Skip to content

Commit 610d9a1

Browse files
claudef3l1x
authored andcommitted
fx: respect an externally provided DOCKER_HOST
The rootless Docker setup hardcoded DOCKER_HOST in /etc/profile and in dockerd-rootless-start, clobbering any value supplied by the environment (workspace template, docker run -e, mounted host socket, remote daemon). Both now treat the rootless socket as a fallback only. The startup script skips starting a daemon when one already answers at DOCKER_HOST, derives XDG_RUNTIME_DIR from a provided unix .../docker.sock so dockerd and the CLI agree on the path, and fails with a clear message for non-unix hosts it cannot serve. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017jPxeenJt19PJStMMeb1Em
1 parent 2ecb3a6 commit 610d9a1

3 files changed

Lines changed: 28 additions & 9 deletions

File tree

‎README.md‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -132,6 +132,9 @@ daemon automatically. The host must permit nested user namespaces — in a Coder
132132
run the workspace container with `privileged = true` (or the equivalent `--userns` setup), and call
133133
`dockerd-rootless-start` from `startup_script` so Docker is ready on boot.
134134

135+
Both variables are defaults. If `DOCKER_HOST` is already set, the image and the script keep that
136+
value. The script starts no daemon if one answers there.
137+
135138
## Development
136139

137140
Images are built and tested per template with the provided `Makefile`. `DOCKER_VARIANT` selects the

‎fx/Dockerfile‎

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,8 @@ ENV GOROOT=/usr/local/go
2020
ENV GOPATH=/home/coder/go
2121
ENV PATH=$GOROOT/bin:$GOPATH/bin:$PATH
2222

23-
# Rootless Docker (docker-in-docker without privileged root)
23+
# Rootless Docker (docker-in-docker without privileged root).
24+
# Defaults. The environment can override them.
2425
ENV XDG_RUNTIME_DIR=/run/user/1000
2526
ENV DOCKER_HOST=unix:///run/user/1000/docker.sock
2627

@@ -127,7 +128,7 @@ RUN \
127128
echo '' >> /etc/profile && \
128129
echo '# Rootless Docker' >> /etc/profile && \
129130
echo 'export XDG_RUNTIME_DIR="${XDG_RUNTIME_DIR:-/run/user/$(id -u)}"' >> /etc/profile && \
130-
echo 'export DOCKER_HOST="unix://${XDG_RUNTIME_DIR}/docker.sock"' >> /etc/profile && \
131+
echo 'export DOCKER_HOST="${DOCKER_HOST:-unix://${XDG_RUNTIME_DIR}/docker.sock}"' >> /etc/profile && \
131132
# OWNERSHIP (coder can upgrade tools) ######################################
132133
chown coder:coder /usr/local/bin/claude /usr/local/bin/opencode && \
133134
chown -R coder:coder /home/coder/go && \

‎fx/dockerd-rootless-start.sh‎

Lines changed: 22 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -8,24 +8,39 @@
88
# dockerd-rootless-start
99
# docker run --rm hello-world
1010
#
11+
# A DOCKER_HOST from the environment is used if set.
12+
#
1113
# Note: the host must allow user namespaces. In Coder, run the container
1214
# with --userns-host or the equivalent template option.
1315
set -euo pipefail
1416

1517
uid="$(id -u)"
16-
export XDG_RUNTIME_DIR="${XDG_RUNTIME_DIR:-/run/user/${uid}}"
17-
export DOCKER_HOST="unix://${XDG_RUNTIME_DIR}/docker.sock"
18+
export DOCKER_HOST="${DOCKER_HOST:-unix://${XDG_RUNTIME_DIR:-/run/user/${uid}}/docker.sock}"
19+
20+
if docker info >/dev/null 2>&1; then
21+
echo "docker daemon already reachable at ${DOCKER_HOST}"
22+
exit 0
23+
fi
24+
25+
# dockerd-rootless.sh listens on ${XDG_RUNTIME_DIR}/docker.sock. Set the runtime
26+
# dir from DOCKER_HOST so the daemon and the CLI use the same socket.
27+
case "$DOCKER_HOST" in
28+
unix://*/docker.sock)
29+
socket="${DOCKER_HOST#unix://}"
30+
export XDG_RUNTIME_DIR="$(dirname "$socket")"
31+
;;
32+
*)
33+
echo "no daemon at DOCKER_HOST=${DOCKER_HOST}" >&2
34+
echo "rootless dockerd needs a unix .../docker.sock path; unset DOCKER_HOST for the default" >&2
35+
exit 1
36+
;;
37+
esac
1838

1939
# /run/user/<uid> lives on tmpfs and is recreated on every container start.
2040
if [ ! -d "$XDG_RUNTIME_DIR" ]; then
2141
sudo install -d -m 0700 -o "$uid" -g "$(id -g)" "$XDG_RUNTIME_DIR"
2242
fi
2343

24-
if docker info >/dev/null 2>&1; then
25-
echo "rootless dockerd already running at ${DOCKER_HOST}"
26-
exit 0
27-
fi
28-
2944
echo "starting rootless dockerd ..."
3045
nohup dockerd-rootless.sh >/tmp/dockerd-rootless.log 2>&1 &
3146

0 commit comments

Comments
 (0)