Root causes found by prebuilding every challenge image in parallel:
- fjb: ghcr.io base is not anonymously pullable here -> official httpd:2.4.
pnpm 12 (via corepack on node:20) fails the install with
ERR_PNPM_IGNORED_BUILDS unless build scripts are approved; neither
onlyBuiltDependencies in pnpm-workspace.yaml nor --no-ignore-scripts
suppresses it. The working sequence is:
pnpm install --ignore-scripts && pnpm approve-builds --all && pnpm rebuild
- xl + kode-viewer: node:20-slim-bookworm is not a real tag -> node:20-bookworm-slim.
- burvesigner: python-dev no longer exists in bookworm -> dropped (python3-dev
was already there and the source has no py2 syntax).
- burvesigner/hirnfick/s3: apt update and install were separate RUN layers;
with the bundled apt-insecure.conf the second invocation re-resolved against
the EOL bullseye-security mirror and 404'd every package. Merged into one
'update && install' layer (fix_apt_layers.py, idempotent).
- consolidate_images.sh: teams used to build a private image per team
(team1-x ... team4-x) because no shared image existed. Since the password is
applied at runtime via chpasswd, one shared services-<name> build is enough;
this reclaims ~1.5 GB, which matters on a 79 GB disk.
- reconcile_team_state(): a challenge enabled while a team was down left
state.json without ports/flag/password, so the next compose render died with
KeyError. Now both the API and the CLI tools reconcile first.
27 lines
657 B
Docker
27 lines
657 B
Docker
FROM python:3.11-slim-bookworm@sha256:a201e091d3e0ccf42319402822b16d23cbcd74ff0576d51622a5e88f63fc85ac
|
|
|
|
ARG PASSWORD
|
|
|
|
WORKDIR /opt
|
|
|
|
COPY apt-insecure.conf /etc/apt/apt.conf.d/99gemastik-insecure
|
|
RUN apt-get -o Acquire::AllowInsecureRepositories=true update && \
|
|
apt-get -y --allow-unauthenticated install -y nano openssh-server \
|
|
gcc curl
|
|
|
|
RUN echo root:${PASSWORD} | chpasswd
|
|
RUN echo "PasswordAuthentication yes" >> /etc/ssh/sshd_config
|
|
RUN echo "PermitRootLogin yes" >> /etc/ssh/sshd_config
|
|
RUN service ssh start
|
|
|
|
COPY src/ .
|
|
RUN touch /flag.txt
|
|
|
|
RUN pip install -r requirements.txt
|
|
RUN chmod +x ./start.sh
|
|
|
|
EXPOSE 8000
|
|
EXPOSE 22
|
|
|
|
CMD ./start.sh
|