Archived
Check NixOS configurations / eval-hosts (pull_request) Successful in 10m39s
Create an IPA group "docker-access" (GID 50010) and pin the local "docker" group to that GID on all Docker hosts. Any IPA user in the docker-access group automatically gains docker socket access through SSSD supplementary-group resolution — no per-host docker.members entry needed. Specific changes: - variables.nix: add dockerAccessGid = 50010 - modules/docker/enable-service.nix: lib.mkForce docker GID to dockerAccessGid, removing the need to name individual IPA users - modules/build-types/docker.nix: remove direct wayne docker.members entry (access now comes from IPA group) - modules/ipa/client.nix: refactor repeated security.* / systemd.* top-level keys into merged attribute sets (fixes statix W20); add security.pam.services.lightdm.makeHomeDir so the GUI login path also creates the home dir on first login Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
30 lines
920 B
Nix
30 lines
920 B
Nix
{ lib, pkgs, vars, ... }:
|
|
|
|
{
|
|
# virtualisation.docker.enable = true;
|
|
virtualisation.docker = {
|
|
enable = true;
|
|
package = pkgs.docker;
|
|
# listenOptions = [
|
|
# "unix:///var/run/docker.sock"
|
|
# "tcp://0.0.0.0:2375"
|
|
#];
|
|
|
|
# daemon.settings = {
|
|
# metrics-addr = "0.0.0.0:9323";
|
|
# experimental = true;
|
|
# };
|
|
};
|
|
# Pin the docker group GID to match the IPA "docker-access" group so that
|
|
# IPA group membership alone grants access to the Docker socket. Any user
|
|
# whose supplementary groups (resolved by SSSD from IPA) include GID
|
|
# vars.dockerAccessGid will pass the socket group-permission check without
|
|
# any per-host users.groups.docker.members entry.
|
|
users.groups.docker.gid = lib.mkForce vars.dockerAccessGid;
|
|
users.users.${vars.primaryUser}.extraGroups = [ "docker" ];
|
|
environment.systemPackages = with pkgs; [
|
|
docker-compose
|
|
docker-buildx
|
|
];
|
|
}
|