forgejo-actions/flake.nix
Tamipes 8436b99f18
Some checks failed
Build and Push docker image / buildAndPush (nix) (push) Failing after 3s
Build and Push docker image / buildAndPush (nix-host) (push) Failing after 3s
feat: add nix-host and also transition to building both images with it
2026-08-22 18:05:28 +02:00

101 lines
3.8 KiB
Nix

{
description = "Base Forgejo Actions Image builder";
inputs = {
nixpkgs.url = "github:nixos/nixpkgs?ref=nixos-unstable";
nix.url = "github:nixos/nix";
niks3 = {
url = "github:Mic92/niks3";
inputs.nixpkgs.follows = "nixpkgs";
};
};
outputs = { nixpkgs, nix, self, ... }@inputs:
let
system = "x86_64-linux";
pkgs = import nixpkgs { inherit system; };
lib = pkgs.lib;
in
{
packages.${system} = rec {
default = nix-with-tools;
minimal-nix = import (nix + "/docker.nix") {
inherit pkgs;
extraPkgs = [ pkgs.nodejs pkgs.busybox ];
Labels = {
"org.opencontainers.image.title" = "Nix (minimal)";
"org.opencontainers.image.source" = "https://git.tami.moe/tamipes/forgejo-actions";
"org.opencontainers.image.vendor" = "Tamipes";
"org.opencontainers.image.version" = pkgs.nix.version;
"org.opencontainers.image.description" = "Nix container image with nodejs";
};
};
nix-with-tools = import (nix + "/docker.nix") {
inherit pkgs;
extraPkgs = [
pkgs.nodejs
pkgs.busybox
pkgs.skopeo
inputs.niks3.packages.${system}.default
];
nixConf = {
extra-substituters = [ "https://nix-cache.tami.moe" "https://niks3-cache.tami.moe" ];
trusted-public-keys = [
"cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY="
"nix-cache.tami.moe:3jrWZ412K0YTFfKMJC6ftc4lsugeMVWDBiudFCAdDb8="
"niks3-garage:l7ZLnM6i0mqqHbMEpHg+UAeqG53u8m/Mhep487dOOOE="
];
};
Labels = {
"org.opencontainers.image.title" = "Nix";
"org.opencontainers.image.source" = "https://git.tami.moe/tamipes/forgejo-actions";
"org.opencontainers.image.vendor" = "Tamipes";
"org.opencontainers.image.version" = pkgs.nix.version;
"org.opencontainers.image.description" = "Nix container image with more cli tools";
};
};
};
nix-host = pkgs.callPackage
({ dockerTools }:
dockerTools.buildImage {
name = "nix-host";
tag = "latest";
runAsRoot = ''
${dockerTools.shadowSetup}
useradd -m -s /run/current-system/sw/bin/bash docker-ci
'';
# volumes to mount
# -v /nix:/nix:ro
# -v /run/current-system:/run/current-system
# -v ${pkgs.buildEnv ... }:/run/container-env
config = {
Entrypoint = [ "/run/current-system/sw/bin/bash" ];
User = "1000:1000";
Env = [
"NIX_REMOTE=daemon"
"PATH=${lib.concatStringsSep ":" [
"/run/current-system/sw/bin"
"/run/current-system/sw/sbin"
"/run/container-env/bin"
# "/run/container-env/sbin" # This might not be needed
]}"
"SSL_CERT_FILE=/run/current-system/etc/ssl/certs/ca-bundle.crt"
"GIT_SSL_CAINFO=/run/current-system/etc/ssl/certs/ca-bundle.crt"
"NIX_SSL_CERT_FILE=/run/current-system/etc/ssl/certs/ca-bundle.crt"
];
Labels = {
"org.opencontainers.image.title" = "Nix Daemon Client";
"org.opencontainers.image.source" = "https://git.tami.moe/tamipes/forgejo-actions";
"org.opencontainers.image.vendor" = "Tamipes";
"org.opencontainers.image.version" = "0.1.0";
"org.opencontainers.image.description" = "Nix container image which is designed to use the host system's nix daemon";
};
};
})
{ };
};
}