2021-12-06 16:07:01 +00:00
|
|
|
{ lib, config, pkgs, ... }:
|
2020-04-24 23:36:52 +00:00
|
|
|
|
2024-01-02 11:29:13 +00:00
|
|
|
{
|
|
|
|
meta = {
|
|
|
|
maintainers = lib.teams.lxc.members;
|
|
|
|
};
|
|
|
|
|
2020-04-24 23:36:52 +00:00
|
|
|
imports = [
|
2023-10-09 19:29:22 +00:00
|
|
|
./lxc-instance-common.nix
|
2024-01-02 11:29:13 +00:00
|
|
|
|
|
|
|
(lib.mkRemovedOptionModule [ "virtualisation" "lxc" "nestedContainer" ] "")
|
|
|
|
(lib.mkRemovedOptionModule [ "virtualisation" "lxc" "privilegedContainer" ] "")
|
2020-04-24 23:36:52 +00:00
|
|
|
];
|
|
|
|
|
2024-01-02 11:29:13 +00:00
|
|
|
options = { };
|
2021-12-06 16:07:01 +00:00
|
|
|
|
|
|
|
config = {
|
|
|
|
boot.isContainer = true;
|
|
|
|
boot.postBootCommands =
|
|
|
|
''
|
|
|
|
# After booting, register the contents of the Nix store in the Nix
|
|
|
|
# database.
|
|
|
|
if [ -f /nix-path-registration ]; then
|
|
|
|
${config.nix.package.out}/bin/nix-store --load-db < /nix-path-registration &&
|
|
|
|
rm /nix-path-registration
|
|
|
|
fi
|
|
|
|
|
|
|
|
# nixos-rebuild also requires a "system" profile
|
|
|
|
${config.nix.package.out}/bin/nix-env -p /nix/var/nix/profiles/system --set /run/current-system
|
|
|
|
'';
|
|
|
|
|
|
|
|
system.build.tarball = pkgs.callPackage ../../lib/make-system-tarball.nix {
|
|
|
|
extraArgs = "--owner=0";
|
2020-04-24 23:36:52 +00:00
|
|
|
|
2021-12-06 16:07:01 +00:00
|
|
|
storeContents = [
|
|
|
|
{
|
|
|
|
object = config.system.build.toplevel;
|
|
|
|
symlink = "none";
|
|
|
|
}
|
|
|
|
];
|
|
|
|
|
|
|
|
contents = [
|
|
|
|
{
|
|
|
|
source = config.system.build.toplevel + "/init";
|
|
|
|
target = "/sbin/init";
|
|
|
|
}
|
2023-01-20 10:41:00 +00:00
|
|
|
# Technically this is not required for lxc, but having also make this configuration work with systemd-nspawn.
|
|
|
|
# Nixos will setup the same symlink after start.
|
|
|
|
{
|
|
|
|
source = config.system.build.toplevel + "/etc/os-release";
|
|
|
|
target = "/etc/os-release";
|
|
|
|
}
|
2021-12-06 16:07:01 +00:00
|
|
|
];
|
|
|
|
|
|
|
|
extraCommands = "mkdir -p proc sys dev";
|
|
|
|
};
|
|
|
|
|
2023-11-16 04:20:00 +00:00
|
|
|
system.build.squashfs = pkgs.callPackage ../../lib/make-squashfs.nix {
|
|
|
|
fileName = "nixos-lxc-image-${pkgs.stdenv.hostPlatform.system}";
|
|
|
|
|
|
|
|
noStrip = true; # keep directory structure
|
|
|
|
comp = "zstd -Xcompression-level 6";
|
|
|
|
|
|
|
|
storeContents = [config.system.build.toplevel];
|
|
|
|
|
|
|
|
pseudoFiles = [
|
|
|
|
"/sbin d 0755 0 0"
|
|
|
|
"/sbin/init s 0555 0 0 ${config.system.build.toplevel}/init"
|
|
|
|
"/dev d 0755 0 0"
|
|
|
|
"/proc d 0555 0 0"
|
|
|
|
"/sys d 0555 0 0"
|
|
|
|
];
|
|
|
|
};
|
|
|
|
|
2023-05-24 13:37:59 +00:00
|
|
|
system.build.installBootLoader = pkgs.writeScript "install-lxd-sbin-init.sh" ''
|
|
|
|
#!${pkgs.runtimeShell}
|
2023-11-16 04:20:00 +00:00
|
|
|
${pkgs.coreutils}/bin/ln -fs "$1/init" /sbin/init
|
2023-05-24 13:37:59 +00:00
|
|
|
'';
|
|
|
|
|
2024-01-02 11:29:13 +00:00
|
|
|
# networkd depends on this, but systemd module disables this for containers
|
|
|
|
systemd.additionalUpstreamSystemUnits = ["systemd-udev-trigger.service"];
|
|
|
|
|
|
|
|
systemd.packages = [ pkgs.distrobuilder.generator ];
|
2020-04-24 23:36:52 +00:00
|
|
|
|
2023-10-09 19:29:22 +00:00
|
|
|
system.activationScripts.installInitScript = lib.mkForce ''
|
2021-12-06 16:07:01 +00:00
|
|
|
ln -fs $systemConfig/init /sbin/init
|
|
|
|
'';
|
|
|
|
};
|
2020-04-24 23:36:52 +00:00
|
|
|
}
|