
|
||||||
exclude = { ".npm", ".git" },
|
|
||||||
},
|
|
||||||
},
|
|
||||||
},
|
|
||||||
},
|
|
||||||
}
|
|
112
.vscode/tasks.json
vendored
112
.vscode/tasks.json
vendored
@ -2,126 +2,48 @@
|
|||||||
"version": "2.0.0",
|
"version": "2.0.0",
|
||||||
"tasks": [
|
"tasks": [
|
||||||
{
|
{
|
||||||
"label": "GitOps(Build): base image",
|
"label": "Build workspace image",
|
||||||
"type": "shell",
|
"type": "shell",
|
||||||
"command": ".bin/gitops build base",
|
"command": "./build-workspace.sh",
|
||||||
"group": "build",
|
|
||||||
"problemMatcher": [],
|
|
||||||
"detail": "build base image using buildah"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"label": "GitOps(Build): workspace image",
|
|
||||||
"type": "shell",
|
|
||||||
"command": ".bin/gitops build workspace",
|
|
||||||
"group": "build",
|
"group": "build",
|
||||||
"problemMatcher": [],
|
"problemMatcher": [],
|
||||||
"detail": "build podman image using buildah"
|
"detail": "build podman image using buildah"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"label": "GitOps(Build): all images",
|
"label": "Clean dangling images",
|
||||||
"type": "shell",
|
"type": "shell",
|
||||||
"command": ".bin/gitops build all",
|
"command": "./clean_dangling_images.sh",
|
||||||
"group": "build",
|
|
||||||
"problemMatcher": [],
|
|
||||||
"detail": "build podman image using buildah"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"label": "GitOps: Clean dangling images",
|
|
||||||
"type": "shell",
|
|
||||||
"command": ".bin/gitops clean",
|
|
||||||
"problemMatcher": [],
|
"problemMatcher": [],
|
||||||
"detail": "Clean podman images"
|
"detail": "Clean podman images"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"label": "GitOps(Update): Containerfile",
|
"label": "Tag image",
|
||||||
"type": "shell",
|
"type": "shell",
|
||||||
"command": ".bin/gitops update containerfile",
|
"command": "podman tag localhost/analytics-backend-workspace:latest localhost:5100/analytics-backend-workspace:latest",
|
||||||
"group": "build",
|
|
||||||
"problemMatcher": [],
|
"problemMatcher": [],
|
||||||
"detail": "Copy Containerfile to $HOME/"
|
"detail": "Tag podman image to localhost 5100"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"label": "GitOps(Update): home.tar.gz",
|
"label": "Push image",
|
||||||
"type": "shell",
|
"type": "shell",
|
||||||
"command": ".bin/gitops update home_tar",
|
"command": "podman push --tls-verify=false localhost:5100/analytics-backend-workspace:latest",
|
||||||
"group": "build",
|
|
||||||
"problemMatcher": [],
|
"problemMatcher": [],
|
||||||
"detail": "Copy home.tar.gz to $HOME/"
|
"detail": "Push podman image to localhost 5100"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"label": "GitOps(Update): gitconfig.template",
|
"label": "Copy ssh_router.sh",
|
||||||
"type": "shell",
|
"type": "shell",
|
||||||
"command": ".bin/gitops update gitconfig",
|
"command": "sudo cp ssh_router.sh /home/infilytics/ && sudo chown -R infilytics:infilytics /home/infilytics/ssh_router.sh",
|
||||||
"group": "build",
|
|
||||||
"problemMatcher": [],
|
"problemMatcher": [],
|
||||||
"detail": "Copy gitconfig.template to $HOME/"
|
"detail": "Copy ssh_router.sh to /home/infilytics"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"label": "GitOps(Update): start.sh",
|
"label": "Copy access.yml",
|
||||||
"type": "shell",
|
"type": "shell",
|
||||||
"command": ".bin/gitops update start.sh",
|
"command": "sudo cp access.yml /home/infilytics/ && sudo chown -R infilytics:infilytics /home/infilytics/access.yml",
|
||||||
"group": "build",
|
|
||||||
"problemMatcher": [],
|
"problemMatcher": [],
|
||||||
"detail": "Copy start.sh to $HOME/"
|
"detail": "Copy access.yml to /home/infilytics"
|
||||||
},
|
|
||||||
{
|
|
||||||
"label": "Create home tarball",
|
|
||||||
"type": "shell",
|
|
||||||
"command": "${workspaceFolder}/.bin/create-home-tarball.sh",
|
|
||||||
"group": "build",
|
|
||||||
"problemMatcher": [],
|
|
||||||
"detail": "create home.tar.gz from .config .local .ssh start.sh"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"label": "Test: start tmux session",
|
|
||||||
"type": "shell",
|
|
||||||
"command": "${workspaceFolder}/.bin/test-tmux.sh",
|
|
||||||
"group": "test",
|
|
||||||
"problemMatcher": [],
|
|
||||||
"detail": "run tmux with project room as home"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"label": "GitOps: Show image status",
|
|
||||||
"type": "shell",
|
|
||||||
"command": ".bin/gitops status",
|
|
||||||
"problemMatcher": [],
|
|
||||||
"detail": "run podman images on remote"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"label": "GitOps: Remove workspace container",
|
|
||||||
"type": "shell",
|
|
||||||
"command": ".bin/gitops remove ${input:container} -f",
|
|
||||||
"problemMatcher": [],
|
|
||||||
"detail": "run podman rm $args on remote"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"label": "GitOps: Remove workspace image",
|
|
||||||
"type": "shell",
|
|
||||||
"command": ".bin/gitops rmi ${input:images}",
|
|
||||||
"problemMatcher": [],
|
|
||||||
"detail": "run podman rmi $args on remote"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"label": "Cleanup worktree",
|
|
||||||
"type": "shell",
|
|
||||||
"command": "git clean -Xfd",
|
|
||||||
"problemMatcher": [],
|
|
||||||
"detail": "delete all untracked files listed in .gitignore"
|
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"inputs": [
|
"inputs": []
|
||||||
{
|
|
||||||
"id": "container",
|
|
||||||
"type": "pickString",
|
|
||||||
"description": "Pick a container",
|
|
||||||
"options": ["pallav", "palak", "param", "darshan"],
|
|
||||||
"default": "pallav"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"id": "images",
|
|
||||||
"type": "promptString",
|
|
||||||
"description": "space separated list of images",
|
|
||||||
"default": ""
|
|
||||||
}
|
|
||||||
]
|
|
||||||
}
|
}
|
||||||
|
2
.ssh/config → 00-allow-git.conf
Executable file → Normal file
2
.ssh/config → 00-allow-git.conf
Executable file → Normal file
@ -1,6 +1,7 @@
|
|||||||
Host alps
|
Host alps
|
||||||
HostName 10.88.0.1
|
HostName 10.88.0.1
|
||||||
User git
|
User git
|
||||||
|
IdentityFile /opt/secure/ssh/id_ed25519
|
||||||
IdentitiesOnly yes
|
IdentitiesOnly yes
|
||||||
StrictHostKeyChecking yes
|
StrictHostKeyChecking yes
|
||||||
Port 2222
|
Port 2222
|
||||||
@ -9,6 +10,7 @@ Host alps
|
|||||||
Host github
|
Host github
|
||||||
HostName github.com
|
HostName github.com
|
||||||
User git
|
User git
|
||||||
|
IdentityFile /opt/secure/ssh/id_ed25519
|
||||||
IdentitiesOnly yes
|
IdentitiesOnly yes
|
||||||
StrictHostKeyChecking yes
|
StrictHostKeyChecking yes
|
||||||
ProxyCommand none
|
ProxyCommand none
|
@ -1,66 +0,0 @@
|
|||||||
# ───────────────────
|
|
||||||
# Stage 1: Base Image
|
|
||||||
# ───────────────────
|
|
||||||
FROM archlinux:base-devel-20250511.0.348143 as base
|
|
||||||
|
|
||||||
ARG DEV_USER=devuser
|
|
||||||
ARG DEV_UID=1000
|
|
||||||
ARG DEV_GID=1000
|
|
||||||
|
|
||||||
# Install all necessary packages and clean up cache
|
|
||||||
RUN pacman -Sy --noconfirm && \
|
|
||||||
pacman -S --noconfirm --needed \
|
|
||||||
base-devel neovim git git-lfs fish tmux go-yq rust starship podman \
|
|
||||||
nodejs python fzf fd ripgrep jdk-openjdk fisher yazi less rust-analyzer \
|
|
||||||
lazygit luarocks python-pynvim npm bash-completion tree-sitter-cli kitty-terminfo \
|
|
||||||
lua51 openssh fortune-mod podman-compose podman-docker && \
|
|
||||||
pacman -Scc --noconfirm && \
|
|
||||||
rm -rf /var/cache/pacman/pkg/* /usr/bin/sshd /usr/lib/systemd/system/sshd.service
|
|
||||||
|
|
||||||
# Create user/groups as per your script, with -l to avoid system user quirks
|
|
||||||
RUN groupadd -g $DEV_GID $DEV_USER && \
|
|
||||||
useradd -l -ms /bin/fish -u $DEV_UID -g $DEV_GID $DEV_USER
|
|
||||||
|
|
||||||
# ────────────────────────
|
|
||||||
# Stage 2: Workspace Image
|
|
||||||
# ────────────────────────
|
|
||||||
FROM base as workspace
|
|
||||||
|
|
||||||
ARG DEV_USER=devuser
|
|
||||||
ARG DEV_UID=1000
|
|
||||||
ARG DEV_GID=1000
|
|
||||||
ARG DEV_HOME=/home/$DEV_USER
|
|
||||||
ARG POD_USER=mypodmanuser
|
|
||||||
ARG POD_UID=1002
|
|
||||||
|
|
||||||
# Use ADD for extracting archives
|
|
||||||
ADD home.tar.gz $DEV_HOME
|
|
||||||
COPY --chmod=755 start.sh $DEV_HOME/
|
|
||||||
|
|
||||||
# Prepare .ssh and known_hosts, and fix permissions only if dirs exist
|
|
||||||
RUN mkdir -p $DEV_HOME/.ssh && \
|
|
||||||
touch /etc/containers/nodocker && \
|
|
||||||
ssh-keyscan -p 2222 10.88.0.1 >> $DEV_HOME/.ssh/known_hosts && \
|
|
||||||
ssh-keyscan -p 22 github.com >> $DEV_HOME/.ssh/known_hosts && \
|
|
||||||
for d in $DEV_HOME/.local \
|
|
||||||
$DEV_HOME/.config/fish/completions \
|
|
||||||
$DEV_HOME/.config/fish/functions \
|
|
||||||
$DEV_HOME/.config/fish/fish_variables \
|
|
||||||
$DEV_HOME/.ssh; do \
|
|
||||||
if [ -e "$d" ]; then chown -R $DEV_USER:$DEV_USER "$d"; fi; \
|
|
||||||
done && \
|
|
||||||
for d in $DEV_HOME/.local \
|
|
||||||
$DEV_HOME/.config \
|
|
||||||
$DEV_HOME/.config/fish \
|
|
||||||
$DEV_HOME/.config/tmux; do \
|
|
||||||
if [ -e "$d" ]; then chown $DEV_USER:$DEV_USER "$d"; fi; \
|
|
||||||
done
|
|
||||||
|
|
||||||
WORKDIR /app
|
|
||||||
USER $DEV_USER
|
|
||||||
|
|
||||||
RUN podman system connection add my-remote --identity $DEV_HOME/.ssh/id_ed25519 \
|
|
||||||
ssh://$POD_USER@10.88.0.1/run/user/${POD_UID}/podman/podman.sock && \
|
|
||||||
podman system connection default my-remote
|
|
||||||
|
|
||||||
CMD ["/home/devuser/start.sh"]
|
|
30
access.yml
Normal file
30
access.yml
Normal file
@ -0,0 +1,30 @@
|
|||||||
|
pallav:
|
||||||
|
name: Pallav Vasa
|
||||||
|
email: pallav@infilytics.in
|
||||||
|
rw:
|
||||||
|
- darshan
|
||||||
|
- param
|
||||||
|
- palak
|
||||||
|
|
||||||
|
darshan:
|
||||||
|
name: Darshan Parmar
|
||||||
|
email: darshan@infilytics.in
|
||||||
|
rw:
|
||||||
|
- param
|
||||||
|
ro:
|
||||||
|
- pallav
|
||||||
|
|
||||||
|
param:
|
||||||
|
name: Param Makawana
|
||||||
|
email: param@infilytics.in
|
||||||
|
ro:
|
||||||
|
- pallav
|
||||||
|
- darshan
|
||||||
|
|
||||||
|
palak:
|
||||||
|
name: Palak Vasa
|
||||||
|
email: pakak@infilytics.in
|
||||||
|
ro:
|
||||||
|
- pallav
|
||||||
|
- param
|
||||||
|
- darshan
|
1
authorized_keys
Normal file
1
authorized_keys
Normal file
@ -0,0 +1 @@
|
|||||||
|
command="/home/infilytics/ssh_router.sh pallav",no-port-forwarding,no-agent-forwarding,no-X11-forwarding ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIK0il/OJiXygyPWYBt05+OQYjJPxgGuP3kP9hLsD/C7x phoenix@sphinx
|
69
build-workspace.sh
Executable file
69
build-workspace.sh
Executable file
@ -0,0 +1,69 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
IMG_NAME="analytics-backend-workspace"
|
||||||
|
DEV_USER=devuser
|
||||||
|
DEV_UID=1001
|
||||||
|
DEV_GID=1001
|
||||||
|
SECURE=/opt/secure
|
||||||
|
DEV_HOME=/home/$DEV_USER
|
||||||
|
|
||||||
|
ctr=$(buildah from archlinux)
|
||||||
|
|
||||||
|
buildah run "$ctr" -- bash -c "\
|
||||||
|
pacman -Sy --noconfirm && pacman -S --noconfirm --needed base-devel neovim git fish tmux \
|
||||||
|
nodejs python podman fzf fd ripgrep jdk-openjdk fisher yazi less buildah \
|
||||||
|
lazygit luarocks python-pynvim npm bash-completion tree-sitter-cli kitty-terminfo \
|
||||||
|
lua51 openssh && pacman -Scc --noconfirm && groupadd secproc && groupadd -g $DEV_GID $DEV_USER && \
|
||||||
|
useradd -ms /bin/fish -G secproc -u $DEV_UID -g $DEV_GID $DEV_USER && mkdir -m 511 -p $SECURE
|
||||||
|
"
|
||||||
|
|
||||||
|
# copy start script, neovim, tmux setup and ssh setup
|
||||||
|
buildah copy --chown $DEV_USER:$DEV_USER "$ctr" ./home/. $DEV_HOME
|
||||||
|
buildah copy "$ctr" 00-allow-git.conf /etc/ssh/ssh_config.d/
|
||||||
|
|
||||||
|
# configure lazyvim
|
||||||
|
# shellcheck disable=SC2016
|
||||||
|
buildah run --user "$DEV_USER" "$ctr" -- fish -c '
|
||||||
|
set -gx HOME '"$DEV_HOME"';
|
||||||
|
mkdir -p $HOME/.ssh;
|
||||||
|
ssh-keyscan -p 2222 10.88.0.1 >> $HOME/.ssh/known_hosts;
|
||||||
|
ssh-keyscan -p 22 github.com >> $HOME/.ssh/known_hosts;
|
||||||
|
fisher install \
|
||||||
|
jorgebucaran/fisher \
|
||||||
|
pure-fish/pure \
|
||||||
|
patrickf1/fzf.fish \
|
||||||
|
jorgebucaran/autopair.fish \
|
||||||
|
gazorby/fish-abbreviation-tips \
|
||||||
|
jethrokuan/z;
|
||||||
|
'
|
||||||
|
|
||||||
|
# lock the files
|
||||||
|
buildah run "$ctr" -- bash -c "\
|
||||||
|
chmod 750 $DEV_HOME/start.sh \
|
||||||
|
$DEV_HOME/.config/lazygit/config.yml \
|
||||||
|
$DEV_HOME/.config/nvim/lua/config/lazy.lua \
|
||||||
|
$DEV_HOME/.config/nvim/init.lua \
|
||||||
|
$DEV_HOME/.config/nvim/README.md \
|
||||||
|
$DEV_HOME/.config/nvim/LICENSE \
|
||||||
|
$DEV_HOME/.config/tmux/tmux.conf && \
|
||||||
|
chown root:secproc $DEV_HOME/start.sh \
|
||||||
|
$DEV_HOME/.config/lazygit/config.yml \
|
||||||
|
$DEV_HOME/.config/nvim/lua/config/lazy.lua \
|
||||||
|
$DEV_HOME/.config/nvim/init.lua \
|
||||||
|
$DEV_HOME/.config/nvim/README.md \
|
||||||
|
$DEV_HOME/.config/nvim/LICENSE \
|
||||||
|
$DEV_HOME/.config/tmux/tmux.conf
|
||||||
|
"
|
||||||
|
|
||||||
|
buildah config \
|
||||||
|
--user $DEV_USER \
|
||||||
|
--workingdir /app \
|
||||||
|
--env CONTAINER_HOST=unix:///run/podman/podman.sock \
|
||||||
|
--cmd "[\"$DEV_HOME/start.sh\"]" \
|
||||||
|
"$ctr"
|
||||||
|
|
||||||
|
buildah commit "$ctr" $IMG_NAME
|
||||||
|
|
||||||
|
echo "✅ $IMG_NAME built."
|
12
clean_dangling_images.sh
Executable file
12
clean_dangling_images.sh
Executable file
@ -0,0 +1,12 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
|
||||||
|
# Get list of image IDs with <none> tag (dangling images)
|
||||||
|
dangling_images=$(podman images -f "dangling=true" -q)
|
||||||
|
|
||||||
|
if [ -z "$dangling_images" ]; then
|
||||||
|
echo "✅ No dangling images to remove."
|
||||||
|
else
|
||||||
|
echo "⚠️ Removing dangling images..."
|
||||||
|
echo "$dangling_images" | xargs podman rmi -f
|
||||||
|
echo "🧹 Done!"
|
||||||
|
fi
|
39
generate-user-config.sh
Executable file
39
generate-user-config.sh
Executable file
@ -0,0 +1,39 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
YAML_FILE="access.yml"
|
||||||
|
TEMPLATE_FILE="gitconfig.template"
|
||||||
|
USER="$1"
|
||||||
|
|
||||||
|
# Extract user fields from YAML
|
||||||
|
GIT_NAME=$(yq ".\"$USER\".name" "$YAML_FILE")
|
||||||
|
GIT_EMAIL=$(yq ".\"$USER\".email" "$YAML_FILE")
|
||||||
|
|
||||||
|
# Ensure fields are not empty
|
||||||
|
if [[ -z "$GIT_NAME" || -z "$GIT_EMAIL" ]]; then
|
||||||
|
echo "❌ Error: User '$USER' not found or missing name/email in $YAML_FILE"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Create output directory
|
||||||
|
USER_DIR="files/$USER"
|
||||||
|
mkdir -p "$USER_DIR"
|
||||||
|
|
||||||
|
# Generate .gitconfig
|
||||||
|
env GIT_NAME="$GIT_NAME" GIT_EMAIL="$GIT_EMAIL" \
|
||||||
|
envsubst <"$TEMPLATE_FILE" >"$USER_DIR/gitconfig"
|
||||||
|
|
||||||
|
echo "✅ .gitconfig created at $USER_DIR/gitconfig"
|
||||||
|
|
||||||
|
# Generate SSH keypair if it doesn't exist
|
||||||
|
KEYFILE="$USER_DIR/id_ed25519"
|
||||||
|
|
||||||
|
if [[ -f "$KEYFILE" ]]; then
|
||||||
|
echo "🔑 SSH key already exists for $USER at $KEYFILE"
|
||||||
|
else
|
||||||
|
ssh-keygen -t ed25519 -N "" -C "$GIT_EMAIL" -f "$KEYFILE"
|
||||||
|
echo "✅ SSH keypair generated at:"
|
||||||
|
echo " 🔐 Private: $KEYFILE"
|
||||||
|
echo " 🔓 Public : $KEYFILE.pub"
|
||||||
|
fi
|
0
.config/lazygit/config.yml → home/.config/lazygit/config.yml
Executable file → Normal file
0
.config/lazygit/config.yml → home/.config/lazygit/config.yml
Executable file → Normal file
0
.config/nvim/.neoconf.json → home/.config/nvim/.neoconf.json
Executable file → Normal file
0
.config/nvim/.neoconf.json → home/.config/nvim/.neoconf.json
Executable file → Normal file
0
.config/nvim/LICENSE → home/.config/nvim/LICENSE
Executable file → Normal file
0
.config/nvim/LICENSE → home/.config/nvim/LICENSE
Executable file → Normal file
0
.config/nvim/README.md → home/.config/nvim/README.md
Executable file → Normal file
0
.config/nvim/README.md → home/.config/nvim/README.md
Executable file → Normal file
0
.config/nvim/init.lua → home/.config/nvim/init.lua
Executable file → Normal file
0
.config/nvim/init.lua → home/.config/nvim/init.lua
Executable file → Normal file
1
.config/nvim/lazyvim.json → home/.config/nvim/lazyvim.json
Executable file → Normal file
1
.config/nvim/lazyvim.json → home/.config/nvim/lazyvim.json
Executable file → Normal file
@ -21,7 +21,6 @@
|
|||||||
"lazyvim.plugins.extras.lang.json",
|
"lazyvim.plugins.extras.lang.json",
|
||||||
"lazyvim.plugins.extras.lang.markdown",
|
"lazyvim.plugins.extras.lang.markdown",
|
||||||
"lazyvim.plugins.extras.lang.python",
|
"lazyvim.plugins.extras.lang.python",
|
||||||
"lazyvim.plugins.extras.lang.rust",
|
|
||||||
"lazyvim.plugins.extras.lang.scala",
|
"lazyvim.plugins.extras.lang.scala",
|
||||||
"lazyvim.plugins.extras.lang.sql",
|
"lazyvim.plugins.extras.lang.sql",
|
||||||
"lazyvim.plugins.extras.lang.toml",
|
"lazyvim.plugins.extras.lang.toml",
|
0
.config/nvim/lua/config/autocmds.lua → home/.config/nvim/lua/config/autocmds.lua
Executable file → Normal file
0
.config/nvim/lua/config/autocmds.lua → home/.config/nvim/lua/config/autocmds.lua
Executable file → Normal file
0
.config/nvim/lua/config/keymaps.lua → home/.config/nvim/lua/config/keymaps.lua
Executable file → Normal file
0
.config/nvim/lua/config/keymaps.lua → home/.config/nvim/lua/config/keymaps.lua
Executable file → Normal file
0
.config/nvim/lua/config/lazy.lua → home/.config/nvim/lua/config/lazy.lua
Executable file → Normal file
0
.config/nvim/lua/config/lazy.lua → home/.config/nvim/lua/config/lazy.lua
Executable file → Normal file
0
.config/nvim/lua/config/options.lua → home/.config/nvim/lua/config/options.lua
Executable file → Normal file
0
.config/nvim/lua/config/options.lua → home/.config/nvim/lua/config/options.lua
Executable file → Normal file
0
.config/nvim/lua/plugins/colorscheme.lua → home/.config/nvim/lua/plugins/colorscheme.lua
Executable file → Normal file
0
.config/nvim/lua/plugins/colorscheme.lua → home/.config/nvim/lua/plugins/colorscheme.lua
Executable file → Normal file
0
.config/nvim/lua/plugins/diffview.lua → home/.config/nvim/lua/plugins/diffview.lua
Executable file → Normal file
0
.config/nvim/lua/plugins/diffview.lua → home/.config/nvim/lua/plugins/diffview.lua
Executable file → Normal file
0
.config/nvim/stylua.toml → home/.config/nvim/stylua.toml
Executable file → Normal file
0
.config/nvim/stylua.toml → home/.config/nvim/stylua.toml
Executable file → Normal file
0
.config/tmux/tmux.conf → home/.config/tmux/tmux.conf
Executable file → Normal file
0
.config/tmux/tmux.conf → home/.config/tmux/tmux.conf
Executable file → Normal file
6
.config/tmux/tmux.conf.local → home/.config/tmux/tmux.conf.local
Executable file → Normal file
6
.config/tmux/tmux.conf.local → home/.config/tmux/tmux.conf.local
Executable file → Normal file
@ -431,9 +431,9 @@ tmux_conf_uninstall_plugins_on_reload=true
|
|||||||
# visit https://github.com/tmux-plugins for available plugins
|
# visit https://github.com/tmux-plugins for available plugins
|
||||||
#set -g @plugin 'tmux-plugins/tmux-copycat'
|
#set -g @plugin 'tmux-plugins/tmux-copycat'
|
||||||
#set -g @plugin 'tmux-plugins/tmux-cpu'
|
#set -g @plugin 'tmux-plugins/tmux-cpu'
|
||||||
set -g @plugin 'tmux-plugins/tmux-resurrect'
|
#set -g @plugin 'tmux-plugins/tmux-resurrect'
|
||||||
set -g @plugin 'tmux-plugins/tmux-continuum'
|
#set -g @plugin 'tmux-plugins/tmux-continuum'
|
||||||
set -g @continuum-restore 'on'
|
#set -g @continuum-restore 'on'
|
||||||
|
|
||||||
set -g @plugin 'catppuccin/tmux'
|
set -g @plugin 'catppuccin/tmux'
|
||||||
|
|
2
home/start.sh
Normal file
2
home/start.sh
Normal file
@ -0,0 +1,2 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
EDITOR=nvim tmux new-session -s "$1"
|
7
nvim-workspace.sh
Executable file
7
nvim-workspace.sh
Executable file
@ -0,0 +1,7 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
|
||||||
|
XDG_CONFIG_HOME="$PWD/home/.config" \
|
||||||
|
XDG_DATA_HOME="$PWD/home/.local/share" \
|
||||||
|
XDG_STATE_HOME="$PWD/home/.local/state" \
|
||||||
|
XDG_CACHE_HOME="$PWD/home/.cache" \
|
||||||
|
nvim
|
5
pre-build.sh
Executable file
5
pre-build.sh
Executable file
@ -0,0 +1,5 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
|
||||||
|
ln -s "$PWD"/zsh-autosuggestions "$PWD"/config/zsh/ohmyzsh/custom/plugins/zsh-autosuggestions
|
||||||
|
ln -s "$PWD"/zsh-syntax-highlighting "$PWD"/config/zsh/ohmyzsh/custom/plugins/zsh-syntax-highlighting
|
||||||
|
rm -rf local/state
|
187
ssh_router.sh
Executable file
187
ssh_router.sh
Executable file
@ -0,0 +1,187 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
|
||||||
|
PERSON="$1"
|
||||||
|
WORKSPACE="$SSH_ORIGINAL_COMMAND"
|
||||||
|
IMAGE="localhost:5100/analytics-backend-workspace:latest"
|
||||||
|
DEV_USER="devuser"
|
||||||
|
|
||||||
|
XDG_RUNTIME_DIR="/run/user/$(id -u)"
|
||||||
|
LOG_FILE="/tmp/.ssh-router-${PERSON}.log"
|
||||||
|
|
||||||
|
log() {
|
||||||
|
echo "[$(date '+%Y-%m-%d %H:%M:%S')] $*" >>"$LOG_FILE"
|
||||||
|
}
|
||||||
|
|
||||||
|
if [[ ! -t 0 ]]; then
|
||||||
|
log "❌ No TTY allocated — refusing to run tmux without an interactive terminal"
|
||||||
|
echo "Error: No TTY. Use 'ssh -t'" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
# log "🧩 IMAGE = '$IMAGE'"
|
||||||
|
# log "🧩 WORKSPACE = '$WORKSPACE'"
|
||||||
|
# log "🧩 PERSON = '$PERSON'"
|
||||||
|
|
||||||
|
# Fallbacks
|
||||||
|
if [[ -z "${WORKSPACE:-}" ]]; then
|
||||||
|
WORKSPACE="$PERSON"
|
||||||
|
log "ℹ️ Defaulted WORKSPACE to $WORKSPACE"
|
||||||
|
fi
|
||||||
|
|
||||||
|
TMUX_SESSION="$WORKSPACE|analytics-backend"
|
||||||
|
|
||||||
|
# Start podman socket service if it's not running
|
||||||
|
if [[ ! -S "$XDG_RUNTIME_DIR/podman/podman.sock" ]]; then
|
||||||
|
log "🔄 Starting Podman socket service for user $USER"
|
||||||
|
systemctl --user start podman.socket || {
|
||||||
|
log "❌ Failed to start podman.socket via systemd"
|
||||||
|
exit 1
|
||||||
|
}
|
||||||
|
|
||||||
|
# Wait briefly for socket to appear
|
||||||
|
sleep 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [[ ! -S "$XDG_RUNTIME_DIR/podman/podman.sock" ]]; then
|
||||||
|
log "❌ Podman socket still missing after startup attempt"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Check if image exists locally
|
||||||
|
if ! podman image exists "$IMAGE"; then
|
||||||
|
log "📦 Image $IMAGE not found locally. Pulling from registry..."
|
||||||
|
|
||||||
|
# Attempt to pull the image from the local registry (insecure HTTP)
|
||||||
|
if ! podman pull --tls-verify=false "$IMAGE"; then
|
||||||
|
log "❌ Failed to pull image from $IMAGE"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
log "✅ Successfully pulled $IMAGE"
|
||||||
|
fi
|
||||||
|
|
||||||
|
case "$SSH_ORIGINAL_COMMAND" in
|
||||||
|
*scp* | *sftp* | *rsync* | *tar*)
|
||||||
|
log "❌ File transfers are disabled"
|
||||||
|
exit 1
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
|
||||||
|
# Function to start the container if not running
|
||||||
|
start_container_if_needed() {
|
||||||
|
if ! podman container exists "$WORKSPACE"; then
|
||||||
|
log "🚀 Creating container $WORKSPACE..."
|
||||||
|
podman run -dit \
|
||||||
|
--userns=keep-id \
|
||||||
|
--name "$WORKSPACE" \
|
||||||
|
--user "$DEV_USER" \
|
||||||
|
--hostname "$WORKSPACE" \
|
||||||
|
--label auto-cleanup=true \
|
||||||
|
-v "${XDG_RUNTIME_DIR}"/podman/podman.sock:/run/podman/podman.sock \
|
||||||
|
-v /home/infilytics/data/"$WORKSPACE":/app \
|
||||||
|
-v /home/infilytics/secrets/"$WORKSPACE"/gitconfig:/home/"$DEV_USER"/.gitconfig:ro \
|
||||||
|
-v /home/infilytics/secrets/"$WORKSPACE"/id_ed25519:/opt/secure/ssh/id_ed25519:ro \
|
||||||
|
-v /home/infilytics/secrets/"$WORKSPACE"/id_ed25519.pub:/opt/secure/ssh/id_ed25519.pub:ro \
|
||||||
|
--entrypoint "/home/$DEV_USER/start.sh" \
|
||||||
|
"$IMAGE" "${TMUX_SESSION}"
|
||||||
|
elif ! podman inspect -f '{{.State.Running}}' "$WORKSPACE" | grep -q true; then
|
||||||
|
log "⚡ Starting existing container $WORKSPACE..."
|
||||||
|
podman start "$WORKSPACE" >/dev/null 2>&1
|
||||||
|
fi
|
||||||
|
sleep 1
|
||||||
|
}
|
||||||
|
|
||||||
|
# After devuser exits...
|
||||||
|
check_devuser_attached() {
|
||||||
|
# Get list of clients
|
||||||
|
client_users=$(podman exec "$WORKSPACE" tmux list-clients -t "$TMUX_SESSION" -F "#{client_user}" 2>/dev/null)
|
||||||
|
|
||||||
|
if echo "$client_users" | grep -q "$DEV_USER"; then
|
||||||
|
log "💡 devuser still attached — container stays running"
|
||||||
|
return 0
|
||||||
|
else
|
||||||
|
log "🏃 $PERSON has logged out — stopping container"
|
||||||
|
podman stop "$WORKSPACE" >/dev/null 2>&1
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
get_access_mode() {
|
||||||
|
local yaml_file="access.yml"
|
||||||
|
local workspace="$1"
|
||||||
|
local person="$2"
|
||||||
|
|
||||||
|
if [[ ! "$workspace" =~ ^[a-zA-Z0-9._-]+$ ]]; then
|
||||||
|
log "❌ Invalid container name: $WORKSPACE"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Special case: user accessing their own workspace
|
||||||
|
if [[ "$workspace" == "$person" ]]; then
|
||||||
|
echo "access=rw"
|
||||||
|
return 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Check rw
|
||||||
|
if yq '.["'"$person"'"].rw // []' "$yaml_file" | grep -q "\b$workspace\b"; then
|
||||||
|
echo "access=rw"
|
||||||
|
return 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Check ro
|
||||||
|
if yq '.["'"$person"'"].ro // []' "$yaml_file" | grep -q "\b$workspace\b"; then
|
||||||
|
echo "access=ro"
|
||||||
|
return 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
# No access → exit with error
|
||||||
|
log "❌ $person has no access to $workspace" >&2
|
||||||
|
exit 1
|
||||||
|
}
|
||||||
|
|
||||||
|
# === Main ===
|
||||||
|
|
||||||
|
read -r access_line < <(get_access_mode "$WORKSPACE" "$PERSON") || exit 1
|
||||||
|
MODE="${access_line#access=}"
|
||||||
|
|
||||||
|
case "$MODE" in
|
||||||
|
rw)
|
||||||
|
start_container_if_needed
|
||||||
|
|
||||||
|
# Run tmux session inside the container
|
||||||
|
if ! podman exec -it --user "$DEV_USER" "$WORKSPACE" tmux has-session -t "$TMUX_SESSION" >/dev/null 2>&1; then
|
||||||
|
if ! podman exec -it -e EDITOR=nvim --user "$DEV_USER" "$WORKSPACE" tmux new-session -d -s "$TMUX_SESSION" >/dev/null 2>&1; then
|
||||||
|
log "❌ Could not create new tmux session. Please contact admin or try again later."
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
|
||||||
|
log "⚡ $PERSON is working on $WORKSPACE's workspace"
|
||||||
|
if ! podman exec -it -e TERM="$TERM" --user "$DEV_USER" "$WORKSPACE" tmux attach -t "$TMUX_SESSION"; then
|
||||||
|
log "❌ Could not attach to tmux session. Please contact admin or try again later."
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
log "⚡ $PERSON finished working on $WORKSPACE's worksapce"
|
||||||
|
|
||||||
|
check_devuser_attached
|
||||||
|
exit 0
|
||||||
|
;;
|
||||||
|
ro)
|
||||||
|
if (podman container exists "$WORKSPACE" && podman inspect -f '{{.State.Running}}' "$WORKSPACE" | grep -q true) >/dev/null 2>&1; then
|
||||||
|
log "📜 $PERSON is viewing $WORKSPACE's workspace"
|
||||||
|
if ! podman exec -it -e TERM="$TERM" --user "$DEV_USER" "$WORKSPACE" tmux attach -r -t "$TMUX_SESSION"; then
|
||||||
|
log "❌ Could not attach to tmux session. Please contact admin or try again later."
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
log "🏃 $PERSON stopped viewing $WORKSPACE's workspace"
|
||||||
|
exit 0
|
||||||
|
else
|
||||||
|
log "❌ Workspace for $WORKSPACE does not exist."
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
;;
|
||||||
|
*)
|
||||||
|
log "❌ Invalid access mode: $MODE"
|
||||||
|
exit 1
|
||||||
|
;;
|
||||||
|
esac
|
Reference in New Issue
Block a user