Sign inSign up

jas4711/debian-with-guix

By jas4711

•Updated 8 months ago

Debian GNU/Linux with GNU Guix

Image
1

936

jas4711/debian-with-guix repository overview

⁠Container Images For Debian With Guix

The debian-with-guix-container project⁠ build and publish container images of Debian GNU/Linux⁠ stable with GNU Guix⁠ installed.

For Guix on Trisquel/Ubuntu see guix-on-dpkg⁠.

You may also be interested in pure Guix containers⁠.

⁠Debian Container With Guix

The images are like normal Debian stable containers⁠ but have the guix tool and a reasonable fresh guix pull.

Supported architectures include amd64, arm64, ppc64el and riscv64. The multi-arch container is called:

registry.gitlab.com/debdistutils/guix/debian-with-guix-container:stable

It may also be accessed via debian-with-guix at Docker Hub⁠ as:

docker.io/jas4711/debian-with-guix:stable

The container images may be used like this:

$ podman run --privileged -it --hostname guix --rm registry.gitlab.com/debdistutils/guix/debian-with-guix-container:stable
root@guix:/# hello
bash: hello: command not found
root@guix:/# guix describe
  guix c9eb69d
    repository URL: https://gitlab.com/debdistutils/guix/mirror.git
    branch: master
    commit: c9eb69ddbf05e77300b59f49f4bb5aa50cae0892
root@guix:/# LC_ALL=C.UTF-8 /root/.config/guix/current/bin/guix-daemon --build-users-group=guixbuild &
[1] 21
root@guix:/# GUIX_PROFILE=/root/.config/guix/current; . "$GUIX_PROFILE/etc/profile"
root@guix:/# guix describe
Generation 2	Nov 28 2025 10:14:11	(current)
  guix c9eb69d
    repository URL: https://gitlab.com/debdistutils/guix/mirror.git
    branch: master
    commit: c9eb69ddbf05e77300b59f49f4bb5aa50cae0892
root@guix:/# guix install --verbosity=0 hello
accepted connection from pid 55, user root
The following package will be installed:
   hello 2.12.2

hint: Consider setting the necessary environment variables by running:

     GUIX_PROFILE="/root/.guix-profile"
     . "$GUIX_PROFILE/etc/profile"

Alternately, see `guix package --search-paths -p "/root/.guix-profile"'.

root@guix:/# GUIX_PROFILE="/root/.guix-profile"
root@guix:/# . "$GUIX_PROFILE/etc/profile"
root@guix:/# hello
Hello, world!
root@guix:/# 

⁠How To Use In A Gitlab Pipeline

Here is an example job that demonstrate how to run guix install to install additional dependencies, and then download and build a package that pick up the installed package from the system.

test-wget-configure-make-libksba-amd64:
  image: registry.gitlab.com/debdistutils/guix/debian-with-guix-container:stable
  before_script:
  - env LC_ALL=C.UTF-8 /root/.config/guix/current/bin/guix-daemon --build-users-group=guixbuild $GUIX_DAEMON_ARG &
  - GUIX_PROFILE=/root/.config/guix/current; . "$GUIX_PROFILE/etc/profile"
  - guix describe
  - guix install libgpg-error
  - GUIX_PROFILE="/root/.guix-profile"; . "$GUIX_PROFILE/etc/profile"
  - apt-get install --update -y --no-install-recommends build-essential wget ca-certificates bzip2
  script:
  - wget https://www.gnupg.org/ftp/gcrypt/libksba/libksba-1.6.7.tar.bz2
  - tar xfa libksba-1.6.7.tar.bz2
  - cd libksba-1.6.7
  - ./configure
  - make V=1
  - make check VERBOSE=t V=1

⁠Design

The images were initially created for use in GitLab CI/CD Pipelines⁠ but should work for any use.

The images are built in a GitLab CI/CD pipeline, see .gitlab-ci.yml⁠.

The containers are derived from official Debian stable images⁠ with Guix installed and a successful run of guix pull, built using buildah⁠ invoked from build.sh⁠ using image/Containerfile⁠ that runs image/setup.sh⁠.

The pipeline also push images to the GitLab container registry⁠, and then also to Docker Hub⁠.

Guix binaries are downloaded from the Guix binary tarballs⁠ project because of upstream download site availability and bandwidth concerns.

This project was started by Simon Josefsson⁠ who claim copyright on this work and license it to you under the AGPLv3+, see the COPYING⁠ file or GNU's AGPLv3.0 page⁠.

⁠Known Limitations

  • Final arm64 containers (only, not amd64) needs guix-daemon --disable-chroot otherwise there is an error message: guix install: error: clone: Invalid argument. Presumably this is because GitLab shared arm64 runners run with restricted privileges, but the GitLab shared amd64 runners run with more privileges. Improving this would be nice.

  • Building the images requires running buildah with --cap-add=CAP_SYS_ADMIN,CAP_NET_ADMIN. On amd64, even --security-opt seccomp=unconfined is needed. It would be nice to build images using less privileges.

Tag summary

Content type

Image

Digest

sha256:39cc6140b…

Size

1.1 GB

Last updated

8 months ago

docker pull jas4711/debian-with-guix:stable