Compare commits

..

7 commits

Author SHA1 Message Date
Ondřej Míchal
c81107b8ac Simplify image name
Currently the images are named as "f<version>/fedora-toolbox". This is
troublesome for new users of toolbox (even those with some background to
containers) because everywhere the image is advertised or talked about
as "fedora-toolbox". This is taken care of by Toolbox CLI but has no
effect on Podman itself (or any other tool capable of working with OCI
images).

Another pain point is in the Fedora registry[0] all "fedora-toolbox"
images get a different entry for every version of Fedora. There is no
single place for all "fedora-toolbox" images.

With this change I propose to only use "fedora-toolbox" as the name of
the container and make use of VERSION to distinguish between versions of
Fedora. Currently when you go to the Fedora registry and find an entry
for "fedora-toolbox" you'll see all previous images. I believe that with
this change that "feature" will be lost. But I personally find that
"feature" to be rather confusing because what usually a user wants the
latest version of a container (I partially base this statement on the
fact that most images are versioned this way; e.g. Ubuntu on Docker
Hub[1]).

[0] https://registry.fedoraproject.org/
[1] https://hub.docker.com/_/ubuntu
2021-02-12 17:32:45 +01:00
d642b9f32a Give access to Avahi to resolve the .local mDNS domain
The nss-mdns plugin for the GNU Name Service Switch (or NSS)
functionality of the GNU C Library is necessary to resolve the .local
mDNS domain. The plugin talks to the Avahi daemon running on the host
to resolve the names.

https://github.com/containers/toolbox/issues/209
2020-11-15 23:17:15 +01:00
7ca1173019 Make locate(1) work inside toolbox containers
This reverts commit 1631209a2d.

https://github.com/containers/toolbox/issues/391
2020-11-15 23:15:55 +01:00
4a34af1a90 extra-packages: Allow X11 clients to run as root
If an X11 client is started inside a 'su -' session, then xauth(1)
needs to be present so that pam_xauth.so can add a new XAUTHORITY
environment variable to the 'su -' session.

https://github.com/containers/toolbox/pull/572
2020-10-30 20:13:44 +01:00
366895197f extra-packages: Add gvfs-client
The gvfs-client package is necessary for GIO-based processes inside
toolbox containers to use the GVfs backend and volume monitor daemons,
and it comes preinstalled on Fedora Silverblue and Workstation.

https://github.com/containers/toolbox/pull/466
2020-06-15 19:51:29 +02:00
Jens Petersen
1631209a2d drop mlocate: https://github.com/containers/toolbox/issues/391 2020-04-19 15:01:41 +08:00
Jens Petersen
6a2b9d4835 try removing uninstalled packages from missing-docs (error 143)
atomic_reactor.util - Package chkconfig available, but not installed.
atomic_reactor.util - No match for argument: chkconfig
atomic_reactor.util - Package dbus-daemon available, but not installed.
atomic_reactor.util - No match for argument: dbus-daemon
atomic_reactor.util - Package rpm-plugin-systemd-inhibit available, but not installed.
atomic_reactor.util - No match for argument: rpm-plugin-systemd-inhibit
:
:
atomic_reactor.util - DEBUG - Running scriptlet: gawk-5.0.1-7.fc32.x86_64  38/38
atomic_reactor.util - DEBUG - Removing intermediate container a533251cf472
atomic_reactor.util - ERROR - {'errorDetail': {'code': 143, 'message': "The command '/bin/sh -c dnf -y reinstall $(<missing-docs)' returned a non-zero code: 143"}, 'error': "The command '/bin/sh -c dnf -y reinstall $(<missing-docs)' returned a non-zero code: 143"}
2020-04-19 15:01:41 +08:00
5 changed files with 125 additions and 9 deletions

27
Dockerfile Normal file
View file

@ -0,0 +1,27 @@
FROM registry.fedoraproject.org/fedora:32
ENV NAME=fedora-toolbox VERSION=32
LABEL com.github.containers.toolbox="true" \
com.github.debarshiray.toolbox="true" \
com.redhat.component="$NAME" \
name="$NAME" \
version="$VERSION" \
usage="This image is meant to be used with the toolbox command" \
summary="Base image for creating Fedora toolbox containers" \
maintainer="Debarshi Ray <rishi@fedoraproject.org>"
COPY README.md /
RUN sed -i '/tsflags=nodocs/d' /etc/dnf/dnf.conf
COPY missing-docs /
RUN dnf -y reinstall $(<missing-docs)
RUN rm /missing-docs
COPY extra-packages /
RUN dnf -y install $(<extra-packages)
RUN rm /extra-packages
RUN dnf clean all
CMD /bin/sh

41
README.md Normal file
View file

@ -0,0 +1,41 @@
# Toolbox — Unprivileged development environment
[Toolbox](https://github.com/debarshiray/toolbox) is a tool that offers a
familiar RPM based environment for developing and debugging software that runs
fully unprivileged using [Podman](https://podman.io/).
The toolbox container is a fully *mutable* container; when you see
`yum install ansible` for example, that's something you can do inside your
toolbox container, without affecting the base operating system.
This is particularly useful on
[OSTree](https://ostree.readthedocs.io/en/latest/) based Fedora systems like
[Silverblue](https://silverblue.fedoraproject.org/). The intention of these
systems is to discourage installation of software on the host, and instead
install software as (or in) containers.
However, this tool doesn't *require* using an OSTree based system — it
works equally well if you're running e.g. existing Fedora Workstation or
Server, and that's a useful way to incrementally adopt containerization.
The toolbox environment is based on an [OCI](https://www.opencontainers.org/)
image. On Fedora this is the `fedora-toolbox` image. This image is then
customized for the current user to create a toolbox container that seamlessly
integrates with the rest of the operating system.
## Usage
### Create your toolbox container:
```
[user@hostname ~]$ toolbox create
[user@hostname ~]$
```
This will create a container, and an image, called
`fedora-toolbox-<your-username>:<version-id>` that's specifically customised
for your host user.
### Enter the toolbox:
```
[user@hostname ~]$ toolbox enter
🔹[user@toolbox ~]$
```

View file

@ -1,9 +0,0 @@
The fedora-toolbox OCI image for Fedora 39 onwards is no longer built using
OpenShift Build Service from the Dockerfile here. It's now being built using
Image Factory from fedora-kickstarts and pungi-fedora [1], as part of the
ToolbxReleaseBlocker Change [2] for Fedora 39.
[1] https://pagure.io/fedora-kickstarts/
https://pagure.io/pungi-fedora/
[2] https://fedoraproject.org/wiki/Changes/ToolbxReleaseBlocker

42
extra-packages Normal file
View file

@ -0,0 +1,42 @@
bash-completion
bzip2
diffutils
dnf-plugins-core
findutils
flatpak-spawn
fpaste
git
gnupg
gnupg2-smime
gvfs-client
hostname
iputils
jwhois
keyutils
krb5-libs
less
lsof
man-db
man-pages
mlocate
mtr
nss-mdns
openssh-clients
passwd
pigz
procps-ng
rsync
shadow-utils
sudo
tcpdump
time
traceroute
tree
unzip
vte-profile
wget
which
words
xorg-x11-xauth
xz
zip

15
missing-docs Normal file
View file

@ -0,0 +1,15 @@
acl
bash
curl
gawk
grep
gzip
libcap
openssl
p11-kit
pam
python3
rpm
sed
systemd
tar