Files
MythEclipse ef385c3397 fix: get all imported challenges building and running
Root causes found by prebuilding every challenge image in parallel:
- fjb: ghcr.io base is not anonymously pullable here -> official httpd:2.4.
  pnpm 12 (via corepack on node:20) fails the install with
  ERR_PNPM_IGNORED_BUILDS unless build scripts are approved; neither
  onlyBuiltDependencies in pnpm-workspace.yaml nor --no-ignore-scripts
  suppresses it. The working sequence is:
    pnpm install --ignore-scripts && pnpm approve-builds --all && pnpm rebuild
- xl + kode-viewer: node:20-slim-bookworm is not a real tag -> node:20-bookworm-slim.
- burvesigner: python-dev no longer exists in bookworm -> dropped (python3-dev
  was already there and the source has no py2 syntax).
- burvesigner/hirnfick/s3: apt update and install were separate RUN layers;
  with the bundled apt-insecure.conf the second invocation re-resolved against
  the EOL bullseye-security mirror and 404'd every package. Merged into one
  'update && install' layer (fix_apt_layers.py, idempotent).
- consolidate_images.sh: teams used to build a private image per team
  (team1-x ... team4-x) because no shared image existed. Since the password is
  applied at runtime via chpasswd, one shared services-<name> build is enough;
  this reclaims ~1.5 GB, which matters on a 79 GB disk.
- reconcile_team_state(): a challenge enabled while a team was down left
  state.json without ports/flag/password, so the next compose render died with
  KeyError. Now both the API and the CLI tools reconcile first.
2026-09-25 21:03:29 +08:00

81 lines
2.3 KiB
Docker

FROM node:20-slim AS base
ENV PNPM_HOME="/pnpm"
ENV PATH="$PNPM_HOME:$PATH"
RUN corepack enable
WORKDIR /app
# pnpm >=10 blocks dependency lifecycle scripts by default and then FAILS the
# install with ERR_PNPM_IGNORED_BUILDS (pnpm 12 still does this even with
# onlyBuiltDependencies in pnpm-workspace.yaml, and --no-ignore-scripts does not
# suppress the error either). esbuild's postinstall places the platform binary
# the Vite build needs, so approve pending build scripts non-interactively.
# --frozen-lockfile is dropped because the added config keys change the lockfile
# hash and would fail the install outright.
COPY ./frontend/pnpm-workspace.yaml ./frontend/package.json ./frontend/pnpm-lock.yaml /app/
RUN pnpm install --ignore-scripts \
&& pnpm approve-builds --all \
&& pnpm rebuild
FROM base AS build
COPY ./frontend/ /app/
RUN pnpm run build
# NOTE: upstream pinned ghcr.io/circleous/httpd, but ghcr.io is not
# anonymously pullable from this host ("failed to fetch oauth token: denied").
# The bundled httpd.conf only uses stock Apache 2.4 modules, so the official
# Docker Hub httpd:2.4 image is a drop-in replacement.
FROM httpd:2.4
WORKDIR /app
COPY ./kauth /app/kauth/
RUN set eux; \
apt-get update; \
apt-get install -y --no-install-recommends \
openssh-server \
pkg-config \
gcc \
curl \
make \
lua5.3 \
liblua5.3-dev \
libsodium-dev \
libsqlite3-dev \
luarocks \
; \
luarocks-5.3 install lua-cjson; \
luarocks-5.3 install lsqlite3; \
luarocks-5.3 install bcrypt; \
cd kauth; \
luarocks-5.3 make; \
cd ..; \
rm -rf kauth;\
apt-get remove -y \
pkg-config \
gcc \
make \
lua5.3 \
liblua5.3-dev; \
echo root:${PASSWORD} | chpasswd \
echo "PasswordAuthentication yes" >> /etc/ssh/sshd_config; \
echo "PermitRootLogin yes" >> /etc/ssh/sshd_config; \
service ssh start; \
apt-get purge -y --auto-remove -o APT::AutoRemove::RecommendsImportant=false;
COPY httpd-foreground /usr/local/bin/
COPY ./httpd.conf /usr/local/apache2/conf/httpd.conf
COPY --chown=www-data:www-data ./fjb.db /app/data/fjb.db
COPY --from=build /app/dist /usr/local/apache2/htdocs
COPY ./src/ /app/lua/
RUN sed -ri "s/SECRETSECRETSECRETSECRETSECRETSE/$(openssl rand -hex 16)/g" /app/lua/secret.lua && \
chmod 644 /app/lua/secret.lua
EXPOSE 80
CMD ["httpd-foreground"]