Files
Pierre Kisters b0131338de Keyring launchers, Firefox default browser, rootless Docker
- keyring.flatpaks / keyring.programs: desktop entries shadowing an app's
  own that run it on the outer bus (one kwalletd6 for both sessions), with
  the wallet's D-Bus names as `flatpak run --talk-name` options (no Flatpak
  overrides), --password-store=kwallet6 for Electron, and login callback
  schemes as default + recommended handlers.
- firefox.defaultBrowser: the launcher as default for http, https and
  text/html.
- docker: rootless dockerd as a user service, socket in the outer runtime
  dir, CLI with DOCKER_HOST for both sessions.
2026-09-29 01:13:47 +02:00

58 lines
2.1 KiB
Markdown

# Rootless Docker
`docker.*`, module `docker`. Options:
[README, Options](../README.md#options).
## Problem
SteamOS has no Docker, and Home Manager can't install the usual root
daemon. Rootless Docker's default socket is in `$XDG_RUNTIME_DIR`, which
differs between the Frame's [two sessions](../README.md#two-sessions), and
the nested desktop can't reach the user service manager.
## What you get
- `dockerd` in rootless mode as the systemd user service `docker.service`
of the Steam session's user manager, started at login and on switch
(never restarted by a switch, which would stop running containers).
- The `docker` CLI on `PATH`, whose default `DOCKER_HOST` is the socket in
the outer runtime dir (`docker.host`,
`unix:///run/user/1000/docker.sock`): it works in both sessions. A
`DOCKER_HOST` you set yourself wins.
SteamOS already has what rootless Docker needs: `newuidmap`/`newgidmap`
with their capabilities, `/etc/subuid` and `/etc/subgid` entries for the
user, user namespaces and cgroup v2 delegation.
## Configuration
```nix
steamFrame.docker.enable = true;
```
Then `docker run --rm hello-world`. `docker.package` replaces the Docker
package (daemon and CLI).
## Caveats
- Rootless limits apply: no ports below 1024 without extra setup,
`--network host` is the rootless network namespace, containers can't
gain real root.
- Images, containers and volumes are app data in `~/.local/share/docker`,
see [App data you create](../README.md#app-data-you-create) for how to
remove them.
- Disabling the module removes the unit but doesn't stop a running daemon:
run `systemctl --user stop docker` first (or add `docker.service` to
`session.services.stop` for that switch).
- Another `docker` package in `home.packages` collides with the wrapped
CLI.
## How it works
The user unit runs `dockerd-rootless` (RootlessKit) with `PATH=/usr/bin`,
for SteamOS's `newuidmap`/`newgidmap`, and `Delegate=yes`. The unit is
added to `session.services.start`, so each switch starts it if it isn't
running. The CLI is the package's `docker` wrapped with a default
`DOCKER_HOST`; nothing is written outside the store (no `daemon.json`, no
Docker context).