diff --git a/Dockerfile b/Dockerfile new file mode 100644 index 0000000..917788f --- /dev/null +++ b/Dockerfile @@ -0,0 +1,26 @@ +FROM registry.fedoraproject.org/fedora:35 + +ENV NAME=fedora-toolbox VERSION=35 +LABEL com.github.containers.toolbox="true" \ + com.github.debarshiray.toolbox="true" \ + com.redhat.component="$NAME" \ + name="$NAME" \ + version="$VERSION" \ + usage="This image is meant to be used with the toolbox command" \ + summary="Base image for creating Fedora toolbox containers" \ + maintainer="Debarshi Ray " + +COPY README.md / + +RUN sed -i '/tsflags=nodocs/d' /etc/dnf/dnf.conf +RUN dnf -y swap coreutils-single coreutils-full + +COPY missing-docs / +RUN dnf -y reinstall $(`. + +### Enter the toolbox: +```console +[user@hostname ~]$ toolbox enter +⬢[user@toolbox ~]$ +``` + +### Remove a toolbox container: +```console +[user@hostname ~]$ toolbox rm fedora-toolbox-33 +[user@hostname ~]$ +``` + +## Dependencies and Building + +Toolbox requires at least Podman 1.4.0 to work, and uses the Meson build +system. + +The following dependencies are required to build it: +- meson +- go-md2man +- systemd +- go +- ninja + +The following dependencies enable various optional features: +- bash-completion + +It can be built and installed as any other typical Meson-based project: +```console +[user@hostname toolbox]$ meson -Dprofile_dir=/etc/profile.d builddir +[user@hostname toolbox]$ ninja -C builddir +[user@hostname toolbox]$ sudo ninja -C builddir install +``` + +Toolbox is written in Go. Consult the +[src/go.mod](https://github.com/containers/toolbox/blob/main/src/go.mod) file +for a full list of all the Go dependencies. + +By default, Toolbox uses Go modules and all the required Go packages are +automatically downloaded as part of the build. There's no need to worry about +the Go dependencies, unless the build environment doesn't have network access +or any such peculiarities. + +## Distro support + +By default, Toolbox creates the container using an +[OCI](https://www.opencontainers.org/) image called +`-toolbox:`, where `` and `` are taken from the +host's `/usr/lib/os-release`. For example, the default image on a Fedora 33 +host would be `fedora-toolbox:33`. + +This default can be overridden by the `--image` option in `toolbox create`, +but operating system distributors should provide an adequately configured +default image to ensure a smooth user experience. + +## Image requirements + +Toolbox customizes newly created containers in a certain way. This requires +certain tools and paths to be present and have certain characteristics inside +the OCI image. + +Tools: +* `getent(1)` +* `id(1)` +* `ln(1)` +* `mkdir(1)`: for hosts where `/home` is a symbolic link to `/var/home` +* `passwd(1)` +* `readlink(1)` +* `rm(1)` +* `rmdir(1)`: for hosts where `/home` is a symbolic link to `/var/home` +* `sleep(1)` +* `test(1)` +* `touch(1)` +* `unlink(1)` +* `useradd(8)` +* `usermod(8)` + +Paths: +* `/etc/host.conf`: optional, if present not a bind mount +* `/etc/hosts`: optional, if present not a bind mount +* `/etc/krb5.conf.d`: directory, not a bind mount +* `/etc/localtime`: optional, if present not a bind mount +* `/etc/machine-id`: optional, not a bind mount +* `/etc/resolv.conf`: optional, if present not a bind mount +* `/etc/timezone`: optional, if present not a bind mount + +Toolbox enables `sudo(8)` access inside containers. The following is necessary +for that to work: + +* The image should have `sudo(8)` enabled for users belonging to either the + `sudo` or `wheel` groups, and the group itself should exist. File an + [issue](https://github.com/containers/toolbox/issues/new) if you really need + support for a different group. However, it's preferable to keep this list as + short as possible. + +* The image should allow empty passwords for `sudo(8)`. This can be achieved + by either adding the `nullok` option to the `PAM(8)` configuration, or by + add the `NOPASSWD` tag to the `sudoers(5)` configuration. + +Since Toolbox only works with OCI images that fulfill certain requirements, +it will refuse images that aren't tagged with +`com.github.containers.toolbox="true"` and +`com.github.debarshiray.toolbox="true"` labels. These labels are meant to be +used by the maintainer of the image to indicate that they have read this +document and tested that the image works with Toolbox. You can use the +following snippet in a Dockerfile for this: +```Dockerfile +LABEL com.github.containers.toolbox="true" \ + com.github.debarshiray.toolbox="true" +``` diff --git a/dead.container b/dead.container deleted file mode 100644 index ac43a2a..0000000 --- a/dead.container +++ /dev/null @@ -1,9 +0,0 @@ -The fedora-toolbox OCI image for Fedora 39 onwards is no longer built using -OpenShift Build Service from the Dockerfile here. It's now being built using -Image Factory from fedora-kickstarts and pungi-fedora [1], as part of the -ToolbxReleaseBlocker Change [2] for Fedora 39. - -[1] https://pagure.io/fedora-kickstarts/ - https://pagure.io/pungi-fedora/ - -[2] https://fedoraproject.org/wiki/Changes/ToolbxReleaseBlocker diff --git a/extra-packages b/extra-packages new file mode 100644 index 0000000..52bf3f3 --- /dev/null +++ b/extra-packages @@ -0,0 +1,45 @@ +bash-completion +bc +bzip2 +diffutils +dnf-plugins-core +findutils +flatpak-spawn +fpaste +git +gnupg +gnupg2-smime +gvfs-client +hostname +iproute +iputils +jwhois +keyutils +krb5-libs +less +lsof +man-db +man-pages +mtr +nano-default-editor +nss-mdns +openssh-clients +passwd +pigz +procps-ng +rsync +shadow-utils +sudo +tcpdump +time +traceroute +tree +unzip +util-linux +vte-profile +wget +which +words +xorg-x11-xauth +xz +zip diff --git a/missing-docs b/missing-docs new file mode 100644 index 0000000..7122f7b --- /dev/null +++ b/missing-docs @@ -0,0 +1,13 @@ +bash +curl +findutils +gawk +grep +gzip +libcap +p11-kit +pam +python3 +rpm +sed +tar