2014-07-27 22:00:59 +00:00
|
|
|
# Systemd services for docker.
|
|
|
|
|
|
|
|
{ config, lib, pkgs, ... }:
|
|
|
|
|
|
|
|
with lib;
|
|
|
|
|
|
|
|
let
|
|
|
|
|
|
|
|
cfg = config.virtualisation.docker;
|
2017-04-26 14:55:36 +00:00
|
|
|
proxy_env = config.networking.proxy.envVars;
|
2021-10-13 20:29:29 +00:00
|
|
|
settingsFormat = pkgs.formats.json {};
|
|
|
|
daemonSettingsFile = settingsFormat.generate "daemon.json" cfg.daemon.settings;
|
2014-07-27 22:00:59 +00:00
|
|
|
in
|
|
|
|
|
|
|
|
{
|
|
|
|
###### interface
|
|
|
|
|
|
|
|
options.virtualisation.docker = {
|
|
|
|
enable =
|
|
|
|
mkOption {
|
|
|
|
type = types.bool;
|
|
|
|
default = false;
|
|
|
|
description = ''
|
|
|
|
This option enables docker, a daemon that manages
|
|
|
|
linux containers. Users in the "docker" group can interact with
|
|
|
|
the daemon (e.g. to start or stop containers) using the
|
|
|
|
{command}`docker` command line tool.
|
|
|
|
'';
|
|
|
|
};
|
2016-12-20 22:24:17 +00:00
|
|
|
|
|
|
|
listenOptions =
|
|
|
|
mkOption {
|
|
|
|
type = types.listOf types.str;
|
2018-12-19 21:44:34 +00:00
|
|
|
default = ["/run/docker.sock"];
|
2016-12-20 22:24:17 +00:00
|
|
|
description = ''
|
|
|
|
A list of unix and tcp docker should listen to. The format follows
|
|
|
|
ListenStream as described in systemd.socket(5).
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
|
|
|
enableOnBoot =
|
2014-07-27 22:00:59 +00:00
|
|
|
mkOption {
|
|
|
|
type = types.bool;
|
2015-11-20 22:01:33 +00:00
|
|
|
default = true;
|
2014-07-27 22:00:59 +00:00
|
|
|
description = ''
|
2016-12-20 22:24:17 +00:00
|
|
|
When enabled dockerd is started on boot. This is required for
|
2019-05-22 15:40:01 +00:00
|
|
|
containers which are created with the
|
|
|
|
`--restart=always` flag to work. If this option is
|
2016-12-20 22:24:17 +00:00
|
|
|
disabled, docker might be started on demand by socket activation.
|
2014-07-27 22:00:59 +00:00
|
|
|
'';
|
|
|
|
};
|
2016-12-20 22:24:17 +00:00
|
|
|
|
2021-12-19 13:16:58 +00:00
|
|
|
daemon.settings =
|
2021-10-13 17:47:37 +00:00
|
|
|
mkOption {
|
2021-10-13 20:29:29 +00:00
|
|
|
type = settingsFormat.type;
|
2021-10-13 17:47:37 +00:00
|
|
|
default = { };
|
|
|
|
example = {
|
|
|
|
ipv6 = true;
|
|
|
|
"fixed-cidr-v6" = "fd00::/80";
|
|
|
|
};
|
|
|
|
description = ''
|
|
|
|
Configuration for docker daemon. The attributes are serialized to JSON used as daemon.conf.
|
|
|
|
See https://docs.docker.com/engine/reference/commandline/dockerd/#daemon-configuration-file
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
2019-02-27 08:44:37 +00:00
|
|
|
enableNvidia =
|
|
|
|
mkOption {
|
|
|
|
type = types.bool;
|
|
|
|
default = false;
|
|
|
|
description = ''
|
2024-07-28 11:12:27 +00:00
|
|
|
**Deprecated**, please use hardware.nvidia-container-toolkit.enable instead.
|
2024-01-28 12:00:32 +00:00
|
|
|
|
2019-02-27 08:44:37 +00:00
|
|
|
Enable nvidia-docker wrapper, supporting NVIDIA GPUs inside docker containers.
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
2016-12-20 22:24:17 +00:00
|
|
|
liveRestore =
|
|
|
|
mkOption {
|
|
|
|
type = types.bool;
|
|
|
|
default = true;
|
|
|
|
description = ''
|
|
|
|
Allow dockerd to be restarted without affecting running container.
|
|
|
|
This option is incompatible with docker swarm.
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
2015-09-03 23:18:19 +00:00
|
|
|
storageDriver =
|
|
|
|
mkOption {
|
2016-09-10 10:55:46 +00:00
|
|
|
type = types.nullOr (types.enum ["aufs" "btrfs" "devicemapper" "overlay" "overlay2" "zfs"]);
|
|
|
|
default = null;
|
2015-09-03 23:18:19 +00:00
|
|
|
description = ''
|
2023-11-21 15:00:36 +00:00
|
|
|
This option determines which Docker
|
|
|
|
[storage driver](https://docs.docker.com/storage/storagedriver/select-storage-driver/)
|
|
|
|
to use.
|
|
|
|
By default it lets docker automatically choose the preferred storage
|
|
|
|
driver.
|
|
|
|
However, it is recommended to specify a storage driver explicitly, as
|
|
|
|
docker's default varies over versions.
|
|
|
|
|
|
|
|
::: {.warning}
|
|
|
|
Changing the storage driver will cause any existing containers
|
|
|
|
and images to become inaccessible.
|
|
|
|
:::
|
2015-09-03 23:18:19 +00:00
|
|
|
'';
|
|
|
|
};
|
2016-09-10 10:55:46 +00:00
|
|
|
|
|
|
|
logDriver =
|
|
|
|
mkOption {
|
2023-01-30 16:04:18 +00:00
|
|
|
type = types.enum ["none" "json-file" "syslog" "journald" "gelf" "fluentd" "awslogs" "splunk" "etwlogs" "gcplogs" "local"];
|
2016-09-10 10:55:46 +00:00
|
|
|
default = "journald";
|
|
|
|
description = ''
|
|
|
|
This option determines which Docker log driver to use.
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
2014-07-27 22:00:59 +00:00
|
|
|
extraOptions =
|
|
|
|
mkOption {
|
2015-04-25 13:25:15 +00:00
|
|
|
type = types.separatedString " ";
|
2014-07-27 22:00:59 +00:00
|
|
|
default = "";
|
|
|
|
description = ''
|
|
|
|
The extra command-line options to pass to
|
|
|
|
{command}`docker` daemon.
|
|
|
|
'';
|
|
|
|
};
|
2017-07-19 16:20:46 +00:00
|
|
|
|
|
|
|
autoPrune = {
|
|
|
|
enable = mkOption {
|
|
|
|
type = types.bool;
|
|
|
|
default = false;
|
|
|
|
description = ''
|
2017-07-21 14:53:50 +00:00
|
|
|
Whether to periodically prune Docker resources. If enabled, a
|
|
|
|
systemd timer will run `docker system prune -f`
|
|
|
|
as specified by the `dates` option.
|
2017-07-19 16:20:46 +00:00
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
|
|
|
flags = mkOption {
|
|
|
|
type = types.listOf types.str;
|
|
|
|
default = [];
|
|
|
|
example = [ "--all" ];
|
|
|
|
description = ''
|
|
|
|
Any additional flags passed to {command}`docker system prune`.
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
|
|
|
dates = mkOption {
|
|
|
|
default = "weekly";
|
|
|
|
type = types.str;
|
|
|
|
description = ''
|
|
|
|
Specification (in the format described by
|
|
|
|
{manpage}`systemd.time(7)`) of the time at
|
|
|
|
which the prune will occur.
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
};
|
2017-09-04 23:02:05 +00:00
|
|
|
|
2023-11-27 00:19:27 +00:00
|
|
|
package = mkPackageOption pkgs "docker" { };
|
2023-05-05 12:23:34 +00:00
|
|
|
|
|
|
|
extraPackages = mkOption {
|
|
|
|
type = types.listOf types.package;
|
|
|
|
default = [ ];
|
|
|
|
example = literalExpression "with pkgs; [ criu ]";
|
|
|
|
description = ''
|
|
|
|
Extra packages to add to PATH for the docker daemon process.
|
|
|
|
'';
|
|
|
|
};
|
2014-07-27 22:00:59 +00:00
|
|
|
};
|
|
|
|
|
|
|
|
###### implementation
|
|
|
|
|
2016-12-24 00:44:10 +00:00
|
|
|
config = mkIf cfg.enable (mkMerge [{
|
2020-09-10 15:30:01 +00:00
|
|
|
boot.kernelModules = [ "bridge" "veth" "br_netfilter" "xt_nat" ];
|
2021-05-07 19:46:21 +00:00
|
|
|
boot.kernel.sysctl = {
|
2021-05-13 10:26:45 +00:00
|
|
|
"net.ipv4.conf.all.forwarding" = mkOverride 98 true;
|
|
|
|
"net.ipv4.conf.default.forwarding" = mkOverride 98 true;
|
2021-05-07 19:46:21 +00:00
|
|
|
};
|
2019-02-27 08:44:37 +00:00
|
|
|
environment.systemPackages = [ cfg.package ]
|
|
|
|
++ optional cfg.enableNvidia pkgs.nvidia-docker;
|
2018-06-29 23:58:35 +00:00
|
|
|
users.groups.docker.gid = config.ids.gids.docker;
|
2017-09-04 23:02:05 +00:00
|
|
|
systemd.packages = [ cfg.package ];
|
2016-12-24 00:44:10 +00:00
|
|
|
|
2024-01-28 12:00:32 +00:00
|
|
|
# Docker 25.0.0 supports CDI by default
|
|
|
|
# (https://docs.docker.com/engine/release-notes/25.0/#new). Encourage
|
|
|
|
# moving to CDI as opposed to having deprecated runtime
|
|
|
|
# wrappers.
|
|
|
|
warnings = lib.optionals (cfg.enableNvidia && (lib.strings.versionAtLeast cfg.package.version "25")) [
|
|
|
|
''
|
2024-07-28 11:12:27 +00:00
|
|
|
You have set virtualisation.docker.enableNvidia. This option is deprecated, please set hardware.nvidia-container-toolkit.enable instead.
|
2024-01-28 12:00:32 +00:00
|
|
|
''
|
|
|
|
];
|
|
|
|
|
2014-07-27 22:00:59 +00:00
|
|
|
systemd.services.docker = {
|
2016-12-20 22:24:17 +00:00
|
|
|
wantedBy = optional cfg.enableOnBoot "multi-user.target";
|
2021-03-25 20:44:59 +00:00
|
|
|
after = [ "network.target" "docker.socket" ];
|
2021-02-01 16:14:43 +00:00
|
|
|
requires = [ "docker.socket" ];
|
2017-04-26 14:55:36 +00:00
|
|
|
environment = proxy_env;
|
2014-07-27 22:00:59 +00:00
|
|
|
serviceConfig = {
|
2021-01-13 10:33:14 +00:00
|
|
|
Type = "notify";
|
2016-12-24 00:44:10 +00:00
|
|
|
ExecStart = [
|
|
|
|
""
|
|
|
|
''
|
2017-09-04 23:02:05 +00:00
|
|
|
${cfg.package}/bin/dockerd \
|
2021-12-19 13:16:58 +00:00
|
|
|
--config-file=${daemonSettingsFile} \
|
2016-12-24 00:44:10 +00:00
|
|
|
${cfg.extraOptions}
|
|
|
|
''];
|
|
|
|
ExecReload=[
|
|
|
|
""
|
|
|
|
"${pkgs.procps}/bin/kill -s HUP $MAINPID"
|
|
|
|
];
|
2017-04-26 14:55:36 +00:00
|
|
|
};
|
2014-07-27 22:00:59 +00:00
|
|
|
|
2019-02-27 08:44:37 +00:00
|
|
|
path = [ pkgs.kmod ] ++ optional (cfg.storageDriver == "zfs") pkgs.zfs
|
2023-05-05 12:23:34 +00:00
|
|
|
++ optional cfg.enableNvidia pkgs.nvidia-docker
|
|
|
|
++ cfg.extraPackages;
|
2015-12-24 11:07:45 +00:00
|
|
|
};
|
2017-03-27 13:11:44 +00:00
|
|
|
|
|
|
|
systemd.sockets.docker = {
|
|
|
|
description = "Docker Socket for the API";
|
|
|
|
wantedBy = [ "sockets.target" ];
|
|
|
|
socketConfig = {
|
|
|
|
ListenStream = cfg.listenOptions;
|
|
|
|
SocketMode = "0660";
|
|
|
|
SocketUser = "root";
|
|
|
|
SocketGroup = "docker";
|
|
|
|
};
|
|
|
|
};
|
2017-07-19 16:20:46 +00:00
|
|
|
|
|
|
|
systemd.services.docker-prune = {
|
|
|
|
description = "Prune docker resources";
|
|
|
|
|
|
|
|
restartIfChanged = false;
|
|
|
|
unitConfig.X-StopOnRemoval = false;
|
|
|
|
|
|
|
|
serviceConfig.Type = "oneshot";
|
|
|
|
|
|
|
|
script = ''
|
2017-09-04 23:02:05 +00:00
|
|
|
${cfg.package}/bin/docker system prune -f ${toString cfg.autoPrune.flags}
|
2017-07-19 16:20:46 +00:00
|
|
|
'';
|
|
|
|
|
|
|
|
startAt = optional cfg.autoPrune.enable cfg.autoPrune.dates;
|
2022-09-23 09:42:00 +00:00
|
|
|
after = [ "docker.service" ];
|
|
|
|
requires = [ "docker.service" ];
|
2017-07-19 16:20:46 +00:00
|
|
|
};
|
2019-02-27 08:44:37 +00:00
|
|
|
|
|
|
|
assertions = [
|
2024-06-16 10:50:18 +00:00
|
|
|
{ assertion = cfg.enableNvidia && pkgs.stdenv.hostPlatform.isx86_64 -> config.hardware.graphics.enable32Bit or false;
|
|
|
|
message = "Option enableNvidia on x86_64 requires 32-bit support libraries";
|
2019-02-27 08:44:37 +00:00
|
|
|
}];
|
2021-10-13 20:48:33 +00:00
|
|
|
|
|
|
|
virtualisation.docker.daemon.settings = {
|
|
|
|
group = "docker";
|
|
|
|
hosts = [ "fd://" ];
|
2021-10-13 21:12:18 +00:00
|
|
|
log-driver = mkDefault cfg.logDriver;
|
|
|
|
storage-driver = mkIf (cfg.storageDriver != null) (mkDefault cfg.storageDriver);
|
|
|
|
live-restore = mkDefault cfg.liveRestore;
|
2021-10-13 20:48:33 +00:00
|
|
|
runtimes = mkIf cfg.enableNvidia {
|
|
|
|
nvidia = {
|
2024-07-29 11:19:29 +00:00
|
|
|
# Use the legacy nvidia-container-runtime wrapper to allow
|
|
|
|
# the `--runtime=nvidia` approach to expose
|
|
|
|
# GPU's. Starting with Docker > 25, CDI can be used
|
|
|
|
# instead, removing the need for runtime wrappers.
|
|
|
|
path = lib.getExe' pkgs.nvidia-docker "nvidia-container-runtime.legacy";
|
2021-10-13 20:48:33 +00:00
|
|
|
};
|
|
|
|
};
|
|
|
|
};
|
2016-12-20 22:24:17 +00:00
|
|
|
}
|
2014-07-27 22:00:59 +00:00
|
|
|
]);
|
|
|
|
|
2017-01-01 08:01:03 +00:00
|
|
|
imports = [
|
2021-01-15 13:56:29 +00:00
|
|
|
(mkRemovedOptionModule ["virtualisation" "docker" "socketActivation"] "This option was removed and socket activation is now always active")
|
2017-01-01 08:01:03 +00:00
|
|
|
];
|
|
|
|
|
2014-07-27 22:00:59 +00:00
|
|
|
}
|