101 lines
3.8 KiB
Nix
101 lines
3.8 KiB
Nix
{
|
|
description = "Base Forgejo Actions Image builder";
|
|
inputs = {
|
|
nixpkgs.url = "github:nixos/nixpkgs?ref=nixos-unstable";
|
|
nix.url = "github:nixos/nix";
|
|
niks3 = {
|
|
url = "github:Mic92/niks3";
|
|
inputs.nixpkgs.follows = "nixpkgs";
|
|
};
|
|
};
|
|
outputs = { nixpkgs, nix, self, ... }@inputs:
|
|
let
|
|
system = "x86_64-linux";
|
|
pkgs = import nixpkgs { inherit system; };
|
|
lib = pkgs.lib;
|
|
in
|
|
{
|
|
packages.${system} = rec {
|
|
default = nix-with-tools;
|
|
|
|
minimal-nix = import (nix + "/docker.nix") {
|
|
inherit pkgs;
|
|
extraPkgs = [ pkgs.nodejs pkgs.busybox ];
|
|
|
|
Labels = {
|
|
"org.opencontainers.image.title" = "Nix (minimal)";
|
|
"org.opencontainers.image.source" = "https://git.tami.moe/tamipes/forgejo-actions";
|
|
"org.opencontainers.image.vendor" = "Tamipes";
|
|
"org.opencontainers.image.version" = pkgs.nix.version;
|
|
"org.opencontainers.image.description" = "Nix container image with nodejs";
|
|
};
|
|
};
|
|
nix-with-tools = import (nix + "/docker.nix") {
|
|
inherit pkgs;
|
|
extraPkgs = [
|
|
pkgs.nodejs
|
|
pkgs.busybox
|
|
pkgs.skopeo
|
|
inputs.niks3.packages.${system}.default
|
|
];
|
|
nixConf = {
|
|
extra-substituters = [ "https://nix-cache.tami.moe" "https://niks3-cache.tami.moe" ];
|
|
trusted-public-keys = [
|
|
"cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY="
|
|
"nix-cache.tami.moe:3jrWZ412K0YTFfKMJC6ftc4lsugeMVWDBiudFCAdDb8="
|
|
"niks3-garage:l7ZLnM6i0mqqHbMEpHg+UAeqG53u8m/Mhep487dOOOE="
|
|
];
|
|
};
|
|
|
|
Labels = {
|
|
"org.opencontainers.image.title" = "Nix";
|
|
"org.opencontainers.image.source" = "https://git.tami.moe/tamipes/forgejo-actions";
|
|
"org.opencontainers.image.vendor" = "Tamipes";
|
|
"org.opencontainers.image.version" = pkgs.nix.version;
|
|
"org.opencontainers.image.description" = "Nix container image with more cli tools";
|
|
};
|
|
};
|
|
};
|
|
nix-host = pkgs.callPackage
|
|
({ dockerTools }:
|
|
dockerTools.buildImage {
|
|
name = "nix-host";
|
|
tag = "latest";
|
|
|
|
runAsRoot = ''
|
|
${dockerTools.shadowSetup}
|
|
useradd -m -s /run/current-system/sw/bin/bash docker-ci
|
|
'';
|
|
|
|
# volumes to mount
|
|
# -v /nix:/nix:ro
|
|
# -v /run/current-system:/run/current-system
|
|
# -v ${pkgs.buildEnv ... }:/run/container-env
|
|
config = {
|
|
Entrypoint = [ "/run/current-system/sw/bin/bash" ];
|
|
User = "1000:1000";
|
|
Env = [
|
|
"NIX_REMOTE=daemon"
|
|
"PATH=${lib.concatStringsSep ":" [
|
|
"/run/current-system/sw/bin"
|
|
"/run/current-system/sw/sbin"
|
|
"/run/container-env/bin"
|
|
# "/run/container-env/sbin" # This might not be needed
|
|
]}"
|
|
|
|
"SSL_CERT_FILE=/run/current-system/etc/ssl/certs/ca-bundle.crt"
|
|
"GIT_SSL_CAINFO=/run/current-system/etc/ssl/certs/ca-bundle.crt"
|
|
"NIX_SSL_CERT_FILE=/run/current-system/etc/ssl/certs/ca-bundle.crt"
|
|
];
|
|
Labels = {
|
|
"org.opencontainers.image.title" = "Nix Daemon Client";
|
|
"org.opencontainers.image.source" = "https://git.tami.moe/tamipes/forgejo-actions";
|
|
"org.opencontainers.image.vendor" = "Tamipes";
|
|
"org.opencontainers.image.version" = "0.1.0";
|
|
"org.opencontainers.image.description" = "Nix container image which is designed to use the host system's nix daemon";
|
|
};
|
|
};
|
|
})
|
|
{ };
|
|
};
|
|
}
|