Docker: Difference between revisions

Joshbuker (talk | contribs)
Add a section for using nvidia with docker containers
DHCP (talk | contribs)
m Using Privileged Ports for Rootless Docker: remove unneeded blank line
 
(9 intermediate revisions by 9 users not shown)
Line 17: Line 17:
To temporarily use Docker in a shell environment, you can run:
To temporarily use Docker in a shell environment, you can run:
</translate>
</translate>
<syntaxhighlight lang="bash">
<syntaxhighlight lang=console>
nix-shell -p docker
$ nix-shell -p docker
</syntaxhighlight>
</syntaxhighlight>
<translate>
<translate>
Line 32: Line 32:
<!--T:7-->
<!--T:7-->
To install Docker on NixOS, add the virtualization.docker module to your system configuration at <code>/etc/nixos/configuration.nix</code>:<ref>https://nixos.org/manual/nixos/stable/options#opt-virtualisation.docker.enable</ref>
To install Docker on NixOS, add the virtualization.docker module to your system configuration at <code>/etc/nixos/configuration.nix</code>:<ref>https://nixos.org/manual/nixos/stable/options#opt-virtualisation.docker.enable</ref>
(Note that it may take a restart for the group changes to take effect.)
</translate>
</translate>
<syntaxhighlight lang="nix">
<syntaxhighlight lang="nix">
Line 52: Line 53:


<translate>
<translate>
== Configuration == <!--T:9-->
== Configuration == <!--T:9-->
</translate>
</translate>
Line 181: Line 183:
To use <code>compose2nix</code> with <code>nix-shell</code> you can use
To use <code>compose2nix</code> with <code>nix-shell</code> you can use
</translate>
</translate>
<syntaxhighlight lang="bash">
<syntaxhighlight lang=console>
nix shell github:aksiksi/compose2nix
$ nix shell github:aksiksi/compose2nix
compose2nix -h
$ compose2nix -h
</syntaxhighlight>
</syntaxhighlight>
<translate>
<translate>
Line 217: Line 219:
Alternatively, you can specify the input and output files with the following flags
Alternatively, you can specify the input and output files with the following flags
</translate>
</translate>
<syntaxhighlight lang="bash">
<syntaxhighlight lang=console>
compose2nix -inputs input.yml -output output.nix -runtime docker
$ compose2nix -inputs input.yml -output output.nix -runtime docker
</syntaxhighlight>
</syntaxhighlight>
<translate>
<translate>
Line 260: Line 262:
     # Optionally customize rootless Docker daemon settings
     # Optionally customize rootless Docker daemon settings
     daemon.settings = {
     daemon.settings = {
      data-root = "~/.local/docker";
       dns = [ "1.1.1.1" "8.8.8.8" ];
       dns = [ "1.1.1.1" "8.8.8.8" ];
       registry-mirrors = [ "https://mirror.gcr.io" ];
       registry-mirrors = [ "https://mirror.gcr.io" ];
Line 294: Line 297:


=== Using Privileged Ports for Rootless Docker ===
=== Using Privileged Ports for Rootless Docker ===
Rootless containers are not able to ports from 0 to 1023 as such port can only be used by privileged users.  This problem can be solved by using port forwarding.
Rootless containers are not able to bind ports from 0 to 1023 as such port can only be used by privileged users.  This problem can be solved by using port forwarding.


Assume you'd like a rootless container to make use of ports 53 (DNS; TPC and UDP) and 80 (web; TCP).  We may force the container to use port 8000 while the firewall is instructed for forward traffic from port 80 to 8000.  Same logic applies for port 53.  Refer to the following example:<syntaxhighlight lang="nixos"># Firewall
Assume you'd like a rootless container to make use of ports 53 (DNS; TPC and UDP) and 80 (web; TCP).  We may force the container to use port 8000 while the firewall is instructed for forward traffic from port 80 to 8000.  Same logic applies for port 53.  Refer to the following example:<syntaxhighlight lang="nixos"># Firewall
Line 301: Line 304:
   allowedTCPPorts = [ 80 8000 53 5300 ];
   allowedTCPPorts = [ 80 8000 53 5300 ];
   allowedUDPPorts = [ 53 5300 ];
   allowedUDPPorts = [ 53 5300 ];
  extraCommands = ''
    iptables -A PREROUTING -t nat -i eth0 -p TCP --dport 80 -j REDIRECT --to-port 8000
    iptables -A PREROUTING -t nat -i eth0 -p TCP --dport 53 -j REDIRECT --to-port 5300
    iptables -A PREROUTING -t nat -i eth0 -p UDP --dport 53 -j REDIRECT --to-port 5300
  '';
};
};


boot.kernel.sysctl = {
boot.kernel.sysctl = {
   "net.ipv4.conf.eth0.forwarding" = 1;    # enable port forwarding
   "net.ipv4.conf.eth0.forwarding" = 1;    # enable port forwarding
};
   
networking = {
  firewall.extraCommands = ''
    iptables -A PREROUTING -t nat -i eth0 -p TCP --dport 80 -j REDIRECT --to-port 8000
    iptables -A PREROUTING -t nat -i eth0 -p TCP --dport 53 -j REDIRECT --to-port 5300
    iptables -A PREROUTING -t nat -i eth0 -p UDP --dport 53 -j REDIRECT --to-port 5300
  '';
};</syntaxhighlight>Whilst the docker-compose.yaml might look like this:<syntaxhighlight lang="dockerfile">
};</syntaxhighlight>Whilst the docker-compose.yaml might look like this:<syntaxhighlight lang="dockerfile">
services:
services:
Line 323: Line 323:
       - "8000:80"
       - "8000:80"
</syntaxhighlight>
</syntaxhighlight>
<translate>
<translate>


Line 389: Line 388:
<translate>
<translate>
<!--T:48-->
<!--T:48-->
An alternative, if using [[flakes]], is to do <code>created = builtins.substring 0 8 self.lastModifiedDate</code>, which uses the commit date, and is therefore reproducible.
An alternative, if using [[flakes]], is to do <code>created = "@" + builtins.toString self.lastModified</code>, which uses the commit date, and is therefore reproducible.
</translate>
</translate>


Line 419: Line 418:
</translate>
</translate>


<syntaxhighlight lang="bash">
<syntaxhighlight lang=console>
skopeo copy docker://lnl7/nix@sha256:632268d5fd9ca87169c65353db99be8b4e2eb41833b626e09688f484222e860f docker-archive:///tmp/image.tgz:lnl7/nix:2.0
$ skopeo copy docker://lnl7/nix@sha256:632268d5fd9ca87169c65353db99be8b4e2eb41833b626e09688f484222e860f docker-archive:///tmp/image.tgz:lnl7/nix:2.0
</syntaxhighlight>
$ nix-hash --base32 --flat --type sha256 /tmp/image.tgz  
 
<syntaxhighlight lang="bash">
nix-hash --base32 --flat --type sha256 /tmp/image.tgz  
</syntaxhighlight>
<syntaxhighlight lang="shell">
1x00ks05cz89k3wc460i03iyyjr7wlr28krk7znavfy2qx5a0hfd
1x00ks05cz89k3wc460i03iyyjr7wlr28krk7znavfy2qx5a0hfd
</syntaxhighlight>
</syntaxhighlight>
Line 602: Line 596:
If you have a service running on the host that exposes a socket, such as mariadb, you can also expose that socket to the container instead. You'll want to expose the folder the socket is in as a volume - so:
If you have a service running on the host that exposes a socket, such as mariadb, you can also expose that socket to the container instead. You'll want to expose the folder the socket is in as a volume - so:
</translate>
</translate>
<syntaxhighlight lang="bash">
<syntaxhighlight lang=nix>
      volumes = [
volumes = [
        "/var/run/mysqld:/mysqld"
  "/var/run/mysqld:/mysqld"
      ];
];
</syntaxhighlight>
</syntaxhighlight>
<translate>
<translate>
<!--T:77-->
<!--T:77-->
to provide access to <code>/var/run/mysqld/mysqld.sock</code>. Sadly, this means you'll have to restart the container when /var/run/mysqld is replaced, e.g. on an upgrade.
to provide access to <code>/var/run/mysqld/mysqld.sock</code>. Sadly, this means you'll have to restart the container when /var/run/mysqld is replaced, e.g. on an upgrade.
</translate>
</translate>


Line 660: Line 653:
When Docker uses too much disk space:
When Docker uses too much disk space:
</translate>
</translate>
<syntaxhighlight lang="bash">
<syntaxhighlight lang=nix>
# Remove unused containers, networks, images, and volumes
# Remove unused containers, networks, images, and volumes
docker system prune -a --volumes
docker system prune -a --volumes
Line 679: Line 672:
<translate>
<translate>
<!--T:91-->
<!--T:91-->
Docker's default subnet (`172.17.0.0/16`) might conflict with your existing network. Configure a different subnet in your `configuration.nix`:
Docker's default subnet (`172.17.0.0/16`) might conflict with your existing network. Configure a different subnet in your <code>configuration.nix</code>:
</translate>
</translate>
<syntaxhighlight lang="nix">
<syntaxhighlight lang="nix">
Line 724: Line 717:


{{File|3={
{{File|3={
   virtualisation.docker.enable = true;
   # virtualisation.docker.enable = true; # This option is deprecated, please set hardware.nvidia-container-toolkit.enable instead.


   hardware.nvidia-container-toolkit.enable = true;
   hardware.nvidia-container-toolkit.enable = true;
  # Prevents: - Option enableNvidia on x86_64 requires 32-bit support libraries
   # Regular Docker
   # Regular Docker
   virtualisation.docker.daemon.settings.features.cdi = true;
   virtualisation.docker.daemon.settings.features.cdi = true;
Line 754: Line 748:
               capabilities: [gpu]
               capabilities: [gpu]
               device_ids:
               device_ids:
                 - nvidia.com/gpu=all|name=compose.yml|lang=yaml}}
                 - nvidia.com/gpu=all
 
volumes:
  ollama: {}|name=compose.yml|lang=yaml}}
<translate>
<translate>


Line 762: Line 757:


<references/>
<references/>
== See also ==
*[https://nixcademy.com/posts/auto-update-containers/ Run and Auto-Update Docker Containers on NixOS, Nixcademy]


[[Category:Applications]]
[[Category:Applications]]