mirror of
https://github.com/lhns/steam-frame-nix.git
synced 2026-10-06 03:00:13 +02:00
Keyring launchers, Firefox default browser, rootless Docker
- keyring.flatpaks / keyring.programs: desktop entries shadowing an app's own that run it on the outer bus (one kwalletd6 for both sessions), with the wallet's D-Bus names as `flatpak run --talk-name` options (no Flatpak overrides), --password-store=kwallet6 for Electron, and login callback schemes as default + recommended handlers. - firefox.defaultBrowser: the launcher as default for http, https and text/html. - docker: rootless dockerd as a user service, socket in the outer runtime dir, CLI with DOCKER_HOST for both sessions.
This commit is contained in:
1 parent
aa9ca183f1
commit
b0131338de
10 files changed
+617
-14
No files matched your search
@@ -0,0 +1,57 @@
|
||||
# Rootless Docker
|
||||
|
||||
`docker.*`, module `docker`. Options:
|
||||
[README, Options](../README.md#options).
|
||||
|
||||
## Problem
|
||||
|
||||
SteamOS has no Docker, and Home Manager can't install the usual root
|
||||
daemon. Rootless Docker's default socket is in `$XDG_RUNTIME_DIR`, which
|
||||
differs between the Frame's [two sessions](../README.md#two-sessions), and
|
||||
the nested desktop can't reach the user service manager.
|
||||
|
||||
## What you get
|
||||
|
||||
- `dockerd` in rootless mode as the systemd user service `docker.service`
|
||||
of the Steam session's user manager, started at login and on switch
|
||||
(never restarted by a switch, which would stop running containers).
|
||||
- The `docker` CLI on `PATH`, whose default `DOCKER_HOST` is the socket in
|
||||
the outer runtime dir (`docker.host`,
|
||||
`unix:///run/user/1000/docker.sock`): it works in both sessions. A
|
||||
`DOCKER_HOST` you set yourself wins.
|
||||
|
||||
SteamOS already has what rootless Docker needs: `newuidmap`/`newgidmap`
|
||||
with their capabilities, `/etc/subuid` and `/etc/subgid` entries for the
|
||||
user, user namespaces and cgroup v2 delegation.
|
||||
|
||||
## Configuration
|
||||
|
||||
```nix
|
||||
steamFrame.docker.enable = true;
|
||||
```
|
||||
|
||||
Then `docker run --rm hello-world`. `docker.package` replaces the Docker
|
||||
package (daemon and CLI).
|
||||
|
||||
## Caveats
|
||||
|
||||
- Rootless limits apply: no ports below 1024 without extra setup,
|
||||
`--network host` is the rootless network namespace, containers can't
|
||||
gain real root.
|
||||
- Images, containers and volumes are app data in `~/.local/share/docker`,
|
||||
see [App data you create](../README.md#app-data-you-create) for how to
|
||||
remove them.
|
||||
- Disabling the module removes the unit but doesn't stop a running daemon:
|
||||
run `systemctl --user stop docker` first (or add `docker.service` to
|
||||
`session.services.stop` for that switch).
|
||||
- Another `docker` package in `home.packages` collides with the wrapped
|
||||
CLI.
|
||||
|
||||
## How it works
|
||||
|
||||
The user unit runs `dockerd-rootless` (RootlessKit) with `PATH=/usr/bin`,
|
||||
for SteamOS's `newuidmap`/`newgidmap`, and `Delegate=yes`. The unit is
|
||||
added to `session.services.start`, so each switch starts it if it isn't
|
||||
running. The CLI is the package's `docker` wrapped with a default
|
||||
`DOCKER_HOST`; nothing is written outside the store (no `daemon.json`, no
|
||||
Docker context).
|
||||
Reference in new issue
Block a user