{ buildah, curl, fakeNss, git, lib, lib', nix, nix-output-monitor, nodejs_24, podman, writeTextFile, name, ... }: let policy = ( writeTextFile { name = "policy.json"; text = '' { "default": [{"type": "insecureAcceptAnything"}] } ''; destination = "/etc/containers/policy.json"; } ); nix-conf = writeTextFile { name = "nix.conf"; text = '' extra-experimental-features = nix-command flakes ''; destination = "/etc/nix/nix.conf"; }; bashrc = writeTextFile { name = "bashrc"; text = '' echo "Loading bashrc" export PATH=${lib.makeBinPath contents} ''; destination = "/etc/bashrc"; }; profile = writeTextFile { name = "profile"; text = '' echo "Loading profile" export PATH=${lib.makeBinPath contents} ''; destination = "/etc/profile"; }; contents = lib'.basePackages ++ [ buildah curl (fakeNss.override { extraPasswdLines = [ "nixbld:x:1001:1001:Build user:/home/nixbld:/noshell" ]; extraGroupLines = [ "nixbld:!:1001:nixbld" ]; }) git nix nix-conf nix-output-monitor nodejs_24 podman policy ]; in lib'.mkImage { name = name "builder"; config.Env = [ "TEMP=/tmp" "PATH=${lib.makeBinPath contents}" ]; # Set this explicitly so that we avoid infinite recursion contents = contents ++ [ bashrc profile ]; extraCommands = '' mkdir -p tmp mkdir -p var/tmp ''; includeNixDB = true; }