legit

Fork of https://git.icyphox.sh/legit

  1. 1
  2. 2
  3. 3
  4. 4
  5. 5
  6. 6
  7. 7
  8. 8
  9. 9
  10. 10
  11. 11
  12. 12
  13. 13
  14. 14
  15. 15
  16. 16
  17. 17
  18. 18
  19. 19
  20. 20
  21. 21
  22. 22
  23. 23
  24. 24
  25. 25
  26. 26
  27. 27
  28. 28
  29. 29
  30. 30
  31. 31
  32. 32
  33. 33
  34. 34
  35. 35
  36. 36
  37. 37
  38. 38
  39. 39
  40. 40
  41. 41
  42. 42
  43. 43
  44. 44
  45. 45
  46. 46
  47. 47
  48. 48
  49. 49
  50. 50
  51. 51
  52. 52
  53. 53
  54. 54
  55. 55
# Copyright 2026 Shota FUJI <pockawoooh@gmail.com>
# SPDX-License-Identifier: MIT

{
  stdenv,
  mkShell,
  podman,
}:

let
  conf = stdenv.mkDerivation {
    name = "podman-config-files";

    # No source.
    unpackPhase = "true";

    postInstall = ''
      mkdir $out
      cat > $out/registries.conf <<EOF
      unqualified-search-registries = ["docker.io"]
      EOF

      # This is meant to be copied under ~/.config/containers/
      cat > $out/policy.json <<EOF
      {
        "default": [{ "type": "insecureAcceptAnything" }]
      }
      EOF

      cat > $out/containers.conf <<EOF
      [engine]
      cgroup_manager="cgroupfs"
      events_logger="file"
      EOF
    '';
  };
in
mkShell {
  packages = [
    podman
    conf
  ];

  shellHook = ''
    if [[ ! -f ~/.config/containers/policy.json && ! -f /etc/containers/policy.json ]]; then
      echo "Create policy.json file for podman."
      echo "https://podman.io/docs/installation#policyjson"
      echo "If you are okay with insecureAcceptAnything for all, run:"
      echo "install -Dm555 ${conf}/policy.json ~/.config/containers/policy.json"
    fi
  '';

  CONTAINERS_REGISTRIES_CONF = "${conf}/registries.conf";
  CONTAINERS_CONF = "${conf}/containers.conf";
}