-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathDockerfile
More file actions
132 lines (113 loc) · 6.02 KB
/
Copy pathDockerfile
File metadata and controls
132 lines (113 loc) · 6.02 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
FROM ghcr.io/astral-sh/uv:0.10-python3.11-trixie-slim
# Build argument for package version
ARG PACKAGE_VERSION=0.0.3a0
# Set environment variables
ENV DEBIAN_FRONTEND=noninteractive
ENV CONFIG_DIR=/config
ENV CONFIG_NAME=config.yaml
VOLUME [ "/config" ]
# Install dependencies
RUN apt-get update && apt-get install -y \
postgresql postgresql-contrib \
rsync \
openssh-client \
apache2-utils \
libpq-dev && \
rm -rf /var/lib/apt/lists/*
RUN apt-get update && apt-get install -y curl unzip && \
curl -fsSL https://github.com/opentofu/opentofu/releases/download/v1.12.5/tofu_1.12.5_linux_amd64.zip -o /tmp/tofu.zip && \
unzip -j /tmp/tofu.zip tofu -d /usr/local/bin && \
rm /tmp/tofu.zip && \
rm -rf /var/lib/apt/lists/*
# nginx is the only network-facing process in this container.
# noVNC is served from /usr/share/kasmvnc/www/ — the Kasm-bundled
# viewer that ships in the kasmvncserver .deb. We MUST NOT use
# Debian's generic `novnc` package: it sends RFB extension message
# types (e.g. 97) that KasmVNC's stricter parser rejects, killing the
# connection on the first mouse/keyboard event. Kasm's bundled noVNC
# is the only viewer that's protocol-compatible with kasmvncserver.
ARG KASMVNC_VERSION=1.5.0
RUN apt-get update && apt-get install -y --no-install-recommends \
nginx curl ca-certificates && \
curl -L -o /tmp/kasmvncserver.deb \
"https://github.com/kasmtech/KasmVNC/releases/download/v${KASMVNC_VERSION}/kasmvncserver_jammy_${KASMVNC_VERSION}_amd64.deb" && \
apt-get install -y --no-install-recommends /tmp/kasmvncserver.deb && \
rm /tmp/kasmvncserver.deb && \
rm -rf /var/lib/apt/lists/*
# cloudflared -- the connector for manual.participant_exposure=cloudflare_tunnel.
# A single static binary (not a tarball, not a .deb), so no unpack step. Harmless
# when unused: start.sh only launches it when the mode is set. Pinned rather than
# floating, and paired with --no-autoupdate at runtime, so what ships is what was
# tested. Must stay in lockstep with Dockerfile.dev.
ARG CLOUDFLARED_VERSION=2026.7.3
RUN curl -L -o /usr/local/bin/cloudflared \
"https://github.com/cloudflare/cloudflared/releases/download/${CLOUDFLARED_VERSION}/cloudflared-linux-amd64" && \
chmod +x /usr/local/bin/cloudflared
# Fix the bundled noVNC viewer's RFB VncAuth handshake. nginx (above)
# serves /static/novnc/ from /usr/share/kasmvnc/www/ on THIS container,
# so the browser-loaded bundle is the allocator's, not the client's.
# The Kasm fork hardcodes `this._rfbCredentials.password=""` immediately
# before `genDES` in `_negotiateStdVNCAuth`, which kills the page's
# `?password=<cred>` and makes the browser send a zero-key challenge
# response — KasmVNC then rejects every login with
# `AuthFailureException`.
#
# Verify-patch-verify: assert the clobber is present pre-sed and gone
# post-sed. A future KasmVNC bundle that refactors the offending line
# (or fixes the upstream bug entirely) will fail this step at build
# time — far better than the silent no-op that the bare sed would
# produce, which only surfaces at smoke-test as another opaque
# `AuthFailureException`.
RUN for f in /usr/share/kasmvnc/www/assets/ui-*.js; do \
grep -q 'this._rfbCredentials.password=""' "$f" \
|| { echo "ERROR: noVNC clobber pattern not present in $f — KasmVNC bundle may have changed; review the sed"; exit 1; }; \
sed -i 's/this\._rfbCredentials\.password="";//g' "$f"; \
! grep -q 'this._rfbCredentials.password=""' "$f" \
|| { echo "ERROR: sed did not remove the clobber from $f"; exit 1; }; \
done
# Raise the viewer's default stream-quality preset from Medium (2) to
# High (3): High lifts the frame-rate cap to 60 FPS (Medium paces motion
# at ~17 FPS) while keeping video_time=5 so H.264 streaming mode can
# still engage — Extreme (4) forces video_time=100, which blocks it.
# Full rationale: docs/architecture.md, desktop-performance section.
# Browsers that already stored
# a preset in localStorage keep their choice; only fresh sessions see
# this default. Verify-patch-verify as above.
RUN for f in /usr/share/kasmvnc/www/assets/ui-*.js; do \
grep -q 'initSetting("video_quality",2)' "$f" \
|| { echo "ERROR: video_quality default not present in $f — KasmVNC bundle may have changed; review the sed"; exit 1; }; \
sed -i 's/initSetting("video_quality",2)/initSetting("video_quality",3)/' "$f"; \
grep -q 'initSetting("video_quality",3)' "$f" \
|| { echo "ERROR: sed did not raise the video_quality default in $f"; exit 1; }; \
done
# wstunnel -- reverse-tunnel connectivity's server side. A single static Go/Rust
# binary; harmless when unused, since start.sh only launches it when
# CONNECTIVITY_MODE=reverse_tunnel. Must stay in lockstep with Dockerfile.dev
# and with the client images.
ARG WSTUNNEL_VERSION=10.6.2
RUN curl -L -o /tmp/wstunnel.tar.gz \
"https://github.com/erebe/wstunnel/releases/download/v${WSTUNNEL_VERSION}/wstunnel_${WSTUNNEL_VERSION}_linux_amd64.tar.gz" && \
tar -xzf /tmp/wstunnel.tar.gz -C /tmp && \
mv /tmp/wstunnel /usr/local/bin/wstunnel && \
chmod +x /usr/local/bin/wstunnel && \
rm -f /tmp/wstunnel.tar.gz
COPY lablink-nginx.conf /etc/nginx/conf.d/lablink.conf
# Disable nginx's default site so it doesn't compete with lablink-nginx.conf.
RUN rm -f /etc/nginx/sites-enabled/default
# Set working directory
WORKDIR /app
# Copy PostgreSQL config
COPY pg_hba.conf /etc/postgresql/15/main/pg_hba.conf
# Install package from PyPI using UV in explicit venv location
RUN uv init --python 3.11 --no-readme && \
uv venv /app/.venv && \
uv add lablink-allocator-service==${PACKAGE_VERSION} --no-cache
# Ensure terraform directory has write permissions for state files
RUN chmod -R 777 /app/.venv/lib/python*/site-packages/lablink_allocator_service/terraform/
# Expose ports for Flask
EXPOSE 5000
# Copy and set permissions for startup script
COPY start.sh /app/start.sh
RUN chmod +x /app/start.sh
# Set the entrypoint script to start the Flask application
CMD ["/bin/bash", "-c", "/app/start.sh"]