Expose the authorized keys tmate feature (#18)
* Expose the authorized keys tmate feature Described here: https://tmate.io/ in "Access Control" The variable accepts the file content in raw format (with \n) and dumps it into a file which tmate reads * Use echo instead of printf * Add missing quote * Only setup tmate settings if debug is activated
This commit is contained in:
@@ -214,6 +214,9 @@ func registerCompile(app *kingpin.Application) {
|
||||
cmd.Flag("tmate-server-ed25519-fingerprint", "tmate server rsa fingerprint").
|
||||
StringVar(&c.Tmate.ED25519)
|
||||
|
||||
cmd.Flag("tmate-authorized-keys", "tmate authorized keys").
|
||||
StringVar(&c.Tmate.AuthorizedKeys)
|
||||
|
||||
// shared pipeline flags
|
||||
c.Flags = internal.ParseFlags(cmd)
|
||||
}
|
||||
|
||||
@@ -114,6 +114,7 @@ type Config struct {
|
||||
Port string `envconfig:"DRONE_TMATE_PORT"`
|
||||
RSA string `envconfig:"DRONE_TMATE_FINGERPRINT_RSA"`
|
||||
ED25519 string `envconfig:"DRONE_TMATE_FINGERPRINT_ED25519"`
|
||||
AuthorizedKeys string `envconfig:"DRONE_TMATE_AUTHORIZED_KEYS"`
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@@ -148,6 +148,7 @@ func (c *daemonCommand) run(*kingpin.ParseContext) error {
|
||||
Port: config.Tmate.Port,
|
||||
RSA: config.Tmate.RSA,
|
||||
ED25519: config.Tmate.ED25519,
|
||||
AuthorizedKeys: config.Tmate.AuthorizedKeys,
|
||||
},
|
||||
Environ: provider.Combine(
|
||||
provider.Static(config.Runner.Environ),
|
||||
|
||||
@@ -348,6 +348,9 @@ func registerExec(app *kingpin.Application) {
|
||||
cmd.Flag("tmate-server-ed25519-fingerprint", "tmate server rsa fingerprint").
|
||||
StringVar(&c.Tmate.ED25519)
|
||||
|
||||
cmd.Flag("tmate-authorized-keys", "tmate authorized keys").
|
||||
StringVar(&c.Tmate.AuthorizedKeys)
|
||||
|
||||
cmd.Flag("debug", "enable debug logging").
|
||||
BoolVar(&c.Debug)
|
||||
|
||||
|
||||
@@ -62,6 +62,7 @@ type Tmate struct {
|
||||
Port string
|
||||
RSA string
|
||||
ED25519 string
|
||||
AuthorizedKeys string
|
||||
}
|
||||
|
||||
// Compiler compiles the Yaml configuration file to an
|
||||
@@ -247,6 +248,10 @@ func (c *Compiler) Compile(ctx context.Context, args runtime.CompilerArgs) runti
|
||||
envs["DRONE_TMATE_PORT"] = c.Tmate.Port
|
||||
envs["DRONE_TMATE_FINGERPRINT_RSA"] = c.Tmate.RSA
|
||||
envs["DRONE_TMATE_FINGERPRINT_ED25519"] = c.Tmate.ED25519
|
||||
|
||||
if c.Tmate.AuthorizedKeys != "" {
|
||||
envs["DRONE_TMATE_AUTHORIZED_KEYS"] = c.Tmate.AuthorizedKeys
|
||||
}
|
||||
}
|
||||
|
||||
// create the .netrc environment variables if not
|
||||
|
||||
@@ -63,14 +63,18 @@ remote_debug() {
|
||||
fi
|
||||
}
|
||||
|
||||
if [ "${DRONE_BUILD_DEBUG}" = "true" ]; then
|
||||
if [ ! -z "${DRONE_TMATE_HOST}" ]; then
|
||||
echo "set -g tmate-server-host $DRONE_TMATE_HOST" >> $HOME/.tmate.conf
|
||||
echo "set -g tmate-server-port $DRONE_TMATE_PORT" >> $HOME/.tmate.conf
|
||||
echo "set -g tmate-server-rsa-fingerprint $DRONE_TMATE_FINGERPRINT_RSA" >> $HOME/.tmate.conf
|
||||
echo "set -g tmate-server-ed25519-fingerprint $DRONE_TMATE_FINGERPRINT_ED25519" >> $HOME/.tmate.conf
|
||||
fi
|
||||
|
||||
if [ "${DRONE_BUILD_DEBUG}" = "true" ]; then
|
||||
if [ ! -z "${DRONE_TMATE_AUTHORIZED_KEYS}" ]; then
|
||||
echo "$DRONE_TMATE_AUTHORIZED_KEYS" > $HOME/.tmate.authorized_keys
|
||||
echo "set -g tmate-authorized-keys \"$HOME/.tmate.authorized_keys\"" >> $HOME/.tmate.conf
|
||||
fi
|
||||
fi
|
||||
trap remote_debug EXIT
|
||||
fi
|
||||
`
|
||||
|
||||
Reference in New Issue
Block a user