feat: add nix-host and also transition to building both images with it
This commit is contained in:
parent
a6c6db37b1
commit
8436b99f18
2 changed files with 50 additions and 4 deletions
12
.github/workflows/build.yml
vendored
12
.github/workflows/build.yml
vendored
|
|
@ -8,11 +8,15 @@ on:
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
buildAndPush:
|
buildAndPush:
|
||||||
runs-on: [ nix ]
|
runs-on: [ nix-host ]
|
||||||
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
|
matrix:
|
||||||
|
containers: ["nix", "nix-host"]
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v4
|
- uses: actions/checkout@v4
|
||||||
- name: Nix build
|
- name: Nix build
|
||||||
run: nix build --extra-experimental-features "flakes nix-command" .
|
run: nix build --extra-experimental-features "flakes nix-command" .${{matrix.containers}}
|
||||||
- name: Setup skopeo
|
- name: Setup skopeo
|
||||||
run: curl -o /etc/containers/policy.json --create-dirs https://raw.githubusercontent.com/containers/skopeo/refs/heads/main/default-policy.json
|
run: curl -o /etc/containers/policy.json --create-dirs https://raw.githubusercontent.com/containers/skopeo/refs/heads/main/default-policy.json
|
||||||
- name: Push Image
|
- name: Push Image
|
||||||
|
|
@ -22,9 +26,9 @@ jobs:
|
||||||
env:
|
env:
|
||||||
USERNAME: tamipes
|
USERNAME: tamipes
|
||||||
UPLOAD_TOKEN: ${{ secrets.UPLOAD_TOKEN }}
|
UPLOAD_TOKEN: ${{ secrets.UPLOAD_TOKEN }}
|
||||||
IMG_URL: git.tami.moe/tamipes/nix
|
IMG_URL: git.tami.moe/tamipes/${{matrix.containers}}
|
||||||
- name: niks3 pin
|
- name: niks3 pin
|
||||||
uses: https://git.tami.moe/actions/niks3-upload@main
|
uses: https://git.tami.moe/actions/niks3-upload@main
|
||||||
with:
|
with:
|
||||||
token: ${{ secrets.NIKS3_TOKEN }}
|
token: ${{ secrets.NIKS3_TOKEN }}
|
||||||
pin: nix-container
|
pin: containers.${{matrix.containers}}
|
||||||
|
|
|
||||||
42
flake.nix
42
flake.nix
|
|
@ -12,6 +12,7 @@
|
||||||
let
|
let
|
||||||
system = "x86_64-linux";
|
system = "x86_64-linux";
|
||||||
pkgs = import nixpkgs { inherit system; };
|
pkgs = import nixpkgs { inherit system; };
|
||||||
|
lib = pkgs.lib;
|
||||||
in
|
in
|
||||||
{
|
{
|
||||||
packages.${system} = rec {
|
packages.${system} = rec {
|
||||||
|
|
@ -55,5 +56,46 @@
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
nix-host = pkgs.callPackage
|
||||||
|
({ dockerTools }:
|
||||||
|
dockerTools.buildImage {
|
||||||
|
name = "nix-host";
|
||||||
|
tag = "latest";
|
||||||
|
|
||||||
|
runAsRoot = ''
|
||||||
|
${dockerTools.shadowSetup}
|
||||||
|
useradd -m -s /run/current-system/sw/bin/bash docker-ci
|
||||||
|
'';
|
||||||
|
|
||||||
|
# volumes to mount
|
||||||
|
# -v /nix:/nix:ro
|
||||||
|
# -v /run/current-system:/run/current-system
|
||||||
|
# -v ${pkgs.buildEnv ... }:/run/container-env
|
||||||
|
config = {
|
||||||
|
Entrypoint = [ "/run/current-system/sw/bin/bash" ];
|
||||||
|
User = "1000:1000";
|
||||||
|
Env = [
|
||||||
|
"NIX_REMOTE=daemon"
|
||||||
|
"PATH=${lib.concatStringsSep ":" [
|
||||||
|
"/run/current-system/sw/bin"
|
||||||
|
"/run/current-system/sw/sbin"
|
||||||
|
"/run/container-env/bin"
|
||||||
|
# "/run/container-env/sbin" # This might not be needed
|
||||||
|
]}"
|
||||||
|
|
||||||
|
"SSL_CERT_FILE=/run/current-system/etc/ssl/certs/ca-bundle.crt"
|
||||||
|
"GIT_SSL_CAINFO=/run/current-system/etc/ssl/certs/ca-bundle.crt"
|
||||||
|
"NIX_SSL_CERT_FILE=/run/current-system/etc/ssl/certs/ca-bundle.crt"
|
||||||
|
];
|
||||||
|
Labels = {
|
||||||
|
"org.opencontainers.image.title" = "Nix Daemon Client";
|
||||||
|
"org.opencontainers.image.source" = "https://git.tami.moe/tamipes/forgejo-actions";
|
||||||
|
"org.opencontainers.image.vendor" = "Tamipes";
|
||||||
|
"org.opencontainers.image.version" = "0.1.0";
|
||||||
|
"org.opencontainers.image.description" = "Nix container image which is designed to use the host system's nix daemon";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
})
|
||||||
|
{ };
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue