#!/bin/bash set -e # Function to extract domain from Git SSH URL extract_domain() { local url=$1 # Handle different SSH URL formats if [[ $url == ssh://* ]]; then # For URLs starting with ssh://, extract the domain echo "$url" | sed -E 's|ssh://[^@]+@([^:/]+).*|\1|' else # For URLs without ssh://, extract the domain after '@' and before ':' echo "$url" | sed -E 's|[^@]+@([^:/]+).*|\1|' fi } # Check if the required environment variables are set if [ -z "$REPO_URL" ]; then echo "Error: REPO_URL environment variable must be set." exit 1 fi if [ -z "$GIT_USER" ]; then echo "Error: GIT_USER environment variable must be set." exit 1 fi if [ -z "$GIT_EMAIL" ]; then echo "Error: GIT_EMAIL environment variable must be set." exit 1 fi # Check if the SSH key exists if [ ! -f /root/.ssh/id_rsa ]; then echo "Error: SSH private key not found at /root/.ssh/id_rsa" exit 1 fi # Ensure the SSH key has the correct permissions chmod 600 /root/.ssh/id_rsa # Extract the domain from the REPO_URL DOMAIN=$(extract_domain "$REPO_URL") # Check if the repository directory already exists if [ ! -d "/workspace/.git" ]; then # Add the SSH configuration for the domain echo "Host $DOMAIN HostName $DOMAIN IdentityFile /root/.ssh/id_rsa StrictHostKeyChecking no " >>/root/.ssh/config # Clone the repository if it doesn't exist git clone "$REPO_URL" /workspace fi # Add the public SSH key to authorized_keys if [ -f /root/.ssh/hostkey.pub ]; then cat /root/.ssh/hostkey.pub >>/root/.ssh/authorized_keys fi # If no teleport edition is given, fallback to oss if [ -z "$TELEPORT_EDITION" ]; then TELEPORT_EDITION="oss" fi # Install Teleport if the environment variables are set if [ -n "$TELEPORT_VERSION" ] && [ -n "$TELEPORT_URL" ]; then echo "Installing Teleport version $TELEPORT_VERSION, edition $TELEPORT_EDITION..." echo "Executing: curl https://goteleport.com/static/install.sh | bash -s ${TELEPORT_VERSION} ${TELEPORT_EDITION}" curl https://goteleport.com/static/install.sh | bash -s "${TELEPORT_VERSION}" "${TELEPORT_EDITION}" else echo "Error: TELEPORT_VERSION and TELEPORT_URL environment variables must be set." exit 1 fi # Change to the repository directory cd /workspace # Install dependencies yarn install # Copy the environment file to the repository's environments directory if [ -f /environment/.dev.env ]; then mkdir -p /workspace/environments cp /environment/.dev.env /workspace/environments/.dev.env fi # Set the git user and email git config --global user.name "$GIT_USER" git config --global user.email "$GIT_EMAIL" # Get the hostname of the machine HOSTNAME=$(hostname) # If teleport token is set and there is no teleport.yaml file, create one if [ -n "$TELEPORT_TOKEN" ] && [ ! -f /etc/teleport.yaml ]; then teleport configure --roles=node --token="$TELEPORT_TOKEN" --proxy="$TELEPORT_URL" --no-acme -o file echo "Created teleport configuration file" fi # File path CONFIG_FILE="/etc/teleport.yaml" # Edit the teleport.yaml file to update the nodename sed -i "s/^ nodename:.*/ nodename: $HOSTNAME/" "$CONFIG_FILE" add_teleport_labels() { if [ -n "$TELEPORT_LABELS" ]; then echo "Adding Teleport labels from TELEPORT_LABELS environment variable..." # Check if ssh_service section exists if ! grep -q "ssh_service:" "$CONFIG_FILE"; then echo "Error: ssh_service section not found in teleport.yaml" return 1 fi # Create a backup cp "$CONFIG_FILE" "$CONFIG_FILE.backup" # Extract existing labels from the config file declare -A EXISTING_LABELS IN_LABELS_SECTION=0 while IFS= read -r line; do # Detect when we enter the labels section if [[ "$line" =~ ^[[:space:]]*labels:[[:space:]]*$ ]]; then IN_LABELS_SECTION=1 continue fi # Detect when we leave the labels section (next top-level key) if [ "$IN_LABELS_SECTION" -eq 1 ] && [[ "$line" =~ ^[[:space:]]*[a-zA-Z_][a-zA-Z0-9_]*:[[:space:]]* ]]; then IN_LABELS_SECTION=0 fi # Extract label key:value pairs if [ "$IN_LABELS_SECTION" -eq 1 ]; then if [[ "$line" =~ ^[[:space:]]+([^:]+):[[:space:]]*(.+)$ ]]; then existing_key=$(echo "${BASH_REMATCH[1]}" | xargs) existing_value=$(echo "${BASH_REMATCH[2]}" | xargs) EXISTING_LABELS["$existing_key"]="$existing_value" fi fi done < "$CONFIG_FILE" # Build the new ssh_service section with existing and new labels NEW_SSH_SECTION="ssh_service:" NEW_SSH_SECTION="$NEW_SSH_SECTION"$'\n'" labels:" # First, add existing labels that are not being replaced for existing_key in "${!EXISTING_LABELS[@]}"; do NEW_SSH_SECTION="$NEW_SSH_SECTION"$'\n'" $existing_key: ${EXISTING_LABELS[$existing_key]}" done # Parse TELEPORT_LABELS and add only new labels IFS=',' read -ra LABELS <<< "$TELEPORT_LABELS" for label in "${LABELS[@]}"; do # Trim whitespace label=$(echo "$label" | xargs) # Check if label contains colon if [[ "$label" == *":"* ]]; then key=$(echo "$label" | cut -d':' -f1 | xargs) value=$(echo "$label" | cut -d':' -f2- | xargs) if [ -n "$key" ] && [ -n "$value" ]; then # Only add if the label key doesn't already exist if [ -z "${EXISTING_LABELS[$key]}" ]; then NEW_SSH_SECTION="$NEW_SSH_SECTION"$'\n'" $key: $value" echo "Added label: $key = $value" else echo "Label '$key' already exists with value '${EXISTING_LABELS[$key]}', skipping" fi else echo "Warning: Invalid label format '$label'. Expected format: key:value" fi else echo "Warning: Label '$label' does not contain colon separator. Expected format: key:value" fi done NEW_SSH_SECTION="$NEW_SSH_SECTION"$'\n'" enabled: \"yes\"" # Replace the ssh_service section awk -v new_section="$NEW_SSH_SECTION" ' BEGIN { in_ssh_service = 0 section_replaced = 0 } /^ssh_service:/ { in_ssh_service = 1 if (!section_replaced) { print new_section section_replaced = 1 } next } in_ssh_service && /^[a-zA-Z_][a-zA-Z0-9_]*:/ { in_ssh_service = 0 } in_ssh_service { next } { print $0 } ' "$CONFIG_FILE" > "$CONFIG_FILE.tmp" # Replace the original file mv "$CONFIG_FILE.tmp" "$CONFIG_FILE" echo "Teleport labels processed successfully" else echo "No TELEPORT_LABELS environment variable set, skipping label configuration" fi } # Add labels to teleport configuration add_teleport_labels # Start Teleport in the background nohup teleport start & # Use NODE_START_COMMAND if set, otherwise default to start:dev START_COMMAND=${NODE_START_COMMAND:-"start:dev"} # Start the application with pm2 exec pm2-runtime "yarn $START_COMMAND"