Skip to content

Share an environment#

An environment is its owner's. Share it with people of the workspace and they may SSH into it, open its IDE and its apps as the owner does — each with their own certificate, so its sessions say who connected. Taking someone off refuses their next connection.

Before you begin#

  • To be the environment's owner, or an admin of the workspace: only they share it.
  • The people you share with must be editors or admins of the workspace (or admins of its organisation). Viewers reach no runtime, shared with or not.
  • For the API tabs, ASTRAEUS_TOKEN, CONSOLE and API as in Create and change a runtime.

Share it#

  1. Open Hesperus → Environments and the environment.
  2. Under People, Shared with, choose a person in Add a person…. It is saved at once. The remove button (×) beside a name takes them off.

When you create one, New environment → Share with does the same.

$ astra env share dev [email protected]
dev is shared with [email protected]: `astra ssh dev` from their computer
$ astra env unshare dev [email protected]
dev is no longer shared with [email protected]: their next connection is refused (one already open runs until it closes)

At creation, --share <e-mail> (repeatable). A person is found by e-mail among the workspace's members and the organisation's admins; anyone else is refused: … is not a member of workspace <workspace>: add them in the console (Settings → Members) first.

The list replaces who it was shared with. People are user:<id>, the user_id of the workspace's members:

$ curl -fsS "$CONSOLE/members" -H "Authorization: Bearer $ASTRAEUS_TOKEN" | jq -r '.items[] | "\(.user_id) \(.email) \(.role)"'
$ curl -fsS -X PUT "$API/notebook-runtimes/dev/members" -H "Authorization: Bearer $ASTRAEUS_TOKEN" \
    -H 'content-type: application/json' \
    -d '{"members": ["user:<their user id>"]}' | jq '.spec.members'

At most 50 people; the owner and repeats are dropped. Anyone else than the owner or an admin is refused with 403 SSH_FORBIDDEN (only runtime dev's owner and the workspace's admins share it).

What the people you share with can do#

  • SSH: astra ssh dev from their computer, with a certificate of their own (Use ssh, scp and rsync). astra ssh config writes hosts only for runtimes they own, so for a shared one they use astra ssh <name>.
  • The IDE: Open IDE or astra env open dev for an IDE environment (Open the IDE in the browser).
  • Apps: open, name and forget its apps (Open a port as an app).

They log in as the environment's one login user (root unless set), so they share its home on the drive: agree on a directory each under /content. Each person's sessions are recorded under their own name (Sessions and audit).

What they cannot do: share it further, or change who it is shared with. Stopping, starting and deleting are not part of sharing: any editor of the workspace may stop, start or delete any runtime.

Taking someone off is checked on their next connection or request; one already open runs until it closes. A certificate already issued reaches nothing once they are off.