]>
Commit | Line | Data |
---|---|---|
1 | # Dockerfile to create an environment that contains the Nix package manager. | |
2 | FROM debian:stable-slim | |
3 | ||
4 | ARG NIX_VERSION | |
5 | ENV NIX_VERSION ${NIX_VERSION:-2.3.9} | |
6 | ARG LANG | |
7 | ENV LANG ${LANG:-"en_US.UTF-8"} | |
8 | ||
9 | RUN addgroup --gid 30000 --system nixbld \ | |
10 | && for i in $(seq 1 30); do adduser --system --disabled-password --home /var/empty --gecos "Nix build user $i" --uid $((30000 + i)) --ingroup nixbld nixbld$i ; done \ | |
11 | && adduser --disabled-password nixuser \ | |
12 | && mkdir -m 0755 /nix && chown nixuser /nix \ | |
13 | && apt update && apt install -y wget xz-utils \ | |
14 | && apt clean && rm -rf /var/lib/apt/lists/* /tmp/* /var/tmp/* \ | |
15 | # sandboxing enabled by default since 2.2 | |
16 | && mkdir -p /etc/nix && echo 'sandbox = false' > /etc/nix/nix.conf | |
17 | ||
18 | USER nixuser | |
19 | ENV USER=nixuser | |
20 | ENV HOME="/home/nixuser" | |
21 | ENV NIX_SYSTEM_PATH="/nix/var/nix/profiles/system" | |
22 | ENV NIX_PROFILE="$HOME/nix-envs" | |
23 | ||
24 | RUN cd && wget https://nixos.org/releases/nix/nix-$NIX_VERSION/nix-$NIX_VERSION-x86_64-linux.tar.xz \ | |
25 | && tar xJf nix-*-x86_64-linux.tar.xz \ | |
26 | && NIX_PROFILE="$NIX_SYSTEM_PATH" ~/nix-*-x86_64-linux/install \ | |
27 | && rm -rf ~/nix-*-* | |
28 | ||
29 | # All subsequent "RUN" will use a login shell | |
30 | SHELL ["/usr/bin/env", "bash", "-l", "-c"] | |
31 | ||
32 | # Create bash profile | |
33 | COPY --chown=nixuser:nixuser files/.profile ${HOME}/.profile | |
34 | ||
35 | RUN nix-channel --add https://nixos.org/channels/nixos-unstable nixpkgs \ | |
36 | && nix-channel --update | |
37 | ||
38 | # Propagate UTF8 | |
39 | # https://github.com/NixOS/nix/issues/599#issuecomment-153885553 | |
40 | # The same is hapenning with stack2nix | |
41 | RUN nix-env -p "$NIX_SYSTEM_PATH" -iA nixpkgs.glibcLocales | |
42 | ||
43 | # < Nix context as a volume | |
44 | # We want to be able to define /nix/store as a volume | |
45 | VOLUME ["/nix"] | |
46 | # /> | |
47 | ||
48 | # Make sure to use "login" shell when running container | |
49 | ENTRYPOINT ["/usr/bin/env", "bash", "-l", "-c"] |