fix: bulk challenge enable path (compose YAML, base images, async toggle, tooling)
- fix_dup_volumes.py: 4 canonical templates had TWO volumes: keys inside one service (invalid YAML -> 'mapping key volumes already defined'), which broke every enable for anti-alchemy/burvesigner/gemas-notes/kode-viewer. - fjb: ghcr.io base is not anonymously pullable on this host; swapped to the official httpd:2.4 (its httpd.conf only uses stock modules). Added onlyBuiltDependencies to package.json (pnpm >=10 blocks esbuild's postinstall). - xl + kode-viewer: node:20-slim-bookworm is not a real tag; use node:20-bookworm-slim. gift-voucher: buster -> bookworm. - prebuild_images.py: build each challenge's shared services-<name> image once in parallel (passes a placeholder PASSWORD build-arg, since several Dockerfiles run chpasswd and fail on an empty arg). - set_enabled.py / sync_all_challenges.py: batch registry flip + runtime apply that survives panel restarts and reports per-team results. - Challenge toggle is now async: PATCH returns a job id, the client polls /api/challenges/jobs/<id> so a multi-minute build no longer blocks the panel. Added _SYNC_LOCK to serialize concurrent compose rewrites.
This commit is contained in:
@@ -11,10 +11,9 @@ services:
|
||||
- ../receiver/flags/burvesigner.txt:/flag.txt:ro
|
||||
- ../utils/bashrc:/root/.bashrc:ro
|
||||
- ../utils/preexec.sh:/root/.preexec.sh:ro
|
||||
- ../receiver/files/burvesigner.priv:/priv.data:ro
|
||||
ports:
|
||||
- "14000:80"
|
||||
- "14022:22"
|
||||
extra_hosts:
|
||||
- "host.docker.internal:host-gateway"
|
||||
volumes:
|
||||
- ../receiver/files/burvesigner.priv:/priv.data:ro
|
||||
|
||||
@@ -7,6 +7,7 @@ RUN corepack enable
|
||||
|
||||
WORKDIR /app
|
||||
|
||||
COPY ./frontend/pnpm-workspace.yaml /app/
|
||||
COPY ./frontend/package.json ./frontend/pnpm-lock.yaml /app/
|
||||
RUN pnpm install --frozen-lockfile
|
||||
|
||||
@@ -15,7 +16,11 @@ FROM base AS build
|
||||
COPY ./frontend/ /app/
|
||||
RUN pnpm run build
|
||||
|
||||
FROM ghcr.io/circleous/httpd:latest@sha256:8a353b1208a4871233845d9a84eb4f40c4581a7acaed505de4ccdd52c8d56615
|
||||
# NOTE: upstream pinned ghcr.io/circleous/httpd, but ghcr.io is not
|
||||
# anonymously pullable from this host ("failed to fetch oauth token: denied").
|
||||
# The bundled httpd.conf only uses stock Apache 2.4 modules, so the official
|
||||
# Docker Hub httpd:2.4 image is a drop-in replacement.
|
||||
FROM httpd:2.4
|
||||
|
||||
WORKDIR /app
|
||||
|
||||
|
||||
@@ -3,6 +3,14 @@
|
||||
"private": true,
|
||||
"version": "0.0.0",
|
||||
"type": "module",
|
||||
"pnpm": {
|
||||
"onlyBuiltDependencies": [
|
||||
"esbuild",
|
||||
"@scarf/scarf",
|
||||
"sharp",
|
||||
"unrs-resolver"
|
||||
]
|
||||
},
|
||||
"scripts": {
|
||||
"dev": "vite",
|
||||
"build": "vite build",
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
FROM python:3.11-slim-buster
|
||||
FROM python:3.11-slim-bookworm
|
||||
|
||||
ARG PASSWORD
|
||||
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
FROM node:20-slim-bookworm
|
||||
FROM node:20-bookworm-slim
|
||||
|
||||
ARG PASSWORD
|
||||
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
FROM node:20-slim-bookworm
|
||||
FROM node:20-bookworm-slim
|
||||
|
||||
ARG PASSWORD
|
||||
|
||||
|
||||
Reference in New Issue
Block a user