Root causes found by prebuilding every challenge image in parallel:
- fjb: ghcr.io base is not anonymously pullable here -> official httpd:2.4.
pnpm 12 (via corepack on node:20) fails the install with
ERR_PNPM_IGNORED_BUILDS unless build scripts are approved; neither
onlyBuiltDependencies in pnpm-workspace.yaml nor --no-ignore-scripts
suppresses it. The working sequence is:
pnpm install --ignore-scripts && pnpm approve-builds --all && pnpm rebuild
- xl + kode-viewer: node:20-slim-bookworm is not a real tag -> node:20-bookworm-slim.
- burvesigner: python-dev no longer exists in bookworm -> dropped (python3-dev
was already there and the source has no py2 syntax).
- burvesigner/hirnfick/s3: apt update and install were separate RUN layers;
with the bundled apt-insecure.conf the second invocation re-resolved against
the EOL bullseye-security mirror and 404'd every package. Merged into one
'update && install' layer (fix_apt_layers.py, idempotent).
- consolidate_images.sh: teams used to build a private image per team
(team1-x ... team4-x) because no shared image existed. Since the password is
applied at runtime via chpasswd, one shared services-<name> build is enough;
this reclaims ~1.5 GB, which matters on a 79 GB disk.
- reconcile_team_state(): a challenge enabled while a team was down left
state.json without ports/flag/password, so the next compose render died with
KeyError. Now both the API and the CLI tools reconcile first.
9 lines
456 B
YAML
9 lines
456 B
YAML
# pnpm 12 (shipped by corepack on node:20) blocks dependency lifecycle scripts
|
|
# by default and then FAILS the install with ERR_PNPM_IGNORED_BUILDS. Neither
|
|
# onlyBuiltDependencies nor --no-ignore-scripts suppresses that error in pnpm 12.
|
|
# The documented opt-out is `strictIgnoredBuiltDependencies: false`; esbuild's
|
|
# postinstall is what places the platform binary the Vite build needs.
|
|
strictIgnoredBuiltDependencies: false
|
|
allowBuilds:
|
|
esbuild: true
|