From 56ff4ca63bcb2089969e325021249af407748f44 Mon Sep 17 00:00:00 2001 From: Jonathan Date: Sat, 11 Oct 2025 13:17:56 +0700 Subject: [PATCH] update cdn docker --- services/cdn/Dockerfile | 67 +++++++++++++++++++++++---------- services/cdn/docker-compose.yml | 8 ++-- 2 files changed, 51 insertions(+), 24 deletions(-) diff --git a/services/cdn/Dockerfile b/services/cdn/Dockerfile index c56849b..20c62e1 100644 --- a/services/cdn/Dockerfile +++ b/services/cdn/Dockerfile @@ -1,38 +1,65 @@ +# Dockerfile FROM python:3.12-slim -ENV PYTHONDONTWRITEBYTECODE=1 \ - PYTHONUNBUFFERED=1 \ - PIP_NO_CACHE_DIR=1 \ - DEBIAN_FRONTEND=noninteractive +# Build-time args +ARG PASSWORD WORKDIR /app -# System deps: exiftool + sshd + bash (sqlite CLI not required for Python sqlite3) -RUN apt-get update \ - && apt-get install -y --no-install-recommends \ +# Prevent interactive prompts & set default DB path (optional, if app uses it) +ENV DEBIAN_FRONTEND=noninteractive +ENV DB_PATH=/data/app.db +ENV PYTHONDONTWRITEBYTECODE=1 \ + PYTHONUNBUFFERED=1 \ + PIP_NO_CACHE_DIR=1 + +# Install packages we need (exiftool, sqlite3, sshd, build tools, editor) +RUN apt-get update && \ + apt-get install -y --no-install-recommends \ libimage-exiftool-perl \ + sqlite3 \ openssh-server \ + build-essential \ bash \ - && rm -rf /var/lib/apt/lists/* + nano \ + && rm -rf /var/lib/apt/lists/* -# Unprivileged user for the app / SSH -RUN useradd -m -d /home/ctfuser -s /bin/bash ctfuser +# Create an unprivileged user for running the app / SSH access +RUN useradd -m -d /home/ctfuser -s /bin/bash ctfuser \ + && if [ -n "${PASSWORD}" ]; then echo "ctfuser:${PASSWORD}" | chpasswd; fi -# SSH minimal setup -RUN mkdir -p /run/sshd && chmod 755 /run/sshd && ssh-keygen -A +# Copy application and requirements +COPY chall/requirements.txt /app/ +RUN pip install --no-cache-dir -r /app/requirements.txt -COPY chall/requirements.txt . -RUN pip install --no-cache-dir -r requirements.txt +COPY chall/ . -COPY /chall /app +# Ensure entrypoint exists and is executable (keeps your existing entrypoint.sh) +RUN chmod +x /app/entrypoint.sh || true -RUN chmod +x /app/entrypoint.sh && mkdir -p /app/uploads && chmod 755 /app/uploads +# Create needed directories and set permissions +RUN mkdir -p /data /app/uploads /run/sshd /notes \ + && chown -R ctfuser:ctfuser /app /app/uploads /notes \ + && chmod 755 /app \ + && chmod 777 /app/uploads +# (intentionally NOT chowning /data here; we’ll fix /data at runtime in case it’s a bind mount) -RUN mkdir -p /data /app/uploads /run/sshd \ - && chown -R ctfuser:ctfuser /app /app/uploads /data \ - && chmod 755 /app +# Create the flag file with safe perms (will be overwritten at runtime if FLAG is set) +RUN touch /flag.txt && chown root:root /flag.txt && chmod 644 /flag.txt +# Configure basic sshd options +RUN echo "PasswordAuthentication yes" >> /etc/ssh/sshd_config && \ + echo "PermitRootLogin no" >> /etc/ssh/sshd_config && \ + echo "AllowUsers ctfuser" >> /etc/ssh/sshd_config && \ + echo "PermitEmptyPasswords no" >> /etc/ssh/sshd_config + +# Generate host keys and make sure /run/sshd exists +RUN ssh-keygen -A || true +RUN mkdir -p /run/sshd && chmod 755 /run/sshd + +# Expose app and ssh ports EXPOSE 8000 EXPOSE 22 -ENTRYPOINT ["/bin/bash", "/app/entrypoint.sh"] +USER root +CMD ["/app/entrypoint.sh"] diff --git a/services/cdn/docker-compose.yml b/services/cdn/docker-compose.yml index 1985562..bd42ecb 100644 --- a/services/cdn/docker-compose.yml +++ b/services/cdn/docker-compose.yml @@ -3,13 +3,13 @@ services: cdn_services: container_name: cdn_container hostname: cdn - build: . + build: + context: . + args: + - PASSWORD=root ports: - "4500:8000" # app - "4522:22" # ssh environment: SECRET_KEY: "c75f1259a4c95bb31563405d488d7bf9c0eaf4d562fd13557624f8e18eb5cfff" - # Optional: set SSH password for ctfuser at runtime - SSH_PASSWORD: "root" - # Optional: override if your app reads it restart: always