From 66c271384409bfe88dbe8b9ad4014b3d7a57d7c9 Mon Sep 17 00:00:00 2001 From: Dessa Simpson Date: Sat, 25 Oct 2025 11:58:07 -0700 Subject: [PATCH 1/3] Overhaul Dockerfile --- Dockerfile | 103 +++++++++++++++++++++++++++++++++++------------------ 1 file changed, 68 insertions(+), 35 deletions(-) diff --git a/Dockerfile b/Dockerfile index 5c2c948..2b8f658 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,50 +1,83 @@ ARG DEBIAN_VERSION=13 -FROM debian:${DEBIAN_VERSION} - -ENV DEBIAN_VERSION=12 - -ENV DEBIAN_FRONTEND=noninteractive - +FROM debian:${DEBIAN_VERSION} AS base SHELL ["/bin/bash", "-c"] +ENV DEBIAN_FRONTEND=noninteractive -RUN source /etc/os-release && apt-get update -y && apt-get install -y curl wget \ -&& wget https://packages.microsoft.com/config/debian/${VERSION_ID}/packages-microsoft-prod.deb \ -&& dpkg -i packages-microsoft-prod.deb \ -&& rm packages-microsoft-prod.deb \ -&& apt-get install -y nix-bin locales curl wget nmap nano vim msmtp msmtp-mta mutt dnsutils python3-full screen \ -irssi git testdisk tcpdump tshark traceroute busybox ncftp mc yafc ftp mosh ncat openssl sqlite3 git elinks emacs \ -python3-pip zsh python3-full python3-pip pipx rsync rclone zip unzip unar p7zip-full iperf3 mtr \ -&& rm -rf /var/lib/apt/lists/* && localedef -i en_US -c -f UTF-8 -A /usr/share/locale/locale.alias en_US.UTF-8 \ -&& mkdir -p /home/linuxbrew/ && chmod -Rv 777 /home/linuxbrew/ && useradd -ms /usr/bin/zsh blueteam \ -&& mkdir -p /nix && chown -R blueteam:blueteam /nix +# Install locales and basic utilities needed for parallel stages +RUN apt-get update && \ + apt-get install --no-install-recommends -y \ + curl git locales nix-bin pipx wget zsh && \ + rm -rf /var/lib/apt/lists/* && \ + localedef -i en_US -c -f UTF-8 -A /usr/share/locale/locale.alias en_US.UTF-8 +ENV LANG=en_US.utf8 -# temporary workaround for missing tools because of debian 13 -RUN for tool in tftp dos2unix unix2dos ssl_client ftpget ftpput cal; do ln -s /bin/busybox /usr/local/bin/$tool; done +# Create blueteam user and miscellaneous directories +RUN useradd -ms /usr/bin/zsh blueteam && \ + mkdir -p /nix/var/nix /home/linuxbrew && \ + chown -R blueteam:blueteam /nix /home/linuxbrew -RUN curl -LO "https://dl.k8s.io/release/$(curl -L -s https://dl.k8s.io/release/stable.txt)/bin/linux/amd64/kubectl" \ -&& install -o root -g root -m 0755 kubectl /usr/local/bin/kubectl +# Grab miscellaneous non-apt utilities +FROM base AS misc +WORKDIR /out +# kubectl, kubectx, kubens, kubectl-cnpg, devbox, direnv +RUN curl -fsSLO "https://dl.k8s.io/release/$(curl -L -s https://dl.k8s.io/release/stable.txt)/bin/linux/amd64/kubectl" && \ + chmod +x kubectl && \ + curl -fsSL "https://github.com/ahmetb/kubectx/releases/download/v0.9.5/kubectx_v0.9.5_linux_x86_64.tar.gz" | \ + tar -xz kubectx && \ + curl -fsSL "https://github.com/ahmetb/kubectx/releases/download/v0.9.5/kubens_v0.9.5_linux_x86_64.tar.gz" | \ + tar -xz kubens && \ + curl -fsSL "https://github.com/cloudnative-pg/cloudnative-pg/raw/main/hack/install-cnpg-plugin.sh" | \ + sh -s -- -b . && \ + curl -fsSL "https://github.com/jetify-com/devbox/releases/download/0.16.0/devbox_0.16.0_linux_amd64.tar.gz" | \ + tar -xz devbox && \ + curl -fsSL "https://direnv.net/install.sh" | \ + bin_path=. bash +# Install Linuxbrew and build homedir +FROM base AS home USER blueteam - WORKDIR /home/blueteam -# FROM HERE WE START WHAT THE USER SPACE LOOKS LIKE - # Install nix channels and update RUN nix-channel --add https://nixos.org/channels/nixpkgs-unstable nixpkgs && nix-channel --update -ENV LANG en_US.utf8 -RUN touch ~/.zshrc \ -&& pipx install --include-deps ansible \ -&& pipx inject --include-apps ansible argcomplete \ -&& pipx ensurepath \ -&& sh -c "$(curl -fsSL https://raw.githubusercontent.com/ohmyzsh/ohmyzsh/master/tools/install.sh)" \ -&& /bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh)" \ -&& echo 'eval $(/home/linuxbrew/.linuxbrew/bin/brew shellenv)' >> ~/.zshrc \ -&& echo 'export PATH="$PATH:/home/blueteam/.local/bin"' >> ~/.zshrc \ -&& echo 'eval $(/home/linuxbrew/.linuxbrew/bin/brew shellenv)' >> ~/.bashrc \ -&& echo 'export PATH="$PATH:/home/blueteam/.local/bin"' >> ~/.bashrc -# note: https://gitee.com/chuanjiao10/kasini3000_agent_linux/raw/master/debian12_install_powershell.bash +# Install Linuxbrew +RUN /bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh)" +# Install pipx packages and configure shells +RUN touch ~/.zshrc && mkdir -p .local/bin && \ + pipx install --include-deps ansible && \ + pipx inject --include-apps ansible argcomplete && \ + sh -c "$(curl -fsSL https://raw.githubusercontent.com/ohmyzsh/ohmyzsh/master/tools/install.sh)" && \ + echo 'eval "$(/home/linuxbrew/.linuxbrew/bin/brew shellenv)"' >> .profile && \ + echo 'eval "$(direnv hook bash)"' >> .bashrc && \ + echo 'eval "$(direnv hook zsh)"' >> .zshrc + +# Final result +FROM base AS final + +# Once Microsoft releases powershell for trixie, uncomment this and add +# powershell to the packages below. +#RUN source /etc/os-release && cd /run && \ +# curl -O https://packages.microsoft.com/config/debian/${VERSION_ID}/packages-microsoft-prod.deb && \ +# dpkg -i packages-microsoft-prod.deb +RUN apt-get update && apt-get install -y --no-install-recommends \ + bash-completion busybox dnsutils dos2unix elinks emacs file ftp iperf3 \ + irssi less man-db manpages mc mosh msmtp msmtp-mta mtr mutt nano ncal \ + ncat ncftp nmap openssh-client openssl p7zip-full patch psmisc \ + python3-full python3-pip rclone rsync screen sqlite3 tcpdump testdisk \ + tftp-hpa traceroute tshark unar unzip vim xxd yafc zip && \ + rm -rf /var/lib/apt/lists/* + +# Add busybox symlinks for any otherwise missing tools +RUN busybox --install + +COPY --from=containerssh/agent /usr/bin/containerssh-agent /usr/bin/containerssh-agent +COPY --from=misc /out /usr/local/bin +COPY --from=home /home /home +COPY --from=home /nix /nix + +USER blueteam +WORKDIR /home/blueteam From 89042e5624f490a056aa01bb746af4a7efc47d99 Mon Sep 17 00:00:00 2001 From: Dessa Simpson Date: Sat, 25 Oct 2025 17:41:33 -0700 Subject: [PATCH 2/3] Add iputils-ping for unprivileged ping capability --- Dockerfile | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/Dockerfile b/Dockerfile index 2b8f658..efcec55 100644 --- a/Dockerfile +++ b/Dockerfile @@ -65,8 +65,8 @@ FROM base AS final # dpkg -i packages-microsoft-prod.deb RUN apt-get update && apt-get install -y --no-install-recommends \ bash-completion busybox dnsutils dos2unix elinks emacs file ftp iperf3 \ - irssi less man-db manpages mc mosh msmtp msmtp-mta mtr mutt nano ncal \ - ncat ncftp nmap openssh-client openssl p7zip-full patch psmisc \ + iputils-ping irssi less man-db manpages mc mosh msmtp msmtp-mta mtr mutt \ + nano ncal ncat ncftp nmap openssh-client openssl p7zip-full patch psmisc \ python3-full python3-pip rclone rsync screen sqlite3 tcpdump testdisk \ tftp-hpa traceroute tshark unar unzip vim xxd yafc zip && \ rm -rf /var/lib/apt/lists/* From b96a6fb9343711f7d2c81f88cce39babb2b7e078 Mon Sep 17 00:00:00 2001 From: Dessa Simpson Date: Thu, 30 Oct 2025 17:54:29 -0700 Subject: [PATCH 3/3] Add ipython3 and powershell (preview) --- Dockerfile | 14 ++++++++++---- 1 file changed, 10 insertions(+), 4 deletions(-) diff --git a/Dockerfile b/Dockerfile index efcec55..1feba79 100644 --- a/Dockerfile +++ b/Dockerfile @@ -65,12 +65,18 @@ FROM base AS final # dpkg -i packages-microsoft-prod.deb RUN apt-get update && apt-get install -y --no-install-recommends \ bash-completion busybox dnsutils dos2unix elinks emacs file ftp iperf3 \ - iputils-ping irssi less man-db manpages mc mosh msmtp msmtp-mta mtr mutt \ - nano ncal ncat ncftp nmap openssh-client openssl p7zip-full patch psmisc \ - python3-full python3-pip rclone rsync screen sqlite3 tcpdump testdisk \ - tftp-hpa traceroute tshark unar unzip vim xxd yafc zip && \ + iputils-ping ipython3 irssi less man-db manpages mc mosh msmtp msmtp-mta \ + mtr mutt nano ncal ncat ncftp nmap openssh-client openssl p7zip-full \ + patch psmisc python3-cryptography python3-full python3-pip rclone rsync \ + screen sqlite3 tcpdump testdisk tftp-hpa traceroute tshark unar unzip \ + vim xxd yafc zip && \ rm -rf /var/lib/apt/lists/* +RUN cd /run && \ + curl -fsSLO "https://github.com/PowerShell/PowerShell/releases/download/v7.6.0-preview.5/powershell-preview_7.6.0-preview.5-1.deb_amd64.deb" && \ + dpkg -i "powershell-preview_7.6.0-preview.5-1.deb_amd64.deb" && \ + ln -s /usr/bin/pwsh{-preview,} + # Add busybox symlinks for any otherwise missing tools RUN busybox --install