diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 0d7537b..d08fc82 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -8,11 +8,15 @@ on: jobs: buildAndPush: - runs-on: [ nix ] + runs-on: [ nix-host ] + strategy: + fail-fast: false + matrix: + containers: ["nix", "nix-host"] steps: - uses: actions/checkout@v4 - name: Nix build - run: nix build --extra-experimental-features "flakes nix-command" . + run: nix build --extra-experimental-features "flakes nix-command" .${{matrix.containers}} - name: Setup skopeo run: curl -o /etc/containers/policy.json --create-dirs https://raw.githubusercontent.com/containers/skopeo/refs/heads/main/default-policy.json - name: Push Image @@ -22,9 +26,9 @@ jobs: env: USERNAME: tamipes UPLOAD_TOKEN: ${{ secrets.UPLOAD_TOKEN }} - IMG_URL: git.tami.moe/tamipes/nix + IMG_URL: git.tami.moe/tamipes/${{matrix.containers}} - name: niks3 pin uses: https://git.tami.moe/actions/niks3-upload@main with: token: ${{ secrets.NIKS3_TOKEN }} - pin: nix-container + pin: containers.${{matrix.containers}} diff --git a/flake.nix b/flake.nix index 8a71c81..cdca942 100644 --- a/flake.nix +++ b/flake.nix @@ -12,6 +12,7 @@ let system = "x86_64-linux"; pkgs = import nixpkgs { inherit system; }; + lib = pkgs.lib; in { packages.${system} = rec { @@ -55,5 +56,46 @@ }; }; }; + nix-host = pkgs.callPackage + ({ dockerTools }: + dockerTools.buildImage { + name = "nix-host"; + tag = "latest"; + + runAsRoot = '' + ${dockerTools.shadowSetup} + useradd -m -s /run/current-system/sw/bin/bash docker-ci + ''; + + # volumes to mount + # -v /nix:/nix:ro + # -v /run/current-system:/run/current-system + # -v ${pkgs.buildEnv ... }:/run/container-env + config = { + Entrypoint = [ "/run/current-system/sw/bin/bash" ]; + User = "1000:1000"; + Env = [ + "NIX_REMOTE=daemon" + "PATH=${lib.concatStringsSep ":" [ + "/run/current-system/sw/bin" + "/run/current-system/sw/sbin" + "/run/container-env/bin" + # "/run/container-env/sbin" # This might not be needed + ]}" + + "SSL_CERT_FILE=/run/current-system/etc/ssl/certs/ca-bundle.crt" + "GIT_SSL_CAINFO=/run/current-system/etc/ssl/certs/ca-bundle.crt" + "NIX_SSL_CERT_FILE=/run/current-system/etc/ssl/certs/ca-bundle.crt" + ]; + Labels = { + "org.opencontainers.image.title" = "Nix Daemon Client"; + "org.opencontainers.image.source" = "https://git.tami.moe/tamipes/forgejo-actions"; + "org.opencontainers.image.vendor" = "Tamipes"; + "org.opencontainers.image.version" = "0.1.0"; + "org.opencontainers.image.description" = "Nix container image which is designed to use the host system's nix daemon"; + }; + }; + }) + { }; }; }