#!/bin/bash # Trial parity: limit DNS to the model endpoint and the toolkit's telemetry, so a session # captured here cannot depend on network the trial agent will not have. Opt-in, best-effort. # # Its own lifecycle step, NOT part of post-start.sh: post-create.sh calls post-start to get # postgres up before it installs the repo's dependencies, so a jail applied there breaks # `bundle install` on every fresh container. postStartCommand runs after postCreateCommand. set -u [ -f /workspace/.devcontainer/dns-jail.sh ] || exit 0 # Read the one line rather than sourcing: with the jail off this must not execute the # worker's .env as a side effect. if [ "${RACCOON_DNS_JAIL:-0}" != "1" ] && ! grep -qE '^[[:space:]]*(export[[:space:]]+)?RACCOON_DNS_JAIL[[:space:]]*=[[:space:]]*"?1"?[[:space:]]*(#.*)?$' \ /workspace/.env 2>/dev/null; then exit 0 fi ( set -a # shellcheck disable=SC1091 . /workspace/.env 2>/dev/null || true set +a bash /workspace/.devcontainer/dns-jail.sh ) || true