Compare commits
31 Commits
v0.5
...
c9460b8ebc
Author | SHA1 | Date | |
---|---|---|---|
c9460b8ebc | |||
9629c3253e | |||
6e11d19510 | |||
a4bfe5a5c0 | |||
54a42ad4d5 | |||
21eee8c3ec | |||
ff72c95012 | |||
3576bf93c2 | |||
d7c7686a9e | |||
a179a3ad23 | |||
56744155cb | |||
eba420cc81 | |||
a9adb834e5 | |||
f422da8d9e | |||
079979292d | |||
14a96035b6 | |||
1fc4153048 | |||
dceda5fb53 | |||
b67af4b482 | |||
61902a8b5b | |||
5181a3c194 | |||
0e2f89bde4 | |||
f09654160a | |||
f8a09a135b | |||
80a3878295 | |||
54e2ec2374 | |||
156b47aded | |||
422a962a85 | |||
991478a0b0 | |||
8812bb4528 | |||
a45494c949 |
@ -1,12 +0,0 @@
|
|||||||
#!/bin/bash
|
|
||||||
|
|
||||||
# Get list of image IDs with <none> tag (dangling images)
|
|
||||||
dangling_images=$(podman images -f "dangling=true" -q)
|
|
||||||
|
|
||||||
if [ -z "$dangling_images" ]; then
|
|
||||||
echo "✅ No dangling images to remove."
|
|
||||||
else
|
|
||||||
echo "⚠️ Removing dangling images..."
|
|
||||||
echo "$dangling_images" | xargs podman rmi -f
|
|
||||||
echo "🧹 Done!"
|
|
||||||
fi
|
|
@ -14,5 +14,5 @@ replace_home() {
|
|||||||
find .config -type d -exec chmod g+x {} +
|
find .config -type d -exec chmod g+x {} +
|
||||||
|
|
||||||
replace_home "$PWD" "/home/devuser"
|
replace_home "$PWD" "/home/devuser"
|
||||||
tar -czf home.tar.gz --owner root --group secproc --xform "s,$PWD,/home/devuser," .config .local .ssh start.sh
|
tar -czf home.tar.gz --owner root:0 --group secproc:1002 --xform "s,$PWD,/home/devuser," .config .local .ssh start.sh
|
||||||
replace_home "/home/devuser" "$PWD"
|
replace_home "/home/devuser" "$PWD"
|
||||||
|
9
.bin/gitops
Executable file
9
.bin/gitops
Executable file
@ -0,0 +1,9 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
|
||||||
|
ssh -F /dev/null \
|
||||||
|
-o HostName=10.88.0.1 \
|
||||||
|
-o Port=22 \
|
||||||
|
-o User=infilytics \
|
||||||
|
-o IdentityFile=~/.ssh/id_ed25519 \
|
||||||
|
-o ProxyCommand=none \
|
||||||
|
gitops -- "$@"
|
@ -1,64 +0,0 @@
|
|||||||
{
|
|
||||||
"LazyVim": { "branch": "main", "commit": "25abbf546d564dc484cf903804661ba12de45507" },
|
|
||||||
"LuaSnip": { "branch": "master", "commit": "c1851d5c519611dfc451b6582961b2602e0af89b" },
|
|
||||||
"SchemaStore.nvim": { "branch": "main", "commit": "ba7bad63cb96dae5a82e48310beada18e8eeafe5" },
|
|
||||||
"blink.cmp": { "branch": "main", "commit": "022521a8910a5543b0251b21c9e1a1e989745796" },
|
|
||||||
"blink.compat": { "branch": "main", "commit": "2ed6d9a28b07fa6f3bface818470605f8896408c" },
|
|
||||||
"bufferline.nvim": { "branch": "main", "commit": "655133c3b4c3e5e05ec549b9f8cc2894ac6f51b3" },
|
|
||||||
"catppuccin": { "branch": "main", "commit": "1bf070129c0b6f77cc23f6a2212dcdc868308c52" },
|
|
||||||
"codeium.nvim": { "branch": "main", "commit": "821b570b526dbb05b57aa4ded578b709a704a38a" },
|
|
||||||
"conform.nvim": { "branch": "master", "commit": "2b2b30260203af3b93a7470ac6c8457ddd6e32d9" },
|
|
||||||
"dial.nvim": { "branch": "master", "commit": "2c7e2750372918f072a20f3cf754d845e143d7c9" },
|
|
||||||
"diffview.nvim": { "branch": "main", "commit": "4516612fe98ff56ae0415a259ff6361a89419b0a" },
|
|
||||||
"flash.nvim": { "branch": "main", "commit": "3c942666f115e2811e959eabbdd361a025db8b63" },
|
|
||||||
"friendly-snippets": { "branch": "main", "commit": "572f5660cf05f8cd8834e096d7b4c921ba18e175" },
|
|
||||||
"gitsigns.nvim": { "branch": "main", "commit": "e399f9748d7cfd8859747c8d6c4e9c8b4d50a1bd" },
|
|
||||||
"grug-far.nvim": { "branch": "main", "commit": "176ba4c42924f4d84ee7d19c9f0081c538f84a88" },
|
|
||||||
"inc-rename.nvim": { "branch": "main", "commit": "2eaff20526ff6101337b84f4b0d238c11f47d7f4" },
|
|
||||||
"lazy.nvim": { "branch": "main", "commit": "6c3bda4aca61a13a9c63f1c1d1b16b9d3be90d7a" },
|
|
||||||
"lazydev.nvim": { "branch": "main", "commit": "2367a6c0a01eb9edb0464731cc0fb61ed9ab9d2c" },
|
|
||||||
"lualine.nvim": { "branch": "master", "commit": "15884cee63a8c205334ab13ab1c891cd4d27101a" },
|
|
||||||
"markdown-preview.nvim": { "branch": "master", "commit": "a923f5fc5ba36a3b17e289dc35dc17f66d0548ee" },
|
|
||||||
"mason-lspconfig.nvim": { "branch": "main", "commit": "1a31f824b9cd5bc6f342fc29e9a53b60d74af245" },
|
|
||||||
"mason-nvim-dap.nvim": { "branch": "main", "commit": "4c2cdc69d69fe00c15ae8648f7e954d99e5de3ea" },
|
|
||||||
"mason.nvim": { "branch": "main", "commit": "fc98833b6da5de5a9c5b1446ac541577059555be" },
|
|
||||||
"mini.ai": { "branch": "main", "commit": "e139eb1101beb0250fea322f8c07a42f0f175688" },
|
|
||||||
"mini.files": { "branch": "main", "commit": "49c855977e9f4821d1ed8179ed44fe098b93ea2a" },
|
|
||||||
"mini.hipatterns": { "branch": "main", "commit": "e5083df391171dc9d8172645606f8496d9443374" },
|
|
||||||
"mini.icons": { "branch": "main", "commit": "397ed3807e96b59709ef3292f0a3e253d5c1dc0a" },
|
|
||||||
"mini.pairs": { "branch": "main", "commit": "69864a2efb36c030877421634487fd90db1e4298" },
|
|
||||||
"mini.surround": { "branch": "main", "commit": "5aab42fcdcf31fa010f012771eda5631c077840a" },
|
|
||||||
"neogen": { "branch": "main", "commit": "d7f9461727751fb07f82011051338a9aba07581d" },
|
|
||||||
"neotest": { "branch": "master", "commit": "862afb2a2219d9ca565f67416fb7003cc0f22c4f" },
|
|
||||||
"neotest-python": { "branch": "master", "commit": "a2861ab3c9a0bf75a56b11835c2bfc8270f5be7e" },
|
|
||||||
"noice.nvim": { "branch": "main", "commit": "0427460c2d7f673ad60eb02b35f5e9926cf67c59" },
|
|
||||||
"nui.nvim": { "branch": "main", "commit": "f535005e6ad1016383f24e39559833759453564e" },
|
|
||||||
"nvim-dap": { "branch": "master", "commit": "8df427aeba0a06c6577dc3ab82de3076964e3b8d" },
|
|
||||||
"nvim-dap-python": { "branch": "master", "commit": "261ce649d05bc455a29f9636dc03f8cdaa7e0e2c" },
|
|
||||||
"nvim-dap-ui": { "branch": "master", "commit": "73a26abf4941aa27da59820fd6b028ebcdbcf932" },
|
|
||||||
"nvim-dap-virtual-text": { "branch": "master", "commit": "df66808cd78b5a97576bbaeee95ed5ca385a9750" },
|
|
||||||
"nvim-jdtls": { "branch": "master", "commit": "c23f200fee469a415c77265ca55b496feb646992" },
|
|
||||||
"nvim-lint": { "branch": "master", "commit": "fdb04e9285edefbe25a02a31a35e8fbb10fe054d" },
|
|
||||||
"nvim-lspconfig": { "branch": "master", "commit": "ac1dfbe3b60e5e23a2cff90e3bd6a3bc88031a57" },
|
|
||||||
"nvim-metals": { "branch": "main", "commit": "f9cc5e7f7bc129b8056f1e5aef7a91c9b5b83664" },
|
|
||||||
"nvim-nio": { "branch": "master", "commit": "21f5324bfac14e22ba26553caf69ec76ae8a7662" },
|
|
||||||
"nvim-treesitter": { "branch": "master", "commit": "066fd6505377e3fd4aa219e61ce94c2b8bdb0b79" },
|
|
||||||
"nvim-treesitter-textobjects": { "branch": "master", "commit": "b0debd5c424969b4baeabdc8f54db3036c691732" },
|
|
||||||
"nvim-ts-autotag": { "branch": "main", "commit": "a1d526af391f6aebb25a8795cbc05351ed3620b5" },
|
|
||||||
"one-small-step-for-vimkind": { "branch": "main", "commit": "ba909c68fed65e268df8a4684bafef4ec889c8bc" },
|
|
||||||
"overseer.nvim": { "branch": "master", "commit": "72c68aab0358c92f451168b704c411c4a3e3410e" },
|
|
||||||
"persistence.nvim": { "branch": "main", "commit": "166a79a55bfa7a4db3e26fc031b4d92af71d0b51" },
|
|
||||||
"plenary.nvim": { "branch": "master", "commit": "857c5ac632080dba10aae49dba902ce3abf91b35" },
|
|
||||||
"render-markdown.nvim": { "branch": "main", "commit": "a1b0988f5ab26698afb56b9c2f0525a4de1195c1" },
|
|
||||||
"snacks.nvim": { "branch": "main", "commit": "bc0630e43be5699bb94dadc302c0d21615421d93" },
|
|
||||||
"todo-comments.nvim": { "branch": "main", "commit": "304a8d204ee787d2544d8bc23cd38d2f929e7cc5" },
|
|
||||||
"tokyonight.nvim": { "branch": "main", "commit": "057ef5d260c1931f1dffd0f052c685dcd14100a3" },
|
|
||||||
"trouble.nvim": { "branch": "main", "commit": "85bedb7eb7fa331a2ccbecb9202d8abba64d37b3" },
|
|
||||||
"ts-comments.nvim": { "branch": "main", "commit": "1bd9d0ba1d8b336c3db50692ffd0955fe1bb9f0c" },
|
|
||||||
"vim-dadbod": { "branch": "master", "commit": "e95afed23712f969f83b4857a24cf9d59114c2e6" },
|
|
||||||
"vim-dadbod-completion": { "branch": "master", "commit": "a8dac0b3cf6132c80dc9b18bef36d4cf7a9e1fe6" },
|
|
||||||
"vim-dadbod-ui": { "branch": "master", "commit": "460432301a5cb280ea265ddfa15c9f3dcd1d26b7" },
|
|
||||||
"vim-illuminate": { "branch": "master", "commit": "fbc16dee336d8cc0d3d2382ea4a53f4a29725abf" },
|
|
||||||
"which-key.nvim": { "branch": "main", "commit": "370ec46f710e058c9c1646273e6b225acf47cbed" },
|
|
||||||
"yanky.nvim": { "branch": "main", "commit": "04775cc6e10ef038c397c407bc17f00a2f52b378" }
|
|
||||||
}
|
|
1
.gitattributes
vendored
Normal file
1
.gitattributes
vendored
Normal file
@ -0,0 +1 @@
|
|||||||
|
home.tar.gz filter=lfs diff=lfs merge=lfs -text
|
2
.gitignore
vendored
2
.gitignore
vendored
@ -4,4 +4,4 @@ logs
|
|||||||
.state
|
.state
|
||||||
.config/fish
|
.config/fish
|
||||||
.npm
|
.npm
|
||||||
home.tar.gz
|
.config/nvim/lazy-lock.json
|
||||||
|
24
.lazy.lua
Normal file
24
.lazy.lua
Normal file
@ -0,0 +1,24 @@
|
|||||||
|
return {
|
||||||
|
"folke/snacks.nvim",
|
||||||
|
opts = {
|
||||||
|
-- show hidden files in snacks.explorer
|
||||||
|
picker = {
|
||||||
|
sources = {
|
||||||
|
explorer = {
|
||||||
|
-- show hidden files like .env
|
||||||
|
hidden = true,
|
||||||
|
-- show files ignored by git like node_modules
|
||||||
|
ignored = false,
|
||||||
|
exclude = { ".git" },
|
||||||
|
},
|
||||||
|
files = {
|
||||||
|
-- show hidden files like .env
|
||||||
|
hidden = true,
|
||||||
|
-- show files ignored by git like node_modules
|
||||||
|
ignored = false,
|
||||||
|
exclude = { ".npm", ".git" },
|
||||||
|
},
|
||||||
|
},
|
||||||
|
},
|
||||||
|
},
|
||||||
|
}
|
99
.vscode/tasks.json
vendored
99
.vscode/tasks.json
vendored
@ -2,70 +2,129 @@
|
|||||||
"version": "2.0.0",
|
"version": "2.0.0",
|
||||||
"tasks": [
|
"tasks": [
|
||||||
{
|
{
|
||||||
"label": "Build workspace image",
|
"label": "GitOps(Build): base image",
|
||||||
"type": "shell",
|
"type": "shell",
|
||||||
"command": "${workspaceFolder}/build-workspace.sh",
|
"command": ".bin/gitops build base",
|
||||||
|
"group": "build",
|
||||||
|
"problemMatcher": [],
|
||||||
|
"detail": "build base image using buildah"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"label": "GitOps(Build): workspace image",
|
||||||
|
"type": "shell",
|
||||||
|
"command": ".bin/gitops build workspace",
|
||||||
"group": "build",
|
"group": "build",
|
||||||
"problemMatcher": [],
|
"problemMatcher": [],
|
||||||
"detail": "build podman image using buildah"
|
"detail": "build podman image using buildah"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"label": "Clean dangling images",
|
"label": "GitOps: Clean dangling images",
|
||||||
"type": "shell",
|
"type": "shell",
|
||||||
"command": "${workspaceFolder}/.bin/clean_dangling_images.sh",
|
"command": ".bin/gitops clean",
|
||||||
"problemMatcher": [],
|
"problemMatcher": [],
|
||||||
"detail": "Clean podman images"
|
"detail": "Clean podman images"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"label": "Tag image",
|
"label": "Gitops(Update): build-base.sh",
|
||||||
"type": "shell",
|
"type": "shell",
|
||||||
"command": "podman tag localhost/analytics-backend-workspace:latest localhost:5100/analytics-backend-workspace:latest",
|
"command": ".bin/gitops update base",
|
||||||
|
"group": "build",
|
||||||
"problemMatcher": [],
|
"problemMatcher": [],
|
||||||
"detail": "Tag podman image to localhost 5100"
|
"detail": "Copy build-base.sh to /home/infilytics/.local/bin/"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"label": "Push image",
|
"label": "GitOps(Update): build-workspace.sh",
|
||||||
"type": "shell",
|
"type": "shell",
|
||||||
"command": "podman push --tls-verify=false localhost:5100/analytics-backend-workspace:latest",
|
"command": ".bin/gitops update workspace",
|
||||||
|
"group": "build",
|
||||||
"problemMatcher": [],
|
"problemMatcher": [],
|
||||||
"detail": "Push podman image to localhost 5100"
|
"detail": "Copy build-workspace.sh to /home/infilytics/.local/bin/"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"label": "Copy ssh_router.sh",
|
"label": "GitOps(Update): ssh_router.sh",
|
||||||
"type": "shell",
|
"type": "shell",
|
||||||
"command": "sudo cp ssh_router.sh /home/infilytics/ && sudo chown -R infilytics:infilytics /home/infilytics/ssh_router.sh",
|
"command": ".bin/gitops update ssh_router",
|
||||||
|
"group": "build",
|
||||||
"problemMatcher": [],
|
"problemMatcher": [],
|
||||||
"detail": "Copy ssh_router.sh to /home/infilytics"
|
"detail": "Copy ssh_router.sh to /home/infilytics/.local/bin/"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"label": "Copy access.yml",
|
"label": "GitOps(Update): access.yml",
|
||||||
"type": "shell",
|
"type": "shell",
|
||||||
"command": "sudo cp access.yml /home/infilytics/ && sudo chown -R infilytics:infilytics /home/infilytics/access.yml",
|
"command": ".bin/gitops update access",
|
||||||
|
"group": "build",
|
||||||
"problemMatcher": [],
|
"problemMatcher": [],
|
||||||
"detail": "Copy access.yml to /home/infilytics"
|
"detail": "Copy access.yml to /home/infilytics/"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"label": "GitOps(Update): gitops_router.sh",
|
||||||
|
"type": "shell",
|
||||||
|
"command": ".bin/gitops update gitops_router",
|
||||||
|
"group": "build",
|
||||||
|
"problemMatcher": [],
|
||||||
|
"detail": "Copy gitops_router.sh to /home/infilytics/.local/bin"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"label": "GitOps(Update): home.tar.gz",
|
||||||
|
"type": "shell",
|
||||||
|
"command": ".bin/gitops update home_tar",
|
||||||
|
"group": "build",
|
||||||
|
"problemMatcher": [],
|
||||||
|
"detail": "Copy home.tar.gz to /home/infilytics/"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"label": "GitOps(Update): gitconfig.template",
|
||||||
|
"type": "shell",
|
||||||
|
"command": ".bin/gitops update gitconfig",
|
||||||
|
"group": "build",
|
||||||
|
"problemMatcher": [],
|
||||||
|
"detail": "Copy gitconfig.template to /home/infilytics/"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"label": "Create home tarball",
|
"label": "Create home tarball",
|
||||||
"type": "shell",
|
"type": "shell",
|
||||||
"command": "${workspaceFolder}/.bin/create-home-tarball.sh",
|
"command": "${workspaceFolder}/.bin/create-home-tarball.sh",
|
||||||
|
"group": "build",
|
||||||
"problemMatcher": [],
|
"problemMatcher": [],
|
||||||
"detail": "create home.tar.gz from .config .local .ssh start.sh"
|
"detail": "create home.tar.gz from .config .local .ssh start.sh"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"label": "Start a tmux test session",
|
"label": "Test: start tmux session",
|
||||||
"type": "shell",
|
"type": "shell",
|
||||||
"group": "test",
|
|
||||||
"command": "${workspaceFolder}/.bin/test-tmux.sh",
|
"command": "${workspaceFolder}/.bin/test-tmux.sh",
|
||||||
|
"group": "test",
|
||||||
"problemMatcher": [],
|
"problemMatcher": [],
|
||||||
"detail": "run tmux with project room as home"
|
"detail": "run tmux with project room as home"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"label": "Delete .gitignore files",
|
"label": "GitOps: Show image status",
|
||||||
|
"type": "shell",
|
||||||
|
"command": ".bin/gitops status",
|
||||||
|
"problemMatcher": [],
|
||||||
|
"detail": "run podman images on remote"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"label": "GitOps: Remove workspace container",
|
||||||
|
"type": "shell",
|
||||||
|
"command": ".bin/gitops remove ${input:container} -f",
|
||||||
|
"problemMatcher": [],
|
||||||
|
"detail": "run podman rm $args on remote"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"label": "Cleanup worktree",
|
||||||
"type": "shell",
|
"type": "shell",
|
||||||
"command": "git clean -Xfd",
|
"command": "git clean -Xfd",
|
||||||
"problemMatcher": [],
|
"problemMatcher": [],
|
||||||
"detail": "delete all untracked files listed in .gitignore"
|
"detail": "delete all untracked files listed in .gitignore"
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"inputs": []
|
"inputs": [
|
||||||
|
{
|
||||||
|
"id": "container",
|
||||||
|
"type": "pickString",
|
||||||
|
"description": "Pick a container",
|
||||||
|
"options": ["pallav", "palak", "param", "darshan"],
|
||||||
|
"default": "pallav"
|
||||||
|
}
|
||||||
|
]
|
||||||
}
|
}
|
||||||
|
18
access.yml
18
access.yml
@ -1,6 +1,24 @@
|
|||||||
pallav:
|
pallav:
|
||||||
name: Pallav Vasa
|
name: Pallav Vasa
|
||||||
email: pallav@infilytics.in
|
email: pallav@infilytics.in
|
||||||
|
commands:
|
||||||
|
build:
|
||||||
|
- base
|
||||||
|
- workspace
|
||||||
|
update:
|
||||||
|
- base
|
||||||
|
- workspace
|
||||||
|
- access
|
||||||
|
- ssh_router
|
||||||
|
- gitops_router
|
||||||
|
- home_tar
|
||||||
|
- gitconfig
|
||||||
|
clean:
|
||||||
|
status:
|
||||||
|
remove:
|
||||||
|
- palak
|
||||||
|
- param
|
||||||
|
- darshan
|
||||||
rw:
|
rw:
|
||||||
- darshan
|
- darshan
|
||||||
- param
|
- param
|
||||||
|
@ -1 +1,5 @@
|
|||||||
command="/home/infilytics/ssh_router.sh pallav",no-port-forwarding,no-agent-forwarding,no-X11-forwarding ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIK0il/OJiXygyPWYBt05+OQYjJPxgGuP3kP9hLsD/C7x phoenix@sphinx
|
command="cd %h && ./local/bin/ssh_router.sh pallav",no-port-forwarding,no-agent-forwarding,no-X11-forwarding ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIK0il/OJiXygyPWYBt05+OQYjJPxgGuP3kP9hLsD/C7x phoenix@sphinx
|
||||||
|
command="cd %h && ./local/bin/ssh_router.sh pallav",no-port-forwarding,no-agent-forwarding,no-X11-forwarding ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIArjJAFfhq8LFJX0aqlhUbUNDglmshEJVeLbfXgdo2mU palla@Sphinx
|
||||||
|
command="cd %h && ./local/bin/ssh_router.sh param",no-port-forwarding,no-agent-forwarding,no-X11-forwarding ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDo3+p2DNLONpS2xsw5bSSrB+OA3a+MZqK29c0AutP63R8iDsrzFnea+Zz4L1Lcl8gFoPft3iL0ASYNeVZBHosQVL4lJc1qk/V6kD1h72oPZHNWBboZN1TKAG023L81if6xeIZu9x8Fzc/LWp487PHsjrI0wvK1ngqKwXiD1hUfIg3fjJMENx4TzFllaG4TA6Kd35rAes6exHwauC+9UALTz1Hns891S8j8j1Mlv52Ujadkc49jFcmsiWMBgGjZo3SnDANFqp9LPcCWNNI7W3H9oQ1A6jxmMf0sQN8i2Xks8mNEPzr41VJksq7WPWlclXLVH6ME+ZVR2gsQGnaz7WhA8oaG9q/2SPJRbluZG15GWsUPZ/fOEPZgU+eFwV8MThQzFY2N495S+L1zyeUDYJtfTMDkjCCzT0Rnd0Pv/afGnmz8AfbmO4+o8aTAUpvHZEibqIWzAuC6gruFKYQQEjr8Jev7kfDaWBCVtLaWII965HFtwUtmGql/1tXyixOiAes= param@param
|
||||||
|
command="cd %h && ./local/bin/ssh_router.sh palak",no-port-forwarding,no-agent-forwarding,no-X14-forwarding ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINNwPgVHczFkb32aW/bNS6XMLKh3YXNUoKHXYdtj5X5B infilytics\palak@Palakv
|
||||||
|
command="cd %h && ./local/bin/gitops_router.sh pallav",no-port-forwarding,no-agent-forwarding,no-X11-forwarding ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEcfbbXNTsoXO+tNwYFsFbz/qkvv5OWH1/TNHaKJb0r3 "pallav@infilytics.in"
|
||||||
|
24
build-base.sh
Executable file
24
build-base.sh
Executable file
@ -0,0 +1,24 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
BASE_IMG_NAME="analytics-backend-base"
|
||||||
|
DEV_USER=devuser
|
||||||
|
DEV_UID=1001
|
||||||
|
DEV_GID=1001
|
||||||
|
|
||||||
|
ctr=$(buildah from archlinux)
|
||||||
|
|
||||||
|
buildah run "$ctr" -- bash -c "
|
||||||
|
pacman -Sy --noconfirm && \
|
||||||
|
pacman -S --noconfirm --needed base-devel neovim git git-lfs fish tmux \
|
||||||
|
nodejs python podman fzf fd ripgrep jdk-openjdk fisher yazi less buildah \
|
||||||
|
lazygit luarocks python-pynvim npm bash-completion tree-sitter-cli kitty-terminfo \
|
||||||
|
lua51 openssh && \
|
||||||
|
pacman -Scc --noconfirm && \
|
||||||
|
groupadd -g $DEV_GID $DEV_USER && \
|
||||||
|
groupadd -g 1002 secproc && \
|
||||||
|
useradd -ms /bin/fish -G secproc -u $DEV_UID -g $DEV_GID $DEV_USER
|
||||||
|
"
|
||||||
|
|
||||||
|
buildah commit "$ctr" $BASE_IMG_NAME
|
||||||
|
echo "✅ $BASE_IMG_NAME built."
|
@ -1,22 +1,12 @@
|
|||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
|
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
|
|
||||||
|
BASE_IMG_NAME="analytics-backend-base"
|
||||||
IMG_NAME="analytics-backend-workspace"
|
IMG_NAME="analytics-backend-workspace"
|
||||||
DEV_USER=devuser
|
DEV_USER=devuser
|
||||||
DEV_UID=1001
|
|
||||||
DEV_GID=1001
|
|
||||||
DEV_HOME=/home/$DEV_USER
|
DEV_HOME=/home/$DEV_USER
|
||||||
|
|
||||||
ctr=$(buildah from archlinux)
|
ctr=$(buildah from "$BASE_IMG_NAME")
|
||||||
|
|
||||||
buildah run "$ctr" -- bash -c "\
|
|
||||||
pacman -Sy --noconfirm && pacman -S --noconfirm --needed base-devel neovim git fish tmux \
|
|
||||||
nodejs python podman fzf fd ripgrep jdk-openjdk fisher yazi less buildah \
|
|
||||||
lazygit luarocks python-pynvim npm bash-completion tree-sitter-cli kitty-terminfo \
|
|
||||||
lua51 openssh && pacman -Scc --noconfirm && groupadd secproc && groupadd -g $DEV_GID $DEV_USER && \
|
|
||||||
useradd -ms /bin/fish -G secproc -u $DEV_UID -g $DEV_GID $DEV_USER
|
|
||||||
"
|
|
||||||
|
|
||||||
buildah add "$ctr" home.tar.gz $DEV_HOME
|
buildah add "$ctr" home.tar.gz $DEV_HOME
|
||||||
|
|
||||||
@ -26,8 +16,9 @@ buildah run "$ctr" -- fish -c '
|
|||||||
ssh-keyscan -p 2222 10.88.0.1 >> $HOME/.ssh/known_hosts;
|
ssh-keyscan -p 2222 10.88.0.1 >> $HOME/.ssh/known_hosts;
|
||||||
ssh-keyscan -p 22 github.com >> $HOME/.ssh/known_hosts;
|
ssh-keyscan -p 22 github.com >> $HOME/.ssh/known_hosts;
|
||||||
chown -R '"$DEV_USER"':'"$DEV_USER"' $HOME/.local $HOME/.config/fish/completions \
|
chown -R '"$DEV_USER"':'"$DEV_USER"' $HOME/.local $HOME/.config/fish/completions \
|
||||||
$HOME/.config/fish/functions $HOME/.config/fish/fish_variables;
|
$HOME/.config/fish/functions $HOME/.config/fish/fish_variables $HOME/.ssh;
|
||||||
chown '"$DEV_USER"':'"$DEV_USER"' $HOME/.config/tmux;
|
chown '"$DEV_USER"':'"$DEV_USER"' $HOME/.config $HOME/.config/fish \
|
||||||
|
$HOME/.config/tmux;
|
||||||
'
|
'
|
||||||
|
|
||||||
buildah config \
|
buildah config \
|
||||||
@ -38,5 +29,4 @@ buildah config \
|
|||||||
"$ctr"
|
"$ctr"
|
||||||
|
|
||||||
buildah commit "$ctr" $IMG_NAME
|
buildah commit "$ctr" $IMG_NAME
|
||||||
|
echo "✅ $IMG_NAME built from $BASE_IMG_NAME."
|
||||||
echo "✅ $IMG_NAME built."
|
|
||||||
|
237
gitops_router.sh
Normal file
237
gitops_router.sh
Normal file
@ -0,0 +1,237 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
PERSON="${1:?Missing PERSON argument}"
|
||||||
|
HOST="alps:3222"
|
||||||
|
PROTOCOL="http"
|
||||||
|
REPO="babbarc/workspaces"
|
||||||
|
BRANCH="master"
|
||||||
|
LOG_FILE="/tmp/.gitops-router-${PERSON}.log"
|
||||||
|
|
||||||
|
# ─────────────────────────────────────────────
|
||||||
|
# ANSI color codes
|
||||||
|
readonly C_RESET='\033[0m'
|
||||||
|
readonly C_INFO='\033[1;34m' # bold blue
|
||||||
|
readonly C_WARN='\033[1;33m' # bold yellow
|
||||||
|
readonly C_ERROR='\033[1;31m' # bold red
|
||||||
|
|
||||||
|
# ─────────────────────────────────────────────
|
||||||
|
# log <level> <message...> with emojis
|
||||||
|
log() {
|
||||||
|
local lvl="${1^^}"
|
||||||
|
shift
|
||||||
|
local icon color
|
||||||
|
|
||||||
|
case "$lvl" in
|
||||||
|
INFO) icon="ℹ️" color="$C_INFO" ;;
|
||||||
|
WARN) icon="⚠️" color="$C_WARN" ;;
|
||||||
|
ERROR) icon="❌" color="$C_ERROR" ;;
|
||||||
|
*) icon="🔹" color="$C_RESET" ;;
|
||||||
|
esac
|
||||||
|
|
||||||
|
local ts
|
||||||
|
ts="$(date '+%Y-%m-%d %H:%M:%S')"
|
||||||
|
printf '%b%s [%s] [%s] %s%b\n' \
|
||||||
|
"$color" "$icon" "$ts" "$lvl" "$*" "$C_RESET" |
|
||||||
|
tee -a "$LOG_FILE"
|
||||||
|
}
|
||||||
|
|
||||||
|
# ─────────────────────────────────────────────
|
||||||
|
# Build the raw URL for fetching files
|
||||||
|
geturl() {
|
||||||
|
local type="$1" file="$2"
|
||||||
|
printf '%s://%s/%s/%s/branch/%s/%s\n' \
|
||||||
|
"$PROTOCOL" "$HOST" "$REPO" "$type" "$BRANCH" "$file"
|
||||||
|
}
|
||||||
|
|
||||||
|
# ─────────────────────────────────────────────
|
||||||
|
# Run a local script
|
||||||
|
run() {
|
||||||
|
local script="$1"
|
||||||
|
"$HOME/.local/bin/$script"
|
||||||
|
}
|
||||||
|
|
||||||
|
# ─────────────────────────────────────────────
|
||||||
|
# Download & install an artifact
|
||||||
|
# update <file> <target-dir> <mode> [<type>]
|
||||||
|
update() {
|
||||||
|
local file="$1" dir="$2" mode="$3" type="${4:-raw}"
|
||||||
|
local url out
|
||||||
|
|
||||||
|
out="$HOME/$dir/$(basename "$file")"
|
||||||
|
url="$(geturl "$type" "$file")"
|
||||||
|
|
||||||
|
[[ -f "$out" ]] && chmod 700 "$out"
|
||||||
|
|
||||||
|
if curl -fsSL "$url" -o "$out"; then
|
||||||
|
log INFO "Downloaded $url → $out"
|
||||||
|
chmod "$mode" "$out"
|
||||||
|
else
|
||||||
|
log ERROR "Failed to download $url"
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
# ─────────────────────────────────────────────
|
||||||
|
# Clean up dangling podman images
|
||||||
|
clean_images() {
|
||||||
|
local dangling
|
||||||
|
dangling="$(podman images -f dangling=true -q)"
|
||||||
|
if [[ -z "$dangling" ]]; then
|
||||||
|
log INFO "No dangling images to remove."
|
||||||
|
else
|
||||||
|
log WARN "Removing dangling images..."
|
||||||
|
echo "$dangling" | xargs podman rmi
|
||||||
|
log INFO "Dangling images removed."
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
# ─────────────────────────────────────────────
|
||||||
|
# Remove host podman containers
|
||||||
|
remove_containers() {
|
||||||
|
local tokens=("$@")
|
||||||
|
local flags=() patterns=() containers=()
|
||||||
|
local valid='^[A-Za-z0-9._-]+$'
|
||||||
|
|
||||||
|
# allow unmatched globs to disappear
|
||||||
|
shopt -s nullglob
|
||||||
|
|
||||||
|
# separate flags (-f, etc.) from name patterns
|
||||||
|
for tok in "${tokens[@]}"; do
|
||||||
|
if [[ "$tok" == -* ]]; then
|
||||||
|
flags+=("$tok")
|
||||||
|
else
|
||||||
|
patterns+=("$tok")
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
|
||||||
|
# validate & expand each pattern
|
||||||
|
for pat in "${patterns[@]}"; do
|
||||||
|
if [[ ! "$pat" =~ $valid ]]; then
|
||||||
|
log ERROR "Invalid container name: '$pat'"
|
||||||
|
shopt -u nullglob
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
containers+=("$pat")
|
||||||
|
done
|
||||||
|
|
||||||
|
shopt -u nullglob
|
||||||
|
|
||||||
|
if ((${#containers[@]} == 0)); then
|
||||||
|
log WARN "No containers matched: ${patterns[*]}"
|
||||||
|
return 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
# pass flags *then* containers to podman rm
|
||||||
|
podman rm "${flags[@]}" "${containers[@]}"
|
||||||
|
}
|
||||||
|
|
||||||
|
# ─────────────────────────────────────────────
|
||||||
|
# validate_command <cmd> [<tok1> <tok2> …]
|
||||||
|
validate_command() {
|
||||||
|
local cmd="$1"
|
||||||
|
shift
|
||||||
|
local tokens=("$@")
|
||||||
|
local yaml="$HOME/access.yml"
|
||||||
|
|
||||||
|
# 1) Is command allowed at all?
|
||||||
|
if [[ "$(yq e ".\"$PERSON\".commands | has(\"$cmd\")" "$yaml")" != "true" ]]; then
|
||||||
|
log ERROR "Unauthorized command: '$cmd'"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
# 2) Load allowed args for this cmd (may be empty array)
|
||||||
|
mapfile -t allowed < <(yq e ".\"$PERSON\".commands.${cmd}[]" "$yaml")
|
||||||
|
|
||||||
|
if [[ "${#allowed[@]}" -eq 0 ]]; then
|
||||||
|
log ERROR "No allowed arguments for command '$cmd' in $yaml"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
# 3) Extract just the non-flag tokens
|
||||||
|
local args=()
|
||||||
|
for tok in "${tokens[@]}"; do
|
||||||
|
[[ "$tok" == -* ]] && continue
|
||||||
|
args+=("$tok")
|
||||||
|
done
|
||||||
|
|
||||||
|
if [[ "$cmd" == "remove" ]]; then
|
||||||
|
# ─ remove: must have at least one arg
|
||||||
|
if ((${#args[@]} == 0)); then
|
||||||
|
log ERROR "Command '$cmd' requires at least one argument: ${allowed[*]}"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
# Validate each against allowed[]
|
||||||
|
for a in "${args[@]}"; do
|
||||||
|
local ok=false
|
||||||
|
for want in "${allowed[@]}"; do
|
||||||
|
[[ "$a" == "$want" ]] && ok=true && break
|
||||||
|
done
|
||||||
|
if ! $ok; then
|
||||||
|
log ERROR "Invalid argument '$a' for '$cmd'; allowed: ${allowed[*]}"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
else
|
||||||
|
# ─ all other cmds: must have exactly one arg
|
||||||
|
if ((${#args[@]} != 1)); then
|
||||||
|
log ERROR "Command '$cmd' requires exactly one argument: ${allowed[*]}"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
# And that single arg must be allowed
|
||||||
|
local a="${args[0]}"
|
||||||
|
local ok=false
|
||||||
|
for want in "${allowed[@]}"; do
|
||||||
|
[[ "$a" == "$want" ]] && ok=true && break
|
||||||
|
done
|
||||||
|
if ! $ok; then
|
||||||
|
log ERROR "Invalid argument '$a' for '$cmd'; allowed: ${allowed[*]}"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
# ─────────────────────────────────────────────
|
||||||
|
# Entry & command parsing
|
||||||
|
if [[ -z "${SSH_ORIGINAL_COMMAND:-}" ]]; then
|
||||||
|
log ERROR "No SSH_ORIGINAL_COMMAND provided."
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
log INFO "SSH_ORIGINAL_COMMAND: $SSH_ORIGINAL_COMMAND"
|
||||||
|
read -ra parts <<<"$SSH_ORIGINAL_COMMAND"
|
||||||
|
cmd="${parts[0]}"
|
||||||
|
args=("${parts[@]:1}")
|
||||||
|
|
||||||
|
validate_command "$cmd" "${args[@]}"
|
||||||
|
|
||||||
|
# ─────────────────────────────────────────────
|
||||||
|
# Dispatch
|
||||||
|
case "$cmd" in
|
||||||
|
build)
|
||||||
|
case "${args[0]}" in
|
||||||
|
base) run build-base.sh ;;
|
||||||
|
workspace) run build-workspace.sh ;;
|
||||||
|
*) log ERROR "build: invalid arg '${args[0]}'" ;;
|
||||||
|
esac
|
||||||
|
;;
|
||||||
|
update)
|
||||||
|
case "${args[0]}" in
|
||||||
|
base) update build-base.sh .local/bin 500 ;;
|
||||||
|
workspace) update build-workspace.sh .local/bin 500 ;;
|
||||||
|
access) update access.yml . 400 ;;
|
||||||
|
ssh_router) update ssh_router.sh .local/bin 500 ;;
|
||||||
|
gitops_router) update gitops_router.sh .local/bin 500 ;;
|
||||||
|
home_tar) update home.tar.gz . 500 media ;;
|
||||||
|
gitconfig) update gitconfig.template . 500 ;;
|
||||||
|
*) log ERROR "update: invalid arg '${args[0]}'" ;;
|
||||||
|
esac
|
||||||
|
;;
|
||||||
|
clean) clean_images ;;
|
||||||
|
status) podman images ;;
|
||||||
|
remove) remove_containers "${args[@]}" ;;
|
||||||
|
*)
|
||||||
|
log ERROR "Unknown command: '$cmd'"
|
||||||
|
exit 127
|
||||||
|
;;
|
||||||
|
esac
|
BIN
home.tar.gz
(Stored with Git LFS)
Normal file
BIN
home.tar.gz
(Stored with Git LFS)
Normal file
Binary file not shown.
255
ssh_router.sh
255
ssh_router.sh
@ -1,187 +1,208 @@
|
|||||||
#!/bin/bash
|
#!/usr/bin/env bash
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
PERSON="$1"
|
PERSON="${1:?Usage: $0 <person>}"
|
||||||
WORKSPACE="$SSH_ORIGINAL_COMMAND"
|
WORKSPACE="${SSH_ORIGINAL_COMMAND:-}"
|
||||||
IMAGE="localhost:5100/analytics-backend-workspace:latest"
|
IMAGE="localhost/analytics-backend-workspace:latest"
|
||||||
DEV_USER="devuser"
|
DEV_USER="devuser"
|
||||||
|
|
||||||
XDG_RUNTIME_DIR="/run/user/$(id -u)"
|
XDG_RUNTIME_DIR="/run/user/$(id -u)"
|
||||||
LOG_FILE="/tmp/.ssh-router-${PERSON}.log"
|
LOG_FILE="/tmp/.ssh-router-${PERSON}.log"
|
||||||
|
|
||||||
|
# ─────────────────────────────────────────────
|
||||||
|
# ANSI colors & emojis
|
||||||
|
readonly C_RESET='\033[0m'
|
||||||
|
readonly C_INFO='\033[1;34m' # blue
|
||||||
|
readonly C_WARN='\033[1;33m' # yellow
|
||||||
|
readonly C_ERROR='\033[1;31m' # red
|
||||||
|
|
||||||
log() {
|
log() {
|
||||||
echo "[$(date '+%Y-%m-%d %H:%M:%S')] $*" >>"$LOG_FILE"
|
local level="${1^^}"
|
||||||
|
shift
|
||||||
|
local icon color
|
||||||
|
case "$level" in
|
||||||
|
INFO) icon="ℹ️" color="$C_INFO" ;;
|
||||||
|
WARN) icon="⚠️" color="$C_WARN" ;;
|
||||||
|
ERROR) icon="❌" color="$C_ERROR" ;;
|
||||||
|
*) icon="🔹" color="$C_RESET" ;;
|
||||||
|
esac
|
||||||
|
local ts
|
||||||
|
ts="$(date '+%Y-%m-%d %H:%M:%S')"
|
||||||
|
printf '%b%s [%s] %s%b\n' \
|
||||||
|
"$color" "$icon" "$ts" "[$level] $*" "$C_RESET" |
|
||||||
|
tee -a "$LOG_FILE"
|
||||||
}
|
}
|
||||||
|
|
||||||
|
# ─────────────────────────────────────────────
|
||||||
|
# Check for interactive TTY
|
||||||
if [[ ! -t 0 ]]; then
|
if [[ ! -t 0 ]]; then
|
||||||
log "❌ No TTY allocated — refusing to run tmux without an interactive terminal"
|
log ERROR "No TTY allocated—refusing to run without an interactive terminal"
|
||||||
echo "Error: No TTY. Use 'ssh -t'" >&2
|
echo "Error: No TTY. Use 'ssh -t'" >&2
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# log "🧩 IMAGE = '$IMAGE'"
|
# ─────────────────────────────────────────────
|
||||||
# log "🧩 WORKSPACE = '$WORKSPACE'"
|
# Default WORKSPACE if empty
|
||||||
# log "🧩 PERSON = '$PERSON'"
|
if [[ -z "$WORKSPACE" ]]; then
|
||||||
|
|
||||||
# Fallbacks
|
|
||||||
if [[ -z "${WORKSPACE:-}" ]]; then
|
|
||||||
WORKSPACE="$PERSON"
|
WORKSPACE="$PERSON"
|
||||||
log "ℹ️ Defaulted WORKSPACE to $WORKSPACE"
|
log INFO "Defaulted WORKSPACE → $WORKSPACE"
|
||||||
fi
|
fi
|
||||||
|
TMUX_SESSION="${WORKSPACE}|analytics-backend"
|
||||||
|
|
||||||
TMUX_SESSION="$WORKSPACE|analytics-backend"
|
# ─────────────────────────────────────────────
|
||||||
|
# Ensure Podman socket is up
|
||||||
# Start podman socket service if it's not running
|
ensure_podman() {
|
||||||
if [[ ! -S "$XDG_RUNTIME_DIR/podman/podman.sock" ]]; then
|
local sock="$XDG_RUNTIME_DIR/podman/podman.sock"
|
||||||
log "🔄 Starting Podman socket service for user $USER"
|
if [[ ! -S "$sock" ]]; then
|
||||||
|
log INFO "Starting podman.socket for user $(id -un)"
|
||||||
systemctl --user start podman.socket || {
|
systemctl --user start podman.socket || {
|
||||||
log "❌ Failed to start podman.socket via systemd"
|
log ERROR "Failed to start podman.socket"
|
||||||
exit 1
|
exit 1
|
||||||
}
|
}
|
||||||
|
|
||||||
# Wait briefly for socket to appear
|
|
||||||
sleep 1
|
sleep 1
|
||||||
fi
|
|
||||||
|
|
||||||
if [[ ! -S "$XDG_RUNTIME_DIR/podman/podman.sock" ]]; then
|
|
||||||
log "❌ Podman socket still missing after startup attempt"
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
# Check if image exists locally
|
|
||||||
if ! podman image exists "$IMAGE"; then
|
|
||||||
log "📦 Image $IMAGE not found locally. Pulling from registry..."
|
|
||||||
|
|
||||||
# Attempt to pull the image from the local registry (insecure HTTP)
|
|
||||||
if ! podman pull --tls-verify=false "$IMAGE"; then
|
|
||||||
log "❌ Failed to pull image from $IMAGE"
|
|
||||||
exit 1
|
|
||||||
fi
|
fi
|
||||||
|
[[ -S "$sock" ]] || {
|
||||||
|
log ERROR "Podman socket still missing"
|
||||||
|
exit 1
|
||||||
|
}
|
||||||
|
}
|
||||||
|
ensure_podman
|
||||||
|
|
||||||
log "✅ Successfully pulled $IMAGE"
|
# ─────────────────────────────────────────────
|
||||||
fi
|
# Ensure IMAGE is present
|
||||||
|
ensure_image() {
|
||||||
|
if ! podman image exists "$IMAGE"; then
|
||||||
|
log WARN "Image $IMAGE not found—pulling"
|
||||||
|
podman pull --tls-verify=false "$IMAGE" || {
|
||||||
|
log ERROR "Failed to pull $IMAGE"
|
||||||
|
exit 1
|
||||||
|
}
|
||||||
|
log INFO "Pulled $IMAGE"
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
ensure_image
|
||||||
|
|
||||||
|
# ─────────────────────────────────────────────
|
||||||
|
# Disallow file transfers
|
||||||
case "$SSH_ORIGINAL_COMMAND" in
|
case "$SSH_ORIGINAL_COMMAND" in
|
||||||
*scp* | *sftp* | *rsync* | *tar*)
|
*scp* | *sftp* | *rsync* | *tar*)
|
||||||
log "❌ File transfers are disabled"
|
log ERROR "File transfers are disabled"
|
||||||
exit 1
|
exit 1
|
||||||
;;
|
;;
|
||||||
esac
|
esac
|
||||||
|
|
||||||
# Function to start the container if not running
|
# ─────────────────────────────────────────────
|
||||||
|
# Generate per-user gitconfig
|
||||||
|
generate_gitconfig() {
|
||||||
|
local access="$HOME/access.yml"
|
||||||
|
local template="$HOME/gitconfig.template"
|
||||||
|
local userdir="$HOME/secrets/$PERSON"
|
||||||
|
local name email
|
||||||
|
|
||||||
|
name=$(yq -r ".\"$PERSON\".name" "$access" 2>/dev/null || echo)
|
||||||
|
email=$(yq -r ".\"$PERSON\".email" "$access" 2>/dev/null || echo)
|
||||||
|
|
||||||
|
if [[ -z "$name" || -z "$email" ]]; then
|
||||||
|
log ERROR "Missing name/email for '$PERSON' in $access"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
mkdir -p "$userdir"
|
||||||
|
GIT_NAME="$name" GIT_EMAIL="$email" \
|
||||||
|
envsubst <"$template" >"$userdir/gitconfig"
|
||||||
|
log INFO ".gitconfig created → $userdir/gitconfig"
|
||||||
|
}
|
||||||
|
|
||||||
|
# ─────────────────────────────────────────────
|
||||||
|
# Start container if absent or stopped
|
||||||
start_container_if_needed() {
|
start_container_if_needed() {
|
||||||
if ! podman container exists "$WORKSPACE"; then
|
if ! podman container exists "$WORKSPACE"; then
|
||||||
log "🚀 Creating container $WORKSPACE..."
|
log INFO "Creating container '$WORKSPACE'"
|
||||||
|
generate_gitconfig
|
||||||
podman run -dit \
|
podman run -dit \
|
||||||
--userns=keep-id \
|
|
||||||
--name "$WORKSPACE" \
|
--name "$WORKSPACE" \
|
||||||
|
--userns=keep-id \
|
||||||
--user "$DEV_USER" \
|
--user "$DEV_USER" \
|
||||||
--hostname "$WORKSPACE" \
|
--hostname "$WORKSPACE" \
|
||||||
--label auto-cleanup=true \
|
--label auto-cleanup=true \
|
||||||
-v "${XDG_RUNTIME_DIR}"/podman/podman.sock:/run/podman/podman.sock \
|
-v "$HOME/data/$WORKSPACE:/app:Z" \
|
||||||
-v /home/infilytics/data/"$WORKSPACE":/app \
|
-v "$HOME/secrets/$WORKSPACE/gitconfig:/home/$DEV_USER/.gitconfig:ro,Z" \
|
||||||
-v /home/infilytics/secrets/"$WORKSPACE"/gitconfig:/home/"$DEV_USER"/.gitconfig:ro \
|
-v "$HOME/secrets/$WORKSPACE/id_ed25519:/home/$DEV_USER/.ssh/id_ed25519:ro,Z" \
|
||||||
-v /home/infilytics/secrets/"$WORKSPACE"/id_ed25519:/home/"$DEV_USER"/.ssh/id_ed25519:ro \
|
-v "$HOME/secrets/$WORKSPACE/id_ed25519.pub:/home/$DEV_USER/.ssh/id_ed25519.pub:ro,Z" \
|
||||||
-v /home/infilytics/secrets/"$WORKSPACE"/id_ed25519.pub:/home/"$DEV_USER"/.ssh/id_ed25519.pub:ro \
|
|
||||||
--entrypoint "/home/$DEV_USER/start.sh" \
|
--entrypoint "/home/$DEV_USER/start.sh" \
|
||||||
"$IMAGE" "${TMUX_SESSION}"
|
"$IMAGE" "$TMUX_SESSION"
|
||||||
elif ! podman inspect -f '{{.State.Running}}' "$WORKSPACE" | grep -q true; then
|
elif ! podman inspect -f '{{.State.Running}}' "$WORKSPACE" | grep -q true; then
|
||||||
log "⚡ Starting existing container $WORKSPACE..."
|
log INFO "Starting existing container '$WORKSPACE'"
|
||||||
podman start "$WORKSPACE" >/dev/null 2>&1
|
podman start "$WORKSPACE" >/dev/null
|
||||||
fi
|
fi
|
||||||
sleep 1
|
sleep 1
|
||||||
}
|
}
|
||||||
|
|
||||||
# After devuser exits...
|
# ─────────────────────────────────────────────
|
||||||
|
# Detach logic: stop container when devuser has left
|
||||||
check_devuser_attached() {
|
check_devuser_attached() {
|
||||||
# Get list of clients
|
local clients
|
||||||
client_users=$(podman exec "$WORKSPACE" tmux list-clients -t "$TMUX_SESSION" -F "#{client_user}" 2>/dev/null)
|
clients=$(podman exec "$WORKSPACE" tmux list-clients -t "$TMUX_SESSION" -F "#{client_user}" 2>/dev/null)
|
||||||
|
if grep -q "^${DEV_USER}\$" <<<"$clients"; then
|
||||||
if echo "$client_users" | grep -q "$DEV_USER"; then
|
log INFO "devuser still attached—keeping container running"
|
||||||
log "💡 devuser still attached — container stays running"
|
|
||||||
return 0
|
|
||||||
else
|
else
|
||||||
log "🏃 $PERSON has logged out — stopping container"
|
log INFO "devuser detached—stopping container"
|
||||||
podman stop "$WORKSPACE" >/dev/null 2>&1
|
podman stop "$WORKSPACE" >/dev/null
|
||||||
return 1
|
|
||||||
fi
|
fi
|
||||||
}
|
}
|
||||||
|
|
||||||
|
# ─────────────────────────────────────────────
|
||||||
|
# Determine access mode (rw|ro) or exit
|
||||||
get_access_mode() {
|
get_access_mode() {
|
||||||
local yaml_file="access.yml"
|
local yaml="access.yml" user="$PERSON" ws="$WORKSPACE"
|
||||||
local workspace="$1"
|
[[ ! "$ws" =~ ^[A-Za-z0-9._-]+$ ]] && {
|
||||||
local person="$2"
|
log ERROR "Invalid workspace name"
|
||||||
|
exit 1
|
||||||
if [[ ! "$workspace" =~ ^[a-zA-Z0-9._-]+$ ]]; then
|
}
|
||||||
log "❌ Invalid container name: $WORKSPACE"
|
if [[ "$user" == "$ws" ]]; then
|
||||||
|
echo rw
|
||||||
|
elif yq -e '.["'"$user"'"].rw[]?' "$yaml" | grep -qx "$ws"; then
|
||||||
|
echo rw
|
||||||
|
elif yq -e '.["'"$user"'"].ro[]?' "$yaml" | grep -qx "$ws"; then
|
||||||
|
echo ro
|
||||||
|
else
|
||||||
|
log ERROR "$user has no access to $ws"
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# Special case: user accessing their own workspace
|
|
||||||
if [[ "$workspace" == "$person" ]]; then
|
|
||||||
echo "access=rw"
|
|
||||||
return 0
|
|
||||||
fi
|
|
||||||
|
|
||||||
# Check rw
|
|
||||||
if yq '.["'"$person"'"].rw // []' "$yaml_file" | grep -q "\b$workspace\b"; then
|
|
||||||
echo "access=rw"
|
|
||||||
return 0
|
|
||||||
fi
|
|
||||||
|
|
||||||
# Check ro
|
|
||||||
if yq '.["'"$person"'"].ro // []' "$yaml_file" | grep -q "\b$workspace\b"; then
|
|
||||||
echo "access=ro"
|
|
||||||
return 0
|
|
||||||
fi
|
|
||||||
|
|
||||||
# No access → exit with error
|
|
||||||
log "❌ $person has no access to $workspace" >&2
|
|
||||||
exit 1
|
|
||||||
}
|
}
|
||||||
|
|
||||||
# === Main ===
|
MODE="$(get_access_mode)"
|
||||||
|
|
||||||
read -r access_line < <(get_access_mode "$WORKSPACE" "$PERSON") || exit 1
|
|
||||||
MODE="${access_line#access=}"
|
|
||||||
|
|
||||||
|
# ─────────────────────────────────────────────
|
||||||
|
# Main dispatch
|
||||||
case "$MODE" in
|
case "$MODE" in
|
||||||
rw)
|
rw)
|
||||||
start_container_if_needed
|
start_container_if_needed
|
||||||
|
|
||||||
# Run tmux session inside the container
|
# Ensure tmux session exists
|
||||||
if ! podman exec -it --user "$DEV_USER" "$WORKSPACE" tmux has-session -t "$TMUX_SESSION" >/dev/null 2>&1; then
|
if ! podman exec -it --user "$DEV_USER" "$WORKSPACE" tmux has-session -t "$TMUX_SESSION" 2>/dev/null; then
|
||||||
if ! podman exec -it -e EDITOR=nvim --user "$DEV_USER" "$WORKSPACE" tmux new-session -d -s "$TMUX_SESSION" >/dev/null 2>&1; then
|
podman exec -it --user "$DEV_USER" "$WORKSPACE" \
|
||||||
log "❌ Could not create new tmux session. Please contact admin or try again later."
|
tmux new-session -d -s "$TMUX_SESSION"
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
fi
|
fi
|
||||||
|
|
||||||
log "⚡ $PERSON is working on $WORKSPACE's workspace"
|
log INFO "$PERSON attaching to workspace '$WORKSPACE'"
|
||||||
if ! podman exec -it -e TERM="$TERM" --user "$DEV_USER" "$WORKSPACE" tmux attach -t "$TMUX_SESSION"; then
|
podman exec -it -e TERM="$TERM" --user "$DEV_USER" "$WORKSPACE" \
|
||||||
log "❌ Could not attach to tmux session. Please contact admin or try again later."
|
tmux attach -t "$TMUX_SESSION"
|
||||||
exit 1
|
log INFO "$PERSON detached from '$WORKSPACE'"
|
||||||
fi
|
|
||||||
log "⚡ $PERSON finished working on $WORKSPACE's worksapce"
|
|
||||||
|
|
||||||
check_devuser_attached
|
check_devuser_attached
|
||||||
exit 0
|
|
||||||
;;
|
;;
|
||||||
ro)
|
ro)
|
||||||
if (podman container exists "$WORKSPACE" && podman inspect -f '{{.State.Running}}' "$WORKSPACE" | grep -q true) >/dev/null 2>&1; then
|
if podman inspect -f '{{.State.Running}}' "$WORKSPACE" 2>/dev/null | grep -q true; then
|
||||||
log "📜 $PERSON is viewing $WORKSPACE's workspace"
|
log INFO "$PERSON viewing workspace '$WORKSPACE'"
|
||||||
if ! podman exec -it -e TERM="$TERM" --user "$DEV_USER" "$WORKSPACE" tmux attach -r -t "$TMUX_SESSION"; then
|
podman exec -it -e TERM="$TERM" --user "$DEV_USER" "$WORKSPACE" \
|
||||||
log "❌ Could not attach to tmux session. Please contact admin or try again later."
|
tmux attach -r -t "$TMUX_SESSION"
|
||||||
exit 1
|
log INFO "$PERSON stopped viewing '$WORKSPACE'"
|
||||||
fi
|
|
||||||
log "🏃 $PERSON stopped viewing $WORKSPACE's workspace"
|
|
||||||
exit 0
|
|
||||||
else
|
else
|
||||||
log "❌ Workspace for $WORKSPACE does not exist."
|
log ERROR "Workspace '$WORKSPACE' is not running"
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
;;
|
;;
|
||||||
*)
|
*)
|
||||||
log "❌ Invalid access mode: $MODE"
|
log ERROR "Unknown access mode: '$MODE'"
|
||||||
exit 1
|
exit 1
|
||||||
;;
|
;;
|
||||||
esac
|
esac
|
||||||
|
Reference in New Issue
Block a user