summary refs log tree commit diff
path: root/nixos/tests/docker.nix
blob: 9096a5868f6cc7e6709688eb44b940d3d89da1cf (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
# This test runs docker and checks if simple container starts

import ./make-test.nix ({ pkgs, ...} : {
  name = "docker";
  meta = with pkgs.stdenv.lib.maintainers; {
    maintainers = [ offline ];
  };

  nodes = {
    docker =
      { config, pkgs, ... }:
        {
          virtualisation.docker.enable = true;

          users.users = {
            noprivs = {
              isNormalUser = true;
              description = "Can't access the docker daemon";
              password = "foobar";
            };

            hasprivs = {
              isNormalUser = true;
              description = "Can access the docker daemon";
              password = "foobar";
              extraGroups = [ "docker" ];
            };
          };
        };
    };

  testScript = ''
    startAll;

    $docker->waitForUnit("sockets.target");
    $docker->succeed("tar cv --files-from /dev/null | docker import - scratchimg");
    $docker->succeed("docker run -d --name=sleeping -v /nix/store:/nix/store -v /run/current-system/sw/bin:/bin scratchimg /bin/sleep 10");
    $docker->succeed("docker ps | grep sleeping");
    $docker->succeed("sudo -u hasprivs docker ps");
    $docker->fail("sudo -u noprivs docker ps");
    $docker->succeed("docker stop sleeping");
  '';
})