Share an environment#
An environment is its owner's. Share it with people of the workspace and they may SSH into it, open its IDE and its apps as the owner does — each with their own certificate, so its sessions say who connected. Taking someone off refuses their next connection.
Before you begin#
- To be the environment's owner, or an admin of the workspace: only they share it.
- The people you share with must be editors or admins of the workspace (or admins of its organisation). Viewers reach no runtime, shared with or not.
- For the API tabs,
ASTRAEUS_TOKEN,CONSOLEandAPIas in Create and change a runtime.
Share it#
- Open Hesperus → Environments and the environment.
- Under People, Shared with, choose a person in Add a person…. It is saved at once. The remove button (×) beside a name takes them off.
When you create one, New environment → Share with does the same.
$ astra env share dev [email protected]
dev is shared with [email protected]: `astra ssh dev` from their computer
$ astra env unshare dev [email protected]
dev is no longer shared with [email protected]: their next connection is refused (one already open runs until it closes)
At creation, --share <e-mail> (repeatable). A person is found by
e-mail among the workspace's members and the organisation's admins;
anyone else is refused: … is not a member of workspace <workspace>: add
them in the console (Settings → Members) first.
The list replaces who it was shared with. People are user:<id>, the
user_id of the workspace's members:
$ curl -fsS "$CONSOLE/members" -H "Authorization: Bearer $ASTRAEUS_TOKEN" | jq -r '.items[] | "\(.user_id) \(.email) \(.role)"'
$ curl -fsS -X PUT "$API/notebook-runtimes/dev/members" -H "Authorization: Bearer $ASTRAEUS_TOKEN" \
-H 'content-type: application/json' \
-d '{"members": ["user:<their user id>"]}' | jq '.spec.members'
At most 50 people; the owner and repeats are dropped. Anyone else than
the owner or an admin is refused with 403 SSH_FORBIDDEN (only
runtime dev's owner and the workspace's admins share it).
What the people you share with can do#
- SSH:
astra ssh devfrom their computer, with a certificate of their own (Use ssh, scp and rsync).astra ssh configwrites hosts only for runtimes they own, so for a shared one they useastra ssh <name>. - The IDE: Open IDE or
astra env open devfor an IDE environment (Open the IDE in the browser). - Apps: open, name and forget its apps (Open a port as an app).
They log in as the environment's one login user (root unless set), so
they share its home on the drive: agree on a directory each under
/content. Each person's sessions are recorded under their own name
(Sessions and audit).
What they cannot do: share it further, or change who it is shared with. Stopping, starting and deleting are not part of sharing: any editor of the workspace may stop, start or delete any runtime.
Taking someone off is checked on their next connection or request; one already open runs until it closes. A certificate already issued reaches nothing once they are off.