Skip to content

Instantly share code, notes, and snippets.

@daemonfire300
Last active September 9, 2026 12:55
Show Gist options
  • Select an option

  • Save daemonfire300/f7a4aad01ccfe638846ce3a43f9d9184 to your computer and use it in GitHub Desktop.

Select an option

Save daemonfire300/f7a4aad01ccfe638846ce3a43f9d9184 to your computer and use it in GitHub Desktop.
sample-nix-in-a-container.yaml
apiVersion: apps/v1
kind: StatefulSet
metadata:
name: devcontainer
labels:
app: devcontainer
spec:
serviceName: devcontainer
replicas: 1
selector:
matchLabels:
app: devcontainer
template:
metadata:
labels:
app: devcontainer
spec:
securityContext:
runAsNonRoot: true
runAsUser: 1000
runAsGroup: 1000
fsGroup: 1000
fsGroupChangePolicy: OnRootMismatch
seccompProfile:
type: RuntimeDefault
containers:
- name: devcontainer
image: devcontainer:dev
imagePullPolicy: IfNotPresent
env:
# Replace this one value when the corporate Nexus uses the
# conventional repository names below. Exact endpoint variables
# remain available as per-resource overrides.
- name: NIX_NEXUS_BASE_URL
value: ""
- name: NIX_CORPORATE_PROXY_URL
value: "http://xzy.corp.proxy:8080"
- name: NIX_BINARY_CACHE_URL
value: ""
- name: NIX_FLAKE_REGISTRY_URL
value: ""
- name: NIXPKGS_TARBALL_URL
value: ""
- name: NIX_BINARY_CACHE_PUBLIC_KEYS
# This is correct for a transparent proxy of cache.nixos.org.
# Replace it if the corporate cache signs NarInfos itself.
value: "cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY="
- name: NIX_BINARY_CACHE_PUBLIC_KEY_FILE
value: ""
- name: NIX_BINARY_CACHE_PUBLIC_KEY_URL
value: ""
- name: NIX_BINARY_CACHE_PUBLIC_KEY_SHA256
value: ""
- name: NIX_TLS_CA_FILE
value: ""
- name: NIX_TLS_CA_URL
value: ""
- name: NIX_TLS_CA_SHA256
value: ""
- name: GITHUB_PROXY_URL
value: ""
securityContext:
readOnlyRootFilesystem: true
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
volumeMounts:
- name: home
mountPath: /home/me
- name: tmp
mountPath: /tmp
- name: nix
mountPath: /nix
- name: devcontainer-nix-trust
mountPath: /etc/devcontainer/nix
readOnly: true
resources:
requests:
cpu: 500m
memory: 1Gi
volumes:
- name: tmp
emptyDir: {}
- name: devcontainer-nix-trust
projected:
sources:
- configMap:
name: devcontainer-nix-trust
optional: true
initContainers:
- name: bootstrap-nix-store
image: devcontainer:dev
imagePullPolicy: IfNotPresent
command:
- /opt/devcontainer/bin/bootstrap-nix-store
env:
- name: HOME
value: /tmp
- name: XDG_CACHE_HOME
value: /tmp/.cache
- name: NIX_CONF_DIR
value: /tmp/nix-conf
# The generated bundle is created on the target PVC by the main
# container; bootstrap only performs local store registration.
- name: SSL_CERT_FILE
value: /etc/ssl/certs/ca-bundle.crt
- name: NIX_SSL_CERT_FILE
value: /etc/ssl/certs/ca-bundle.crt
- name: CURL_CA_BUNDLE
value: /etc/ssl/certs/ca-bundle.crt
securityContext:
readOnlyRootFilesystem: true
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
volumeMounts:
- name: nix
mountPath: /nix-bootstrap/nix
- name: tmp
mountPath: /tmp
volumeClaimTemplates:
- metadata:
name: home
spec:
accessModes:
- ReadWriteOnce
resources:
requests:
storage: 20Gi
- metadata:
name: nix
spec:
accessModes:
- ReadWriteOnce
resources:
requests:
storage: 20Gi
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment