Files
attack-defense-platform/services/cdn/Dockerfile
T
root 24dbf0a662 draggable topology + attack visualizer + tools in containers
- topology nodes draggable (pointer events, SVG transform), layout hint shown
- attack visualizer: /api/attacks logs attacker->target events; red pulsing
  dashed arcs on recent attacks (60s hot), ⚔ counts ok/fail
- submit_flag now takes attacker_idx vs target_idx (A/D semantics); UI has
  target dropdown (enemy teams), leaderboard records target
- containers get vim+curl+wget+netcat+git+pip3 (Dockerfiles blogpost/cdn/
  phew/sheesh/warmup); warmup base ubuntu:20.04 EOL -> 24.04
- team portal: target dropdown refreshed after login (was empty pre-auth)
2026-09-23 18:05:44 +08:00

72 lines
2.1 KiB
Docker
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Dockerfile
FROM python:3.12-slim
# Build-time args
ARG PASSWORD
WORKDIR /app
# Prevent interactive prompts & set default DB path (optional, if app uses it)
ENV DEBIAN_FRONTEND=noninteractive
ENV DB_PATH=/data/app.db
ENV PYTHONDONTWRITEBYTECODE=1 \
PYTHONUNBUFFERED=1 \
PIP_NO_CACHE_DIR=1
# Install packages we need (exiftool, sqlite3, sshd, build tools, editor)
RUN apt-get update && \
apt-get install -y --no-install-recommends \
libimage-exiftool-perl \
sqlite3 \
openssh-server \
build-essential \
bash \
nano \
vim \
curl \
wget \
netcat-openbsd \
git \
python3-pip \
&& rm -rf /var/lib/apt/lists/*
# Create an unprivileged user for running the app / SSH access
RUN useradd -m -d /home/ctfuser -s /bin/bash ctfuser \
&& if [ -n "${PASSWORD}" ]; then echo "ctfuser:${PASSWORD}" | chpasswd; fi
# Copy application and requirements
COPY chall/requirements.txt /app/
RUN pip install --no-cache-dir -r /app/requirements.txt
COPY chall/ .
# Ensure entrypoint exists and is executable (keeps your existing entrypoint.sh)
RUN chmod +x /app/entrypoint.sh || true
# Create needed directories and set permissions
RUN mkdir -p /data /app/uploads /run/sshd /notes \
&& chown -R ctfuser:ctfuser /app /app/uploads /notes \
&& chmod 755 /app \
&& chmod 777 /app/uploads
# (intentionally NOT chowning /data here; we’ll fix /data at runtime in case it’s a bind mount)
# Create the flag file with safe perms (will be overwritten at runtime if FLAG is set)
RUN touch /flag.txt && chown root:root /flag.txt && chmod 644 /flag.txt
# Configure basic sshd options
RUN echo "PasswordAuthentication yes" >> /etc/ssh/sshd_config && \
echo "PermitRootLogin no" >> /etc/ssh/sshd_config && \
echo "AllowUsers ctfuser" >> /etc/ssh/sshd_config && \
echo "PermitEmptyPasswords no" >> /etc/ssh/sshd_config
# Generate host keys and make sure /run/sshd exists
RUN ssh-keygen -A || true
RUN mkdir -p /run/sshd && chmod 755 /run/sshd
# Expose app and ssh ports
EXPOSE 8000
EXPOSE 22
USER root
CMD ["/app/entrypoint.sh"]