Compare commits
11 Commits
v0.6
...
c9460b8ebc
Author | SHA1 | Date | |
---|---|---|---|
c9460b8ebc | |||
9629c3253e | |||
6e11d19510 | |||
a4bfe5a5c0 | |||
54a42ad4d5 | |||
21eee8c3ec | |||
ff72c95012 | |||
3576bf93c2 | |||
d7c7686a9e | |||
a179a3ad23 | |||
56744155cb |
8
.vscode/tasks.json
vendored
8
.vscode/tasks.json
vendored
@ -72,6 +72,14 @@
|
||||
"problemMatcher": [],
|
||||
"detail": "Copy home.tar.gz to /home/infilytics/"
|
||||
},
|
||||
{
|
||||
"label": "GitOps(Update): gitconfig.template",
|
||||
"type": "shell",
|
||||
"command": ".bin/gitops update gitconfig",
|
||||
"group": "build",
|
||||
"problemMatcher": [],
|
||||
"detail": "Copy gitconfig.template to /home/infilytics/"
|
||||
},
|
||||
{
|
||||
"label": "Create home tarball",
|
||||
"type": "shell",
|
||||
|
18
access.yml
18
access.yml
@ -1,6 +1,24 @@
|
||||
pallav:
|
||||
name: Pallav Vasa
|
||||
email: pallav@infilytics.in
|
||||
commands:
|
||||
build:
|
||||
- base
|
||||
- workspace
|
||||
update:
|
||||
- base
|
||||
- workspace
|
||||
- access
|
||||
- ssh_router
|
||||
- gitops_router
|
||||
- home_tar
|
||||
- gitconfig
|
||||
clean:
|
||||
status:
|
||||
remove:
|
||||
- palak
|
||||
- param
|
||||
- darshan
|
||||
rw:
|
||||
- darshan
|
||||
- param
|
||||
|
@ -1 +1,5 @@
|
||||
command="/home/infilytics/ssh_router.sh pallav",no-port-forwarding,no-agent-forwarding,no-X11-forwarding ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIK0il/OJiXygyPWYBt05+OQYjJPxgGuP3kP9hLsD/C7x phoenix@sphinx
|
||||
command="cd %h && ./local/bin/ssh_router.sh pallav",no-port-forwarding,no-agent-forwarding,no-X11-forwarding ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIK0il/OJiXygyPWYBt05+OQYjJPxgGuP3kP9hLsD/C7x phoenix@sphinx
|
||||
command="cd %h && ./local/bin/ssh_router.sh pallav",no-port-forwarding,no-agent-forwarding,no-X11-forwarding ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIArjJAFfhq8LFJX0aqlhUbUNDglmshEJVeLbfXgdo2mU palla@Sphinx
|
||||
command="cd %h && ./local/bin/ssh_router.sh param",no-port-forwarding,no-agent-forwarding,no-X11-forwarding ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDo3+p2DNLONpS2xsw5bSSrB+OA3a+MZqK29c0AutP63R8iDsrzFnea+Zz4L1Lcl8gFoPft3iL0ASYNeVZBHosQVL4lJc1qk/V6kD1h72oPZHNWBboZN1TKAG023L81if6xeIZu9x8Fzc/LWp487PHsjrI0wvK1ngqKwXiD1hUfIg3fjJMENx4TzFllaG4TA6Kd35rAes6exHwauC+9UALTz1Hns891S8j8j1Mlv52Ujadkc49jFcmsiWMBgGjZo3SnDANFqp9LPcCWNNI7W3H9oQ1A6jxmMf0sQN8i2Xks8mNEPzr41VJksq7WPWlclXLVH6ME+ZVR2gsQGnaz7WhA8oaG9q/2SPJRbluZG15GWsUPZ/fOEPZgU+eFwV8MThQzFY2N495S+L1zyeUDYJtfTMDkjCCzT0Rnd0Pv/afGnmz8AfbmO4+o8aTAUpvHZEibqIWzAuC6gruFKYQQEjr8Jev7kfDaWBCVtLaWII965HFtwUtmGql/1tXyixOiAes= param@param
|
||||
command="cd %h && ./local/bin/ssh_router.sh palak",no-port-forwarding,no-agent-forwarding,no-X14-forwarding ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINNwPgVHczFkb32aW/bNS6XMLKh3YXNUoKHXYdtj5X5B infilytics\palak@Palakv
|
||||
command="cd %h && ./local/bin/gitops_router.sh pallav",no-port-forwarding,no-agent-forwarding,no-X11-forwarding ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEcfbbXNTsoXO+tNwYFsFbz/qkvv5OWH1/TNHaKJb0r3 "pallav@infilytics.in"
|
||||
|
279
gitops_router.sh
279
gitops_router.sh
@ -1,114 +1,237 @@
|
||||
#!/usr/bin/env bash
|
||||
set -euo pipefail
|
||||
|
||||
PERSON="$1"
|
||||
PERSON="${1:?Missing PERSON argument}"
|
||||
HOST="alps:3222"
|
||||
PROTOCOL="http"
|
||||
REPO="babbarc/workspaces"
|
||||
BRANCH="master"
|
||||
|
||||
LOG_FILE="/tmp/.gitops-router-${PERSON}.log"
|
||||
|
||||
# ─────────────────────────────────────────────
|
||||
# ANSI color codes
|
||||
readonly C_RESET='\033[0m'
|
||||
readonly C_INFO='\033[1;34m' # bold blue
|
||||
readonly C_WARN='\033[1;33m' # bold yellow
|
||||
readonly C_ERROR='\033[1;31m' # bold red
|
||||
|
||||
# ─────────────────────────────────────────────
|
||||
# log <level> <message...> with emojis
|
||||
log() {
|
||||
local level="${1^^}" # convert to uppercase
|
||||
local lvl="${1^^}"
|
||||
shift
|
||||
echo "[$(date '+%Y-%m-%d %H:%M:%S')] [$level] $*" | tee -a "$LOG_FILE"
|
||||
local icon color
|
||||
|
||||
case "$lvl" in
|
||||
INFO) icon="ℹ️" color="$C_INFO" ;;
|
||||
WARN) icon="⚠️" color="$C_WARN" ;;
|
||||
ERROR) icon="❌" color="$C_ERROR" ;;
|
||||
*) icon="🔹" color="$C_RESET" ;;
|
||||
esac
|
||||
|
||||
local ts
|
||||
ts="$(date '+%Y-%m-%d %H:%M:%S')"
|
||||
printf '%b%s [%s] [%s] %s%b\n' \
|
||||
"$color" "$icon" "$ts" "$lvl" "$*" "$C_RESET" |
|
||||
tee -a "$LOG_FILE"
|
||||
}
|
||||
|
||||
log info "Received SSH_ORIGINAL_COMMAND: $SSH_ORIGINAL_COMMAND"
|
||||
|
||||
# Ensure the variable is set
|
||||
if [[ -z "${SSH_ORIGINAL_COMMAND:-}" ]]; then
|
||||
log error "No SSH_ORIGINAL_COMMAND provided."
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# ─────────────────────────────────────────────
|
||||
# Build the raw URL for fetching files
|
||||
geturl() {
|
||||
echo "$PROTOCOL://$HOST/$REPO/$1/branch/$BRANCH/$2"
|
||||
local type="$1" file="$2"
|
||||
printf '%s://%s/%s/%s/branch/%s/%s\n' \
|
||||
"$PROTOCOL" "$HOST" "$REPO" "$type" "$BRANCH" "$file"
|
||||
}
|
||||
|
||||
function run() {
|
||||
"$HOME"/.local/bin/"$1"
|
||||
# ─────────────────────────────────────────────
|
||||
# Run a local script
|
||||
run() {
|
||||
local script="$1"
|
||||
"$HOME/.local/bin/$script"
|
||||
}
|
||||
|
||||
function update() {
|
||||
type=${4:-raw}
|
||||
fname=$(basename "$1")
|
||||
output_path="$HOME/$2/$fname"
|
||||
url=$(geturl "$type" "$1")
|
||||
# ─────────────────────────────────────────────
|
||||
# Download & install an artifact
|
||||
# update <file> <target-dir> <mode> [<type>]
|
||||
update() {
|
||||
local file="$1" dir="$2" mode="$3" type="${4:-raw}"
|
||||
local url out
|
||||
|
||||
[ -f "$output_path" ] && chmod 700 "$output_path"
|
||||
curl -fsSL "$url" -o "$output_path" && log info "Downloaded $url to $output_path"
|
||||
chmod "$3" "$output_path"
|
||||
}
|
||||
out="$HOME/$dir/$(basename "$file")"
|
||||
url="$(geturl "$type" "$file")"
|
||||
|
||||
clean_images() {
|
||||
# Get list of image IDs with <none> tag (dangling images)
|
||||
dangling_images=$(podman images -f "dangling=true" -q)
|
||||
[[ -f "$out" ]] && chmod 700 "$out"
|
||||
|
||||
if [ -z "$dangling_images" ]; then
|
||||
echo "✅ No dangling images to remove."
|
||||
if curl -fsSL "$url" -o "$out"; then
|
||||
log INFO "Downloaded $url → $out"
|
||||
chmod "$mode" "$out"
|
||||
else
|
||||
echo "⚠️ Removing dangling images..."
|
||||
echo "$dangling_images" | xargs podman rmi
|
||||
echo "🧹 Done!"
|
||||
log ERROR "Failed to download $url"
|
||||
return 1
|
||||
fi
|
||||
}
|
||||
|
||||
# Strip arguments and parse command
|
||||
read -r command args <<<"$SSH_ORIGINAL_COMMAND"
|
||||
# ─────────────────────────────────────────────
|
||||
# Clean up dangling podman images
|
||||
clean_images() {
|
||||
local dangling
|
||||
dangling="$(podman images -f dangling=true -q)"
|
||||
if [[ -z "$dangling" ]]; then
|
||||
log INFO "No dangling images to remove."
|
||||
else
|
||||
log WARN "Removing dangling images..."
|
||||
echo "$dangling" | xargs podman rmi
|
||||
log INFO "Dangling images removed."
|
||||
fi
|
||||
}
|
||||
|
||||
# Define command routing
|
||||
case "$command" in
|
||||
# ─────────────────────────────────────────────
|
||||
# Remove host podman containers
|
||||
remove_containers() {
|
||||
local tokens=("$@")
|
||||
local flags=() patterns=() containers=()
|
||||
local valid='^[A-Za-z0-9._-]+$'
|
||||
|
||||
# allow unmatched globs to disappear
|
||||
shopt -s nullglob
|
||||
|
||||
# separate flags (-f, etc.) from name patterns
|
||||
for tok in "${tokens[@]}"; do
|
||||
if [[ "$tok" == -* ]]; then
|
||||
flags+=("$tok")
|
||||
else
|
||||
patterns+=("$tok")
|
||||
fi
|
||||
done
|
||||
|
||||
# validate & expand each pattern
|
||||
for pat in "${patterns[@]}"; do
|
||||
if [[ ! "$pat" =~ $valid ]]; then
|
||||
log ERROR "Invalid container name: '$pat'"
|
||||
shopt -u nullglob
|
||||
return 1
|
||||
fi
|
||||
containers+=("$pat")
|
||||
done
|
||||
|
||||
shopt -u nullglob
|
||||
|
||||
if ((${#containers[@]} == 0)); then
|
||||
log WARN "No containers matched: ${patterns[*]}"
|
||||
return 0
|
||||
fi
|
||||
|
||||
# pass flags *then* containers to podman rm
|
||||
podman rm "${flags[@]}" "${containers[@]}"
|
||||
}
|
||||
|
||||
# ─────────────────────────────────────────────
|
||||
# validate_command <cmd> [<tok1> <tok2> …]
|
||||
validate_command() {
|
||||
local cmd="$1"
|
||||
shift
|
||||
local tokens=("$@")
|
||||
local yaml="$HOME/access.yml"
|
||||
|
||||
# 1) Is command allowed at all?
|
||||
if [[ "$(yq e ".\"$PERSON\".commands | has(\"$cmd\")" "$yaml")" != "true" ]]; then
|
||||
log ERROR "Unauthorized command: '$cmd'"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# 2) Load allowed args for this cmd (may be empty array)
|
||||
mapfile -t allowed < <(yq e ".\"$PERSON\".commands.${cmd}[]" "$yaml")
|
||||
|
||||
if [[ "${#allowed[@]}" -eq 0 ]]; then
|
||||
log ERROR "No allowed arguments for command '$cmd' in $yaml"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# 3) Extract just the non-flag tokens
|
||||
local args=()
|
||||
for tok in "${tokens[@]}"; do
|
||||
[[ "$tok" == -* ]] && continue
|
||||
args+=("$tok")
|
||||
done
|
||||
|
||||
if [[ "$cmd" == "remove" ]]; then
|
||||
# ─ remove: must have at least one arg
|
||||
if ((${#args[@]} == 0)); then
|
||||
log ERROR "Command '$cmd' requires at least one argument: ${allowed[*]}"
|
||||
exit 1
|
||||
fi
|
||||
# Validate each against allowed[]
|
||||
for a in "${args[@]}"; do
|
||||
local ok=false
|
||||
for want in "${allowed[@]}"; do
|
||||
[[ "$a" == "$want" ]] && ok=true && break
|
||||
done
|
||||
if ! $ok; then
|
||||
log ERROR "Invalid argument '$a' for '$cmd'; allowed: ${allowed[*]}"
|
||||
exit 1
|
||||
fi
|
||||
done
|
||||
else
|
||||
# ─ all other cmds: must have exactly one arg
|
||||
if ((${#args[@]} != 1)); then
|
||||
log ERROR "Command '$cmd' requires exactly one argument: ${allowed[*]}"
|
||||
exit 1
|
||||
fi
|
||||
# And that single arg must be allowed
|
||||
local a="${args[0]}"
|
||||
local ok=false
|
||||
for want in "${allowed[@]}"; do
|
||||
[[ "$a" == "$want" ]] && ok=true && break
|
||||
done
|
||||
if ! $ok; then
|
||||
log ERROR "Invalid argument '$a' for '$cmd'; allowed: ${allowed[*]}"
|
||||
exit 1
|
||||
fi
|
||||
fi
|
||||
}
|
||||
|
||||
# ─────────────────────────────────────────────
|
||||
# Entry & command parsing
|
||||
if [[ -z "${SSH_ORIGINAL_COMMAND:-}" ]]; then
|
||||
log ERROR "No SSH_ORIGINAL_COMMAND provided."
|
||||
exit 1
|
||||
fi
|
||||
|
||||
log INFO "SSH_ORIGINAL_COMMAND: $SSH_ORIGINAL_COMMAND"
|
||||
read -ra parts <<<"$SSH_ORIGINAL_COMMAND"
|
||||
cmd="${parts[0]}"
|
||||
args=("${parts[@]:1}")
|
||||
|
||||
validate_command "$cmd" "${args[@]}"
|
||||
|
||||
# ─────────────────────────────────────────────
|
||||
# Dispatch
|
||||
case "$cmd" in
|
||||
build)
|
||||
case "$args" in
|
||||
base)
|
||||
run build-base.sh
|
||||
;;
|
||||
workspace)
|
||||
run build-workspace.sh
|
||||
;;
|
||||
*)
|
||||
log error "Invalid arguments for build command: $args"
|
||||
;;
|
||||
case "${args[0]}" in
|
||||
base) run build-base.sh ;;
|
||||
workspace) run build-workspace.sh ;;
|
||||
*) log ERROR "build: invalid arg '${args[0]}'" ;;
|
||||
esac
|
||||
;;
|
||||
update)
|
||||
case "$args" in
|
||||
workspace)
|
||||
update build-workspace.sh .local/bin 500
|
||||
;;
|
||||
base)
|
||||
update build-base.sh .local/bin 500
|
||||
;;
|
||||
access)
|
||||
update access.yml . 400
|
||||
;;
|
||||
ssh_router)
|
||||
update ssh_router.sh .local/bin 500
|
||||
;;
|
||||
gitops_router)
|
||||
update gitops_router.sh .local/bin 500
|
||||
;;
|
||||
home_tar)
|
||||
update home.tar.gz . 500 media
|
||||
;;
|
||||
*)
|
||||
log error "Invalid arguments for update command: $args"
|
||||
;;
|
||||
case "${args[0]}" in
|
||||
base) update build-base.sh .local/bin 500 ;;
|
||||
workspace) update build-workspace.sh .local/bin 500 ;;
|
||||
access) update access.yml . 400 ;;
|
||||
ssh_router) update ssh_router.sh .local/bin 500 ;;
|
||||
gitops_router) update gitops_router.sh .local/bin 500 ;;
|
||||
home_tar) update home.tar.gz . 500 media ;;
|
||||
gitconfig) update gitconfig.template . 500 ;;
|
||||
*) log ERROR "update: invalid arg '${args[0]}'" ;;
|
||||
esac
|
||||
;;
|
||||
clean)
|
||||
clean_images
|
||||
;;
|
||||
status)
|
||||
podman images
|
||||
;;
|
||||
remove)
|
||||
podman rm "$args"
|
||||
;;
|
||||
clean) clean_images ;;
|
||||
status) podman images ;;
|
||||
remove) remove_containers "${args[@]}" ;;
|
||||
*)
|
||||
log error "Unknown command: $command"
|
||||
log ERROR "Unknown command: '$cmd'"
|
||||
exit 127
|
||||
;;
|
||||
esac
|
||||
|
257
ssh_router.sh
257
ssh_router.sh
@ -1,187 +1,208 @@
|
||||
#!/bin/bash
|
||||
#!/usr/bin/env bash
|
||||
set -euo pipefail
|
||||
|
||||
PERSON="$1"
|
||||
WORKSPACE="$SSH_ORIGINAL_COMMAND"
|
||||
PERSON="${1:?Usage: $0 <person>}"
|
||||
WORKSPACE="${SSH_ORIGINAL_COMMAND:-}"
|
||||
IMAGE="localhost/analytics-backend-workspace:latest"
|
||||
DEV_USER="devuser"
|
||||
|
||||
XDG_RUNTIME_DIR="/run/user/$(id -u)"
|
||||
LOG_FILE="/tmp/.ssh-router-${PERSON}.log"
|
||||
|
||||
# ─────────────────────────────────────────────
|
||||
# ANSI colors & emojis
|
||||
readonly C_RESET='\033[0m'
|
||||
readonly C_INFO='\033[1;34m' # blue
|
||||
readonly C_WARN='\033[1;33m' # yellow
|
||||
readonly C_ERROR='\033[1;31m' # red
|
||||
|
||||
log() {
|
||||
echo "[$(date '+%Y-%m-%d %H:%M:%S')] $*" >>"$LOG_FILE"
|
||||
local level="${1^^}"
|
||||
shift
|
||||
local icon color
|
||||
case "$level" in
|
||||
INFO) icon="ℹ️" color="$C_INFO" ;;
|
||||
WARN) icon="⚠️" color="$C_WARN" ;;
|
||||
ERROR) icon="❌" color="$C_ERROR" ;;
|
||||
*) icon="🔹" color="$C_RESET" ;;
|
||||
esac
|
||||
local ts
|
||||
ts="$(date '+%Y-%m-%d %H:%M:%S')"
|
||||
printf '%b%s [%s] %s%b\n' \
|
||||
"$color" "$icon" "$ts" "[$level] $*" "$C_RESET" |
|
||||
tee -a "$LOG_FILE"
|
||||
}
|
||||
|
||||
# ─────────────────────────────────────────────
|
||||
# Check for interactive TTY
|
||||
if [[ ! -t 0 ]]; then
|
||||
log "❌ No TTY allocated — refusing to run tmux without an interactive terminal"
|
||||
log ERROR "No TTY allocated—refusing to run without an interactive terminal"
|
||||
echo "Error: No TTY. Use 'ssh -t'" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# log "🧩 IMAGE = '$IMAGE'"
|
||||
# log "🧩 WORKSPACE = '$WORKSPACE'"
|
||||
# log "🧩 PERSON = '$PERSON'"
|
||||
|
||||
# Fallbacks
|
||||
if [[ -z "${WORKSPACE:-}" ]]; then
|
||||
# ─────────────────────────────────────────────
|
||||
# Default WORKSPACE if empty
|
||||
if [[ -z "$WORKSPACE" ]]; then
|
||||
WORKSPACE="$PERSON"
|
||||
log "ℹ️ Defaulted WORKSPACE to $WORKSPACE"
|
||||
log INFO "Defaulted WORKSPACE → $WORKSPACE"
|
||||
fi
|
||||
TMUX_SESSION="${WORKSPACE}|analytics-backend"
|
||||
|
||||
TMUX_SESSION="$WORKSPACE|analytics-backend"
|
||||
|
||||
# Start podman socket service if it's not running
|
||||
if [[ ! -S "$XDG_RUNTIME_DIR/podman/podman.sock" ]]; then
|
||||
log "🔄 Starting Podman socket service for user $USER"
|
||||
systemctl --user start podman.socket || {
|
||||
log "❌ Failed to start podman.socket via systemd"
|
||||
# ─────────────────────────────────────────────
|
||||
# Ensure Podman socket is up
|
||||
ensure_podman() {
|
||||
local sock="$XDG_RUNTIME_DIR/podman/podman.sock"
|
||||
if [[ ! -S "$sock" ]]; then
|
||||
log INFO "Starting podman.socket for user $(id -un)"
|
||||
systemctl --user start podman.socket || {
|
||||
log ERROR "Failed to start podman.socket"
|
||||
exit 1
|
||||
}
|
||||
sleep 1
|
||||
fi
|
||||
[[ -S "$sock" ]] || {
|
||||
log ERROR "Podman socket still missing"
|
||||
exit 1
|
||||
}
|
||||
}
|
||||
ensure_podman
|
||||
|
||||
# Wait briefly for socket to appear
|
||||
sleep 1
|
||||
fi
|
||||
|
||||
if [[ ! -S "$XDG_RUNTIME_DIR/podman/podman.sock" ]]; then
|
||||
log "❌ Podman socket still missing after startup attempt"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Check if image exists locally
|
||||
if ! podman image exists "$IMAGE"; then
|
||||
log "📦 Image $IMAGE not found locally. Pulling from registry..."
|
||||
|
||||
# Attempt to pull the image from the local registry (insecure HTTP)
|
||||
if ! podman pull --tls-verify=false "$IMAGE"; then
|
||||
log "❌ Failed to pull image from $IMAGE"
|
||||
exit 1
|
||||
# ─────────────────────────────────────────────
|
||||
# Ensure IMAGE is present
|
||||
ensure_image() {
|
||||
if ! podman image exists "$IMAGE"; then
|
||||
log WARN "Image $IMAGE not found—pulling"
|
||||
podman pull --tls-verify=false "$IMAGE" || {
|
||||
log ERROR "Failed to pull $IMAGE"
|
||||
exit 1
|
||||
}
|
||||
log INFO "Pulled $IMAGE"
|
||||
fi
|
||||
}
|
||||
ensure_image
|
||||
|
||||
log "✅ Successfully pulled $IMAGE"
|
||||
fi
|
||||
|
||||
# ─────────────────────────────────────────────
|
||||
# Disallow file transfers
|
||||
case "$SSH_ORIGINAL_COMMAND" in
|
||||
*scp* | *sftp* | *rsync* | *tar*)
|
||||
log "❌ File transfers are disabled"
|
||||
log ERROR "File transfers are disabled"
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
|
||||
# Function to start the container if not running
|
||||
# ─────────────────────────────────────────────
|
||||
# Generate per-user gitconfig
|
||||
generate_gitconfig() {
|
||||
local access="$HOME/access.yml"
|
||||
local template="$HOME/gitconfig.template"
|
||||
local userdir="$HOME/secrets/$PERSON"
|
||||
local name email
|
||||
|
||||
name=$(yq -r ".\"$PERSON\".name" "$access" 2>/dev/null || echo)
|
||||
email=$(yq -r ".\"$PERSON\".email" "$access" 2>/dev/null || echo)
|
||||
|
||||
if [[ -z "$name" || -z "$email" ]]; then
|
||||
log ERROR "Missing name/email for '$PERSON' in $access"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
mkdir -p "$userdir"
|
||||
GIT_NAME="$name" GIT_EMAIL="$email" \
|
||||
envsubst <"$template" >"$userdir/gitconfig"
|
||||
log INFO ".gitconfig created → $userdir/gitconfig"
|
||||
}
|
||||
|
||||
# ─────────────────────────────────────────────
|
||||
# Start container if absent or stopped
|
||||
start_container_if_needed() {
|
||||
if ! podman container exists "$WORKSPACE"; then
|
||||
log "🚀 Creating container $WORKSPACE..."
|
||||
log INFO "Creating container '$WORKSPACE'"
|
||||
generate_gitconfig
|
||||
podman run -dit \
|
||||
--userns=keep-id \
|
||||
--name "$WORKSPACE" \
|
||||
--userns=keep-id \
|
||||
--user "$DEV_USER" \
|
||||
--hostname "$WORKSPACE" \
|
||||
--label auto-cleanup=true \
|
||||
-v "${XDG_RUNTIME_DIR}"/podman/podman.sock:/run/podman/podman.sock \
|
||||
-v /home/infilytics/data/"$WORKSPACE":/app \
|
||||
-v /home/infilytics/secrets/"$WORKSPACE"/gitconfig:/home/"$DEV_USER"/.gitconfig:ro \
|
||||
-v /home/infilytics/secrets/"$WORKSPACE"/id_ed25519:/home/"$DEV_USER"/.ssh/id_ed25519:ro \
|
||||
-v /home/infilytics/secrets/"$WORKSPACE"/id_ed25519.pub:/home/"$DEV_USER"/.ssh/id_ed25519.pub:ro \
|
||||
-v "$HOME/data/$WORKSPACE:/app:Z" \
|
||||
-v "$HOME/secrets/$WORKSPACE/gitconfig:/home/$DEV_USER/.gitconfig:ro,Z" \
|
||||
-v "$HOME/secrets/$WORKSPACE/id_ed25519:/home/$DEV_USER/.ssh/id_ed25519:ro,Z" \
|
||||
-v "$HOME/secrets/$WORKSPACE/id_ed25519.pub:/home/$DEV_USER/.ssh/id_ed25519.pub:ro,Z" \
|
||||
--entrypoint "/home/$DEV_USER/start.sh" \
|
||||
"$IMAGE" "${TMUX_SESSION}"
|
||||
"$IMAGE" "$TMUX_SESSION"
|
||||
elif ! podman inspect -f '{{.State.Running}}' "$WORKSPACE" | grep -q true; then
|
||||
log "⚡ Starting existing container $WORKSPACE..."
|
||||
podman start "$WORKSPACE" >/dev/null 2>&1
|
||||
log INFO "Starting existing container '$WORKSPACE'"
|
||||
podman start "$WORKSPACE" >/dev/null
|
||||
fi
|
||||
sleep 1
|
||||
}
|
||||
|
||||
# After devuser exits...
|
||||
# ─────────────────────────────────────────────
|
||||
# Detach logic: stop container when devuser has left
|
||||
check_devuser_attached() {
|
||||
# Get list of clients
|
||||
client_users=$(podman exec "$WORKSPACE" tmux list-clients -t "$TMUX_SESSION" -F "#{client_user}" 2>/dev/null)
|
||||
|
||||
if echo "$client_users" | grep -q "$DEV_USER"; then
|
||||
log "💡 devuser still attached — container stays running"
|
||||
return 0
|
||||
local clients
|
||||
clients=$(podman exec "$WORKSPACE" tmux list-clients -t "$TMUX_SESSION" -F "#{client_user}" 2>/dev/null)
|
||||
if grep -q "^${DEV_USER}\$" <<<"$clients"; then
|
||||
log INFO "devuser still attached—keeping container running"
|
||||
else
|
||||
log "🏃 $PERSON has logged out — stopping container"
|
||||
podman stop "$WORKSPACE" >/dev/null 2>&1
|
||||
return 1
|
||||
log INFO "devuser detached—stopping container"
|
||||
podman stop "$WORKSPACE" >/dev/null
|
||||
fi
|
||||
}
|
||||
|
||||
# ─────────────────────────────────────────────
|
||||
# Determine access mode (rw|ro) or exit
|
||||
get_access_mode() {
|
||||
local yaml_file="access.yml"
|
||||
local workspace="$1"
|
||||
local person="$2"
|
||||
|
||||
if [[ ! "$workspace" =~ ^[a-zA-Z0-9._-]+$ ]]; then
|
||||
log "❌ Invalid container name: $WORKSPACE"
|
||||
local yaml="access.yml" user="$PERSON" ws="$WORKSPACE"
|
||||
[[ ! "$ws" =~ ^[A-Za-z0-9._-]+$ ]] && {
|
||||
log ERROR "Invalid workspace name"
|
||||
exit 1
|
||||
}
|
||||
if [[ "$user" == "$ws" ]]; then
|
||||
echo rw
|
||||
elif yq -e '.["'"$user"'"].rw[]?' "$yaml" | grep -qx "$ws"; then
|
||||
echo rw
|
||||
elif yq -e '.["'"$user"'"].ro[]?' "$yaml" | grep -qx "$ws"; then
|
||||
echo ro
|
||||
else
|
||||
log ERROR "$user has no access to $ws"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Special case: user accessing their own workspace
|
||||
if [[ "$workspace" == "$person" ]]; then
|
||||
echo "access=rw"
|
||||
return 0
|
||||
fi
|
||||
|
||||
# Check rw
|
||||
if yq '.["'"$person"'"].rw // []' "$yaml_file" | grep -q "\b$workspace\b"; then
|
||||
echo "access=rw"
|
||||
return 0
|
||||
fi
|
||||
|
||||
# Check ro
|
||||
if yq '.["'"$person"'"].ro // []' "$yaml_file" | grep -q "\b$workspace\b"; then
|
||||
echo "access=ro"
|
||||
return 0
|
||||
fi
|
||||
|
||||
# No access → exit with error
|
||||
log "❌ $person has no access to $workspace" >&2
|
||||
exit 1
|
||||
}
|
||||
|
||||
# === Main ===
|
||||
|
||||
read -r access_line < <(get_access_mode "$WORKSPACE" "$PERSON") || exit 1
|
||||
MODE="${access_line#access=}"
|
||||
MODE="$(get_access_mode)"
|
||||
|
||||
# ─────────────────────────────────────────────
|
||||
# Main dispatch
|
||||
case "$MODE" in
|
||||
rw)
|
||||
start_container_if_needed
|
||||
|
||||
# Run tmux session inside the container
|
||||
if ! podman exec -it --user "$DEV_USER" "$WORKSPACE" tmux has-session -t "$TMUX_SESSION" >/dev/null 2>&1; then
|
||||
if ! podman exec -it -e EDITOR=nvim --user "$DEV_USER" "$WORKSPACE" tmux new-session -d -s "$TMUX_SESSION" >/dev/null 2>&1; then
|
||||
log "❌ Could not create new tmux session. Please contact admin or try again later."
|
||||
exit 1
|
||||
fi
|
||||
# Ensure tmux session exists
|
||||
if ! podman exec -it --user "$DEV_USER" "$WORKSPACE" tmux has-session -t "$TMUX_SESSION" 2>/dev/null; then
|
||||
podman exec -it --user "$DEV_USER" "$WORKSPACE" \
|
||||
tmux new-session -d -s "$TMUX_SESSION"
|
||||
fi
|
||||
|
||||
log "⚡ $PERSON is working on $WORKSPACE's workspace"
|
||||
if ! podman exec -it -e TERM="$TERM" --user "$DEV_USER" "$WORKSPACE" tmux attach -t "$TMUX_SESSION"; then
|
||||
log "❌ Could not attach to tmux session. Please contact admin or try again later."
|
||||
exit 1
|
||||
fi
|
||||
log "⚡ $PERSON finished working on $WORKSPACE's worksapce"
|
||||
|
||||
log INFO "$PERSON attaching to workspace '$WORKSPACE'"
|
||||
podman exec -it -e TERM="$TERM" --user "$DEV_USER" "$WORKSPACE" \
|
||||
tmux attach -t "$TMUX_SESSION"
|
||||
log INFO "$PERSON detached from '$WORKSPACE'"
|
||||
check_devuser_attached
|
||||
exit 0
|
||||
;;
|
||||
ro)
|
||||
if (podman container exists "$WORKSPACE" && podman inspect -f '{{.State.Running}}' "$WORKSPACE" | grep -q true) >/dev/null 2>&1; then
|
||||
log "📜 $PERSON is viewing $WORKSPACE's workspace"
|
||||
if ! podman exec -it -e TERM="$TERM" --user "$DEV_USER" "$WORKSPACE" tmux attach -r -t "$TMUX_SESSION"; then
|
||||
log "❌ Could not attach to tmux session. Please contact admin or try again later."
|
||||
exit 1
|
||||
fi
|
||||
log "🏃 $PERSON stopped viewing $WORKSPACE's workspace"
|
||||
exit 0
|
||||
if podman inspect -f '{{.State.Running}}' "$WORKSPACE" 2>/dev/null | grep -q true; then
|
||||
log INFO "$PERSON viewing workspace '$WORKSPACE'"
|
||||
podman exec -it -e TERM="$TERM" --user "$DEV_USER" "$WORKSPACE" \
|
||||
tmux attach -r -t "$TMUX_SESSION"
|
||||
log INFO "$PERSON stopped viewing '$WORKSPACE'"
|
||||
else
|
||||
log "❌ Workspace for $WORKSPACE does not exist."
|
||||
log ERROR "Workspace '$WORKSPACE' is not running"
|
||||
exit 1
|
||||
fi
|
||||
;;
|
||||
*)
|
||||
log "❌ Invalid access mode: $MODE"
|
||||
log ERROR "Unknown access mode: '$MODE'"
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
|
Reference in New Issue
Block a user