workspaces/ssh_router.sh

94 lines
2.8 KiB
Bash
Raw Normal View History

#!/bin/bash
MODE="$1" # 'rw' or 'readonly'
CONTAINER="$SSH_ORIGINAL_COMMAND"
IMAGE="analytics-backend-workspace" # change to match your setup
TMUX_SESSION="analytics-backend"
DEV_USER="devuser"
TMUX_CMD=(tmux -S /tmp/tmux-shared/dev-socket)
log() {
echo "[$(date '+%Y-%m-%d %H:%M:%S')] $*"
}
if [[ ! "$CONTAINER" =~ ^[a-zA-Z0-9._-]+$ ]]; then
log "❌ Invalid container name: $CONTAINER"
exit 1
fi
# Function to start the container if not running
start_container_if_needed() {
if ! podman container exists "$CONTAINER"; then
log "🚀 Creating container $CONTAINER..."
podman run -dit \
--userns=keep-id \
--name "$CONTAINER" \
--user "$DEV_USER" \
--hostname "$CONTAINER" \
--label auto-cleanup=true \
-v "${XDG_RUNTIME_DIR}"/podman/podman.sock:/run/podman/podman.sock \
"$IMAGE"
elif ! podman inspect -f '{{.State.Running}}' "$CONTAINER" | grep -q true; then
log "⚡ Starting existing container $CONTAINER..."
podman start "$CONTAINER" >/dev/null 2>&1
fi
sleep 1
}
# After devuser exits...
check_devuser_attached() {
# Get list of clients
client_users=$(podman exec "$CONTAINER" "${TMUX_CMD[@]}" list-clients -t "$TMUX_SESSION" -F "#{client_user}" 2>/dev/null)
if echo "$client_users" | grep -q "$DEV_USER"; then
log "💡 devuser still attached — container stays running"
return 0
else
log "⚠️ $CONTAINER has exited — stopping container"
podman stop "$CONTAINER" >/dev/null 2>&1
return 1
fi
}
# === Main ===
case "$MODE" in
rw)
start_container_if_needed
# Run $TMUX_CMD session inside the container
if ! podman exec -it --user "$DEV_USER" "$CONTAINER" "${TMUX_CMD[@]}" has-session -t "$TMUX_SESSION" >/dev/null 2>&1; then
if ! podman exec -it --user "$DEV_USER" "$CONTAINER" "${TMUX_CMD[@]}" new-session -s "$TMUX_SESSION" >/dev/null 2>&1; then
log "❌ Could not create new ${TMUX_CMD[*]} session. Please contact admin or try again later."
2025-04-17 06:55:36 +01:00
exit 1
fi
else
log "$CONTAINER reattaching..."
if ! podman exec -it --user "$DEV_USER" "$CONTAINER" "${TMUX_CMD[@]}" attach -t "$TMUX_SESSION" 2>/dev/null; then
log "❌ Could not attach to ${TMUX_CMD[*]} session. Please contact admin or try again later."
2025-04-17 06:55:36 +01:00
exit 1
fi
fi
check_devuser_attached
2025-04-17 06:36:42 +01:00
exit 0
;;
ro)
if (podman container exists "$CONTAINER" && podman inspect -f '{{.State.Running}}' "$CONTAINER" | grep -q true) >/dev/null 2>&1; then
2025-04-18 02:22:13 +01:00
if podman exec -it --user "$DEV_USER" "$CONTAINER" "${TMUX_CMD[@]}" attach -r -t "$TMUX_SESSION"; then
log "❌ Could not attach to ${TMUX_CMD[*]} session. Please contact admin or try again later."
2025-04-17 06:55:36 +01:00
exit 1
fi
2025-04-17 06:36:42 +01:00
exit 0
else
log "❌ Container $CONTAINER does not exist."
exit 1
fi
;;
*)
log "❌ Invalid access mode: $MODE"
exit 1
;;
esac