Compare commits
20 Commits
13ea1a2620
...
main
| Author | SHA1 | Date | |
|---|---|---|---|
|
03df535d76
|
|||
|
d6ef16cd24
|
|||
|
a0ea04d2bd
|
|||
|
d7468a444b
|
|||
|
f25b6966ef
|
|||
|
9f1b65b781
|
|||
|
d81fa7d3a1
|
|||
|
7e27784a9a
|
|||
|
b5dd280e5a
|
|||
|
bb43c758f9
|
|||
|
407ba8afae
|
|||
|
aa3d5d5bb8
|
|||
|
28766d5e87
|
|||
|
51f7e95104
|
|||
|
497d4e76d0
|
|||
|
6ae5ff5a6c
|
|||
|
611c16a087
|
|||
|
26266017c2
|
|||
|
c6fa393c03
|
|||
| 27d2f05a3d |
@@ -3,21 +3,17 @@ on:
|
||||
push:
|
||||
branches: ["main"]
|
||||
paths:
|
||||
[
|
||||
"containers/fedora/**",
|
||||
"containers/go/**",
|
||||
"containers/infra/**",
|
||||
".gitea/workflows/kali.yaml",
|
||||
]
|
||||
- "containers/fedora/**"
|
||||
- "containers/go/**"
|
||||
- "containers/infra/**"
|
||||
- ".gitea/workflows/fedora.yaml"
|
||||
pull_request:
|
||||
branches: ["main"]
|
||||
paths:
|
||||
[
|
||||
"containers/fedora/**",
|
||||
"containers/go/**",
|
||||
"containers/infra/**",
|
||||
".gitea/workflows/kali.yaml",
|
||||
]
|
||||
- "containers/fedora/**"
|
||||
- "containers/go/**"
|
||||
- "containers/infra/**"
|
||||
- ".gitea/workflows/fedora.yaml"
|
||||
schedule:
|
||||
- cron: "0 16 * * FRI"
|
||||
|
||||
@@ -41,24 +37,33 @@ jobs:
|
||||
context: ./containers/fedora
|
||||
file: ./containers/fedora/Containerfile
|
||||
push: true
|
||||
tags: |
|
||||
git.plabble.org/job79/fedora:${{ github.ref_name }}
|
||||
git.plabble.org/job79/fedora:latest
|
||||
tags: git.plabble.org/job79/fedora:${{ github.ref_name }}
|
||||
build-args: TAG=${{ github.ref_name }}
|
||||
outputs: type=image,oci-mediatypes=true,compression=zstd,compression-level=3,force-compression=true
|
||||
- name: Build and push go container
|
||||
uses: docker/build-push-action@v5
|
||||
with:
|
||||
context: ./containers/go
|
||||
file: ./containers/go/Containerfile
|
||||
push: true
|
||||
tags: |
|
||||
git.plabble.org/job79/go:${{ github.ref_name }}
|
||||
git.plabble.org/job79/go:latest
|
||||
tags: git.plabble.org/job79/go:${{ github.ref_name }}
|
||||
build-args: TAG=${{ github.ref_name }}
|
||||
outputs: type=image,oci-mediatypes=true,compression=zstd,compression-level=3,force-compression=true
|
||||
- name: Build and push infra container
|
||||
uses: docker/build-push-action@v5
|
||||
with:
|
||||
context: ./containers/infra
|
||||
file: ./containers/infra/Containerfile
|
||||
push: true
|
||||
tags: |
|
||||
git.plabble.org/job79/infra:${{ github.ref_name }}
|
||||
git.plabble.org/job79/infra:latest
|
||||
tags: git.plabble.org/job79/infra:${{ github.ref_name }}
|
||||
build-args: TAG=${{ github.ref_name }}
|
||||
outputs: type=image,oci-mediatypes=true,compression=zstd,compression-level=3,force-compression=true
|
||||
- name: Build and push vms container
|
||||
uses: docker/build-push-action@v5
|
||||
with:
|
||||
context: ./containers/vms
|
||||
file: ./containers/vms/Containerfile
|
||||
push: true
|
||||
tags: git.plabble.org/job79/vms:${{ github.ref_name }}
|
||||
build-args: TAG=${{ github.ref_name }}
|
||||
outputs: type=image,oci-mediatypes=true,compression=zstd,compression-level=3,force-compression=true
|
||||
|
||||
@@ -1,34 +0,0 @@
|
||||
name: Build container
|
||||
on:
|
||||
push:
|
||||
branches: ["main"]
|
||||
paths: ["containers/kali/**", ".gitea/workflows/kali.yaml"]
|
||||
pull_request:
|
||||
branches: ["main"]
|
||||
paths: ["containers/kali/**", ".gitea/workflows/kali.yaml"]
|
||||
schedule:
|
||||
- cron: "0 16 * * FRI"
|
||||
|
||||
jobs:
|
||||
fedora-build:
|
||||
runs-on: job-latest
|
||||
steps:
|
||||
- name: Clone repo
|
||||
uses: actions/checkout@v4
|
||||
- name: Setup Docker Buildx
|
||||
uses: docker/setup-buildx-action@v3
|
||||
- name: Login to Registry
|
||||
uses: docker/login-action@v3
|
||||
with:
|
||||
registry: git.plabble.org
|
||||
username: ${{ secrets.REGISTRY_USERNAME }}
|
||||
password: ${{ secrets.REGISTRY_TOKEN }}
|
||||
- name: Build and push kali container
|
||||
uses: docker/build-push-action@v5
|
||||
with:
|
||||
context: ./containers/kali
|
||||
file: ./containers/kali/Containerfile
|
||||
push: true
|
||||
tags: |
|
||||
git.plabble.org/job79/kali:${{ github.ref_name }}
|
||||
git.plabble.org/job79/kali:latest
|
||||
@@ -4,6 +4,7 @@
|
||||
export EDITOR=nvim \
|
||||
WAYLAND_DISPLAY=wayland-0 \
|
||||
XDG_RUNTIME_DIR=/run/user/1000 \
|
||||
SSH_AUTH_SOCK=/run/user/1000/ssh-auth-sock \
|
||||
PS1="\[\e[30;46m\] \h | \w \[\e[0;36m\]\[\e[m\] " \
|
||||
TZ="Europe/Amsterdam"
|
||||
|
||||
|
||||
@@ -1,3 +1,4 @@
|
||||
#!/bin/bash
|
||||
export DBUS_SESSION_BUS_ADDRESS=unix:path=/tmp/bus
|
||||
host-spawn -cwd "${PWD/#$HOME/$HOST_HOME}" \
|
||||
$([ "$(basename "$0")" != "host" ] && echo "$(basename "$0")") "$@"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
[user]
|
||||
email = job@plabble.org
|
||||
name = Job79
|
||||
signingKey = ~/.ssh/id_ed25519.pub
|
||||
signingKey = ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPsqM6ABAaCTQZ+llFXD3CXrYYuIHDEnvz8IBbXddYEc job@plabble.org
|
||||
[gpg]
|
||||
format = ssh
|
||||
[commit]
|
||||
|
||||
@@ -1,4 +1,7 @@
|
||||
FROM git.plabble.org/job79/fedora
|
||||
ARG TAG
|
||||
FROM git.plabble.org/job79/fedora:${TAG}
|
||||
USER root
|
||||
|
||||
RUN dnf -y install go
|
||||
|
||||
USER user
|
||||
|
||||
@@ -1,2 +1,2 @@
|
||||
#!/bin/bash
|
||||
arg "-v $HOME/Documents/devc/go:/home/user/projects"
|
||||
arg "-v $HOME/Documents/go:/home/user/Documents/go"
|
||||
|
||||
@@ -1,5 +1,9 @@
|
||||
FROM git.plabble.org/job79/fedora
|
||||
ARG TAG
|
||||
FROM git.plabble.org/job79/fedora:${TAG}
|
||||
USER root
|
||||
|
||||
RUN dnf -y install kubectl openssl
|
||||
RUN curl -sL https://talos.dev/install | sh
|
||||
RUN curl -s https://fluxcd.io/install.sh | bash
|
||||
|
||||
USER user
|
||||
|
||||
@@ -1,2 +1,2 @@
|
||||
#!/bin/bash
|
||||
arg "-v $HOME/Documents/devc/infra:/home/user/projects"
|
||||
arg "-v $HOME/Documents/infra:/home/user/Documents/infra"
|
||||
|
||||
@@ -1,17 +0,0 @@
|
||||
FROM docker.io/kalilinux/kali-rolling
|
||||
|
||||
# === install system packages ===
|
||||
RUN apt update && \
|
||||
apt -y install iputils-ping sudo \
|
||||
zoxide git npm neovim gawk jq unzip fd-find lazygit
|
||||
|
||||
# === setup user ===
|
||||
RUN useradd -ms /bin/bash user && \
|
||||
usermod -aG sudo user && sed -i 's/^%sudo\s\+ALL=(ALL:ALL)\s\+ALL$/%sudo\tALL=(ALL:ALL)\tNOPASSWD: ALL/' /etc/sudoers && \
|
||||
mkdir -p /run/user/1000 && chown user:user /run/user/1000
|
||||
|
||||
USER user
|
||||
WORKDIR /home/user
|
||||
RUN mkdir -p .config .local .cache
|
||||
RUN git clone https://git.plabble.org/Job79/neovim-config.git .config/nvim
|
||||
VOLUME /home/user
|
||||
7
containers/vms/Containerfile
Normal file
7
containers/vms/Containerfile
Normal file
@@ -0,0 +1,7 @@
|
||||
ARG TAG
|
||||
FROM git.plabble.org/job79/fedora:${TAG}
|
||||
USER root
|
||||
|
||||
RUN dnf -y install qemu-system-x86
|
||||
|
||||
USER user
|
||||
6
containers/vms/config.sh
Normal file
6
containers/vms/config.sh
Normal file
@@ -0,0 +1,6 @@
|
||||
#!/bin/bash
|
||||
arg "-v $HOME/Documents/vms:/home/user/Documents/vms"
|
||||
arg "--net host"
|
||||
arg "--device /dev/kvm"
|
||||
arg "--device /dev/dri"
|
||||
arg "--security-opt seccomp=unconfined"
|
||||
57
devc.sh
57
devc.sh
@@ -29,14 +29,17 @@ default_args() {
|
||||
# clipboard (wl-copy) and gui applications working.
|
||||
[ -e "/run/user/$UID/wayland-0" ] && arg "-v /run/user/$UID/wayland-0:/run/user/1000/wayland-0"
|
||||
|
||||
# Mount the ssh socket to get ssh working.
|
||||
[ -e "$SSH_AUTH_SOCK" ] && arg "-v $SSH_AUTH_SOCK:/run/user/1000/ssh-auth-sock"
|
||||
|
||||
# Make the user home dir a volume so it survives container
|
||||
# restarts. Use copy to keep the homedir files from the image.
|
||||
# restarts. Use copy to keep the files from the image.
|
||||
arg "-v $name:/home/user:copy"
|
||||
|
||||
# If there is custom configuration for the container, load
|
||||
# it here.
|
||||
config_file="$(dirname "$(realpath "$0")")/containers/$name/config.sh"
|
||||
[ -f "${config_file}" ] && source "${config_file}"
|
||||
[ -f "$config_file" ] && source "${config_file}"
|
||||
}
|
||||
|
||||
# param_args returns the podman run arguments based on the
|
||||
@@ -46,16 +49,24 @@ param_args() {
|
||||
case "$1" in
|
||||
-gpu) # Enable gpu acceleration.
|
||||
arg "--device /dev/dri" ;;
|
||||
-kvm) # Enable KVM.
|
||||
arg "--device /dev/kvm" ;;
|
||||
-usb) # Enable USB access.
|
||||
arg "--device /dev/bus/usb" ;;
|
||||
-host-spawn) # Enable spawning host commands from inside the container using host-spawn.
|
||||
arg "-v /run/user/$UID/bus:/tmp/bus"
|
||||
arg "-e HOST_HOME=$HOME" # Use to translate paths.
|
||||
arg "-e DBUS_SESSION_BUS_ADDRESS='unix:path=/tmp/bus'"
|
||||
arg "-e HOST_HOME=$HOME" # Used to translate paths.
|
||||
;;
|
||||
-x11)
|
||||
arg "-e DISPLAY=$DISPLAY"
|
||||
-x11) # Enable X11 support.
|
||||
arg "-v /tmp/.X11-unix:/tmp/.X11-unix"
|
||||
arg "-e XAUTHORITY=/run/user/1000/.Xauthority"
|
||||
arg "-v $XAUTHORITY:/run/user/1000/.Xauthority:ro"
|
||||
arg "-e DISPLAY=$DISPLAY"
|
||||
arg "-e XAUTHORITY=/run/user/1000/.Xauthority"
|
||||
;;
|
||||
-mnt) # Mount directory.
|
||||
shift
|
||||
arg "-w /mnt/"
|
||||
arg "-v $1:/mnt/$([ ! -d "$1" ] && echo 'file')"
|
||||
;;
|
||||
*) # Use unknown arguments a podman arguments.
|
||||
arg "$1" ;;
|
||||
@@ -65,18 +76,11 @@ param_args() {
|
||||
}
|
||||
|
||||
### MAIN ###
|
||||
# Get container registry from DEVC_REGISTRY env variable.
|
||||
if [ -n "${DEVC_REGISTRY:-}" ]; then
|
||||
registry="$DEVC_REGISTRY"
|
||||
else
|
||||
log "registry unknown; set the DEVC_REGISTRY environment variable" 'x' 31
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Get the devcontainer name from the first argument. If not
|
||||
# provided, use the last used name when possible.
|
||||
if [[ $# -gt 0 ]] && [[ ${1:-} != -* ]]; then
|
||||
image="$1"
|
||||
[[ "$image" != *:* ]] && image="$image:main"
|
||||
echo "$image" >"$HOME/.local/share/devc-previous-container"
|
||||
shift
|
||||
elif [ -f "$HOME/.local/share/devc-previous-container" ]; then
|
||||
@@ -87,12 +91,27 @@ else
|
||||
fi
|
||||
name="${image%:*}"
|
||||
|
||||
# Create a new container when the container is not running or
|
||||
# when any arguments are provided.
|
||||
# Get container registry from the DEVC_REGISTRY env
|
||||
# variable.
|
||||
if [ -n "${DEVC_REGISTRY:-}" ]; then
|
||||
registry="$DEVC_REGISTRY"
|
||||
else
|
||||
log "registry unknown; set the DEVC_REGISTRY environment variable" 'x' 31
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Get container command from the DEVC_COMMAND env variable
|
||||
# if set, else use bash -l.
|
||||
if [ -z "${DEVC_COMMAND:-}" ]; then
|
||||
DEVC_COMMAND="bash -l"
|
||||
fi
|
||||
|
||||
# When container is not running or arguments are provided,
|
||||
# recreate it.
|
||||
if [ "$(podman container inspect "$name" -f {{.State.Running}} 2>&1)" != 'true' ] || [[ $# -gt 0 ]]; then
|
||||
log "starting devcontainer..."
|
||||
podman container rm -f -t 0 "$name" 1>/dev/null
|
||||
podman run -td $(default_args) $(param_args $@) "$registry/$name"
|
||||
podman run -td $(default_args) $(param_args $@) "$registry/$image"
|
||||
fi
|
||||
|
||||
podman exec -it "$name" bash -l
|
||||
podman exec --detach-keys "ctrl-@" -it "$name" ${DEVC_COMMAND:-}
|
||||
|
||||
Reference in New Issue
Block a user