Sign inSign up

jas4711/guix

By jas4711

•Updated 2 days ago

GNU Guix Container Images

Image
Operating systems
2

5.1K

jas4711/guix repository overview

⁠GNU Guix Container Images

The guix-container project⁠ build and publish reproducible container images of GNU Guix⁠.

For Guix on Debian GNU/Linux see debian-with-guix⁠ and for Guix on Trisquel/Ubuntu, see guix-on-dpkg⁠.

⁠Supported Tags

The images may be downloaded from jas4711/guix at Docker Hub⁠. The amd64, arm64 and ppc64el architectures are supported.

The following tag refers to a container image with usual tools like bash, coreutils, grep, gcc, findutils, tar, gzip, git, make, etc:

  • docker.io/jas4711/guix:latest

If you want a smaller image (without gcc) with GNU Bash and GNU CoreUtils, where guix install FOO using substitutes can still be made to work, there is a slim tag:

  • docker.io/jas4711/guix:slim

Installing packages in the container is quite slow, so we provide a larger extra tag with more pre-installed packages:

  • docker.io/jas4711/guix:extra

The same tags at the guix-container GitLab Container registry⁠, which may be faster to download from GitLab.com shared runners, are also available:

  • registry.gitlab.com/debdistutils/guix/container:latest
  • registry.gitlab.com/debdistutils/guix/container:slim
  • registry.gitlab.com/debdistutils/guix/container:extra

⁠How To Use With Podman

On your own machine you may run images using podman⁠ as follows.

$ podman run --privileged -it --entrypoint=/bin/sh registry.gitlab.com/debdistutils/guix/container:latest
sh-5.1# env HOME=/ guix describe # https://issues.guix.gnu.org/74949
  guix 790c9ff
    repository URL: https://git.savannah.gnu.org/git/guix.git
    branch: master
    commit: 790c9ffe596e3deabf175e030adee5fb706aa981
sh-5.1# exit

To install packages via binary substitutes, you have to run the following set of commands:

cp -rL /gnu/store/*profile/etc/* /etc/
groupadd --gid 0 root
useradd --uid 0 --gid root --shell /bin/sh --home-dir / --system root
groupadd --system guixbuild
for i in $(seq -w 1 10); do useradd -g guixbuild -G guixbuild -d /var/empty -s $(command -v nologin) -c "Guix build user $i" --system guixbuilder$i; done
env LANG=C.UTF-8 guix-daemon --disable-chroot --build-users-group=guixbuild &
guix archive --authorize < /share/guix/ci.guix.gnu.org.pub
guix archive --authorize < /share/guix/bordeaux.guix.gnu.org.pub
guix install hello
GUIX_PROFILE="/var/guix/profiles/per-user/root/guix-profile"
. "$GUIX_PROFILE/etc/profile"
hello

Earlier, to avoid --disable-chroot you ironically have to start podman with more privileges by using --privileged as in:

$ podman run --privileged -it --entrypoint=/bin/sh registry.gitlab.com/debdistutils/guix/container:latest

A slightly more fine grained mechanism is to use the --cap-add parameter to add the CAP_SYS_ADMIN, CAP_NET_RAW, and CAP_NET_ADMIN permissions:

$ podman run --cap-add=CAP_SYS_ADMIN,CAP_NET_RAW,CAP_NET_ADMIN -it --entrypoint=/bin/sh registry.gitlab.com/debdistutils/guix/container:latest

Another parameter that relax security mechanisms that can allow guix-daemon to work includes --security-opt seccomp=unconfined.

You should consider the implications of these parameters before using them.

Current guix-daemon refuses to work⁠ in privilege-less container environment.

⁠How to use in a GitLab pipeline

Here is an example job that demonstrate how to run guix install to install additional dependencies, and then download and build a package that pick up the installed package from the system.

The GitLab.com shared amd64 runners run in privileged mode, so --disable-chroot is not needed.

test-amd64-latest-wget-configure-make-libksba:
  image: registry.gitlab.com/debdistutils/guix/container:latest
  before_script:
  - groupadd --gid 0 root
  - useradd --uid 0 --gid root --shell /bin/sh --home-dir / --system root
  - cp -rL /gnu/store/*profile/etc/* /etc/
  - groupadd --system guixbuild
  - for i in $(seq -w 1 10); do useradd -g guixbuild -G guixbuild -d /var/empty -s $(command -v nologin) -c "Guix build user $i" --system guixbuilder$i; done
  - export HOME=/
  - env LANG=C.UTF-8 guix-daemon --build-users-group=guixbuild &
  - guix archive --authorize < /share/guix/ci.guix.gnu.org.pub
  - guix archive --authorize < /share/guix/bordeaux.guix.gnu.org.pub
  - guix describe
  - guix install libgpg-error
  - GUIX_PROFILE="//.guix-profile"
  - . "$GUIX_PROFILE/etc/profile"
  script:
  - wget https://www.gnupg.org/ftp/gcrypt/libksba/libksba-1.6.7.tar.bz2
  - tar xfa libksba-1.6.7.tar.bz2
  - cd libksba-1.6.7
  - ./configure
  - make V=1
  - make check VERBOSE=t V=1

⁠More GitLab examples

The images are used in our own pipeline too, read the test-* jobs in .gitlab-ci.yml⁠ and inspect job outputs:

https://gitlab.com/debdistutils/guix/container/-/pipelines⁠

More complete testing of all images is done in a separate project:

https://gitlab.com/debdistutils/guix/container-selftests⁠

⁠Gash-based image

There is an image with Gash and Gash Utils⁠ for a pure Guile POSIX shell and tool experience. No bash or coreutils!

The tag is: registry.gitlab.com/debdistutils/guix/container:gash

$ podman run --env HOME=/ --env USER=jas --entrypoint /bin/gash -it registry.gitlab.com/debdistutils/guix/container:gash
jas@0af969062bc9:~# echo *
bin dev etc gnu proc run share sys tmp
jas@0af969062bc9:~# echo foo > foo
jas@0af969062bc9:~# echo bar > bar
jas@0af969062bc9:~# cmp foo bar
foo bar differ: char 0, in line 1
jas@0af969062bc9:~# echo *
bar bin dev etc foo gnu proc run share sys tmp
jas@0af969062bc9:~# cmp --help
Usage: cmp [OPTION]... FILES
Compare FILES byte by byte.

Options:
      --help              display this help and exit
  -s, --quiet, --silent   suppress all normal output
      --version           output version information and exit
jas@0af969062bc9:~# cmp --version
cmp (GASH) 0.2.0
jas@0af969062bc9:~#

⁠How the images are made

Read .gitlab-ci.yml⁠.

⁠License

This project was started by Simon Josefsson⁠ and is licensed under the AGPLv3+, see the COPYING⁠ file or GNU's AGPLv3.0 page⁠.

⁠Known quirks

  • export HOME=/ - https://issues.guix.gnu.org/74949⁠ https://issues.guix.gnu.org/74948⁠

  • Launching guix-daemon & - Could this be started by the container automatically? Could 'guix install' launch it when needed?

  • GUIX_PROFILE="//.guix-profile"; . "$GUIX_PROFILE/etc/profile" required after running guix install, could it be automatically invoked somehow? Recommend guix shell instead?

  • GUIX_PROFILE=/root/.config/guix/current; . "$GUIX_PROFILE/etc/profile" - Needed when using debian-with-guix image, could it be automatically invoked somehow?

  • Need for podman --entrypoint=/bin/sh - we can't specify a default with guix pack because GitLab jobs cannot then avoid specifying an entry-point, ironically. See https://lists.gnu.org/archive/html/help-guix/2024-12/msg00170.html⁠

  • GitLab pipeline job entrypoints: the four possible entry-point approaches behave somewhat different depending on how guix pack was invoked. See https://lists.gnu.org/archive/html/help-guix/2024-12/msg00160.html⁠

  • podman run --privileged needed to avoid --disable-chroot, why is that?

  • guix pull: error: while setting up the build environment: cannot set loopback interface flags: Operation not permitted: Somehow --disable-chroot is required when creating the container using buildah. Which --cap-add help?

  • guix archive --authorize < /share/guix/... - Could this be run automatically somehow? Or a new image with this having been run published.

  • /bin/bash: line 5: grep: command not found - Error messages happening inside GitLab runners if the container image doesn't have 'grep'. GitLab/runners appears to be running some silent command that isn't visisble.

  • guix pack: warning: could not determine provenance of package guix - How to silence that when running guix pack guix ... -save-provenance from within a image created via guix pack guix ... -save-provenance?

  • skopeo copy --insecure-policy - Can we write a real policy file with non-insecure settings? Used for pushing container images to GitLab registry.

  • guix-daemon --disable-chroot - Seems to sometimes be needed to avoid error messages like guix package: error: cloning builder process: Invalid argument when running guix install. However it is flaky, sometimes needed and sometimes not needed (when substitutes are available?).

⁠Resolved quirks

  • loading tar component manifest.json: archive/tar: invalid tar header from Skopeo in Debian bookworm, need more recent skopeo.

  • Error: payload does not match any of the supported image formats: * docker-archive: loading tar component manifest.json: archive/tar: invalid tar header from podman in Debian bookworm, you need more recent podman.

  • The debian-with-guix container needs to use --disable-chroot otherwise guix pull fails with guix pull: error: cloning builder process: Operation not permitted. Solved with --cap-add=CAP_SYS_ADMIN,CAP_NET_RAW,CAP_NET_ADMIN. But later regressed for another reason (see above).

  • arm64 support - https://issues.guix.gnu.org/75080⁠

  • ppc64el support - https://codeberg.org/guix/guix/pulls/4686⁠

  • export CWD=/ - No longer a problem?

  • Adding nss-certs to the guix pack command breaks: (symlink "NetLock_Arany_=Class_Gold=_F?tan?s?tv?ny.pem" #) Throw to key encoding-error' with args ("scm_to_stringn" "cannot convert wide string to output locale" 84 #f #f)'. - Fixed with LC_ALL=C.UTF-8.

  • substitute: guix substitute: warning: ACL for archive imports seems to be uninitialized, substitutes may be unavailable - Fixed by running guix archive --authorize.

  • guix install fails: guix perform-download: error: refusing to run with elevated privileges (UID 0) - Fixed by adding groups/users and using --build-users-group.

Tag summary

Content type

Image

Digest

sha256:c7da6af32…

Size

464.2 MB

Last updated

2 days ago

docker pull jas4711/guix