Commit Graph

113 Commits

Author SHA1 Message Date
Robert Hensing
b3f4821490 nixos/tests/containers-eval: init + improve error messages 2026-09-17 07:14:55 +02:00
Robert Hensing
a9d3cf39fa nixos/nixos-containers: report host nix options accurately 2026-09-17 07:14:53 +02:00
Robert Hensing
bf78e69f9e nixos/nixos-containers: fix typo
Pre-existing, so separate commit.
2026-09-17 07:14:22 +02:00
Robert Hensing
dea68e7db0 nixos/nixos-containers: assert flake container needs nix on host 2026-09-17 07:14:22 +02:00
Robert Hensing
960f040ac7 nixos/nixos-containers: report assertions correctly
It used to report

    error: expected a set but found a string: "<the actual message>"
2026-09-17 07:14:22 +02:00
Robert Hensing
7657773d57 nixos/nixos-containers: fix flake container eval
See 4c9db6cedb (r199475394)
2026-09-17 07:14:17 +02:00
Robert Hensing
28cf1a03f6 nixosTests: do not depend on nix by default (#553728) 2026-09-06 18:50:51 +00:00
rnhmjoj
374555fd64 nixos/containers: fixup 21e032ff95 2026-08-21 10:49:15 +02:00
Robert Hensing
4c9db6cedb nixos/nixos-containers: support nix.enable = false
The container tests generally don't need this, it seems to work fine
so far, and this could genuinely be useful in image-based deployments.

Why an error instead of inheriting the setting?
Containers do not and should not inherit a parent setting like this.
If a container declares requiring too much, that's the mistake.
If the host does not support a container's declared environment, that's
a host problem.
If the container inherits the setting from the parent, the container's
configuration is not respected.

Example of the error message:
nodes.machine.containers.web-noip requires a Nix daemon but the host does not provided it, as option nodes.machine.nix.daemon.enable is disabled
2026-08-17 23:31:24 +02:00
Michele Guerini Rocco
21e032ff95 nixos/containers: fix IPv4-mapped addresses (#536638) 2026-08-16 22:25:34 +00:00
Leon Schuermann
aa19ec5231 nixos-containers: fix dummyConfig localMacAddress default
In a13b423085 ("nixos-containers: allow hard-coding container veth MAC address &
add IPv6 SLAAC test case (#462775)") I had a typo in the `localMacAddress`
setting used for the dummy container config to generate the systemd service
template. I don't think this actually causes any breakage, but it's good to fix
for consistency's sake nonetheless.
2026-07-04 15:10:21 -04:00
rnhmjoj
0d665774b3 nixos/containers: fix IPv4-mapped addresses
lib.network.ipv6.fromString tries to parse the address and fails with
IPv4-mapped addresses, but we actually just want to extract the prefix,
so do this using string operations, as for IPv4.

Fixes issue #530543.
2026-06-29 14:18:48 +02:00
George Shammas
217d834eb9 nixos/containers: fix default gateway with privateNetwork (v2)
The fix in #523016 fixes an issue with the default gateway, however it
does so by unconditionally defining `networking.interfaces.eth0`. This
makes so if you had other methods of defining the addresses for eth0,
those now get blanked out.

Instead, move the logic around so we only define
networking.interfaces.eth0 if we really have to.
2026-05-25 22:17:45 -04:00
rnhmjoj
47e19f5f91 nixos/containers: fix default gateway with privateNetwork
Fixes issue reported here https://github.com/NixOS/nixpkgs/pull/515773#issuecomment-4501563586

Containers with privateNetwork have an eth0 interface configured
imperatively by the container setup script, so the networking-interfaces.nix module
doesn't know about it. Specifying the default gateway then fails
silently, unless this setup is mirrored in networking.interfaces.eth0
inside the container.
2026-05-23 09:37:17 +02:00
Lucas Savva
a13b423085 nixos-containers: allow hard-coding container veth MAC address & add IPv6 SLAAC test case (#462775) 2026-05-03 23:12:33 +00:00
Franz Pletz
1b786dda36 nixos/nixos-containers: fix interface name escaping in systemd.device unit name (#478341) 2026-04-04 19:02:50 +00:00
Philip Taron
04f9003b98 nixos-containers: remove unnecessary _file using __curPos
The module system's fallback is sufficient for this inline module.
2026-03-19 11:45:38 -07:00
nikstur
b9f2fa1c7d nixos/nixos-containers: create load bearing /usr/bin
/usr/bin is load bearing and needs to be inside a root before nspawn
will pivot to it.

This will allow us to drop systemd/0003-Fix-NixOS-containers.patch
2026-02-12 23:19:07 +01:00
Dyego Aurélio
28096cc5e3 treewide: apply nixfmt 1.2.0 2026-01-22 18:37:56 -03:00
NAHO
a2ed7e8d88 nixos: remove optional builtins prefixes from prelude functions
Remove optional builtins prefixes from prelude functions by running:

    builtins=(
      abort
      baseNameOf
      break
      derivation
      derivationStrict
      dirOf
      false
      fetchGit
      fetchMercurial
      fetchTarball
      fetchTree
      fromTOML
      import
      isNull
      map
      null
      placeholder
      removeAttrs
      scopedImport
      throw
      toString
      true
    )

    fd \
      --exclude doc/manual/release-notes \
      --type file \
      . \
      nixos \
      --exec-batch sed --in-place --regexp-extended "
        s/\<builtins\.($(
          printf '%s\n' "${builtins[@]}" |
            paste --delimiter '|' --serial -
        ))\>/\1/g
      "

    nix fmt
2026-01-15 16:07:55 +01:00
Rvfg
bf3d134bd6 nixos/nixos-containers: format 2026-01-09 17:23:58 +08:00
Rvfg
cbe6c1767d nixos/nixos-containers: fix interface name escaping in systemd.device unit name
systemd escapes interface names in generated .device units.
e.g. dummy-test -> dummy\x2dtest
2026-01-09 16:55:42 +08:00
Leon Schuermann
a2cd0a2cf7 nixos-containers: allow hard-coding container veth MAC address
When using a NixOS container with `privateNetwork = true;` (i.e., a
veth network device), it automatically gets assigned a random, locally
administered unicast MAC address. While this is fine for many
purposes, when attaching this container to a larger Layer 2 network
where it interacts with other services, like an external DHCP server
or IPv6 gateway sending out router advertisements, the MAC address of
the container matters.

This commit thus adds a `macAddress` option to containers. If set,
this MAC address will be assigned to the container-side of the `veth`
interface very early during container boot (before executing the stage
2 init script). This is crucial to ensure that no services run in the
container using the prior, random MAC automatically assigned to the
`veth` device. Otherweise, I've had problems using systemd units or
the activation scripts to set the address early enough during
container boot to use it, for example, for IPv6 SLAAC address
assignment.
2025-11-18 14:50:41 -05:00
Victor Engmark
e9d4990ab1 nixos-container: Conform to ShellCheck 2025-10-09 18:18:44 +02:00
Maximilian Bosch
a6b0564b7d nixos/filesystems: fix special file-systems for systemd-nspawn (#345899) 2025-10-03 19:33:31 +00:00
h7x4
3f78de8457 nixos/nixos-containers: use types.port 2025-09-22 16:33:03 +02:00
Maximilian Bosch
a532cb052e nixos/containers: add boot.isNspawnContainer option
There are a bunch of components such as incus or LXC that also use
`boot.isContainer`, so we'd have to differentiate between "OS container"
and "actually nspawn".

This became necessary for the file-systems part where nspawn takes care
of setting up special filesystems like `/proc`, `/dev` etc., but others
don't.

To allow for a `boot.isContainer` being less overloaded, this introduces
`boot.isNspawnContainer` that is exclusively used for nspawn-specific
things. When `true`, `boot.isContainer = true;` is implied.
2025-09-21 13:26:23 +02:00
Emily
7c4b56bd12 nixos/nixos-containers: actually eliminate costs if no containers are used (#427001) 2025-08-25 19:53:32 +01:00
dish
970dcca69c treewide: Fix links in module documentation 2025-08-25 12:55:11 -04:00
zimward
29be71ca49 nixos/nixos-containers: actually eliminate costs if no containers are used 2025-08-24 22:16:29 +02:00
Wolfgang Walther
5a0711127c treewide: run nixfmt 1.0.0 2025-07-24 13:55:40 +02:00
Gwendolyn Kornak
b5b04bb146 nixos/nixos-containers: add flake to container start script
Integrated the flake container setup into the spawn script for systemd-nspawn.
The trickiest part of this was ensuring the underlying per-container is built.
With the .conf file created, running `nixos-container update` creates all the necessary per-container structure.
We call this command at start to ensure the structure is created only if the per-container system isnt there.
Note: This also means the flake gets updated to branch HEAD when the container is started for the first time.
2025-07-05 17:22:15 -07:00
Gwendolyn Kornak
9a3173dacd nixos/nixos-containers: add flake option
While the nixos-container command allows for the creation of containers pointing to a flake, the declarative module doesn't have this option.
Adds the flake option for nixos-container declarative approach. Creates the /etc/nixos-container .conf file similar to how the command preforms it.
2025-07-05 17:21:37 -07:00
John Titor
c87464cb0c Revert "treewide: migrate nixos modules to networking.hosts"
This reverts commit cd64f1bd87.
2025-06-09 00:10:05 +05:30
John Titor
cd64f1bd87 treewide: migrate nixos modules to networking.hosts
Signed-off-by: John Titor <50095635+JohnRTitor@users.noreply.github.com>
2025-06-07 23:09:46 +05:30
Louis Opter
9d3a171dbf nixos/containers: fix shell error when privateUsers=no
Details in #387773.
2025-04-05 00:36:42 +00:00
Silvan Mosberger
374e6bcc40 treewide: Format all Nix files
Format all Nix files using the officially approved formatter,
making the CI check introduced in the previous commit succeed:

  nix-build ci -A fmt.check

This is the next step of the of the [implementation](https://github.com/NixOS/nixfmt/issues/153)
of the accepted [RFC 166](https://github.com/NixOS/rfcs/pull/166).

This commit will lead to merge conflicts for a number of PRs,
up to an estimated ~1100 (~33%) among the PRs with activity in the past 2
months, but that should be lower than what it would be without the previous
[partial treewide format](https://github.com/NixOS/nixpkgs/pull/322537).

Merge conflicts caused by this commit can now automatically be resolved while rebasing using the
[auto-rebase script](8616af08d9/maintainers/scripts/auto-rebase).

If you run into any problems regarding any of this, please reach out to the
[formatting team](https://nixos.org/community/teams/formatting/) by
pinging @NixOS/nix-formatting.
2025-04-01 20:10:43 +02:00
Kevin Boulain
c2d4e8f4cb nixos/nixos-containers: user options take precedence over module ones
I think this is the norm in NixOS modules. This allows to start a
container with '--volatile=overlay --link-journal=host' in order to
persist logs across runs of a container running with a temporary root.
While '--ephemeral' omits '--link-journal=try-guest', it's not possible
to run an ephemeral container when linking the journal:
https://github.com/systemd/systemd/issues/1666
2025-03-09 11:08:56 +01:00
Ramses
51e84098b5 nixos-container: avoid subshell when testing $PRIVATE_USERS (#383056) 2025-02-19 10:46:48 +01:00
Jean-Baptiste Giraudeau
57c96ff6ef nixos-container: avoid subshell when testing $PRIVATE_USERS
So that the script is not rejected by https://www.shellcheck.net/wiki/SC2235
 under `systemd.enableStrictShellChecks = true;`
2025-02-18 09:41:55 +01:00
Sandro
86f9eeb816 nixos-container: add support for --private-users (#362210) 2025-02-18 00:09:56 +01:00
Christian Kögler
bbd8de2fdd nixos-container: do not touch os-release if it is a symlink (#353366) 2025-02-16 07:43:34 +01:00
Jean-Baptiste Giraudeau
c8f83ec641 nixos-container: add support for --private-users
imply bind mounts with idmap option when user namespacing is enabled,
 so that /nix/store and friends are correctly own by root user.
2025-02-12 14:28:57 +01:00
Robert Hensing
0b47fba230 Revert "nixos/nixpkgs: make config.nixpkgs.{localSystem,crossSystem,buildPlatform,hostPlatform} write only"
This reverts commit 0a19371146.
2025-02-05 14:29:18 +01:00
Wolfgang Walther
0a19371146 nixos/nixpkgs: make config.nixpkgs.{localSystem,crossSystem,buildPlatform,hostPlatform} write only
The description for options.nixpkgs.system already hints at this:

  Neither ${opt.system} nor any other option in nixpkgs.* is meant
  to be read by modules and configurations.
  Use pkgs.stdenv.hostPlatform instead.

We can support this goal by not elaborating the systems anymore, forcing
users to go via pkgs.stdenv.

This will prevent problems when making the top-level package sets
composable in the next commit. For this to work, you should pass a fully
elaborated system to nixpkgs' localSystem or crossSystem options.
2025-02-01 12:04:59 +01:00
Peder Bergebakken Sundt
953f72e76e nixos/*: tag manpage references 2025-01-27 02:47:01 +01:00
Nico Felbinger
e65d6fba75 nixos-containers: add networkNamespace option 2024-12-23 00:18:02 +01:00
Paul Grandperrin
853d34898d nixos-containers: fix enableTun option
When using private users, `mknod /dev/net/tun` is run from the guest and therefor needs the `m` modifier.
2024-11-19 14:43:02 +01:00
taku0
a009d2b73f nixos-container: do not touch os-release if it is a symlink
`/etc/os-release` of NixOS containers, which are
`/var/lib/nixos-containers/*/etc/os-release` on the host, are usually
symlinks to the absolute path `/etc/static/os-release` but it doesn't
exist in non-NixOS host.  Since `startScript` is evaluated by the host
system, both `[ -e "$root/etc/os-release" ]` and
`touch "$root/etc/os-release"` fail, so that the container fails to
start on the second boot (on the first boot, the symlink doesn't exist,
so the command succeeds).

This commit avoids `touch "$root/etc/os-release"` if
`$root/etc/os-release` is a symlink, so imperative NixOS containers are
usable on non-NixOS host.
2024-11-03 22:02:50 +09:00
r-vdp
cc28f2bef5 nixos/containers: Fix shellcheck issues 2024-10-03 17:57:41 +02:00