mirror of
https://github.com/lhns/steam-frame-nix.git
synced 2026-10-06 04:04:16 +02:00
- keyring.flatpaks / keyring.programs: desktop entries shadowing an app's own that run it on the outer bus (one kwalletd6 for both sessions), with the wallet's D-Bus names as `flatpak run --talk-name` options (no Flatpak overrides), --password-store=kwallet6 for Electron, and login callback schemes as default + recommended handlers. - firefox.defaultBrowser: the launcher as default for http, https and text/html. - docker: rootless dockerd as a user service, socket in the outer runtime dir, CLI with DOCKER_HOST for both sessions.
82 lines
2.8 KiB
Nix
82 lines
2.8 KiB
Nix
# Rootless Docker as a systemd user service (home-manager can't install a
|
|
# root daemon). SteamOS already provides what it needs: newuidmap/newgidmap
|
|
# with their capabilities in /usr/bin, /etc/subuid and /etc/subgid entries
|
|
# for the user, user namespaces and cgroup v2 delegation.
|
|
# - The socket is in the outer runtime dir (session.runtimeDir): the nested
|
|
# desktop has its own XDG_RUNTIME_DIR, so the CLI gets DOCKER_HOST as a
|
|
# default in its wrapper instead of relying on $XDG_RUNTIME_DIR.
|
|
# - Started, never restarted, on switch (session.services.start): a restart
|
|
# would stop running containers.
|
|
# Nothing is written outside the store by this module; dockerd keeps its data
|
|
# (images, containers, volumes) in ~/.local/share/docker (app data).
|
|
{ config, lib, pkgs, ... }:
|
|
let
|
|
cfg = config.steamFrame.docker;
|
|
host = "unix://${config.steamFrame.session.runtimeDir}/docker.sock";
|
|
|
|
cli = pkgs.symlinkJoin {
|
|
name = "docker-rootless-cli";
|
|
paths = [ cfg.package ];
|
|
nativeBuildInputs = [ pkgs.makeWrapper ];
|
|
postBuild = ''
|
|
wrapProgram $out/bin/docker --set-default DOCKER_HOST ${host}
|
|
'';
|
|
};
|
|
in {
|
|
imports = [ ./cleanup.nix ];
|
|
|
|
options.steamFrame.docker = {
|
|
enable = lib.mkEnableOption ''
|
|
rootless Docker: dockerd as a user service and the docker CLI, usable
|
|
from both sessions'';
|
|
package = lib.mkOption {
|
|
type = lib.types.package;
|
|
default = pkgs.docker;
|
|
defaultText = lib.literalExpression "pkgs.docker";
|
|
description = ''
|
|
Docker package: dockerd-rootless for the service, the CLI (wrapped
|
|
with DOCKER_HOST) on PATH.
|
|
'';
|
|
};
|
|
host = lib.mkOption {
|
|
type = lib.types.str;
|
|
readOnly = true;
|
|
default = host;
|
|
defaultText = lib.literalExpression
|
|
''"unix://''${config.steamFrame.session.runtimeDir}/docker.sock"'';
|
|
description = "DOCKER_HOST of the daemon (for other clients).";
|
|
};
|
|
};
|
|
|
|
config = lib.mkIf cfg.enable {
|
|
home.packages = [ cli ];
|
|
|
|
systemd.user.services.docker = {
|
|
Unit = {
|
|
Description = "Docker Application Container Engine (Rootless)";
|
|
StartLimitIntervalSec = 60;
|
|
StartLimitBurst = 3;
|
|
};
|
|
Service = {
|
|
Type = "notify";
|
|
# /usr/bin for SteamOS's newuidmap/newgidmap (they need their caps).
|
|
Environment = "PATH=/usr/bin";
|
|
ExecStart = "${cfg.package}/bin/dockerd-rootless";
|
|
ExecReload = "${pkgs.procps}/bin/kill -s HUP $MAINPID";
|
|
TimeoutSec = 0;
|
|
Restart = "always";
|
|
RestartSec = 2;
|
|
LimitNOFILE = "infinity";
|
|
LimitNPROC = "infinity";
|
|
LimitCORE = "infinity";
|
|
Delegate = true;
|
|
NotifyAccess = "all";
|
|
KillMode = "mixed";
|
|
};
|
|
Install.WantedBy = [ "default.target" ];
|
|
};
|
|
|
|
steamFrame.session.services.start = [ "docker.service" ];
|
|
};
|
|
}
|