Chat Logs

  1. * phaleth joined #primate
  2. * phaleth joined #primate
  3. phalethwinamp works well on this linux https://images4.imagebam.com/4b/e0/01/ME1DN6UL_o.png
  4. bluehi phaleth
  5. blueLOL
  6. blueTIL: you can nest classes in CSS
  7. blueI've been so out of css dev that the world has progressed and I totally missed it
  8. blueso instead of writing `.header .title {}`, you can write `.header { display: flex; \n.title { font-size: 22px } }`
  9. blueso for repopack.com, we'll need two containers and a volume: the js runtime container, a postgres db, and storage for repos
  10. * phaleth joined #primate
  11. bluewb
  12. phalethhi blue
  13. phalethbut is css nesting well supported in all browsers?
  14. blueyes phaleth
  15. bluehttps://caniuse.com/?search=css+nesting
  16. nevet"css nesting" | Can I use... Support tables for HTML5, CSS3, etc
  17. blueunless you're on ie 11 :P
  18. blueit's amazing what modern css can do. it's almost like you don't need all this garbage tailwind nonsense
  19. bluedreamreal: https://www.youtube.com/watch?v=uF8YUB4kRBw
  20. nevetYouTube: Iron Maiden - Seventh Son Of A Seventh Son | Bruno Terrosa
  21. skillbot04,01โ–บ 14,01YouTube :: Iron Maiden - Seventh Son Of A Seventh Son
  22. phaleththat's nice
  23. blueyes
  24. phalethtailwind pretty much restricts code splitting
  25. blueyes
  26. bluebtw, phaleth, within those nested elements, & refers to the parent element
  27. phalethok
  28. bluephaleth: ssh://gitea.repopack.app:2200/repopack/website.git
  29. blueor rather, the web address, I mean
  30. blueI shoved out a big updated, though it's not ready for deployment yet
  31. blueupdate*
  32. blueif you do wish to have a look at it locally, you need a local postgres db which you can configure in .env.local
  33. blueI got the git stuff mostly done for browsing files, now doing items / apps
  34. phalethok, is the update on master branch? looks like master is 1 month old
  35. blueyes. I've squashed and force-pushed, so it would show that way
  36. phalethah, ok, I see the nested css
  37. blueyeah, there's still a lot of nonsense I need to clean up
  38. phalethwell, I gotta figure out how to run rootful podman without sudo
  39. blueya
  40. phalethguess using tcp instead of unix sockets should do
  41. blueso once I finish the items view, I'll do the apps view. and then we'll need the podman api to work
  42. bluewe also need ssh to work on port 22 on repopack.com
  43. bluethat can happen later, but we do need it
  44. blueby which I meant git+ssh, using the git@ user
  45. blueso you can do `git clone git@repopack.com/primate/primate`
  46. blueI mean `git clone git@repopack.com:primate/primate`
  47. bluethe rp repo itself will be under the repopack org, /web, I think
  48. bluethen we can move everything else from gitea
  49. phalethprolly only a git user is needed the, doesn't need to have sudo privs or really shouldn't need sudo privs at all
  50. blueyes
  51. phalethcause ssh connectivity is available to repopack.com
  52. blueyes. we only need to figure how we map the paths, you know?
  53. blueso git clone git@repopack.com/repopack/web needs to map to wherever the repo is. and the problem is we need to check for permissions
  54. phalethonly haproxy comes to mind atm, cause ssh is tcp
  55. blueugh, I keep writing / instead of :
  56. blueso we need to pass those git operations through a filter that checks against the db, that's the only difficult part
  57. phalethcheck for permissions against database user?
  58. bluein the past, when I was doing adaptivecloud, I used the ssh2 package for it
  59. blueyes
  60. phalethI mean, somebody stored in user tables
  61. blueyou need to know if you have permissions to clone the repo / write to it
  62. bluefor that, you need to query the postgres db
  63. phalethah, well, so you need a tcp proxy for node/deno
  64. blueprobably, yes. because, we need to do this:
  65. phalethcause dynamic processing is hard to do with haproxy
  66. bluesomeone uses git clone (or git push) -> we see a pubkey -> pubkey is in db -> we map pubkey to user -> we check if user has permissions to access the repo
  67. phalethhaproxy will just send the path to the tcp proxy behind it
  68. bluethat's fair. the complexity is that haproxy needs to hand in the pubkey
  69. bluesince that's the user identifier here
  70. phalethif it's in a header then that's done automatically
  71. bluecan haproxy do that?
  72. blueI don't think it's in the header, it's a tcp request
  73. phalethoh, right, ssh
  74. blueit's part of the ssh protocol which extends tcp
  75. phaleththat means path is also not available
  76. bluethis is one of the reasons I used https://www.npmjs.com/package/ssh2 for adaptivecloud
  77. bluebut if you have a better idea, I'm open
  78. phalethyeah, use a proper protocol instead of tcp
  79. phalethhaproxy will just had it over as tcp
  80. bluecould haproxy forward the request completely to a backend running ssh2, *if* the user is git?
  81. bluethat would be nice
  82. phalethhaproxy already does that for gitea
  83. blueok, then that's what we're gonna do
  84. phalethit's just the git user is within the gitea container
  85. bluewe could have a git user inside the repopack/web container, too
  86. phalethand so it could be the same for repopack I guess, just run the thing within container
  87. blueyes
  88. blueit would need to be an additional port exposed by the container, but that's ok
  89. phaleththe beauty of ssh is that it's already secure, so there is no need for haproxy to interfere with the traffic and so the repopack website app can do whatever it needs to do
  90. phalethjust like gitea does
  91. blueright. but the reason I was wary to use ssh2 was that it essentially reimplements openssh
  92. bluebut if it runs inside the container I suppose that's ok
  93. bluewe need programmatic ssh, either way
  94. phalethwell, if you really want port 22 then we can reconfigure the openssh server running on the host and put the alternative port number to our ~/.ssh/config on our client machines
  95. phalethso that 22 is free for haproxy to use
  96. blueyes, that's the idea
  97. bluethat way `git clone git@repopack.com:repopack/web` just works
  98. phalethI did 2200 or whatever for gitea cause I don't think it should be made available to like normal public anyway
  99. blueyeah
  100. phalethok, configuring openssh server is easy
  101. bluecool
  102. bluebtw, if you're testing the repopack repo locally, you can add this to your .git/config:
  103. blue[remote "local"] url = /home/blue/git/repopack/repos/primate/primate fetch = +refs/heads/*:refs/remotes/local/*
  104. blue(in 3 lines)
  105. blueand replace the url by your local path to the project
  106. bluethen you boot up the app, create a primate namespace, create a primate project in it, then `git push local` inside your checkout of the primate repo
  107. phalethmight wanna add that to readme
  108. bluethen you can see how it looks
  109. bluek
  110. bluewill do shortly
  111. bluephaleth: I've pushed out instructions, tell me if it's coherent to you
  112. bluehttps://gitea.repopack.app/repopack/website#readme
  113. phalethyeah, never tried devdb
  114. bluethat's my tool
  115. phalethI guess I should try to figure out the non sudo access to podman REST api first
  116. blueyou can also just create a postgres container
  117. phalethyeah :)
  118. phalethblue: the podman API over TCP without sudo is available https://gitea.repopack.app/repopack/provision/commit/e191214fcf86efa04f2830ab1d048dc882c2d037
  119. bluephaleth: awesome!
  120. phalethyeah, it's actually http, will be needed to control podman remotely
  121. bluecool