diff --git a/fedora-40/Containerfile b/fedora-40/Containerfile index a41b737..e09c00b 100644 --- a/fedora-40/Containerfile +++ b/fedora-40/Containerfile @@ -16,15 +16,38 @@ RUN dnf update -y --setopt install_weak_deps=False && \ java-11-openjdk java-11-openjdk-devel \ java-17-openjdk java-17-openjdk-devel \ java-21-openjdk java-21-openjdk-devel \ - && \ + qemu-user-static && \ dnf group install -y --setopt install_weak_deps=False "C Development Tools and Libraries" && \ dnf group install -y --setopt install_weak_deps=False "Container Management" --exclude container-selinux &&\ dnf clean all -y +ADD containers.conf /etc/containers/ + # Adjust storage.conf to enable Fuse storage. RUN sed -i -e 's|^#mount_program|mount_program|g' -e '/additionalimage.*/a "/var/lib/shared",' /etc/containers/storage.conf RUN mkdir -p /var/lib/shared/overlay-images /var/lib/shared/overlay-layers; touch /var/lib/shared/overlay-images/images.lock; touch /var/lib/shared/overlay-layers/layers.lock +# Define uid/gid ranges for our user https://github.com/containers/buildah/issues/3053 +RUN useradd action && \ + echo -e "act:1:999\act:1001:64535" > /etc/subuid && \ + echo -e "act:1:999\act:1001:64535" > /etc/subgid && \ + mkdir -p /home/action/.local/share/containers && \ + mkdir -p /home/action/.config/containers && \ + chown -R action:action /home/action +# See: https://github.com/containers/buildah/issues/4669 +# Copy & modify the config for the `build` user and remove the global +# `runroot` and `graphroot` which current `build` user cannot access, +# in such case storage will choose a runroot in `/var/tmp`. +RUN sed -e 's|^#mount_program|mount_program|g' \ + -e 's|^graphroot|#graphroot|g' \ + -e 's|^runroot|#runroot|g' \ + /etc/containers/storage.conf \ + > /home/build/.config/containers/storage.conf && \ + chown build:build /home/build/.config/containers/storage.conf + +VOLUME /var/lib/containers +VOLUME /home/action/.local/share/containers + # Set up environment variables to note that this is # not starting with usernamespace and default to # isolate the filesystem with chroot. diff --git a/fedora-40/containers.conf b/fedora-40/containers.conf new file mode 100644 index 0000000..0bf45cd --- /dev/null +++ b/fedora-40/containers.conf @@ -0,0 +1,2 @@ +[engine] +cgroup_manager = "cgroupfs"