|
| 1 | +#!/bin/bash |
| 2 | +set -eux -o pipefail |
| 3 | + |
| 4 | + |
| 5 | +if [ "${LIMA_CIDATA_CONTAINERD_SYSTEM}" != 1 ] && [ "${LIMA_CIDATA_CONTAINERD_USER}" != 1 ]; then |
| 6 | + exit 0 |
| 7 | +fi |
| 8 | + |
| 9 | +# This script does not work unless systemd is available |
| 10 | +command -v systemctl 2>&1 >/dev/null || exit 0 |
| 11 | + |
| 12 | +if [ ! -x /usr/local/bin/nerdctl ]; then |
| 13 | + tar Cxzf /usr/local "${LIMA_CIDATA_MNT}"/nerdctl-full.tgz |
| 14 | +fi |
| 15 | + |
| 16 | +if [ "${LIMA_CIDATA_CONTAINERD_SYSTEM}" = 1 ]; then |
| 17 | + mkdir -p /etc/containerd |
| 18 | + cat >"/etc/containerd/config.toml" <<EOF |
| 19 | + version = 2 |
| 20 | + [proxy_plugins] |
| 21 | + [proxy_plugins."stargz"] |
| 22 | + type = "snapshot" |
| 23 | + address = "/run/containerd-stargz-grpc/containerd-stargz-grpc.sock" |
| 24 | +EOF |
| 25 | + systemctl enable --now containerd buildkit stargz-snapshotter |
| 26 | +fi |
| 27 | + |
| 28 | +if [ "${LIMA_CIDATA_CONTAINERD_USER}" = 1 ]; then |
| 29 | + modprobe tap || true |
| 30 | + if [ ! -e "/home/${LIMA_CIDATA_USER}.linux/.config/containerd/config.toml" ]; then |
| 31 | + mkdir -p "/home/${LIMA_CIDATA_USER}.linux/.config/containerd" |
| 32 | + cat >"/home/${LIMA_CIDATA_USER}.linux/.config/containerd/config.toml" <<EOF |
| 33 | + version = 2 |
| 34 | + [proxy_plugins] |
| 35 | + [proxy_plugins."fuse-overlayfs"] |
| 36 | + type = "snapshot" |
| 37 | + address = "/run/user/${LIMA_CIDATA_UID}/containerd-fuse-overlayfs.sock" |
| 38 | + [proxy_plugins."stargz"] |
| 39 | + type = "snapshot" |
| 40 | + address = "/run/user/${LIMA_CIDATA_UID}/containerd-stargz-grpc/containerd-stargz-grpc.sock" |
| 41 | +EOF |
| 42 | + chown -R "${LIMA_CIDATA_USER}" "/home/${LIMA_CIDATA_USER}.linux/.config" |
| 43 | + fi |
| 44 | + selinux= |
| 45 | + if command -v selinuxenabled 2>&1 >/dev/null && selinuxenabled; then |
| 46 | + selinux=1 |
| 47 | + fi |
| 48 | + if [ ! -e "/home/${LIMA_CIDATA_USER}}}.linux/.config/systemd/user/containerd.service" ]; then |
| 49 | + until [ -e "/run/user/${LIMA_CIDATA_UID}/systemd/private" ]; do sleep 3; done |
| 50 | + if [ -n "$selinux" ]; then |
| 51 | + echo "Temporarily disabling SELinux, during installing containerd units" |
| 52 | + setenforce 0 |
| 53 | + fi |
| 54 | + sudo -iu "${LIMA_CIDATA_USER}" "XDG_RUNTIME_DIR=/run/user/${LIMA_CIDATA_UID}" systemctl --user enable --now dbus |
| 55 | + sudo -iu "${LIMA_CIDATA_USER}" "XDG_RUNTIME_DIR=/run/user/${LIMA_CIDATA_UID}" containerd-rootless-setuptool.sh install |
| 56 | + sudo -iu "${LIMA_CIDATA_USER}" "XDG_RUNTIME_DIR=/run/user/${LIMA_CIDATA_UID}" containerd-rootless-setuptool.sh install-buildkit |
| 57 | + sudo -iu "${LIMA_CIDATA_USER}" "XDG_RUNTIME_DIR=/run/user/${LIMA_CIDATA_UID}" containerd-rootless-setuptool.sh install-fuse-overlayfs |
| 58 | + if ! sudo -iu "${LIMA_CIDATA_USER}" "XDG_RUNTIME_DIR=/run/user/${LIMA_CIDATA_UID}" containerd-rootless-setuptool.sh install-stargz; then |
| 59 | + echo >&2 "WARNING: rootless stargz does not seem supported on this host (kernel older than 5.11?)" |
| 60 | + fi |
| 61 | + if [ -n "$selinux" ]; then |
| 62 | + echo "Restoring SELinux" |
| 63 | + setenforce 1 |
| 64 | + fi |
| 65 | + fi |
| 66 | +fi |
0 commit comments