2018-12-31 00:39:02 +01:00
|
|
|
|
;;; GNU Guix --- Functional package management for GNU
|
|
|
|
|
;;; Copyright © 2018 Danny Milosavljevic <dannym@scratchpost.org>
|
2020-04-26 17:58:58 +02:00
|
|
|
|
;;; Copyright © 2020 Jakub Kądziołka <kuba@kadziolka.net>
|
2020-06-02 02:54:40 +02:00
|
|
|
|
;;; Copyright © 2020 Maxim Cournoyer <maxim.cournoyer@gmail.com>
|
2020-09-14 15:35:36 +02:00
|
|
|
|
;;; Copyright © 2020 Efraim Flashner <efraim@flashner.co.il>
|
2020-09-19 18:40:38 +02:00
|
|
|
|
;;; Copyright © 2020 Jesse Dowell <jessedowell@gmail.com>
|
2018-12-31 00:39:02 +01:00
|
|
|
|
;;;
|
|
|
|
|
;;; This file is part of GNU Guix.
|
|
|
|
|
;;;
|
|
|
|
|
;;; GNU Guix is free software; you can redistribute it and/or modify it
|
|
|
|
|
;;; under the terms of the GNU General Public License as published by
|
|
|
|
|
;;; the Free Software Foundation; either version 3 of the License, or (at
|
|
|
|
|
;;; your option) any later version.
|
|
|
|
|
;;;
|
|
|
|
|
;;; GNU Guix is distributed in the hope that it will be useful, but
|
|
|
|
|
;;; WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
|
;;; MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
|
;;; GNU General Public License for more details.
|
|
|
|
|
;;;
|
|
|
|
|
;;; You should have received a copy of the GNU General Public License
|
|
|
|
|
;;; along with GNU Guix. If not, see <http://www.gnu.org/licenses/>.
|
|
|
|
|
|
|
|
|
|
(define-module (gnu services docker)
|
|
|
|
|
#:use-module (gnu services)
|
|
|
|
|
#:use-module (gnu services configuration)
|
|
|
|
|
#:use-module (gnu services base)
|
|
|
|
|
#:use-module (gnu services dbus)
|
|
|
|
|
#:use-module (gnu services shepherd)
|
|
|
|
|
#:use-module (gnu system shadow)
|
|
|
|
|
#:use-module (gnu packages docker)
|
2019-06-04 22:29:40 +02:00
|
|
|
|
#:use-module (gnu packages linux) ;singularity
|
2018-12-31 00:39:02 +01:00
|
|
|
|
#:use-module (guix records)
|
|
|
|
|
#:use-module (guix gexp)
|
|
|
|
|
#:use-module (guix packages)
|
|
|
|
|
|
|
|
|
|
#:export (docker-configuration
|
2019-06-04 22:29:40 +02:00
|
|
|
|
docker-service-type
|
|
|
|
|
singularity-service-type))
|
2018-12-31 00:39:02 +01:00
|
|
|
|
|
2019-04-05 08:34:16 +02:00
|
|
|
|
;;; We're not using serialize-configuration, but we must define this because
|
|
|
|
|
;;; the define-configuration macro validates it exists.
|
|
|
|
|
(define (serialize-boolean field-name val)
|
|
|
|
|
"")
|
|
|
|
|
|
2018-12-31 00:39:02 +01:00
|
|
|
|
(define-configuration docker-configuration
|
|
|
|
|
(docker
|
|
|
|
|
(package docker)
|
|
|
|
|
"Docker daemon package.")
|
2020-09-15 00:10:55 +02:00
|
|
|
|
(docker-cli
|
|
|
|
|
(package docker-cli)
|
|
|
|
|
"Docker client package.")
|
2018-12-31 00:39:02 +01:00
|
|
|
|
(containerd
|
|
|
|
|
(package containerd)
|
2019-04-05 08:34:16 +02:00
|
|
|
|
"containerd package.")
|
|
|
|
|
(proxy
|
|
|
|
|
(package docker-libnetwork-cmd-proxy)
|
|
|
|
|
"The proxy package to support inter-container and outside-container
|
|
|
|
|
loop-back communications.")
|
|
|
|
|
(enable-proxy?
|
|
|
|
|
(boolean #t)
|
2020-06-02 02:54:40 +02:00
|
|
|
|
"Enable or disable the user-land proxy (enabled by default).")
|
|
|
|
|
(debug?
|
|
|
|
|
(boolean #f)
|
2020-08-16 10:09:07 +02:00
|
|
|
|
"Enable or disable debug output.")
|
|
|
|
|
(enable-iptables?
|
|
|
|
|
(boolean #t)
|
|
|
|
|
"Enable addition of iptables rules (enabled by default)."))
|
2018-12-31 00:39:02 +01:00
|
|
|
|
|
|
|
|
|
(define %docker-accounts
|
|
|
|
|
(list (user-group (name "docker") (system? #t))))
|
|
|
|
|
|
|
|
|
|
(define (%containerd-activation config)
|
|
|
|
|
(let ((state-dir "/var/lib/containerd"))
|
|
|
|
|
#~(begin
|
|
|
|
|
(use-modules (guix build utils))
|
|
|
|
|
(mkdir-p #$state-dir))))
|
|
|
|
|
|
|
|
|
|
(define (%docker-activation config)
|
|
|
|
|
(%containerd-activation config)
|
|
|
|
|
(let ((state-dir "/var/lib/docker"))
|
|
|
|
|
#~(begin
|
|
|
|
|
(use-modules (guix build utils))
|
|
|
|
|
(mkdir-p #$state-dir))))
|
|
|
|
|
|
|
|
|
|
(define (containerd-shepherd-service config)
|
2020-06-02 02:54:40 +02:00
|
|
|
|
(let* ((package (docker-configuration-containerd config))
|
|
|
|
|
(debug? (docker-configuration-debug? config)))
|
2018-12-31 00:39:02 +01:00
|
|
|
|
(shepherd-service
|
|
|
|
|
(documentation "containerd daemon.")
|
|
|
|
|
(provision '(containerd))
|
|
|
|
|
(start #~(make-forkexec-constructor
|
2020-06-02 02:54:40 +02:00
|
|
|
|
(list (string-append #$package "/bin/containerd")
|
|
|
|
|
#$@(if debug?
|
|
|
|
|
'("--log-level=debug")
|
|
|
|
|
'()))
|
2019-01-10 03:54:28 +01:00
|
|
|
|
#:log-file "/var/log/containerd.log"))
|
2018-12-31 00:39:02 +01:00
|
|
|
|
(stop #~(make-kill-destructor)))))
|
|
|
|
|
|
|
|
|
|
(define (docker-shepherd-service config)
|
2019-04-05 08:34:16 +02:00
|
|
|
|
(let* ((docker (docker-configuration-docker config))
|
|
|
|
|
(enable-proxy? (docker-configuration-enable-proxy? config))
|
2020-08-16 10:09:07 +02:00
|
|
|
|
(enable-iptables? (docker-configuration-enable-iptables? config))
|
2020-06-02 02:54:40 +02:00
|
|
|
|
(proxy (docker-configuration-proxy config))
|
|
|
|
|
(debug? (docker-configuration-debug? config)))
|
2018-12-31 00:39:02 +01:00
|
|
|
|
(shepherd-service
|
|
|
|
|
(documentation "Docker daemon.")
|
|
|
|
|
(provision '(dockerd))
|
2019-01-10 19:16:06 +01:00
|
|
|
|
(requirement '(containerd
|
2019-02-11 18:29:01 +01:00
|
|
|
|
dbus-system
|
|
|
|
|
elogind
|
2019-01-10 19:16:06 +01:00
|
|
|
|
file-system-/sys/fs/cgroup/blkio
|
|
|
|
|
file-system-/sys/fs/cgroup/cpu
|
|
|
|
|
file-system-/sys/fs/cgroup/cpuset
|
|
|
|
|
file-system-/sys/fs/cgroup/devices
|
|
|
|
|
file-system-/sys/fs/cgroup/memory
|
2020-04-26 17:58:58 +02:00
|
|
|
|
file-system-/sys/fs/cgroup/pids
|
2019-02-11 18:29:01 +01:00
|
|
|
|
networking
|
|
|
|
|
udev))
|
2018-12-31 00:39:02 +01:00
|
|
|
|
(start #~(make-forkexec-constructor
|
|
|
|
|
(list (string-append #$docker "/bin/dockerd")
|
2019-04-05 08:34:16 +02:00
|
|
|
|
"-p" "/var/run/docker.pid"
|
2020-06-02 02:54:40 +02:00
|
|
|
|
#$@(if debug?
|
|
|
|
|
'("--debug" "--log-level=debug")
|
|
|
|
|
'())
|
2020-09-21 14:02:23 +02:00
|
|
|
|
(if #$enable-proxy?
|
|
|
|
|
'("--userland-proxy=true"
|
|
|
|
|
(string-append
|
|
|
|
|
"--userland-proxy-path=" #$proxy "/bin/proxy"))
|
|
|
|
|
'("--userland-proxy=false"))
|
2020-08-16 10:09:07 +02:00
|
|
|
|
(if #$enable-iptables?
|
|
|
|
|
"--iptables"
|
|
|
|
|
"--iptables=false"))
|
2018-12-31 00:39:02 +01:00
|
|
|
|
#:pid-file "/var/run/docker.pid"
|
|
|
|
|
#:log-file "/var/log/docker.log"))
|
|
|
|
|
(stop #~(make-kill-destructor)))))
|
|
|
|
|
|
|
|
|
|
(define docker-service-type
|
|
|
|
|
(service-type (name 'docker)
|
|
|
|
|
(description "Provide capability to run Docker application
|
|
|
|
|
bundles in Docker containers.")
|
|
|
|
|
(extensions
|
|
|
|
|
(list
|
2020-09-14 15:35:36 +02:00
|
|
|
|
;; Make sure the 'docker' command is available.
|
|
|
|
|
(service-extension profile-service-type
|
2020-09-15 00:10:55 +02:00
|
|
|
|
(compose list docker-configuration-docker-cli))
|
2018-12-31 00:39:02 +01:00
|
|
|
|
(service-extension activation-service-type
|
|
|
|
|
%docker-activation)
|
|
|
|
|
(service-extension shepherd-root-service-type
|
2019-01-10 14:50:47 +01:00
|
|
|
|
(lambda (config)
|
|
|
|
|
(list (containerd-shepherd-service config)
|
|
|
|
|
(docker-shepherd-service config))))
|
2018-12-31 00:39:02 +01:00
|
|
|
|
(service-extension account-service-type
|
|
|
|
|
(const %docker-accounts))))
|
|
|
|
|
(default-value (docker-configuration))))
|
2019-06-04 22:29:40 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
;;;
|
|
|
|
|
;;; Singularity.
|
|
|
|
|
;;;
|
|
|
|
|
|
|
|
|
|
(define %singularity-activation
|
|
|
|
|
(with-imported-modules '((guix build utils))
|
|
|
|
|
#~(begin
|
|
|
|
|
(use-modules (guix build utils))
|
|
|
|
|
|
|
|
|
|
(define %mount-directory
|
|
|
|
|
"/var/singularity/mnt/")
|
|
|
|
|
|
|
|
|
|
;; Create the directories that Singularity 2.6 expects to find. Make
|
|
|
|
|
;; them #o755 like the 'install-data-hook' rule in 'Makefile.am' of
|
|
|
|
|
;; Singularity 2.6.1.
|
|
|
|
|
(for-each (lambda (directory)
|
|
|
|
|
(let ((directory (string-append %mount-directory
|
|
|
|
|
directory)))
|
|
|
|
|
(mkdir-p directory)
|
|
|
|
|
(chmod directory #o755)))
|
|
|
|
|
'("container" "final" "overlay" "session"))
|
|
|
|
|
(chmod %mount-directory #o755))))
|
|
|
|
|
|
|
|
|
|
(define (singularity-setuid-programs singularity)
|
|
|
|
|
"Return the setuid-root programs that SINGULARITY needs."
|
|
|
|
|
(define helpers
|
|
|
|
|
;; The helpers, under a meaningful name.
|
|
|
|
|
(computed-file "singularity-setuid-helpers"
|
|
|
|
|
#~(begin
|
|
|
|
|
(mkdir #$output)
|
|
|
|
|
(for-each (lambda (program)
|
|
|
|
|
(symlink (string-append #$singularity
|
|
|
|
|
"/libexec/singularity"
|
|
|
|
|
"/bin/"
|
|
|
|
|
program "-suid")
|
|
|
|
|
(string-append #$output
|
|
|
|
|
"/singularity-"
|
|
|
|
|
program
|
|
|
|
|
"-helper")))
|
|
|
|
|
'("action" "mount" "start")))))
|
|
|
|
|
|
|
|
|
|
(list (file-append helpers "/singularity-action-helper")
|
|
|
|
|
(file-append helpers "/singularity-mount-helper")
|
|
|
|
|
(file-append helpers "/singularity-start-helper")))
|
|
|
|
|
|
|
|
|
|
(define singularity-service-type
|
|
|
|
|
(service-type (name 'singularity)
|
|
|
|
|
(description
|
|
|
|
|
"Install the Singularity application bundle tool.")
|
|
|
|
|
(extensions
|
|
|
|
|
(list (service-extension setuid-program-service-type
|
|
|
|
|
singularity-setuid-programs)
|
|
|
|
|
(service-extension activation-service-type
|
|
|
|
|
(const %singularity-activation))))
|
|
|
|
|
(default-value singularity)))
|