nixos-config/modules/docker.nix

48 lines
1.3 KiB
Nix
Raw Normal View History

# SPDX-FileCopyrightText: 2020-2021 Simon Bruder <simon@sbruder.de>
#
# SPDX-License-Identifier: AGPL-3.0-or-later
2021-01-17 19:32:01 +01:00
{ config, lib, pkgs, ... }:
2020-08-22 17:44:39 +02:00
{
2021-01-17 19:32:01 +01:00
# This uses a custom option (instead of `virtualisation.docker.enable`) since
# `virtualisation.oci-containers` conditionally sets
# `virtualisation.docker.enable` and therefore causes an infinite recursion.
options.sbruder.docker.enable = lib.mkEnableOption "docker with ipv6nat";
2020-08-22 17:44:39 +02:00
2021-01-17 19:32:01 +01:00
config = lib.mkIf config.sbruder.docker.enable {
environment.systemPackages = with pkgs; [
docker-compose
docker-credential-helpers
docker-ls
];
virtualisation = {
docker = {
enable = true;
logDriver = "journald";
extraOptions = lib.concatStringsSep " " [
2021-01-17 19:32:01 +01:00
"--ipv6"
"--fixed-cidr-v6=fd00:d0ce:d0ce:d0ce::/64"
];
};
2020-08-22 17:44:39 +02:00
2021-01-17 19:32:01 +01:00
oci-containers.containers.ipv6nat = {
image = "robbertkl/ipv6nat";
volumes = [
"/var/run/docker.sock:/var/run/docker.sock:ro"
];
extraOptions = [
"--network=host"
"--cap-drop=ALL"
"--cap-add=NET_ADMIN"
"--cap-add=NET_RAW"
"--cap-add=SYS_MODULE"
];
};
};
2020-08-22 17:44:39 +02:00
2021-01-17 19:32:01 +01:00
environment.etc."modules-load.d/ipv6nat.conf".text = "ip6_tables\n";
};
2020-08-22 17:44:39 +02:00
}