mirror of
https://github.com/lhns/steam-frame-nix.git
synced 2026-10-06 00:00:16 +02:00
- keyring.flatpaks / keyring.programs: desktop entries shadowing an app's own that run it on the outer bus (one kwalletd6 for both sessions), with the wallet's D-Bus names as `flatpak run --talk-name` options (no Flatpak overrides), --password-store=kwallet6 for Electron, and login callback schemes as default + recommended handlers. - firefox.defaultBrowser: the launcher as default for http, https and text/html. - docker: rootless dockerd as a user service, socket in the outer runtime dir, CLI with DOCKER_HOST for both sessions.
58 lines
2.1 KiB
Markdown
58 lines
2.1 KiB
Markdown
# Rootless Docker
|
|
|
|
`docker.*`, module `docker`. Options:
|
|
[README, Options](../README.md#options).
|
|
|
|
## Problem
|
|
|
|
SteamOS has no Docker, and Home Manager can't install the usual root
|
|
daemon. Rootless Docker's default socket is in `$XDG_RUNTIME_DIR`, which
|
|
differs between the Frame's [two sessions](../README.md#two-sessions), and
|
|
the nested desktop can't reach the user service manager.
|
|
|
|
## What you get
|
|
|
|
- `dockerd` in rootless mode as the systemd user service `docker.service`
|
|
of the Steam session's user manager, started at login and on switch
|
|
(never restarted by a switch, which would stop running containers).
|
|
- The `docker` CLI on `PATH`, whose default `DOCKER_HOST` is the socket in
|
|
the outer runtime dir (`docker.host`,
|
|
`unix:///run/user/1000/docker.sock`): it works in both sessions. A
|
|
`DOCKER_HOST` you set yourself wins.
|
|
|
|
SteamOS already has what rootless Docker needs: `newuidmap`/`newgidmap`
|
|
with their capabilities, `/etc/subuid` and `/etc/subgid` entries for the
|
|
user, user namespaces and cgroup v2 delegation.
|
|
|
|
## Configuration
|
|
|
|
```nix
|
|
steamFrame.docker.enable = true;
|
|
```
|
|
|
|
Then `docker run --rm hello-world`. `docker.package` replaces the Docker
|
|
package (daemon and CLI).
|
|
|
|
## Caveats
|
|
|
|
- Rootless limits apply: no ports below 1024 without extra setup,
|
|
`--network host` is the rootless network namespace, containers can't
|
|
gain real root.
|
|
- Images, containers and volumes are app data in `~/.local/share/docker`,
|
|
see [App data you create](../README.md#app-data-you-create) for how to
|
|
remove them.
|
|
- Disabling the module removes the unit but doesn't stop a running daemon:
|
|
run `systemctl --user stop docker` first (or add `docker.service` to
|
|
`session.services.stop` for that switch).
|
|
- Another `docker` package in `home.packages` collides with the wrapped
|
|
CLI.
|
|
|
|
## How it works
|
|
|
|
The user unit runs `dockerd-rootless` (RootlessKit) with `PATH=/usr/bin`,
|
|
for SteamOS's `newuidmap`/`newgidmap`, and `Delegate=yes`. The unit is
|
|
added to `session.services.start`, so each switch starts it if it isn't
|
|
running. The CLI is the package's `docker` wrapped with a default
|
|
`DOCKER_HOST`; nothing is written outside the store (no `daemon.json`, no
|
|
Docker context).
|