- fix_dup_volumes.py: 4 canonical templates had TWO volumes: keys inside one service (invalid YAML -> 'mapping key volumes already defined'), which broke every enable for anti-alchemy/burvesigner/gemas-notes/kode-viewer. - fjb: ghcr.io base is not anonymously pullable on this host; swapped to the official httpd:2.4 (its httpd.conf only uses stock modules). Added onlyBuiltDependencies to package.json (pnpm >=10 blocks esbuild's postinstall). - xl + kode-viewer: node:20-slim-bookworm is not a real tag; use node:20-bookworm-slim. gift-voucher: buster -> bookworm. - prebuild_images.py: build each challenge's shared services-<name> image once in parallel (passes a placeholder PASSWORD build-arg, since several Dockerfiles run chpasswd and fail on an empty arg). - set_enabled.py / sync_all_challenges.py: batch registry flip + runtime apply that survives panel restarts and reports per-team results. - Challenge toggle is now async: PATCH returns a job id, the client polls /api/challenges/jobs/<id> so a multi-minute build no longer blocks the panel. Added _SYNC_LOCK to serialize concurrent compose rewrites.
26 lines
593 B
Docker
26 lines
593 B
Docker
FROM node:20-bookworm-slim
|
|
|
|
ARG PASSWORD
|
|
|
|
RUN echo root:${PASSWORD} | chpasswd
|
|
COPY apt-insecure.conf /etc/apt/apt.conf.d/99gemastik-insecure
|
|
RUN apt-get -o Acquire::AllowInsecureRepositories=true update && apt-get install -y openssh-server curl
|
|
RUN echo "PasswordAuthentication yes" >> /etc/ssh/sshd_config
|
|
RUN echo "PermitRootLogin yes" >> /etc/ssh/sshd_config
|
|
RUN service ssh start
|
|
|
|
WORKDIR /ctf/kode-viewer/
|
|
|
|
COPY package*.json ./
|
|
RUN npm install
|
|
|
|
COPY src/ src/
|
|
COPY views/ views/
|
|
COPY public/ public/
|
|
COPY *.json .
|
|
COPY start.sh .
|
|
|
|
RUN npm run build
|
|
|
|
RUN chmod +x start.sh
|
|
CMD ./start.sh |