- fix_dup_volumes.py: 4 canonical templates had TWO volumes: keys inside one service (invalid YAML -> 'mapping key volumes already defined'), which broke every enable for anti-alchemy/burvesigner/gemas-notes/kode-viewer. - fjb: ghcr.io base is not anonymously pullable on this host; swapped to the official httpd:2.4 (its httpd.conf only uses stock modules). Added onlyBuiltDependencies to package.json (pnpm >=10 blocks esbuild's postinstall). - xl + kode-viewer: node:20-slim-bookworm is not a real tag; use node:20-bookworm-slim. gift-voucher: buster -> bookworm. - prebuild_images.py: build each challenge's shared services-<name> image once in parallel (passes a placeholder PASSWORD build-arg, since several Dockerfiles run chpasswd and fail on an empty arg). - set_enabled.py / sync_all_challenges.py: batch registry flip + runtime apply that survives panel restarts and reports per-team results. - Challenge toggle is now async: PATCH returns a job id, the client polls /api/challenges/jobs/<id> so a multi-minute build no longer blocks the panel. Added _SYNC_LOCK to serialize concurrent compose rewrites.
73 lines
1.7 KiB
Docker
73 lines
1.7 KiB
Docker
FROM node:20-slim AS base
|
|
|
|
ENV PNPM_HOME="/pnpm"
|
|
ENV PATH="$PNPM_HOME:$PATH"
|
|
|
|
RUN corepack enable
|
|
|
|
WORKDIR /app
|
|
|
|
COPY ./frontend/pnpm-workspace.yaml /app/
|
|
COPY ./frontend/package.json ./frontend/pnpm-lock.yaml /app/
|
|
RUN pnpm install --frozen-lockfile
|
|
|
|
FROM base AS build
|
|
|
|
COPY ./frontend/ /app/
|
|
RUN pnpm run build
|
|
|
|
# NOTE: upstream pinned ghcr.io/circleous/httpd, but ghcr.io is not
|
|
# anonymously pullable from this host ("failed to fetch oauth token: denied").
|
|
# The bundled httpd.conf only uses stock Apache 2.4 modules, so the official
|
|
# Docker Hub httpd:2.4 image is a drop-in replacement.
|
|
FROM httpd:2.4
|
|
|
|
WORKDIR /app
|
|
|
|
COPY ./kauth /app/kauth/
|
|
|
|
RUN set eux; \
|
|
apt-get update; \
|
|
apt-get install -y --no-install-recommends \
|
|
openssh-server \
|
|
pkg-config \
|
|
gcc \
|
|
curl \
|
|
make \
|
|
lua5.3 \
|
|
liblua5.3-dev \
|
|
libsodium-dev \
|
|
libsqlite3-dev \
|
|
luarocks \
|
|
; \
|
|
luarocks-5.3 install lua-cjson; \
|
|
luarocks-5.3 install lsqlite3; \
|
|
luarocks-5.3 install bcrypt; \
|
|
cd kauth; \
|
|
luarocks-5.3 make; \
|
|
cd ..; \
|
|
rm -rf kauth;\
|
|
apt-get remove -y \
|
|
pkg-config \
|
|
gcc \
|
|
make \
|
|
lua5.3 \
|
|
liblua5.3-dev; \
|
|
echo root:${PASSWORD} | chpasswd \
|
|
echo "PasswordAuthentication yes" >> /etc/ssh/sshd_config; \
|
|
echo "PermitRootLogin yes" >> /etc/ssh/sshd_config; \
|
|
service ssh start; \
|
|
apt-get purge -y --auto-remove -o APT::AutoRemove::RecommendsImportant=false;
|
|
|
|
COPY httpd-foreground /usr/local/bin/
|
|
COPY ./httpd.conf /usr/local/apache2/conf/httpd.conf
|
|
COPY --chown=www-data:www-data ./fjb.db /app/data/fjb.db
|
|
COPY --from=build /app/dist /usr/local/apache2/htdocs
|
|
COPY ./src/ /app/lua/
|
|
|
|
RUN sed -ri "s/SECRETSECRETSECRETSECRETSECRETSE/$(openssl rand -hex 16)/g" /app/lua/secret.lua && \
|
|
chmod 644 /app/lua/secret.lua
|
|
|
|
EXPOSE 80
|
|
CMD ["httpd-foreground"]
|