Files
devcontainers/vibe-dev/entrypoint.sh
enoch 518eb5a90e Add Oh My Pi and improve dev container config
- Install @oh-my-pi/pi-coding-agent and move Go binaries to /usr/local/bin
- Add omp-data volume and make web port configurable via PORT_WEB
- Replace aider self-check with omp in Makefile
- Harden entrypoint: avoid exporting API keys to SSH env and overwrite
  mounted public key into authorized_keys
- Add .dockerignore, simplify .env.example, and document omp in README
2026-06-22 21:51:56 +08:00

38 lines
1.1 KiB
Bash
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
#!/bin/bash
set -e
# 1. 准备 SSH 目录
mkdir -p /root/.ssh
chmod 700 /root/.ssh
touch /root/.ssh/authorized_keys
touch /root/.ssh/environment
# 仅同步非敏感环境变量到 SSH environment
# (API Keys 通过 compose env_file 注入进程环境,不落盘,避免明文泄露)
printenv | grep -E '^(PATH|BUN|CARGO|RUST|TERM|SHELL|WORKSPACE)' > /root/.ssh/environment
# 2. 动态注入挂载的公钥 (每次启动重建 authorized_keys避免旧公钥残留)
# 持久化公钥请通过 .env 的 SSH_PUB_KEY_PATH 配置
if [ -f /tmp/host_id_ed25519.pub ]; then
echo "检测到挂载的公钥,正在注入..."
cp /tmp/host_id_ed25519.pub /root/.ssh/authorized_keys
echo "✅ 公钥注入成功"
else
# 没有挂载公钥时保留已有 authorized_keys (用户可能用 make add-key 手动加过)
touch /root/.ssh/authorized_keys
fi
# 3. 强制修复权限 (SSH 对此非常敏感)
chmod 600 /root/.ssh/authorized_keys
chown -R root:root /root/.ssh
# 根据不同 OS 启动 SSH
if [ -f /usr/sbin/sshd ]; then
/usr/sbin/sshd # Fedora 路径
else
service ssh start # Ubuntu 路径
fi
exec "$@"