-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathDockerfile
More file actions
88 lines (77 loc) · 3.5 KB
/
Copy pathDockerfile
File metadata and controls
88 lines (77 loc) · 3.5 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
FROM ubuntu:22.04
ARG APT_MIRROR=http://mirrors.tuna.tsinghua.edu.cn/ubuntu
ARG PIP_INDEX_URL=https://pypi.tuna.tsinghua.edu.cn/simple
ARG PIP_TRUSTED_HOST=pypi.tuna.tsinghua.edu.cn
ARG MINICONDA_URL=https://mirrors.tuna.tsinghua.edu.cn/anaconda/miniconda/Miniconda3-latest-Linux-x86_64.sh
ARG MSFINSTALL_URL=https://github.com/rapid7/metasploit-omnibus/raw/master/config/templates/metasploit-framework-wrappers/msfupdate.erb
ENV DEBIAN_FRONTEND=noninteractive
ENV LANG=en_US.UTF-8
ENV LANGUAGE=en_US:en
ENV LC_ALL=en_US.UTF-8
ENV PATH=/opt/conda/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
ENV PIP_INDEX_URL=${PIP_INDEX_URL}
ENV PIP_TRUSTED_HOST=${PIP_TRUSTED_HOST}
ENV PIP_DISABLE_PIP_VERSION_CHECK=1
RUN sed -i \
-e "s|http://archive.ubuntu.com/ubuntu|${APT_MIRROR}|g" \
-e "s|http://security.ubuntu.com/ubuntu|${APT_MIRROR}|g" \
-e "s|http://ports.ubuntu.com/ubuntu-ports|${APT_MIRROR}|g" \
/etc/apt/sources.list && \
apt-get update && \
apt-get install -y --no-install-recommends \
wget \
curl \
gnupg \
lsb-release \
ca-certificates \
software-properties-common \
locales \
sudo \
vim \
net-tools \
iptables \
tcpdump \
nano \
tmux \
bzip2 \
nmap \
whatweb \
lsof \
iproute2 \
postgresql \
postgresql-contrib && \
locale-gen en_US.UTF-8 && \
rm -rf /var/lib/apt/lists/*
RUN wget "${MINICONDA_URL}" -O /tmp/miniconda.sh && \
bash /tmp/miniconda.sh -b -p /opt/conda && \
rm -f /tmp/miniconda.sh && \
conda tos accept --override-channels --channel https://repo.anaconda.com/pkgs/main && \
conda tos accept --override-channels --channel https://repo.anaconda.com/pkgs/r
COPY environment.yml requirements.txt .tmux.conf /tmp/build-context/
COPY entrypoint.sh /usr/local/bin/agentserver-entrypoint
# The checked-in environment.yml contains a host-specific prefix. Strip it so
# the environment is created inside the container at /opt/conda/envs/pentest.
RUN sed '/^prefix:/d' /tmp/build-context/environment.yml > /tmp/build-context/environment.rewritten.yml && \
conda env create -f /tmp/build-context/environment.rewritten.yml && \
chmod -R a+r /opt/conda && \
find /opt/conda -type d -exec chmod a+x {} \; && \
conda clean -afy
WORKDIR /root
RUN wget "${MSFINSTALL_URL}" -O /root/msfinstall && \
chmod +x /root/msfinstall && \
/root/msfinstall && \
/opt/metasploit-framework/bin/msfconsole --version && \
chmod +x /usr/local/bin/agentserver-entrypoint
RUN groupadd -g 1000 devuser && \
useradd -u 1000 -g devuser -m -s /bin/bash devuser && \
echo "devuser ALL=(ALL) NOPASSWD:ALL" > /etc/sudoers.d/devuser && \
chmod 0440 /etc/sudoers.d/devuser && \
install -o devuser -g devuser -m 0644 /tmp/build-context/requirements.txt /home/devuser/requirements.txt && \
install -o devuser -g devuser -m 0644 /tmp/build-context/.tmux.conf /home/devuser/.tmux.conf && \
rm -rf /tmp/build-context
ENV PATH=/home/devuser/.local/bin:/opt/conda/envs/pentest/bin:/opt/conda/bin:/opt/metasploit-framework/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
WORKDIR /home/devuser
RUN sudo -E -H -u devuser /opt/conda/bin/conda config --set auto_activate_base false && \
sudo -E -H -u devuser /opt/conda/envs/pentest/bin/python -m pip install --user --no-cache-dir -r /home/devuser/requirements.txt
ENTRYPOINT ["/usr/local/bin/agentserver-entrypoint"]
CMD ["/bin/bash"]