The guix-container project build and publish reproducible container images of GNU Guix.
For Guix on Debian GNU/Linux see debian-with-guix and for Guix on Trisquel/Ubuntu, see guix-on-dpkg.
The images may be downloaded from jas4711/guix at Docker
Hub. The amd64, arm64 and
ppc64el architectures are supported.
The following tag refers to a container image with usual tools like bash, coreutils, grep, gcc, findutils, tar, gzip, git, make, etc:
docker.io/jas4711/guix:latestIf you want a smaller image (without gcc) with GNU Bash and GNU
CoreUtils, where guix install FOO using substitutes can still be
made to work, there is a slim tag:
docker.io/jas4711/guix:slimInstalling packages in the container is quite slow, so we provide a
larger extra tag with more pre-installed packages:
docker.io/jas4711/guix:extraThe same tags at the guix-container GitLab Container registry, which may be faster to download from GitLab.com shared runners, are also available:
registry.gitlab.com/debdistutils/guix/container:latestregistry.gitlab.com/debdistutils/guix/container:slimregistry.gitlab.com/debdistutils/guix/container:extraOn your own machine you may run images using podman as follows.
$ podman run --privileged -it --entrypoint=/bin/sh registry.gitlab.com/debdistutils/guix/container:latest
sh-5.1# env HOME=/ guix describe # https://issues.guix.gnu.org/74949
guix 790c9ff
repository URL: https://git.savannah.gnu.org/git/guix.git
branch: master
commit: 790c9ffe596e3deabf175e030adee5fb706aa981
sh-5.1# exit
To install packages via binary substitutes, you have to run the following set of commands:
cp -rL /gnu/store/*profile/etc/* /etc/
groupadd --gid 0 root
useradd --uid 0 --gid root --shell /bin/sh --home-dir / --system root
groupadd --system guixbuild
for i in $(seq -w 1 10); do useradd -g guixbuild -G guixbuild -d /var/empty -s $(command -v nologin) -c "Guix build user $i" --system guixbuilder$i; done
env LANG=C.UTF-8 guix-daemon --disable-chroot --build-users-group=guixbuild &
guix archive --authorize < /share/guix/ci.guix.gnu.org.pub
guix archive --authorize < /share/guix/bordeaux.guix.gnu.org.pub
guix install hello
GUIX_PROFILE="/var/guix/profiles/per-user/root/guix-profile"
. "$GUIX_PROFILE/etc/profile"
hello
Earlier, to avoid --disable-chroot you ironically have to start
podman with more privileges by using --privileged as in:
$ podman run --privileged -it --entrypoint=/bin/sh registry.gitlab.com/debdistutils/guix/container:latest
A slightly more fine grained mechanism is to use the --cap-add
parameter to add the CAP_SYS_ADMIN, CAP_NET_RAW, and
CAP_NET_ADMIN permissions:
$ podman run --cap-add=CAP_SYS_ADMIN,CAP_NET_RAW,CAP_NET_ADMIN -it --entrypoint=/bin/sh registry.gitlab.com/debdistutils/guix/container:latest
Another parameter that relax security mechanisms that can allow
guix-daemon to work includes --security-opt seccomp=unconfined.
You should consider the implications of these parameters before using them.
Current guix-daemon refuses to
work in privilege-less
container environment.
Here is an example job that demonstrate how to run guix install to
install additional dependencies, and then download and build a package
that pick up the installed package from the system.
The GitLab.com shared amd64 runners run in privileged mode, so
--disable-chroot is not needed.
test-amd64-latest-wget-configure-make-libksba:
image: registry.gitlab.com/debdistutils/guix/container:latest
before_script:
- groupadd --gid 0 root
- useradd --uid 0 --gid root --shell /bin/sh --home-dir / --system root
- cp -rL /gnu/store/*profile/etc/* /etc/
- groupadd --system guixbuild
- for i in $(seq -w 1 10); do useradd -g guixbuild -G guixbuild -d /var/empty -s $(command -v nologin) -c "Guix build user $i" --system guixbuilder$i; done
- export HOME=/
- env LANG=C.UTF-8 guix-daemon --build-users-group=guixbuild &
- guix archive --authorize < /share/guix/ci.guix.gnu.org.pub
- guix archive --authorize < /share/guix/bordeaux.guix.gnu.org.pub
- guix describe
- guix install libgpg-error
- GUIX_PROFILE="//.guix-profile"
- . "$GUIX_PROFILE/etc/profile"
script:
- wget https://www.gnupg.org/ftp/gcrypt/libksba/libksba-1.6.7.tar.bz2
- tar xfa libksba-1.6.7.tar.bz2
- cd libksba-1.6.7
- ./configure
- make V=1
- make check VERBOSE=t V=1
The images are used in our own pipeline too, read the test-* jobs in
.gitlab-ci.yml and inspect job outputs:
https://gitlab.com/debdistutils/guix/container/-/pipelines
More complete testing of all images is done in a separate project:
https://gitlab.com/debdistutils/guix/container-selftests
There is an image with Gash and Gash Utils for a pure Guile POSIX shell and tool experience. No bash or coreutils!
The tag is: registry.gitlab.com/debdistutils/guix/container:gash
$ podman run --env HOME=/ --env USER=jas --entrypoint /bin/gash -it registry.gitlab.com/debdistutils/guix/container:gash
jas@0af969062bc9:~# echo *
bin dev etc gnu proc run share sys tmp
jas@0af969062bc9:~# echo foo > foo
jas@0af969062bc9:~# echo bar > bar
jas@0af969062bc9:~# cmp foo bar
foo bar differ: char 0, in line 1
jas@0af969062bc9:~# echo *
bar bin dev etc foo gnu proc run share sys tmp
jas@0af969062bc9:~# cmp --help
Usage: cmp [OPTION]... FILES
Compare FILES byte by byte.
Options:
--help display this help and exit
-s, --quiet, --silent suppress all normal output
--version output version information and exit
jas@0af969062bc9:~# cmp --version
cmp (GASH) 0.2.0
jas@0af969062bc9:~#
Read .gitlab-ci.yml.
This project was started by Simon Josefsson and is licensed under the AGPLv3+, see the COPYING file or GNU's AGPLv3.0 page.
export HOME=/ -
https://issues.guix.gnu.org/74949
https://issues.guix.gnu.org/74948
Launching guix-daemon & - Could this be started by the container
automatically? Could 'guix install' launch it when needed?
GUIX_PROFILE="//.guix-profile"; . "$GUIX_PROFILE/etc/profile"
required after running guix install, could it be automatically
invoked somehow? Recommend guix shell instead?
GUIX_PROFILE=/root/.config/guix/current; . "$GUIX_PROFILE/etc/profile" - Needed when using
debian-with-guix image, could it be automatically invoked somehow?
Need for podman --entrypoint=/bin/sh - we can't specify a default
with guix pack because GitLab jobs cannot then avoid specifying an
entry-point, ironically. See
https://lists.gnu.org/archive/html/help-guix/2024-12/msg00170.html
GitLab pipeline job entrypoints: the four possible entry-point
approaches behave somewhat different depending on how guix pack
was invoked. See
https://lists.gnu.org/archive/html/help-guix/2024-12/msg00160.html
podman run --privileged needed to avoid --disable-chroot, why is
that?
guix pull: error: while setting up the build environment: cannot set loopback interface flags: Operation not permitted: Somehow
--disable-chroot is required when creating the container using
buildah. Which --cap-add help?
guix archive --authorize < /share/guix/... - Could this be run
automatically somehow? Or a new image with this having been run
published.
/bin/bash: line 5: grep: command not found - Error messages
happening inside GitLab runners if the container image doesn't have
'grep'. GitLab/runners appears to be running some silent command
that isn't visisble.
guix pack: warning: could not determine provenance of package guix - How to silence that when running guix pack guix ... -save-provenance from within a image created via guix pack guix ... -save-provenance?
skopeo copy --insecure-policy - Can we write a real policy file
with non-insecure settings? Used for pushing container images to
GitLab registry.
guix-daemon --disable-chroot - Seems to sometimes be needed to
avoid error messages like guix package: error: cloning builder process: Invalid argument when running guix install. However it
is flaky, sometimes needed and sometimes not needed (when
substitutes are available?).
loading tar component manifest.json: archive/tar: invalid tar header from Skopeo in Debian bookworm, need more recent skopeo.
Error: payload does not match any of the supported image formats: * docker-archive: loading tar component manifest.json: archive/tar: invalid tar header from podman in Debian bookworm, you need more
recent podman.
The debian-with-guix container needs to use --disable-chroot
otherwise guix pull fails with guix pull: error: cloning builder process: Operation not permitted. Solved with
--cap-add=CAP_SYS_ADMIN,CAP_NET_RAW,CAP_NET_ADMIN. But later
regressed for another reason (see above).
arm64 support - https://issues.guix.gnu.org/75080
ppc64el support - https://codeberg.org/guix/guix/pulls/4686
export CWD=/ - No longer a problem?
Adding nss-certs to the guix pack command breaks: (symlink "NetLock_Arany_=Class_Gold=_F?tan?s?tv?ny.pem" #) Throw to key encoding-error' with args ("scm_to_stringn" "cannot convert wide string to output locale" 84 #f #f)'. - Fixed with LC_ALL=C.UTF-8.
substitute: guix substitute: warning: ACL for archive imports seems to be uninitialized, substitutes may be unavailable - Fixed by
running guix archive --authorize.
guix install fails: guix perform-download: error: refusing to run with elevated privileges (UID 0) - Fixed by adding groups/users
and using --build-users-group.
Content type
Image
Digest
sha256:c7da6af32…
Size
464.2 MB
Last updated
2 days ago
docker pull jas4711/guix