Files
attack-defense-platform/services/blogpost/Dockerfile
T
Hermes 7d6258e94e fix: use bookworm base for blogpost; route receiver history via :18080
- blogpost: python:3.11-slim-bullseye is EOL (apt 404s), switch to bookworm
- utils/bashrc: host port 80 is taken by Traefik/Coolify, preexec posts to :18080
- ignore receiver .venv
2026-09-23 13:54:46 +08:00

65 lines
2.0 KiB
Docker
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Dockerfile
# python:3.11-slim-bookworm (Debian 12, supported) — bullseye is EOL and its
# apt repos 404, so we build on the current stable slim image instead.
FROM python:3.11-slim-bookworm
# Build-time args
ARG PASSWORD
WORKDIR /app
# Prevent interactive prompts during apt installs
ENV DEBIAN_FRONTEND=noninteractive
ENV DB_PATH=/data/app.db
# Install packages we need (exiftool, sqlite3, sshd, build tools, editor)
RUN apt-get update && \
apt-get install -y --no-install-recommends \
libimage-exiftool-perl \
sqlite3 \
openssh-server \
build-essential \
bash \
nano \
&& rm -rf /var/lib/apt/lists/*
# Create an unprivileged user for running the app / SSH access
RUN useradd -m -d /home/ctfuser -s /bin/bash ctfuser \
&& if [ -n "${PASSWORD}" ]; then echo "ctfuser:${PASSWORD}" | chpasswd; fi
# Copy application and requirements
COPY chall/requirements.txt /app/
RUN pip install --no-cache-dir -r /app/requirements.txt
COPY chall/ .
# Ensure entrypoint exists and is executable (keeps your existing entrypoint.sh)
RUN chmod +x /app/entrypoint.sh || true
# Create needed directories and set permissions
RUN mkdir -p /data /app/uploads /run/sshd /notes \
&& chown -R ctfuser:ctfuser /app /app/uploads /notes \
&& chmod 755 /app \
&& chmod 777 /app/uploads
# (intentionally NOT chowning /data here; we’ll fix /data at runtime in case it’s a bind mount)
# Create the flag file with safe perms (will be overwritten at runtime if FLAG is set)
RUN touch /flag.txt && chown root:root /flag.txt && chmod 644 /flag.txt
# Configure basic sshd options
RUN echo "PasswordAuthentication yes" >> /etc/ssh/sshd_config && \
echo "PermitRootLogin no" >> /etc/ssh/sshd_config && \
echo "AllowUsers ctfuser" >> /etc/ssh/sshd_config && \
echo "PermitEmptyPasswords no" >> /etc/ssh/sshd_config
# Generate host keys and make sure /run/sshd exists
RUN ssh-keygen -A || true
RUN mkdir -p /run/sshd && chmod 755 /run/sshd
# Expose app and ssh ports
EXPOSE 8000
EXPOSE 22
USER root
CMD ["/app/entrypoint.sh"]