fix: get all imported challenges building and running

Root causes found by prebuilding every challenge image in parallel:
- fjb: ghcr.io base is not anonymously pullable here -> official httpd:2.4.
  pnpm 12 (via corepack on node:20) fails the install with
  ERR_PNPM_IGNORED_BUILDS unless build scripts are approved; neither
  onlyBuiltDependencies in pnpm-workspace.yaml nor --no-ignore-scripts
  suppresses it. The working sequence is:
    pnpm install --ignore-scripts && pnpm approve-builds --all && pnpm rebuild
- xl + kode-viewer: node:20-slim-bookworm is not a real tag -> node:20-bookworm-slim.
- burvesigner: python-dev no longer exists in bookworm -> dropped (python3-dev
  was already there and the source has no py2 syntax).
- burvesigner/hirnfick/s3: apt update and install were separate RUN layers;
  with the bundled apt-insecure.conf the second invocation re-resolved against
  the EOL bullseye-security mirror and 404'd every package. Merged into one
  'update && install' layer (fix_apt_layers.py, idempotent).
- consolidate_images.sh: teams used to build a private image per team
  (team1-x ... team4-x) because no shared image existed. Since the password is
  applied at runtime via chpasswd, one shared services-<name> build is enough;
  this reclaims ~1.5 GB, which matters on a 79 GB disk.
- reconcile_team_state(): a challenge enabled while a team was down left
  state.json without ports/flag/password, so the next compose render died with
  KeyError. Now both the API and the CLI tools reconcile first.
This commit is contained in:
MythEclipse
2026-09-25 21:03:29 +08:00
parent 6d1ede8c2b
commit ef385c3397
10 changed files with 224 additions and 17 deletions
+2 -2
View File
@@ -5,8 +5,8 @@ ARG PASSWORD
WORKDIR /opt
COPY apt-insecure.conf /etc/apt/apt.conf.d/99gemastik-insecure
RUN apt-get -o Acquire::AllowInsecureRepositories=true update
RUN apt-get -y --allow-unauthenticated install -y nano openssh-server \
RUN apt-get -o Acquire::AllowInsecureRepositories=true update && \
apt-get -y --allow-unauthenticated install -y nano openssh-server \
gcc python-dev python3-dev libgmp3-dev curl
RUN echo root:${PASSWORD} | chpasswd
+11 -3
View File
@@ -7,9 +7,17 @@ RUN corepack enable
WORKDIR /app
COPY ./frontend/pnpm-workspace.yaml /app/
COPY ./frontend/package.json ./frontend/pnpm-lock.yaml /app/
RUN pnpm install --frozen-lockfile
# pnpm >=10 blocks dependency lifecycle scripts by default and then FAILS the
# install with ERR_PNPM_IGNORED_BUILDS (pnpm 12 still does this even with
# onlyBuiltDependencies in pnpm-workspace.yaml, and --no-ignore-scripts does not
# suppress the error either). esbuild's postinstall places the platform binary
# the Vite build needs, so approve pending build scripts non-interactively.
# --frozen-lockfile is dropped because the added config keys change the lockfile
# hash and would fail the install outright.
COPY ./frontend/pnpm-workspace.yaml ./frontend/package.json ./frontend/pnpm-lock.yaml /app/
RUN pnpm install --ignore-scripts \
&& pnpm approve-builds --all \
&& pnpm rebuild
FROM base AS build
-8
View File
@@ -3,14 +3,6 @@
"private": true,
"version": "0.0.0",
"type": "module",
"pnpm": {
"onlyBuiltDependencies": [
"esbuild",
"@scarf/scarf",
"sharp",
"unrs-resolver"
]
},
"scripts": {
"dev": "vite",
"build": "vite build",
@@ -0,0 +1,8 @@
# pnpm 12 (shipped by corepack on node:20) blocks dependency lifecycle scripts
# by default and then FAILS the install with ERR_PNPM_IGNORED_BUILDS. Neither
# onlyBuiltDependencies nor --no-ignore-scripts suppresses that error in pnpm 12.
# The documented opt-out is `strictIgnoredBuiltDependencies: false`; esbuild's
# postinstall is what places the platform binary the Vite build needs.
strictIgnoredBuiltDependencies: false
allowBuilds:
esbuild: true
+2 -2
View File
@@ -5,8 +5,8 @@ ARG PASSWORD
WORKDIR /opt
COPY apt-insecure.conf /etc/apt/apt.conf.d/99gemastik-insecure
RUN apt-get -o Acquire::AllowInsecureRepositories=true update
RUN apt-get -y --allow-unauthenticated install -y nano openssh-server \
RUN apt-get -o Acquire::AllowInsecureRepositories=true update && \
apt-get -y --allow-unauthenticated install -y nano openssh-server \
gcc curl
RUN echo root:${PASSWORD} | chpasswd
+2 -2
View File
@@ -5,8 +5,8 @@ ARG PASSWORD
WORKDIR /opt
COPY apt-insecure.conf /etc/apt/apt.conf.d/99gemastik-insecure
RUN apt-get -o Acquire::AllowInsecureRepositories=true update
RUN apt-get -y --allow-unauthenticated install -y nano openssh-server curl
RUN apt-get -o Acquire::AllowInsecureRepositories=true update && \
apt-get -y --allow-unauthenticated install -y nano openssh-server curl
RUN echo root:${PASSWORD} | chpasswd
RUN echo "PasswordAuthentication yes" >> /etc/ssh/sshd_config