Add builder image

This commit is contained in:
Greg Hellings
2025-11-25 20:16:06 -06:00
parent d64a000657
commit 81223079c2
4 changed files with 70 additions and 10 deletions
+1
View File
@@ -33,6 +33,7 @@ default:
- IMG: - IMG:
- img-bitwarden - img-bitwarden
- img-immich - img-immich
- img-builder
script: script:
- nix --extra-experimental-features "nix-command flakes" build ".#${IMG}" - nix --extra-experimental-features "nix-command flakes" build ".#${IMG}"
- cp -L result "${IMG}.tar.gz" - cp -L result "${IMG}.tar.gz"
-9
View File
@@ -4,15 +4,6 @@
{ {
description = "Greg's machines!"; description = "Greg's machines!";
nixConfig = {
extra-substituters = [
"https://greg-hellings.cachix.org"
];
extra-trusted-public-keys = [
"greg-hellings.cachix.org-1:y01Jl/L5evlhxdnUW6n56AiI1k8g1wxWhTxJCe7XSco="
];
};
inputs = { inputs = {
agenix = { agenix = {
url = "github:ryantm/agenix"; url = "github:ryantm/agenix";
+2 -1
View File
@@ -1,4 +1,4 @@
{ pkgs, ... }: { pkgs, top, ... }:
let let
c = pkgs.callPackage; c = pkgs.callPackage;
@@ -16,6 +16,7 @@ in
inject-darwin = c ./inject-darwin.nix { }; inject-darwin = c ./inject-darwin.nix { };
inject = c ./inject.nix { }; inject = c ./inject.nix { };
img-bitwarden = c ./img-bitwarden.nix { }; img-bitwarden = c ./img-bitwarden.nix { };
img-builder = c ./img-builder.nix { inherit top; };
img-immich = c ./img-immich.nix { }; img-immich = c ./img-immich.nix { };
qemu-hook = c ./qemu-hook.nix { }; qemu-hook = c ./qemu-hook.nix { };
setup-ssh = c ./setup-ssh { }; setup-ssh = c ./setup-ssh { };
+67
View File
@@ -0,0 +1,67 @@
{
bashInteractive,
dockerTools,
git,
lib,
nix,
pkgs,
podman,
top,
writeShellApplication,
...
}:
let
policy = (
pkgs.writeTextFile {
name = "policy.json";
text = ''
{
"default": [{"type": "insecureAcceptAnything"}]
}
'';
destination = "/etc/containers/policy.json";
}
);
activate = writeShellApplication {
name = "activate";
runtimeInputs = [ bashInteractive ];
text = ''
mkdir -p /etc/containers
cp ${policy}/etc/containers/policy.json /etc/containers/policy.json;
bash "$@"
'';
};
in
(import "${nix.src.outPath}/docker.nix" {
inherit pkgs;
name = "img-builder";
tag = "latest";
bundleNixpkgs = false;
Cmd = [
(lib.getExe activate)
];
extraPkgs = [
dockerTools.caCertificates
podman
];
flake-registry = (pkgs.formats.json { }).generate "flake-registry.json" ({
version = 2;
flakes.nixpkgs = {
exact = true;
from = {
id = "nixpkgs";
type = "indirect";
};
to = "${top.nixunstable}";
};
});
gitMinimal = git; # We want the full version in this
maxLayers = 111;
nixConf = {
experimental-features = [
"nix-command"
"flakes"
];
};
})