diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 5142be5..d08fc82 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -5,7 +5,6 @@ on: push: branches: - main - - "*" jobs: buildAndPush: @@ -17,7 +16,7 @@ jobs: steps: - uses: actions/checkout@v4 - name: Nix build - run: nix build --extra-experimental-features "flakes nix-command" .#${{matrix.containers}} + run: nix build --extra-experimental-features "flakes nix-command" .${{matrix.containers}} - name: Setup skopeo run: curl -o /etc/containers/policy.json --create-dirs https://raw.githubusercontent.com/containers/skopeo/refs/heads/main/default-policy.json - name: Push Image diff --git a/flake.nix b/flake.nix index 9480db0..cdca942 100644 --- a/flake.nix +++ b/flake.nix @@ -8,7 +8,7 @@ inputs.nixpkgs.follows = "nixpkgs"; }; }; - outputs = { nixpkgs, ... }@inputs: + outputs = { nixpkgs, nix, self, ... }@inputs: let system = "x86_64-linux"; pkgs = import nixpkgs { inherit system; }; @@ -17,9 +17,8 @@ { packages.${system} = rec { default = nix-with-tools; - nix = nix-with-tools; - minimal-nix = import (inputs.nix + "/docker.nix") { + minimal-nix = import (nix + "/docker.nix") { inherit pkgs; extraPkgs = [ pkgs.nodejs pkgs.busybox ]; @@ -31,7 +30,7 @@ "org.opencontainers.image.description" = "Nix container image with nodejs"; }; }; - nix-with-tools = import (inputs.nix + "/docker.nix") { + nix-with-tools = import (nix + "/docker.nix") { inherit pkgs; extraPkgs = [ pkgs.nodejs @@ -64,29 +63,25 @@ tag = "latest"; runAsRoot = '' - mkdir /etc - # ${pkgs.shadow}/bin/useradd -m -s /run/current-system/sw/bin/bash docker-ci - - chmod 777 /tmp - mkdir -p /var/tmp - chmod 777 /var/tmp + ${dockerTools.shadowSetup} + useradd -m -s /run/current-system/sw/bin/bash docker-ci ''; # volumes to mount # -v /nix:/nix:ro # -v /run/current-system:/run/current-system - # -v /var/cache/docker-ci:/.cache # -v ${pkgs.buildEnv ... }:/run/container-env config = { Entrypoint = [ "/run/current-system/sw/bin/bash" ]; - # User = "1000:1000"; + User = "1000:1000"; Env = [ "NIX_REMOTE=daemon" "PATH=${lib.concatStringsSep ":" [ - "/run/container-env/bin" - "/run/current-system/sw/bin" - "/run/current-system/sw/sbin" - ]}" + "/run/current-system/sw/bin" + "/run/current-system/sw/sbin" + "/run/container-env/bin" + # "/run/container-env/sbin" # This might not be needed + ]}" "SSL_CERT_FILE=/run/current-system/etc/ssl/certs/ca-bundle.crt" "GIT_SSL_CAINFO=/run/current-system/etc/ssl/certs/ca-bundle.crt"