Branch: refs/heads/master
Home: https://github.com/NixOS/nixpkgs
Commit: c6529ac9eb03145449d0d8af4aa1123935a88a1a
https://github.com/NixOS/nixpkgs/commit/c6529ac9eb03145449d0d8af4aa1123935a88a1a
Author: Eelco Dolstra <[email protected]>
Date: 2013-11-27 (Wed, 27 Nov 2013)
Changed paths:
M nixos/modules/services/databases/postgresql.nix
Log Message:
-----------
postgresql: Fix the port option
Also clarify the description of the enableTCPIP option.
Commit: 57f145a7f8c3bd01e5ac1927cb0e1b14658fa7aa
https://github.com/NixOS/nixpkgs/commit/57f145a7f8c3bd01e5ac1927cb0e1b14658fa7aa
Author: Eelco Dolstra <[email protected]>
Date: 2013-11-27 (Wed, 27 Nov 2013)
Changed paths:
M nixos/modules/services/misc/nix-daemon.nix
Log Message:
-----------
When setting $NIX_REMOTE, check whether /nix/var/nix/db is writable
In NixOS containers, root doesn't have write permission to
/nix/var/nix/db, so it has to use the daemon.
Commit: 9ee30cd9b51c46cea7193993d006bb4301588001
https://github.com/NixOS/nixpkgs/commit/9ee30cd9b51c46cea7193993d006bb4301588001
Author: Eelco Dolstra <[email protected]>
Date: 2013-11-27 (Wed, 27 Nov 2013)
Changed paths:
M nixos/lib/eval-config.nix
M nixos/modules/module-list.nix
M nixos/modules/services/hardware/udev.nix
M nixos/modules/system/activation/top-level.nix
M nixos/modules/system/boot/kernel.nix
M nixos/modules/system/boot/loader/grub/grub.nix
M nixos/modules/system/boot/modprobe.nix
M nixos/modules/system/boot/stage-1.nix
M nixos/modules/system/boot/systemd.nix
A nixos/modules/virtualisation/containers.nix
Log Message:
-----------
Add support for lightweight NixOS containers
You can now say:
systemd.containers.foo.config =
{ services.openssh.enable = true;
services.openssh.ports = [ 2022 ];
users.extraUsers.root.openssh.authorizedKeys.keys = [ "ssh-dss ..." ];
};
which defines a NixOS instance with the given configuration running
inside a lightweight container.
You can also manage the configuration of the container independently
from the host:
systemd.containers.foo.path = "/nix/var/nix/profiles/containers/foo";
where "path" is a NixOS system profile. It can be created/updated by
doing:
$ nix-env --set -p /nix/var/nix/profiles/containers/foo \
-f '<nixos>' -A system -I nixos-config=foo.nix
The container configuration (foo.nix) should define
boot.isContainer = true;
to optimise away the building of a kernel and initrd. This is done
automatically when using the "config" route.
On the host, a lightweight container appears as the service
"container-<name>.service". The container is like a regular NixOS
(virtual) machine, except that it doesn't have its own kernel. It has
its own root file system (by default /var/lib/containers/<name>), but
shares the Nix store of the host (as a read-only bind mount). It also
has access to the network devices of the host.
Currently, if the configuration of the container changes, running
"nixos-rebuild switch" on the host will cause the container to be
rebooted. In the future we may want to send some message to the
container so that it can activate the new container configuration
without rebooting.
Containers are not perfectly isolated yet. In particular, the host's
/sys/fs/cgroup is mounted (writable!) in the guest.
Compare: https://github.com/NixOS/nixpkgs/compare/469ce846c34a...9ee30cd9b51c
_______________________________________________
nix-commits mailing list
[email protected]
http://lists.science.uu.nl/mailman/listinfo/nix-commits