Compare commits

..

16 Commits

Author SHA1 Message Date
f8b38996df feat: add package go-yq to build image 2025-05-17 14:43:42 +00:00
d488a87dd4 feat: upgrade gitops ability to fetch files from different repos 2025-05-17 14:42:06 +00:00
3e361cd03c feat: separate access validation logic for gitops commands into a separate file 2025-05-17 14:38:56 +00:00
fd0c07e954 feat: remove buildah scripts and adapt project to use Containerfile 2025-05-17 13:21:36 +00:00
d3f5e93ad8 feat: add containerfile for our builds 2025-05-17 13:12:00 +00:00
c9460b8ebc chore: update command access for pallav 2025-05-17 11:37:50 +00:00
9629c3253e fix: validate commands, improve remove container logic, standardize logs in gitops router 2025-05-17 11:37:06 +00:00
6e11d19510 feat: update authorized_keys file 2025-05-17 10:04:00 +00:00
a4bfe5a5c0 feat: use %h instead of hard coded paths in authorized_keys 2025-05-17 09:44:31 +00:00
54a42ad4d5 fix: use $HOME variable in place of hard coded path values 2025-05-17 09:39:07 +00:00
21eee8c3ec feat: remove access to host podman socket 2025-05-17 09:35:48 +00:00
ff72c95012 style: beatify and optimize ssh router with chatgpt 2025-05-17 09:21:48 +00:00
3576bf93c2 style: beautify and optimize gitops router with chatgpt 2025-05-17 09:15:50 +00:00
d7c7686a9e feat: generate gitconfig on the fly before creating container 2025-05-17 09:04:26 +00:00
a179a3ad23 chore: add task to copy gitconfig.template 2025-05-17 09:02:58 +00:00
56744155cb feat: add gitops function to update gitconfig template 2025-05-17 08:59:58 +00:00
8 changed files with 372 additions and 254 deletions

8
.vscode/tasks.json vendored
View File

@ -72,6 +72,14 @@
"problemMatcher": [], "problemMatcher": [],
"detail": "Copy home.tar.gz to /home/infilytics/" "detail": "Copy home.tar.gz to /home/infilytics/"
}, },
{
"label": "GitOps(Update): gitconfig.template",
"type": "shell",
"command": ".bin/gitops update gitconfig",
"group": "build",
"problemMatcher": [],
"detail": "Copy gitconfig.template to /home/infilytics/"
},
{ {
"label": "Create home tarball", "label": "Create home tarball",
"type": "shell", "type": "shell",

60
Containerfile Normal file
View File

@ -0,0 +1,60 @@
# ───────────────────
# Stage 1: Base Image
# ───────────────────
FROM archlinux:base-devel-20250511.0.348143 as base
ARG DEV_USER=devuser
ARG DEV_UID=1001
ARG DEV_GID=1001
# Install all necessary packages and clean up cache
RUN pacman -Sy --noconfirm && \
pacman -S --noconfirm --needed \
base-devel neovim git git-lfs fish tmux go-yq \
nodejs python podman fzf fd ripgrep jdk-openjdk fisher yazi less \
lazygit luarocks python-pynvim npm bash-completion tree-sitter-cli kitty-terminfo \
lua51 openssh && \
pacman -Scc --noconfirm && \
rm -rf /var/cache/pacman/pkg/*
# Create user/groups as per your script, with -l to avoid system user quirks
RUN groupadd -g $DEV_GID $DEV_USER && \
groupadd -g 1002 secproc && \
useradd -l -ms /bin/fish -G secproc -u $DEV_UID -g $DEV_GID $DEV_USER
# ────────────────────────
# Stage 2: Workspace Image
# ────────────────────────
FROM base as workspace
ARG DEV_USER=devuser
ARG DEV_UID=1001
ARG DEV_GID=1001
ARG DEV_HOME=/home/$DEV_USER
# Use ADD for extracting archives
ADD home.tar.gz $DEV_HOME
# Prepare .ssh and known_hosts, and fix permissions only if dirs exist
RUN mkdir -p $DEV_HOME/.ssh && \
ssh-keyscan -p 2222 10.88.0.1 >> $DEV_HOME/.ssh/known_hosts && \
ssh-keyscan -p 22 github.com >> $DEV_HOME/.ssh/known_hosts && \
for d in $DEV_HOME/.local \
$DEV_HOME/.config/fish/completions \
$DEV_HOME/.config/fish/functions \
$DEV_HOME/.config/fish/fish_variables \
$DEV_HOME/.ssh; do \
if [ -e "$d" ]; then chown -R $DEV_USER:$DEV_USER "$d"; fi; \
done && \
for d in $DEV_HOME/.local \
$DEV_HOME/.config \
$DEV_HOME/.config/fish \
$DEV_HOME/.config/tmux; do \
if [ -e "$d" ]; then chown $DEV_USER:$DEV_USER "$d"; fi; \
done
WORKDIR /app
ENV CONTAINER_HOST=unix:///run/podman/podman.sock
USER $DEV_USER
CMD ["/home/devuser/start.sh"]

View File

@ -1,6 +1,24 @@
pallav: pallav:
name: Pallav Vasa name: Pallav Vasa
email: pallav@infilytics.in email: pallav@infilytics.in
commands:
build:
- base
- workspace
- all
update:
- access
- ssh_router
- gitops_router
- home_tar
- gitconfig
- containerfile
clean:
status:
remove:
- palak
- param
- darshan
rw: rw:
- darshan - darshan
- param - param

View File

@ -1 +1,5 @@
command="/home/infilytics/ssh_router.sh pallav",no-port-forwarding,no-agent-forwarding,no-X11-forwarding ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIK0il/OJiXygyPWYBt05+OQYjJPxgGuP3kP9hLsD/C7x phoenix@sphinx command="cd %h && ./local/bin/ssh_router.sh pallav",no-port-forwarding,no-agent-forwarding,no-X11-forwarding ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIK0il/OJiXygyPWYBt05+OQYjJPxgGuP3kP9hLsD/C7x phoenix@sphinx
command="cd %h && ./local/bin/ssh_router.sh pallav",no-port-forwarding,no-agent-forwarding,no-X11-forwarding ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIArjJAFfhq8LFJX0aqlhUbUNDglmshEJVeLbfXgdo2mU palla@Sphinx
command="cd %h && ./local/bin/ssh_router.sh param",no-port-forwarding,no-agent-forwarding,no-X11-forwarding ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDo3+p2DNLONpS2xsw5bSSrB+OA3a+MZqK29c0AutP63R8iDsrzFnea+Zz4L1Lcl8gFoPft3iL0ASYNeVZBHosQVL4lJc1qk/V6kD1h72oPZHNWBboZN1TKAG023L81if6xeIZu9x8Fzc/LWp487PHsjrI0wvK1ngqKwXiD1hUfIg3fjJMENx4TzFllaG4TA6Kd35rAes6exHwauC+9UALTz1Hns891S8j8j1Mlv52Ujadkc49jFcmsiWMBgGjZo3SnDANFqp9LPcCWNNI7W3H9oQ1A6jxmMf0sQN8i2Xks8mNEPzr41VJksq7WPWlclXLVH6ME+ZVR2gsQGnaz7WhA8oaG9q/2SPJRbluZG15GWsUPZ/fOEPZgU+eFwV8MThQzFY2N495S+L1zyeUDYJtfTMDkjCCzT0Rnd0Pv/afGnmz8AfbmO4+o8aTAUpvHZEibqIWzAuC6gruFKYQQEjr8Jev7kfDaWBCVtLaWII965HFtwUtmGql/1tXyixOiAes= param@param
command="cd %h && ./local/bin/ssh_router.sh palak",no-port-forwarding,no-agent-forwarding,no-X14-forwarding ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINNwPgVHczFkb32aW/bNS6XMLKh3YXNUoKHXYdtj5X5B infilytics\palak@Palakv
command="cd %h && ./local/bin/gitops_router.sh pallav",no-port-forwarding,no-agent-forwarding,no-X11-forwarding ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEcfbbXNTsoXO+tNwYFsFbz/qkvv5OWH1/TNHaKJb0r3 "pallav@infilytics.in"

View File

@ -1,24 +0,0 @@
#!/bin/bash
set -euo pipefail
BASE_IMG_NAME="analytics-backend-base"
DEV_USER=devuser
DEV_UID=1001
DEV_GID=1001
ctr=$(buildah from archlinux)
buildah run "$ctr" -- bash -c "
pacman -Sy --noconfirm && \
pacman -S --noconfirm --needed base-devel neovim git git-lfs fish tmux \
nodejs python podman fzf fd ripgrep jdk-openjdk fisher yazi less buildah \
lazygit luarocks python-pynvim npm bash-completion tree-sitter-cli kitty-terminfo \
lua51 openssh && \
pacman -Scc --noconfirm && \
groupadd -g $DEV_GID $DEV_USER && \
groupadd -g 1002 secproc && \
useradd -ms /bin/fish -G secproc -u $DEV_UID -g $DEV_GID $DEV_USER
"
buildah commit "$ctr" $BASE_IMG_NAME
echo "$BASE_IMG_NAME built."

View File

@ -1,32 +0,0 @@
#!/bin/bash
set -euo pipefail
BASE_IMG_NAME="analytics-backend-base"
IMG_NAME="analytics-backend-workspace"
DEV_USER=devuser
DEV_HOME=/home/$DEV_USER
ctr=$(buildah from "$BASE_IMG_NAME")
buildah add "$ctr" home.tar.gz $DEV_HOME
# shellcheck disable=SC2016
buildah run "$ctr" -- fish -c '
set -gx HOME '"$DEV_HOME"';
ssh-keyscan -p 2222 10.88.0.1 >> $HOME/.ssh/known_hosts;
ssh-keyscan -p 22 github.com >> $HOME/.ssh/known_hosts;
chown -R '"$DEV_USER"':'"$DEV_USER"' $HOME/.local $HOME/.config/fish/completions \
$HOME/.config/fish/functions $HOME/.config/fish/fish_variables $HOME/.ssh;
chown '"$DEV_USER"':'"$DEV_USER"' $HOME/.config $HOME/.config/fish \
$HOME/.config/tmux;
'
buildah config \
--user $DEV_USER \
--workingdir /app \
--env CONTAINER_HOST=unix:///run/podman/podman.sock \
--cmd "[\"$DEV_HOME/start.sh\"]" \
"$ctr"
buildah commit "$ctr" $IMG_NAME
echo "$IMG_NAME built from $BASE_IMG_NAME."

View File

@ -1,114 +1,177 @@
#!/usr/bin/env bash #!/usr/bin/env bash
set -euo pipefail set -euo pipefail
PERSON="$1" PERSON="${1:?Missing PERSON argument}"
HOST="alps:3222" HOST="alps:3222"
PROTOCOL="http" PROTOCOL="http"
REPO="babbarc/workspaces" REPO=("babbarc/workspaces" "babbarc/workspaces-sec-alps-infilytics")
BRANCH="master" BRANCH="master"
LOG_FILE="/tmp/.gitops-router-${PERSON}.log" LOG_FILE="/tmp/.gitops-router-${PERSON}.log"
# ─────────────────────────────────────────────
# ANSI color codes
readonly C_RESET='\033[0m'
readonly C_INFO='\033[1;34m' # bold blue
readonly C_WARN='\033[1;33m' # bold yellow
readonly C_ERROR='\033[1;31m' # bold red
# ─────────────────────────────────────────────
# log <level> <message...> with emojis
log() { log() {
local level="${1^^}" # convert to uppercase local lvl="${1^^}"
shift shift
echo "[$(date '+%Y-%m-%d %H:%M:%S')] [$level] $*" | tee -a "$LOG_FILE" local icon color
case "$lvl" in
INFO) icon="" color="$C_INFO" ;;
WARN) icon="⚠️" color="$C_WARN" ;;
ERROR) icon="❌" color="$C_ERROR" ;;
*) icon="🔹" color="$C_RESET" ;;
esac
local ts
ts="$(date '+%Y-%m-%d %H:%M:%S')"
printf '%b%s [%s] [%s] %s%b\n' \
"$color" "$icon" "$ts" "$lvl" "$*" "$C_RESET" |
tee -a "$LOG_FILE"
} }
log info "Received SSH_ORIGINAL_COMMAND: $SSH_ORIGINAL_COMMAND" # ─────────────────────────────────────────────
# Build the raw URL for fetching files
geturl() {
local repo="$1" type="$2" file="$3"
printf '%s://%s/%s/%s/branch/%s/%s\n' \
"$PROTOCOL" "$HOST" "${REPO[$repo]}" "$type" "$BRANCH" "$file"
}
# Ensure the variable is set # ─────────────────────────────────────────────
# Run a local script
run() {
local script="$1"
"$HOME/.local/bin/$script"
}
# ─────────────────────────────────────────────
# Download & install an artifact
# update <repo> <file> <target-dir> <mode> [<type>]
update() {
local repo="$1" file="$2" dir="$3" mode="$4" type="${5:-raw}"
local url out
out="$HOME/$dir/$(basename "$file")"
url="$(geturl "$repo" "$type" "$file")"
[[ -f "$out" ]] && chmod 700 "$out"
if curl -fsSL "$url" -o "$out"; then
log INFO "Downloaded $url$out"
chmod "$mode" "$out"
else
log ERROR "Failed to download $url"
return 1
fi
}
# ─────────────────────────────────────────────
# Clean up dangling podman images
clean_images() {
local dangling
dangling="$(podman images -f dangling=true -q)"
if [[ -z "$dangling" ]]; then
log INFO "No dangling images to remove."
else
log WARN "Removing dangling images..."
echo "$dangling" | xargs podman rmi
log INFO "Dangling images removed."
fi
}
# ─────────────────────────────────────────────
# Remove host podman containers
remove_containers() {
local tokens=("$@")
local flags=() patterns=() containers=()
local valid='^[A-Za-z0-9._-]+$'
# allow unmatched globs to disappear
shopt -s nullglob
# separate flags (-f, etc.) from name patterns
for tok in "${tokens[@]}"; do
if [[ "$tok" == -* ]]; then
flags+=("$tok")
else
patterns+=("$tok")
fi
done
# validate & expand each pattern
for pat in "${patterns[@]}"; do
if [[ ! "$pat" =~ $valid ]]; then
log ERROR "Invalid container name: '$pat'"
shopt -u nullglob
return 1
fi
containers+=("$pat")
done
shopt -u nullglob
if ((${#containers[@]} == 0)); then
log WARN "No containers matched: ${patterns[*]}"
return 0
fi
# pass flags *then* containers to podman rm
podman rm "${flags[@]}" "${containers[@]}"
}
# ─────────────────────────────────────────────
# validate_command <workspace> <cmd> [<tok1> <tok2> …]
source "$HOME"/.local/bin/validate_command_access.sh
# ─────────────────────────────────────────────
# Entry & command parsing
if [[ -z "${SSH_ORIGINAL_COMMAND:-}" ]]; then if [[ -z "${SSH_ORIGINAL_COMMAND:-}" ]]; then
log error "No SSH_ORIGINAL_COMMAND provided." log ERROR "No SSH_ORIGINAL_COMMAND provided."
exit 1 exit 1
fi fi
geturl() { log INFO "SSH_ORIGINAL_COMMAND: $SSH_ORIGINAL_COMMAND"
echo "$PROTOCOL://$HOST/$REPO/$1/branch/$BRANCH/$2" read -ra parts <<<"$SSH_ORIGINAL_COMMAND"
} cmd="${parts[0]}"
args=("${parts[@]:1}")
function run() { validate_command "$PERSON" "$cmd" "${args[@]}"
"$HOME"/.local/bin/"$1"
}
function update() { # ─────────────────────────────────────────────
type=${4:-raw} # Dispatch
fname=$(basename "$1") case "$cmd" in
output_path="$HOME/$2/$fname"
url=$(geturl "$type" "$1")
[ -f "$output_path" ] && chmod 700 "$output_path"
curl -fsSL "$url" -o "$output_path" && log info "Downloaded $url to $output_path"
chmod "$3" "$output_path"
}
clean_images() {
# Get list of image IDs with <none> tag (dangling images)
dangling_images=$(podman images -f "dangling=true" -q)
if [ -z "$dangling_images" ]; then
echo "✅ No dangling images to remove."
else
echo "⚠️ Removing dangling images..."
echo "$dangling_images" | xargs podman rmi
echo "🧹 Done!"
fi
}
# Strip arguments and parse command
read -r command args <<<"$SSH_ORIGINAL_COMMAND"
# Define command routing
case "$command" in
build) build)
case "$args" in case "${args[0]}" in
base) base) podman build --target base -t analytics-backend-base . ;;
run build-base.sh workspace) podman build --target base -t analytics-backend-base . ;;
;; all) podman build -t analytics-backend-workspace . ;;
workspace) *) log ERROR "build: invalid arg '${args[0]}'" ;;
run build-workspace.sh
;;
*)
log error "Invalid arguments for build command: $args"
;;
esac esac
;; ;;
update) update)
case "$args" in case "${args[0]}" in
workspace) containerfile) update 0 Containerfile . 500 ;;
update build-workspace.sh .local/bin 500 access) update 1 access.yml . 400 ;;
;; ssh_router) update 0 ssh_router.sh .local/bin 500 ;;
base) gitops_router) update 0 gitops_router.sh .local/bin 500 ;;
update build-base.sh .local/bin 500 validate_command) update 1 validate_command_access.sh .local/bin 500 ;;
;; home_tar) update 0 home.tar.gz . 500 media ;;
access) gitconfig) update 1 gitconfig.template . 500 ;;
update access.yml . 400 *) log ERROR "update: invalid arg '${args[0]}'" ;;
;;
ssh_router)
update ssh_router.sh .local/bin 500
;;
gitops_router)
update gitops_router.sh .local/bin 500
;;
home_tar)
update home.tar.gz . 500 media
;;
*)
log error "Invalid arguments for update command: $args"
;;
esac esac
;; ;;
clean) clean) clean_images ;;
clean_images status) podman images ;;
;; remove) remove_containers "${args[@]}" ;;
status)
podman images
;;
remove)
podman rm "$args"
;;
*) *)
log error "Unknown command: $command" log ERROR "Unknown command: '$cmd'"
exit 127 exit 127
;; ;;
esac esac

View File

@ -1,187 +1,208 @@
#!/bin/bash #!/usr/bin/env bash
set -euo pipefail
PERSON="$1" PERSON="${1:?Usage: $0 <person>}"
WORKSPACE="$SSH_ORIGINAL_COMMAND" WORKSPACE="${SSH_ORIGINAL_COMMAND:-}"
IMAGE="localhost/analytics-backend-workspace:latest" IMAGE="localhost/analytics-backend-workspace:latest"
DEV_USER="devuser" DEV_USER="devuser"
XDG_RUNTIME_DIR="/run/user/$(id -u)" XDG_RUNTIME_DIR="/run/user/$(id -u)"
LOG_FILE="/tmp/.ssh-router-${PERSON}.log" LOG_FILE="/tmp/.ssh-router-${PERSON}.log"
# ─────────────────────────────────────────────
# ANSI colors & emojis
readonly C_RESET='\033[0m'
readonly C_INFO='\033[1;34m' # blue
readonly C_WARN='\033[1;33m' # yellow
readonly C_ERROR='\033[1;31m' # red
log() { log() {
echo "[$(date '+%Y-%m-%d %H:%M:%S')] $*" >>"$LOG_FILE" local level="${1^^}"
shift
local icon color
case "$level" in
INFO) icon="" color="$C_INFO" ;;
WARN) icon="⚠️" color="$C_WARN" ;;
ERROR) icon="❌" color="$C_ERROR" ;;
*) icon="🔹" color="$C_RESET" ;;
esac
local ts
ts="$(date '+%Y-%m-%d %H:%M:%S')"
printf '%b%s [%s] %s%b\n' \
"$color" "$icon" "$ts" "[$level] $*" "$C_RESET" |
tee -a "$LOG_FILE"
} }
# ─────────────────────────────────────────────
# Check for interactive TTY
if [[ ! -t 0 ]]; then if [[ ! -t 0 ]]; then
log "No TTY allocatedrefusing to run tmux without an interactive terminal" log ERROR "No TTY allocatedrefusing to run without an interactive terminal"
echo "Error: No TTY. Use 'ssh -t'" >&2 echo "Error: No TTY. Use 'ssh -t'" >&2
exit 1 exit 1
fi fi
# log "🧩 IMAGE = '$IMAGE'" # ─────────────────────────────────────────────
# log "🧩 WORKSPACE = '$WORKSPACE'" # Default WORKSPACE if empty
# log "🧩 PERSON = '$PERSON'" if [[ -z "$WORKSPACE" ]]; then
# Fallbacks
if [[ -z "${WORKSPACE:-}" ]]; then
WORKSPACE="$PERSON" WORKSPACE="$PERSON"
log " Defaulted WORKSPACE to $WORKSPACE" log INFO "Defaulted WORKSPACE $WORKSPACE"
fi fi
TMUX_SESSION="${WORKSPACE}|analytics-backend"
TMUX_SESSION="$WORKSPACE|analytics-backend" # ─────────────────────────────────────────────
# Ensure Podman socket is up
# Start podman socket service if it's not running ensure_podman() {
if [[ ! -S "$XDG_RUNTIME_DIR/podman/podman.sock" ]]; then local sock="$XDG_RUNTIME_DIR/podman/podman.sock"
log "🔄 Starting Podman socket service for user $USER" if [[ ! -S "$sock" ]]; then
log INFO "Starting podman.socket for user $(id -un)"
systemctl --user start podman.socket || { systemctl --user start podman.socket || {
log "Failed to start podman.socket via systemd" log ERROR "Failed to start podman.socket"
exit 1 exit 1
} }
# Wait briefly for socket to appear
sleep 1 sleep 1
fi fi
[[ -S "$sock" ]] || {
if [[ ! -S "$XDG_RUNTIME_DIR/podman/podman.sock" ]]; then log ERROR "Podman socket still missing"
log "❌ Podman socket still missing after startup attempt"
exit 1 exit 1
fi }
}
ensure_podman
# Check if image exists locally # ─────────────────────────────────────────────
# Ensure IMAGE is present
ensure_image() {
if ! podman image exists "$IMAGE"; then if ! podman image exists "$IMAGE"; then
log "📦 Image $IMAGE not found locally. Pulling from registry..." log WARN "Image $IMAGE not found—pulling"
podman pull --tls-verify=false "$IMAGE" || {
# Attempt to pull the image from the local registry (insecure HTTP) log ERROR "Failed to pull $IMAGE"
if ! podman pull --tls-verify=false "$IMAGE"; then
log "❌ Failed to pull image from $IMAGE"
exit 1 exit 1
}
log INFO "Pulled $IMAGE"
fi fi
}
ensure_image
log "✅ Successfully pulled $IMAGE" # ─────────────────────────────────────────────
fi # Disallow file transfers
case "$SSH_ORIGINAL_COMMAND" in case "$SSH_ORIGINAL_COMMAND" in
*scp* | *sftp* | *rsync* | *tar*) *scp* | *sftp* | *rsync* | *tar*)
log "File transfers are disabled" log ERROR "File transfers are disabled"
exit 1 exit 1
;; ;;
esac esac
# Function to start the container if not running # ─────────────────────────────────────────────
# Generate per-user gitconfig
generate_gitconfig() {
local access="$HOME/access.yml"
local template="$HOME/gitconfig.template"
local userdir="$HOME/secrets/$PERSON"
local name email
name=$(yq -r ".\"$PERSON\".name" "$access" 2>/dev/null || echo)
email=$(yq -r ".\"$PERSON\".email" "$access" 2>/dev/null || echo)
if [[ -z "$name" || -z "$email" ]]; then
log ERROR "Missing name/email for '$PERSON' in $access"
exit 1
fi
mkdir -p "$userdir"
GIT_NAME="$name" GIT_EMAIL="$email" \
envsubst <"$template" >"$userdir/gitconfig"
log INFO ".gitconfig created → $userdir/gitconfig"
}
# ─────────────────────────────────────────────
# Start container if absent or stopped
start_container_if_needed() { start_container_if_needed() {
if ! podman container exists "$WORKSPACE"; then if ! podman container exists "$WORKSPACE"; then
log "🚀 Creating container $WORKSPACE..." log INFO "Creating container '$WORKSPACE'"
generate_gitconfig
podman run -dit \ podman run -dit \
--userns=keep-id \
--name "$WORKSPACE" \ --name "$WORKSPACE" \
--userns=keep-id \
--user "$DEV_USER" \ --user "$DEV_USER" \
--hostname "$WORKSPACE" \ --hostname "$WORKSPACE" \
--label auto-cleanup=true \ --label auto-cleanup=true \
-v "${XDG_RUNTIME_DIR}"/podman/podman.sock:/run/podman/podman.sock \ -v "$HOME/data/$WORKSPACE:/app:Z" \
-v /home/infilytics/data/"$WORKSPACE":/app \ -v "$HOME/secrets/$WORKSPACE/gitconfig:/home/$DEV_USER/.gitconfig:ro,Z" \
-v /home/infilytics/secrets/"$WORKSPACE"/gitconfig:/home/"$DEV_USER"/.gitconfig:ro \ -v "$HOME/secrets/$WORKSPACE/id_ed25519:/home/$DEV_USER/.ssh/id_ed25519:ro,Z" \
-v /home/infilytics/secrets/"$WORKSPACE"/id_ed25519:/home/"$DEV_USER"/.ssh/id_ed25519:ro \ -v "$HOME/secrets/$WORKSPACE/id_ed25519.pub:/home/$DEV_USER/.ssh/id_ed25519.pub:ro,Z" \
-v /home/infilytics/secrets/"$WORKSPACE"/id_ed25519.pub:/home/"$DEV_USER"/.ssh/id_ed25519.pub:ro \
--entrypoint "/home/$DEV_USER/start.sh" \ --entrypoint "/home/$DEV_USER/start.sh" \
"$IMAGE" "${TMUX_SESSION}" "$IMAGE" "$TMUX_SESSION"
elif ! podman inspect -f '{{.State.Running}}' "$WORKSPACE" | grep -q true; then elif ! podman inspect -f '{{.State.Running}}' "$WORKSPACE" | grep -q true; then
log "Starting existing container $WORKSPACE..." log INFO "Starting existing container '$WORKSPACE'"
podman start "$WORKSPACE" >/dev/null 2>&1 podman start "$WORKSPACE" >/dev/null
fi fi
sleep 1 sleep 1
} }
# After devuser exits... # ─────────────────────────────────────────────
# Detach logic: stop container when devuser has left
check_devuser_attached() { check_devuser_attached() {
# Get list of clients local clients
client_users=$(podman exec "$WORKSPACE" tmux list-clients -t "$TMUX_SESSION" -F "#{client_user}" 2>/dev/null) clients=$(podman exec "$WORKSPACE" tmux list-clients -t "$TMUX_SESSION" -F "#{client_user}" 2>/dev/null)
if grep -q "^${DEV_USER}\$" <<<"$clients"; then
if echo "$client_users" | grep -q "$DEV_USER"; then log INFO "devuser still attached—keeping container running"
log "💡 devuser still attached — container stays running"
return 0
else else
log "🏃 $PERSON has logged out — stopping container" log INFO "devuser detached—stopping container"
podman stop "$WORKSPACE" >/dev/null 2>&1 podman stop "$WORKSPACE" >/dev/null
return 1
fi fi
} }
# ─────────────────────────────────────────────
# Determine access mode (rw|ro) or exit
get_access_mode() { get_access_mode() {
local yaml_file="access.yml" local yaml="access.yml" user="$PERSON" ws="$WORKSPACE"
local workspace="$1" [[ ! "$ws" =~ ^[A-Za-z0-9._-]+$ ]] && {
local person="$2" log ERROR "Invalid workspace name"
if [[ ! "$workspace" =~ ^[a-zA-Z0-9._-]+$ ]]; then
log "❌ Invalid container name: $WORKSPACE"
exit 1
fi
# Special case: user accessing their own workspace
if [[ "$workspace" == "$person" ]]; then
echo "access=rw"
return 0
fi
# Check rw
if yq '.["'"$person"'"].rw // []' "$yaml_file" | grep -q "\b$workspace\b"; then
echo "access=rw"
return 0
fi
# Check ro
if yq '.["'"$person"'"].ro // []' "$yaml_file" | grep -q "\b$workspace\b"; then
echo "access=ro"
return 0
fi
# No access → exit with error
log "$person has no access to $workspace" >&2
exit 1 exit 1
} }
if [[ "$user" == "$ws" ]]; then
echo rw
elif yq -e '.["'"$user"'"].rw[]?' "$yaml" | grep -qx "$ws"; then
echo rw
elif yq -e '.["'"$user"'"].ro[]?' "$yaml" | grep -qx "$ws"; then
echo ro
else
log ERROR "$user has no access to $ws"
exit 1
fi
}
# === Main === MODE="$(get_access_mode)"
read -r access_line < <(get_access_mode "$WORKSPACE" "$PERSON") || exit 1
MODE="${access_line#access=}"
# ─────────────────────────────────────────────
# Main dispatch
case "$MODE" in case "$MODE" in
rw) rw)
start_container_if_needed start_container_if_needed
# Run tmux session inside the container # Ensure tmux session exists
if ! podman exec -it --user "$DEV_USER" "$WORKSPACE" tmux has-session -t "$TMUX_SESSION" >/dev/null 2>&1; then if ! podman exec -it --user "$DEV_USER" "$WORKSPACE" tmux has-session -t "$TMUX_SESSION" 2>/dev/null; then
if ! podman exec -it -e EDITOR=nvim --user "$DEV_USER" "$WORKSPACE" tmux new-session -d -s "$TMUX_SESSION" >/dev/null 2>&1; then podman exec -it --user "$DEV_USER" "$WORKSPACE" \
log "❌ Could not create new tmux session. Please contact admin or try again later." tmux new-session -d -s "$TMUX_SESSION"
exit 1
fi
fi fi
log "$PERSON is working on $WORKSPACE's workspace" log INFO "$PERSON attaching to workspace '$WORKSPACE'"
if ! podman exec -it -e TERM="$TERM" --user "$DEV_USER" "$WORKSPACE" tmux attach -t "$TMUX_SESSION"; then podman exec -it -e TERM="$TERM" --user "$DEV_USER" "$WORKSPACE" \
log "❌ Could not attach to tmux session. Please contact admin or try again later." tmux attach -t "$TMUX_SESSION"
exit 1 log INFO "$PERSON detached from '$WORKSPACE'"
fi
log "$PERSON finished working on $WORKSPACE's worksapce"
check_devuser_attached check_devuser_attached
exit 0
;; ;;
ro) ro)
if (podman container exists "$WORKSPACE" && podman inspect -f '{{.State.Running}}' "$WORKSPACE" | grep -q true) >/dev/null 2>&1; then if podman inspect -f '{{.State.Running}}' "$WORKSPACE" 2>/dev/null | grep -q true; then
log "📜 $PERSON is viewing $WORKSPACE's workspace" log INFO "$PERSON viewing workspace '$WORKSPACE'"
if ! podman exec -it -e TERM="$TERM" --user "$DEV_USER" "$WORKSPACE" tmux attach -r -t "$TMUX_SESSION"; then podman exec -it -e TERM="$TERM" --user "$DEV_USER" "$WORKSPACE" \
log "❌ Could not attach to tmux session. Please contact admin or try again later." tmux attach -r -t "$TMUX_SESSION"
exit 1 log INFO "$PERSON stopped viewing '$WORKSPACE'"
fi
log "🏃 $PERSON stopped viewing $WORKSPACE's workspace"
exit 0
else else
log "Workspace for $WORKSPACE does not exist." log ERROR "Workspace '$WORKSPACE' is not running"
exit 1 exit 1
fi fi
;; ;;
*) *)
log "❌ Invalid access mode: $MODE" log ERROR "Unknown access mode: '$MODE'"
exit 1 exit 1
;; ;;
esac esac