style: beatify and optimize ssh router with chatgpt
This commit is contained in:
parent
3576bf93c2
commit
ff72c95012
261
ssh_router.sh
261
ssh_router.sh
@ -1,210 +1,209 @@
|
|||||||
#!/bin/bash
|
#!/usr/bin/env bash
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
PERSON="$1"
|
PERSON="${1:?Usage: $0 <person>}"
|
||||||
WORKSPACE="$SSH_ORIGINAL_COMMAND"
|
WORKSPACE="${SSH_ORIGINAL_COMMAND:-}"
|
||||||
IMAGE="localhost/analytics-backend-workspace:latest"
|
IMAGE="localhost/analytics-backend-workspace:latest"
|
||||||
DEV_USER="devuser"
|
DEV_USER="devuser"
|
||||||
|
|
||||||
XDG_RUNTIME_DIR="/run/user/$(id -u)"
|
XDG_RUNTIME_DIR="/run/user/$(id -u)"
|
||||||
LOG_FILE="/tmp/.ssh-router-${PERSON}.log"
|
LOG_FILE="/tmp/.ssh-router-${PERSON}.log"
|
||||||
|
|
||||||
|
# ─────────────────────────────────────────────
|
||||||
|
# ANSI colors & emojis
|
||||||
|
readonly C_RESET='\033[0m'
|
||||||
|
readonly C_INFO='\033[1;34m' # blue
|
||||||
|
readonly C_WARN='\033[1;33m' # yellow
|
||||||
|
readonly C_ERROR='\033[1;31m' # red
|
||||||
|
|
||||||
log() {
|
log() {
|
||||||
echo "[$(date '+%Y-%m-%d %H:%M:%S')] $*" >>"$LOG_FILE"
|
local level="${1^^}"
|
||||||
|
shift
|
||||||
|
local icon color
|
||||||
|
case "$level" in
|
||||||
|
INFO) icon="ℹ️" color="$C_INFO" ;;
|
||||||
|
WARN) icon="⚠️" color="$C_WARN" ;;
|
||||||
|
ERROR) icon="❌" color="$C_ERROR" ;;
|
||||||
|
*) icon="🔹" color="$C_RESET" ;;
|
||||||
|
esac
|
||||||
|
local ts
|
||||||
|
ts="$(date '+%Y-%m-%d %H:%M:%S')"
|
||||||
|
printf '%b%s [%s] %s%b\n' \
|
||||||
|
"$color" "$icon" "$ts" "[$level] $*" "$C_RESET" |
|
||||||
|
tee -a "$LOG_FILE"
|
||||||
}
|
}
|
||||||
|
|
||||||
|
# ─────────────────────────────────────────────
|
||||||
|
# Check for interactive TTY
|
||||||
if [[ ! -t 0 ]]; then
|
if [[ ! -t 0 ]]; then
|
||||||
log "❌ No TTY allocated — refusing to run tmux without an interactive terminal"
|
log ERROR "No TTY allocated—refusing to run without an interactive terminal"
|
||||||
echo "Error: No TTY. Use 'ssh -t'" >&2
|
echo "Error: No TTY. Use 'ssh -t'" >&2
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# log "🧩 IMAGE = '$IMAGE'"
|
# ─────────────────────────────────────────────
|
||||||
# log "🧩 WORKSPACE = '$WORKSPACE'"
|
# Default WORKSPACE if empty
|
||||||
# log "🧩 PERSON = '$PERSON'"
|
if [[ -z "$WORKSPACE" ]]; then
|
||||||
|
|
||||||
# Fallbacks
|
|
||||||
if [[ -z "${WORKSPACE:-}" ]]; then
|
|
||||||
WORKSPACE="$PERSON"
|
WORKSPACE="$PERSON"
|
||||||
log "ℹ️ Defaulted WORKSPACE to $WORKSPACE"
|
log INFO "Defaulted WORKSPACE → $WORKSPACE"
|
||||||
fi
|
fi
|
||||||
|
TMUX_SESSION="${WORKSPACE}|analytics-backend"
|
||||||
|
|
||||||
TMUX_SESSION="$WORKSPACE|analytics-backend"
|
# ─────────────────────────────────────────────
|
||||||
|
# Ensure Podman socket is up
|
||||||
# Start podman socket service if it's not running
|
ensure_podman() {
|
||||||
if [[ ! -S "$XDG_RUNTIME_DIR/podman/podman.sock" ]]; then
|
local sock="$XDG_RUNTIME_DIR/podman/podman.sock"
|
||||||
log "🔄 Starting Podman socket service for user $USER"
|
if [[ ! -S "$sock" ]]; then
|
||||||
systemctl --user start podman.socket || {
|
log INFO "Starting podman.socket for user $(id -un)"
|
||||||
log "❌ Failed to start podman.socket via systemd"
|
systemctl --user start podman.socket || {
|
||||||
|
log ERROR "Failed to start podman.socket"
|
||||||
|
exit 1
|
||||||
|
}
|
||||||
|
sleep 1
|
||||||
|
fi
|
||||||
|
[[ -S "$sock" ]] || {
|
||||||
|
log ERROR "Podman socket still missing"
|
||||||
exit 1
|
exit 1
|
||||||
}
|
}
|
||||||
|
}
|
||||||
|
ensure_podman
|
||||||
|
|
||||||
# Wait briefly for socket to appear
|
# ─────────────────────────────────────────────
|
||||||
sleep 1
|
# Ensure IMAGE is present
|
||||||
fi
|
ensure_image() {
|
||||||
|
if ! podman image exists "$IMAGE"; then
|
||||||
if [[ ! -S "$XDG_RUNTIME_DIR/podman/podman.sock" ]]; then
|
log WARN "Image $IMAGE not found—pulling"
|
||||||
log "❌ Podman socket still missing after startup attempt"
|
podman pull --tls-verify=false "$IMAGE" || {
|
||||||
exit 1
|
log ERROR "Failed to pull $IMAGE"
|
||||||
fi
|
exit 1
|
||||||
|
}
|
||||||
# Check if image exists locally
|
log INFO "Pulled $IMAGE"
|
||||||
if ! podman image exists "$IMAGE"; then
|
|
||||||
log "📦 Image $IMAGE not found locally. Pulling from registry..."
|
|
||||||
|
|
||||||
# Attempt to pull the image from the local registry (insecure HTTP)
|
|
||||||
if ! podman pull --tls-verify=false "$IMAGE"; then
|
|
||||||
log "❌ Failed to pull image from $IMAGE"
|
|
||||||
exit 1
|
|
||||||
fi
|
fi
|
||||||
|
}
|
||||||
|
ensure_image
|
||||||
|
|
||||||
log "✅ Successfully pulled $IMAGE"
|
# ─────────────────────────────────────────────
|
||||||
fi
|
# Disallow file transfers
|
||||||
|
|
||||||
case "$SSH_ORIGINAL_COMMAND" in
|
case "$SSH_ORIGINAL_COMMAND" in
|
||||||
*scp* | *sftp* | *rsync* | *tar*)
|
*scp* | *sftp* | *rsync* | *tar*)
|
||||||
log "❌ File transfers are disabled"
|
log ERROR "File transfers are disabled"
|
||||||
exit 1
|
exit 1
|
||||||
;;
|
;;
|
||||||
esac
|
esac
|
||||||
|
|
||||||
|
# ─────────────────────────────────────────────
|
||||||
|
# Generate per-user gitconfig
|
||||||
generate_gitconfig() {
|
generate_gitconfig() {
|
||||||
access="$HOME/access.yml"
|
local access="$HOME/access.yml"
|
||||||
template="$HOME/gitconfig.template"
|
local template="$HOME/gitconfig.template"
|
||||||
user_dir="$HOME/secrets/$PERSON"
|
local userdir="$HOME/secrets/$PERSON"
|
||||||
|
local name email
|
||||||
|
|
||||||
# Extract user fields from YAML
|
name=$(yq -r ".\"$PERSON\".name" "$access" 2>/dev/null || echo)
|
||||||
name=$(yq ".\"$PERSON\".name" "$access")
|
email=$(yq -r ".\"$PERSON\".email" "$access" 2>/dev/null || echo)
|
||||||
email=$(yq ".\"$PERSON\".email" "$access")
|
|
||||||
|
|
||||||
# Ensure fields are not empty
|
|
||||||
if [[ -z "$name" || -z "$email" ]]; then
|
if [[ -z "$name" || -z "$email" ]]; then
|
||||||
echo "❌ Error: User '$PERSON' not found or missing name/email in $access"
|
log ERROR "Missing name/email for '$PERSON' in $access"
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# Generate .gitconfig
|
mkdir -p "$userdir"
|
||||||
env GIT_NAME="$name" GIT_EMAIL="$email" \
|
GIT_NAME="$name" GIT_EMAIL="$email" \
|
||||||
envsubst <"$template" >"$user_dir/gitconfig"
|
envsubst <"$template" >"$userdir/gitconfig"
|
||||||
|
log INFO ".gitconfig created → $userdir/gitconfig"
|
||||||
echo "✅ .gitconfig created at $user_dir/gitconfig"
|
|
||||||
}
|
}
|
||||||
|
|
||||||
# Function to start the container if not running
|
# ─────────────────────────────────────────────
|
||||||
|
# Start container if absent or stopped
|
||||||
start_container_if_needed() {
|
start_container_if_needed() {
|
||||||
if ! podman container exists "$WORKSPACE"; then
|
if ! podman container exists "$WORKSPACE"; then
|
||||||
log "🚀 Creating container $WORKSPACE..."
|
log INFO "Creating container '$WORKSPACE'"
|
||||||
generate_gitconfig
|
generate_gitconfig
|
||||||
podman run -dit \
|
podman run -dit \
|
||||||
--userns=keep-id \
|
|
||||||
--name "$WORKSPACE" \
|
--name "$WORKSPACE" \
|
||||||
|
--userns=keep-id \
|
||||||
--user "$DEV_USER" \
|
--user "$DEV_USER" \
|
||||||
--hostname "$WORKSPACE" \
|
--hostname "$WORKSPACE" \
|
||||||
--label auto-cleanup=true \
|
--label auto-cleanup=true \
|
||||||
-v "${XDG_RUNTIME_DIR}"/podman/podman.sock:/run/podman/podman.sock \
|
-v "${XDG_RUNTIME_DIR}/podman/podman.sock:/run/podman/podman.sock:Z" \
|
||||||
-v /home/infilytics/data/"$WORKSPACE":/app \
|
-v "/home/infilytics/data/$WORKSPACE:/app:Z" \
|
||||||
-v /home/infilytics/secrets/"$WORKSPACE"/gitconfig:/home/"$DEV_USER"/.gitconfig:ro \
|
-v "/home/infilytics/secrets/$WORKSPACE/gitconfig:/home/$DEV_USER/.gitconfig:ro,Z" \
|
||||||
-v /home/infilytics/secrets/"$WORKSPACE"/id_ed25519:/home/"$DEV_USER"/.ssh/id_ed25519:ro \
|
-v "/home/infilytics/secrets/$WORKSPACE/id_ed25519:/home/$DEV_USER/.ssh/id_ed25519:ro,Z" \
|
||||||
-v /home/infilytics/secrets/"$WORKSPACE"/id_ed25519.pub:/home/"$DEV_USER"/.ssh/id_ed25519.pub:ro \
|
-v "/home/infilytics/secrets/$WORKSPACE/id_ed25519.pub:/home/$DEV_USER/.ssh/id_ed25519.pub:ro,Z" \
|
||||||
--entrypoint "/home/$DEV_USER/start.sh" \
|
--entrypoint "/home/$DEV_USER/start.sh" \
|
||||||
"$IMAGE" "${TMUX_SESSION}"
|
"$IMAGE" "$TMUX_SESSION"
|
||||||
elif ! podman inspect -f '{{.State.Running}}' "$WORKSPACE" | grep -q true; then
|
elif ! podman inspect -f '{{.State.Running}}' "$WORKSPACE" | grep -q true; then
|
||||||
log "⚡ Starting existing container $WORKSPACE..."
|
log INFO "Starting existing container '$WORKSPACE'"
|
||||||
podman start "$WORKSPACE" >/dev/null 2>&1
|
podman start "$WORKSPACE" >/dev/null
|
||||||
fi
|
fi
|
||||||
sleep 1
|
sleep 1
|
||||||
}
|
}
|
||||||
|
|
||||||
# After devuser exits...
|
# ─────────────────────────────────────────────
|
||||||
|
# Detach logic: stop container when devuser has left
|
||||||
check_devuser_attached() {
|
check_devuser_attached() {
|
||||||
# Get list of clients
|
local clients
|
||||||
client_users=$(podman exec "$WORKSPACE" tmux list-clients -t "$TMUX_SESSION" -F "#{client_user}" 2>/dev/null)
|
clients=$(podman exec "$WORKSPACE" tmux list-clients -t "$TMUX_SESSION" -F "#{client_user}" 2>/dev/null)
|
||||||
|
if grep -q "^${DEV_USER}\$" <<<"$clients"; then
|
||||||
if echo "$client_users" | grep -q "$DEV_USER"; then
|
log INFO "devuser still attached—keeping container running"
|
||||||
log "💡 devuser still attached — container stays running"
|
|
||||||
return 0
|
|
||||||
else
|
else
|
||||||
log "🏃 $PERSON has logged out — stopping container"
|
log INFO "devuser detached—stopping container"
|
||||||
podman stop "$WORKSPACE" >/dev/null 2>&1
|
podman stop "$WORKSPACE" >/dev/null
|
||||||
return 1
|
|
||||||
fi
|
fi
|
||||||
}
|
}
|
||||||
|
|
||||||
|
# ─────────────────────────────────────────────
|
||||||
|
# Determine access mode (rw|ro) or exit
|
||||||
get_access_mode() {
|
get_access_mode() {
|
||||||
local yaml_file="access.yml"
|
local yaml="access.yml" user="$PERSON" ws="$WORKSPACE"
|
||||||
local workspace="$1"
|
[[ ! "$ws" =~ ^[A-Za-z0-9._-]+$ ]] && {
|
||||||
local person="$2"
|
log ERROR "Invalid workspace name"
|
||||||
|
exit 1
|
||||||
if [[ ! "$workspace" =~ ^[a-zA-Z0-9._-]+$ ]]; then
|
}
|
||||||
log "❌ Invalid container name: $WORKSPACE"
|
if [[ "$user" == "$ws" ]]; then
|
||||||
|
echo rw
|
||||||
|
elif yq -e '.["'"$user"'"].rw[]?' "$yaml" | grep -qx "$ws"; then
|
||||||
|
echo rw
|
||||||
|
elif yq -e '.["'"$user"'"].ro[]?' "$yaml" | grep -qx "$ws"; then
|
||||||
|
echo ro
|
||||||
|
else
|
||||||
|
log ERROR "$user has no access to $ws"
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# Special case: user accessing their own workspace
|
|
||||||
if [[ "$workspace" == "$person" ]]; then
|
|
||||||
echo "access=rw"
|
|
||||||
return 0
|
|
||||||
fi
|
|
||||||
|
|
||||||
# Check rw
|
|
||||||
if yq '.["'"$person"'"].rw // []' "$yaml_file" | grep -q "\b$workspace\b"; then
|
|
||||||
echo "access=rw"
|
|
||||||
return 0
|
|
||||||
fi
|
|
||||||
|
|
||||||
# Check ro
|
|
||||||
if yq '.["'"$person"'"].ro // []' "$yaml_file" | grep -q "\b$workspace\b"; then
|
|
||||||
echo "access=ro"
|
|
||||||
return 0
|
|
||||||
fi
|
|
||||||
|
|
||||||
# No access → exit with error
|
|
||||||
log "❌ $person has no access to $workspace" >&2
|
|
||||||
exit 1
|
|
||||||
}
|
}
|
||||||
|
|
||||||
# === Main ===
|
MODE="$(get_access_mode)"
|
||||||
|
|
||||||
read -r access_line < <(get_access_mode "$WORKSPACE" "$PERSON") || exit 1
|
|
||||||
MODE="${access_line#access=}"
|
|
||||||
|
|
||||||
|
# ─────────────────────────────────────────────
|
||||||
|
# Main dispatch
|
||||||
case "$MODE" in
|
case "$MODE" in
|
||||||
rw)
|
rw)
|
||||||
start_container_if_needed
|
start_container_if_needed
|
||||||
|
|
||||||
# Run tmux session inside the container
|
# Ensure tmux session exists
|
||||||
if ! podman exec -it --user "$DEV_USER" "$WORKSPACE" tmux has-session -t "$TMUX_SESSION" >/dev/null 2>&1; then
|
if ! podman exec -it --user "$DEV_USER" "$WORKSPACE" tmux has-session -t "$TMUX_SESSION" 2>/dev/null; then
|
||||||
if ! podman exec -it -e EDITOR=nvim --user "$DEV_USER" "$WORKSPACE" tmux new-session -d -s "$TMUX_SESSION" >/dev/null 2>&1; then
|
podman exec -it --user "$DEV_USER" "$WORKSPACE" \
|
||||||
log "❌ Could not create new tmux session. Please contact admin or try again later."
|
tmux new-session -d -s "$TMUX_SESSION"
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
fi
|
fi
|
||||||
|
|
||||||
log "⚡ $PERSON is working on $WORKSPACE's workspace"
|
log INFO "$PERSON attaching to workspace '$WORKSPACE'"
|
||||||
if ! podman exec -it -e TERM="$TERM" --user "$DEV_USER" "$WORKSPACE" tmux attach -t "$TMUX_SESSION"; then
|
podman exec -it -e TERM="$TERM" --user "$DEV_USER" "$WORKSPACE" \
|
||||||
log "❌ Could not attach to tmux session. Please contact admin or try again later."
|
tmux attach -t "$TMUX_SESSION"
|
||||||
exit 1
|
log INFO "$PERSON detached from '$WORKSPACE'"
|
||||||
fi
|
|
||||||
log "⚡ $PERSON finished working on $WORKSPACE's worksapce"
|
|
||||||
|
|
||||||
check_devuser_attached
|
check_devuser_attached
|
||||||
exit 0
|
|
||||||
;;
|
;;
|
||||||
ro)
|
ro)
|
||||||
if (podman container exists "$WORKSPACE" && podman inspect -f '{{.State.Running}}' "$WORKSPACE" | grep -q true) >/dev/null 2>&1; then
|
if podman inspect -f '{{.State.Running}}' "$WORKSPACE" 2>/dev/null | grep -q true; then
|
||||||
log "📜 $PERSON is viewing $WORKSPACE's workspace"
|
log INFO "$PERSON viewing workspace '$WORKSPACE'"
|
||||||
if ! podman exec -it -e TERM="$TERM" --user "$DEV_USER" "$WORKSPACE" tmux attach -r -t "$TMUX_SESSION"; then
|
podman exec -it -e TERM="$TERM" --user "$DEV_USER" "$WORKSPACE" \
|
||||||
log "❌ Could not attach to tmux session. Please contact admin or try again later."
|
tmux attach -r -t "$TMUX_SESSION"
|
||||||
exit 1
|
log INFO "$PERSON stopped viewing '$WORKSPACE'"
|
||||||
fi
|
|
||||||
log "🏃 $PERSON stopped viewing $WORKSPACE's workspace"
|
|
||||||
exit 0
|
|
||||||
else
|
else
|
||||||
log "❌ Workspace for $WORKSPACE does not exist."
|
log ERROR "Workspace '$WORKSPACE' is not running"
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
;;
|
;;
|
||||||
*)
|
*)
|
||||||
log "❌ Invalid access mode: $MODE"
|
log ERROR "Unknown access mode: '$MODE'"
|
||||||
exit 1
|
exit 1
|
||||||
;;
|
;;
|
||||||
esac
|
esac
|
||||||
|
Loading…
x
Reference in New Issue
Block a user