- Rename repo/domain: attack-defense-platform / attackdefense.imrnes.team (all refs replaced)
- challenge_registry.json: single source of truth (28 challs across gemastik18/xvi/xvii)
- teams.py: registry-driven CHALLENGES, set_challenge_enabled, sync_challenge_runtime
(apply enable/disable to live teams: build/up or stop/remove + receiver restart)
- compose_gen.py: render per-team compose from canonical per-challenge templates
(image reuse, per-team ports 30xxx, flag mounts, passwords)
- gen_canonical_composes.py: canonical docker-compose.yml for all services
- import_new_challenges.py: import XVI/XVII services + EOL base image fixes
(debian:buster→bookworm, node:14→20, python:3.7-slim→3.11)
- receiver: xvi package (10 checkers) + xvii package (12 generic checkers),
Challenge base reads PASSWORD_<team_port> from env; gen_receiver_main.py
generates per-team main.py from registry
- main.py: /api/challenges returns full registry; PATCH /api/challenges/<name>
toggles enabled + applies to live teams
- index.html: 🏗️ Challenge Manager tab (toggle per challenge, grouped by set)
- SLA bonus now dynamic (all enabled challenges, not hardcoded 6)
36 lines
1.1 KiB
Docker
36 lines
1.1 KiB
Docker
FROM public.ecr.aws/docker/library/alpine:latest
|
|
|
|
ARG PASSWORD
|
|
|
|
RUN \
|
|
apk update && \
|
|
apk add openrc --no-cache && \
|
|
apk add openssh-server && \
|
|
apk add openssl && \
|
|
rc-update add sshd && \
|
|
rc-status && \
|
|
touch /run/openrc/softlevel
|
|
|
|
RUN echo root:${PASSWORD} | chpasswd
|
|
RUN echo "PasswordAuthentication yes" >> /etc/ssh/sshd_config
|
|
RUN echo "PermitRootLogin yes" >> /etc/ssh/sshd_config
|
|
|
|
RUN apk add bash curl shadow
|
|
RUN chsh -s /bin/bash root
|
|
|
|
RUN apk add --no-cache --repository http://dl-cdn.alpinelinux.org/alpine/edge/community gleam rebar3 make gcc musl-dev
|
|
ADD https://raw.githubusercontent.com/openembedded/openembedded-core/master/meta/recipes-core/musl/bsd-headers/sys-queue.h /usr/include/sys/queue.h
|
|
|
|
WORKDIR /ctf/gleam-drive
|
|
|
|
COPY src src/
|
|
COPY *.toml .
|
|
COPY start.sh .
|
|
|
|
RUN gleam build
|
|
|
|
RUN cat /dev/urandom | head -c 16 > .aes-key
|
|
RUN openssl req -x509 -newkey rsa:4096 -keyout key.pem -out cert.pem -sha256 -days 3650 -nodes -subj "/C=XX/ST=GleamDriveState/L=GleamDriveCity/O=GleamDriveCompany/OU=GleamDriveCompanySection/CN=GleamDrive"
|
|
|
|
RUN chmod +x start.sh
|
|
CMD ./start.sh |