- keyring.flatpaks / keyring.programs: desktop entries shadowing an app's own that run it on the outer bus (one kwalletd6 for both sessions), with the wallet's D-Bus names as `flatpak run --talk-name` options (no Flatpak overrides), --password-store=kwallet6 for Electron, and login callback schemes as default + recommended handlers. - firefox.defaultBrowser: the launcher as default for http, https and text/html. - docker: rootless dockerd as a user service, socket in the outer runtime dir, CLI with DOCKER_HOST for both sessions.
2.1 KiB
Rootless Docker
docker.*, module docker. Options:
README, Options.
Problem
SteamOS has no Docker, and Home Manager can't install the usual root
daemon. Rootless Docker's default socket is in $XDG_RUNTIME_DIR, which
differs between the Frame's two sessions, and
the nested desktop can't reach the user service manager.
What you get
dockerdin rootless mode as the systemd user servicedocker.serviceof the Steam session's user manager, started at login and on switch (never restarted by a switch, which would stop running containers).- The
dockerCLI onPATH, whose defaultDOCKER_HOSTis the socket in the outer runtime dir (docker.host,unix:///run/user/1000/docker.sock): it works in both sessions. ADOCKER_HOSTyou set yourself wins.
SteamOS already has what rootless Docker needs: newuidmap/newgidmap
with their capabilities, /etc/subuid and /etc/subgid entries for the
user, user namespaces and cgroup v2 delegation.
Configuration
steamFrame.docker.enable = true;
Then docker run --rm hello-world. docker.package replaces the Docker
package (daemon and CLI).
Caveats
- Rootless limits apply: no ports below 1024 without extra setup,
--network hostis the rootless network namespace, containers can't gain real root. - Images, containers and volumes are app data in
~/.local/share/docker, see App data you create for how to remove them. - Disabling the module removes the unit but doesn't stop a running daemon:
run
systemctl --user stop dockerfirst (or adddocker.servicetosession.services.stopfor that switch). - Another
dockerpackage inhome.packagescollides with the wrapped CLI.
How it works
The user unit runs dockerd-rootless (RootlessKit) with PATH=/usr/bin,
for SteamOS's newuidmap/newgidmap, and Delegate=yes. The unit is
added to session.services.start, so each switch starts it if it isn't
running. The CLI is the package's docker wrapped with a default
DOCKER_HOST; nothing is written outside the store (no daemon.json, no
Docker context).