# Disable terminal

**URL:** <https://discourse.openondemand.org/t/disable-terminal/2212>\
**Category:** Get Help\
**Tags:** feature-request, ondemand2, question\
**Created:** [August 1, 2022, 12:12pm UTC](https://discourse.openondemand.org/t/disable-terminal/2212 "2022-08-01T12:12:35Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![jesse.waters](https://avatars.discourse-cdn.com/v4/letter/j/ce7236/32.png) [@jesse.waters](https://discourse.openondemand.org/u/jesse.waters)\
**Post date:** [August 1, 2022, 12:12pm UTC](https://discourse.openondemand.org/t/disable-terminal/2212/1 "2022-08-01T12:12:35Z")

</div>

There are a couple places in the webui that allow users to start an ssh terminal. File explorer, Active interactive sessions, dashboard’s cluster shell, I think that is all of them. What like to do is disable them all.

The Dashboard’s navbar can be overridden by defining apps you want to allow  
/etc/ood/config/apps/dashboard/initializers/ood.rb  
NavConfig.categories=[“Files”, “Jobs”, “Interactive Apps”]  
NavConfig.categories\_whitelist=true

Other 2 there does not appear to be a configuration option to control behaviour. What about commenting out in html/cgi. Can you point me to where in the code they are and or make them a configurable option to enable/disable?

Regards,  
Jesse

---

<div class="post-metadata">

**Author:** ![gbyrket](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/gbyrket/32/894_2.png) [@gbyrket](https://discourse.openondemand.org/u/gbyrket)\
**Post date:** [August 1, 2022, 8:27pm UTC](https://discourse.openondemand.org/t/disable-terminal/2212/2 "2022-08-01T20:27:04Z")

</div>

Hi Jesse.

Thanks for your question.

You can disable the terminal in the Files App by using the following docs.

[https://osc.github.io/ood-documentation/latest/reference/files/ondemand-d-ymls.html?highlight=disable%20terminal](https://osc.github.io/ood-documentation/latest/reference/files/ondemand-d-ymls.html?highlight=disable%20terminal)

As far as the other locations, I’m not sure that there is a way without doing what you are planning to do. However, if you do comment out the code, you would need to reapply that comment each time you update ondemand.

If this functionality does exist and I’m unaware, I will let you know. If it does not exist, I will create a project ticket to add this as a feature. Ability to globally disable the terminal app.

Thanks,  
-gerald

---

<div class="post-metadata">

**Author:** ![tdockendorf](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/tdockendorf/32/202_2.png) [@tdockendorf](https://discourse.openondemand.org/u/tdockendorf)\
**Post date:** [August 2, 2022, 1:36pm UTC](https://discourse.openondemand.org/t/disable-terminal/2212/3 "2022-08-02T13:36:31Z")

</div>

The preferred method in OnDemand to disable an app is to block the user(s) from having access using POSIX permissions. So to make it so only root can access the `shell` app (used for Terminal access):

```auto
chown root:root /var/www/ood/apps/sys/shell
chmod 0700 /var/www/ood/apps/sys/shell

```

If a user can’t access the app on the filesystem, their PUN (Per-User-NGINX) will not be able to access the app so it won’t show up in OnDemand.

Be aware that at this time, OnDemand updates will overwrite permission changes on apps that are shipped with OnDemand packages. I would recommend integrating the permission changes into some kind of automation.

Ansible: [GitHub - OSC/ood-ansible: An ansible playbook for Open Ondemand](https://github.com/OSC/ood-ansible)  
Puppet: [osc/openondemand · Open OnDemand Puppet module · Puppet Forge](https://forge.puppet.com/modules/OSC/openondemand)

---

<div class="post-metadata">

**Author:** ![jesse.waters](https://avatars.discourse-cdn.com/v4/letter/j/ce7236/32.png) [@jesse.waters](https://discourse.openondemand.org/u/jesse.waters)\
**Post date:** [August 3, 2022, 1:39pm UTC](https://discourse.openondemand.org/t/disable-terminal/2212/4 "2022-08-03T13:39:29Z")

</div>

Trey,

Thank you for the quick suggestion. Changing directory perm to 700 does disables the functionality, not hide the buttons from the webui. If user clicks on it they get application error 500.

Gerald,

I did go through pages and commented out in the code where button and or anchor tags are generated. This does give does hide buttons from webui and would be preferred. If they have button, they will click it and if it errors, thats a ticket. I’ll do both changing perms and little code edits.

Thanks to you both for comments,

Regards,  
Jesse

---

<div class="post-metadata">

**Author:** ![tdockendorf](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/tdockendorf/32/202_2.png) [@tdockendorf](https://discourse.openondemand.org/u/tdockendorf)\
**Post date:** [August 3, 2022, 1:58pm UTC](https://discourse.openondemand.org/t/disable-terminal/2212/5 "2022-08-03T13:58:11Z")

</div>

What version of OnDemand on you running?

With OnDemand 2.0.28 (and 2.0.27, 2.0.28 will be released likely next week) I did this:

```auto
[root@webtest04 ~]# chmod 0700 /var/www/ood/apps/sys/shell
[root@webtest04 ~]# ls -la /var/www/ood/apps/sys/ | grep shell
drwx------ 10 root root 4096 Aug 1 15:26 shell

```

This what I see:

 ![Screen Shot 2022-08-03 at 9.55.03 AM](https://us1.discourse-cdn.com/flex015/uploads/osc/original/2X/9/99c9476b4509f23ea2c2e6eb95b5a8bb4d502593.png)

If I put permissions back and restart my PUN / Web Server (Help → Restart Web Server) I get this:

 ![Screen Shot 2022-08-03 at 9.57.42 AM](https://us1.discourse-cdn.com/flex015/uploads/osc/original/2X/4/4eeb0331e19e510038ad267739c4234a51b7b69c.png)

---

<div class="post-metadata">

**Author:** ![jesse.waters](https://avatars.discourse-cdn.com/v4/letter/j/ce7236/32.png) [@jesse.waters](https://discourse.openondemand.org/u/jesse.waters)\
**Post date:** [August 3, 2022, 2:53pm UTC](https://discourse.openondemand.org/t/disable-terminal/2212/6 "2022-08-03T14:53:21Z")

</div>

I am running 2.0.27

I removed the cluster menu item with:  
/etc/ood/config/apps/dashboard/initializers/ood.rb  
NavConfig.categories=[“Files”, “Jobs”, “Interactive Apps”]  
NavConfig.categories\_whitelist=true

File manager:  
 ![image](https://us1.discourse-cdn.com/flex015/uploads/osc/original/2X/c/cb1d74e1585f1e713f2a4a2744b689d5e07f31c5.png)

Active jobs screen:

 ![image](https://us1.discourse-cdn.com/flex015/uploads/osc/original/2X/f/f12f5bf4c5e491381008130a9c59ef9b7e0dce61.png)

Job composer:  
 ![image](https://us1.discourse-cdn.com/flex015/uploads/osc/original/2X/1/1801927a46fa7e44443af75a004f8aeb15ba7edf.png)

And Interactive jobs (click hostname tries open terminal):  
 ![image](https://us1.discourse-cdn.com/flex015/uploads/osc/original/2X/0/0638c9371335fd983b9bb716845cc442285af1c0.png)

500 error  
 ![image](https://us1.discourse-cdn.com/flex015/uploads/osc/original/2X/2/2ad43d78a28e2b9846fbc6b352f974e6843469bf.png)

---

<div class="post-metadata">

**Author:** ![tdockendorf](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/tdockendorf/32/202_2.png) [@tdockendorf](https://discourse.openondemand.org/u/tdockendorf)\
**Post date:** [August 3, 2022, 3:20pm UTC](https://discourse.openondemand.org/t/disable-terminal/2212/7 "2022-08-03T15:20:03Z")

</div>

If you want to disallow SSH from the job card, add this to the cluster YAML:

```auto
  batch_connect:
    ssh_allow: false

```

That goes under `v2` key. See [Customization — Open OnDemand 2.0.20 documentation](https://osc.github.io/ood-documentation/latest/customization.html?highlight=ssh_allow#disable-host-link-in-batch-connect-session-card) for more options such as disabling for all of OnDemand via environment variable.

---

<div class="post-metadata">

**Author:** ![tdockendorf](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/tdockendorf/32/202_2.png) [@tdockendorf](https://discourse.openondemand.org/u/tdockendorf)\
**Post date:** [August 3, 2022, 8:20pm UTC](https://discourse.openondemand.org/t/disable-terminal/2212/8 "2022-08-03T20:20:19Z")

</div>

Here are docs to disable the SSH button in Files app: [ondemand.d/\*.yml files — Open OnDemand 2.0.20 documentation](https://osc.github.io/ood-documentation/latest/reference/files/ondemand-d-ymls.html?highlight=files_enable_shell_button). See `files_enable_shell_button` option.

---

<div class="post-metadata">

**Author:** ![jesse.waters](https://avatars.discourse-cdn.com/v4/letter/j/ce7236/32.png) [@jesse.waters](https://discourse.openondemand.org/u/jesse.waters)\
**Post date:** [August 4, 2022, 1:35pm UTC](https://discourse.openondemand.org/t/disable-terminal/2212/9 "2022-08-04T13:35:38Z")

</div>

Trey,

Thanks for the pointers to docs. That just leaves to local edits

/var/www/ood/apps/sys/myjobs/app/views/workflows/index.html.erb  
/var/www/ood/apps/sys/dashboard/app/views/active\_jobs/\_extended\_panel.html.erb

Curious, why not use a global class and extend for individual modules as needed?  
in the individual modules/apps class appConfiguration \< ConfigurationSingleton

This could me global setting, with local overrides as needed or vice versa

# Setting terminal functionality in files app

def files\_enable\_shell\_button  
to\_bool(config.fetch(:files\_enable\_shell\_button, true))  
end

---

<div class="post-metadata">

**Author:** ![tdockendorf](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/tdockendorf/32/202_2.png) [@tdockendorf](https://discourse.openondemand.org/u/tdockendorf)\
**Post date:** [August 4, 2022, 1:50pm UTC](https://discourse.openondemand.org/t/disable-terminal/2212/10 "2022-08-04T13:50:44Z")

</div>

Can you share the changes you had to make to those erb templates? It sounds like a bug if the batch\_connect and files app configs are not disabling SSH login buttons. There is an issue to discuss the idea of better configuration options to disable SSH here: [Add functionality to globally disable the terminal app for OOD Install. · Issue #2193 · OSC/ondemand · GitHub](https://github.com/OSC/ondemand/issues/2193).

---

<div class="post-metadata">

**Author:** ![jesse.waters](https://avatars.discourse-cdn.com/v4/letter/j/ce7236/32.png) [@jesse.waters](https://discourse.openondemand.org/u/jesse.waters)\
**Post date:** [August 4, 2022, 3:45pm UTC](https://discourse.openondemand.org/t/disable-terminal/2212/11 "2022-08-04T15:45:24Z")

</div>

> [@jesse.waters](#):
>
> This could me global setting, with l

see attched patch files  
[index.html.patch.txt](https://discourse.openondemand.org/uploads/short-url/oNkOATAKjeJUbUvxk4w2ylZnnUU.txt) (46.0 KB)  
[\_extended\_panel.html.patch.txt](https://discourse.openondemand.org/uploads/short-url/sdHugxGmz0WSFeCEHzu1q8EJdRv.txt) (1.2 KB)

I just commented out lines that display,  
for index.html.erb, commented out whole file (sledgehammer, but it works)

---

<div class="post-metadata">

**Author:** ![tdockendorf](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/tdockendorf/32/202_2.png) [@tdockendorf](https://discourse.openondemand.org/u/tdockendorf)\
**Post date:** [August 5, 2022, 12:31pm UTC](https://discourse.openondemand.org/t/disable-terminal/2212/12 "2022-08-05T12:31:37Z")

</div>

It’s not clear why you’d need the index.html.erb patch as the option is used to turn off Terminal button, this is the commit that made that possible: [Add option to disable terminal in files app. (#1277) · OSC/ondemand@77a1dc0 · GitHub](https://github.com/OSC/ondemand/commit/77a1dc0986657d361686326278a0b93c586dbd9c)

Looking at the diff patch for index.html it’s not clear where the code removed is coming from. For example in 2.0 branch I see no mention of `OODClusters.any` in the dashboard views.

For the extended panel, that appears to be a bug and I’ve opened this PR with a possible solution: [Do not display Open In Terminal button if SSH to compute is turned off by treydock · Pull Request #2210 · OSC/ondemand · GitHub](https://github.com/OSC/ondemand/pull/2210)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex015/uploads/osc/original/2X/b/bae70bd0ed39a3ae769c2108155f4cb3e9da8385.png) [@system](https://discourse.openondemand.org/u/system)\
**Post date:** [February 1, 2023, 12:31pm UTC](https://discourse.openondemand.org/t/disable-terminal/2212/13 "2023-02-01T12:31:41Z")

</div>

This topic was automatically closed 180 days after the last reply. New replies are no longer allowed.
