pr-fix-actions-on-repo #1

Closed
tamipes wants to merge 10 commits from pr-fix-actions-on-repo into main
2 changed files with 19 additions and 12 deletions

View file

@ -5,6 +5,7 @@ on:
push: push:
branches: branches:
- main - main
- "*"
jobs: jobs:
buildAndPush: buildAndPush:
@ -16,7 +17,8 @@ jobs:
steps: steps:
- uses: actions/checkout@v4 - uses: actions/checkout@v4
- name: Nix build - name: Nix build
run: nix build --extra-experimental-features "flakes nix-command" .${{matrix.containers}} run: |
nix build --extra-experimental-features "flakes nix-command" .#${{matrix.containers}}
- name: Setup skopeo - name: Setup skopeo
run: curl -o /etc/containers/policy.json --create-dirs https://raw.githubusercontent.com/containers/skopeo/refs/heads/main/default-policy.json run: curl -o /etc/containers/policy.json --create-dirs https://raw.githubusercontent.com/containers/skopeo/refs/heads/main/default-policy.json
- name: Push Image - name: Push Image

View file

@ -8,7 +8,7 @@
inputs.nixpkgs.follows = "nixpkgs"; inputs.nixpkgs.follows = "nixpkgs";
}; };
}; };
outputs = { nixpkgs, nix, self, ... }@inputs: outputs = { nixpkgs, ... }@inputs:
let let
system = "x86_64-linux"; system = "x86_64-linux";
pkgs = import nixpkgs { inherit system; }; pkgs = import nixpkgs { inherit system; };
@ -17,8 +17,9 @@
{ {
packages.${system} = rec { packages.${system} = rec {
default = nix-with-tools; default = nix-with-tools;
nix = nix-with-tools;
minimal-nix = import (nix + "/docker.nix") { minimal-nix = import (inputs.nix + "/docker.nix") {
inherit pkgs; inherit pkgs;
extraPkgs = [ pkgs.nodejs pkgs.busybox ]; extraPkgs = [ pkgs.nodejs pkgs.busybox ];
@ -30,7 +31,7 @@
"org.opencontainers.image.description" = "Nix container image with nodejs"; "org.opencontainers.image.description" = "Nix container image with nodejs";
}; };
}; };
nix-with-tools = import (nix + "/docker.nix") { nix-with-tools = import (inputs.nix + "/docker.nix") {
inherit pkgs; inherit pkgs;
extraPkgs = [ extraPkgs = [
pkgs.nodejs pkgs.nodejs
@ -63,25 +64,29 @@
tag = "latest"; tag = "latest";
runAsRoot = '' runAsRoot = ''
${dockerTools.shadowSetup} mkdir /etc
useradd -m -s /run/current-system/sw/bin/bash docker-ci # ${pkgs.shadow}/bin/useradd -m -s /run/current-system/sw/bin/bash docker-ci
chmod 777 /tmp
mkdir -p /var/tmp
chmod 777 /var/tmp
''; '';
# volumes to mount # volumes to mount
# -v /nix:/nix:ro # -v /nix:/nix:ro
# -v /run/current-system:/run/current-system # -v /run/current-system:/run/current-system
# -v /var/cache/docker-ci:/.cache
# -v ${pkgs.buildEnv ... }:/run/container-env # -v ${pkgs.buildEnv ... }:/run/container-env
config = { config = {
Entrypoint = [ "/run/current-system/sw/bin/bash" ]; Entrypoint = [ "/run/current-system/sw/bin/bash" ];
User = "1000:1000"; # User = "1000:1000";
Env = [ Env = [
"NIX_REMOTE=daemon" "NIX_REMOTE=daemon"
"PATH=${lib.concatStringsSep ":" [ "PATH=${lib.concatStringsSep ":" [
"/run/current-system/sw/bin" "/run/container-env/bin"
"/run/current-system/sw/sbin" "/run/current-system/sw/bin"
"/run/container-env/bin" "/run/current-system/sw/sbin"
# "/run/container-env/sbin" # This might not be needed ]}"
]}"
"SSL_CERT_FILE=/run/current-system/etc/ssl/certs/ca-bundle.crt" "SSL_CERT_FILE=/run/current-system/etc/ssl/certs/ca-bundle.crt"
"GIT_SSL_CAINFO=/run/current-system/etc/ssl/certs/ca-bundle.crt" "GIT_SSL_CAINFO=/run/current-system/etc/ssl/certs/ca-bundle.crt"