feat: nix-host updates
All checks were successful
Build and Push docker image / buildAndPush (nix-host) (push) Successful in 8s
Build and Push docker image / buildAndPush (nix) (push) Successful in 36s

- set up minimal fhs
- use root, things work with it
- add cache note
- correct ordering of `PATH`
This commit is contained in:
Tamipes 2026-08-22 20:25:22 +02:00
parent 0c26f377c7
commit a5703817fe

View file

@ -64,24 +64,28 @@
tag = "latest"; tag = "latest";
runAsRoot = '' runAsRoot = ''
${dockerTools.shadowSetup} mkdir /etc
useradd -m -s /run/current-system/sw/bin/bash docker-ci # ${pkgs.shadow}/bin/useradd -m -s /run/current-system/sw/bin/bash docker-ci
chmod 777 /tmp
mkdir -p /var/tmp
chmod 777 /var/tmp
''; '';
# volumes to mount # volumes to mount
# -v /nix:/nix:ro # -v /nix:/nix:ro
# -v /run/current-system:/run/current-system # -v /run/current-system:/run/current-system
# -v /var/cache/docker-ci:/.cache
# -v ${pkgs.buildEnv ... }:/run/container-env # -v ${pkgs.buildEnv ... }:/run/container-env
config = { config = {
Entrypoint = [ "/run/current-system/sw/bin/bash" ]; Entrypoint = [ "/run/current-system/sw/bin/bash" ];
User = "1000:1000"; # User = "1000:1000";
Env = [ Env = [
"NIX_REMOTE=daemon" "NIX_REMOTE=daemon"
"PATH=${lib.concatStringsSep ":" [ "PATH=${lib.concatStringsSep ":" [
"/run/container-env/bin"
"/run/current-system/sw/bin" "/run/current-system/sw/bin"
"/run/current-system/sw/sbin" "/run/current-system/sw/sbin"
"/run/container-env/bin"
# "/run/container-env/sbin" # This might not be needed
]}" ]}"
"SSL_CERT_FILE=/run/current-system/etc/ssl/certs/ca-bundle.crt" "SSL_CERT_FILE=/run/current-system/etc/ssl/certs/ca-bundle.crt"