Files
Pierre Kisters b0131338de Keyring launchers, Firefox default browser, rootless Docker
- keyring.flatpaks / keyring.programs: desktop entries shadowing an app's
  own that run it on the outer bus (one kwalletd6 for both sessions), with
  the wallet's D-Bus names as `flatpak run --talk-name` options (no Flatpak
  overrides), --password-store=kwallet6 for Electron, and login callback
  schemes as default + recommended handlers.
- firefox.defaultBrowser: the launcher as default for http, https and
  text/html.
- docker: rootless dockerd as a user service, socket in the outer runtime
  dir, CLI with DOCKER_HOST for both sessions.
2026-09-29 01:13:47 +02:00

2.1 KiB

Rootless Docker

docker.*, module docker. Options: README, Options.

Problem

SteamOS has no Docker, and Home Manager can't install the usual root daemon. Rootless Docker's default socket is in $XDG_RUNTIME_DIR, which differs between the Frame's two sessions, and the nested desktop can't reach the user service manager.

What you get

  • dockerd in rootless mode as the systemd user service docker.service of the Steam session's user manager, started at login and on switch (never restarted by a switch, which would stop running containers).
  • The docker CLI on PATH, whose default DOCKER_HOST is the socket in the outer runtime dir (docker.host, unix:///run/user/1000/docker.sock): it works in both sessions. A DOCKER_HOST you set yourself wins.

SteamOS already has what rootless Docker needs: newuidmap/newgidmap with their capabilities, /etc/subuid and /etc/subgid entries for the user, user namespaces and cgroup v2 delegation.

Configuration

steamFrame.docker.enable = true;

Then docker run --rm hello-world. docker.package replaces the Docker package (daemon and CLI).

Caveats

  • Rootless limits apply: no ports below 1024 without extra setup, --network host is the rootless network namespace, containers can't gain real root.
  • Images, containers and volumes are app data in ~/.local/share/docker, see App data you create for how to remove them.
  • Disabling the module removes the unit but doesn't stop a running daemon: run systemctl --user stop docker first (or add docker.service to session.services.stop for that switch).
  • Another docker package in home.packages collides with the wrapped CLI.

How it works

The user unit runs dockerd-rootless (RootlessKit) with PATH=/usr/bin, for SteamOS's newuidmap/newgidmap, and Delegate=yes. The unit is added to session.services.start, so each switch starts it if it isn't running. The CLI is the package's docker wrapped with a default DOCKER_HOST; nothing is written outside the store (no daemon.json, no Docker context).