https://github.com/vpsfreecz/vpsadminos
Host for Linux system containers based on NixOS, ZFS and LXC
https://github.com/vpsfreecz/vpsadminos
containers linux lxc nix nixos zfs
Last synced: 3 months ago
JSON representation
Host for Linux system containers based on NixOS, ZFS and LXC
- Host: GitHub
- URL: https://github.com/vpsfreecz/vpsadminos
- Owner: vpsfreecz
- License: mit
- Created: 2017-11-03T01:02:00.000Z (almost 8 years ago)
- Default Branch: staging
- Last Pushed: 2024-10-29T18:38:22.000Z (11 months ago)
- Last Synced: 2024-10-29T20:39:02.316Z (11 months ago)
- Topics: containers, linux, lxc, nix, nixos, zfs
- Language: Ruby
- Homepage: https://vpsadminos.org
- Size: 14.5 MB
- Stars: 161
- Watchers: 13
- Forks: 27
- Open Issues: 5
-
Metadata Files:
- Readme: README.md
- License: LICENSE.txt
Awesome Lists containing this project
- awesome-starred - vpsfreecz/vpsadminos - Host for Linux system containers based on NixOS, ZFS and LXC (linux)
README
# vpsAdminOS
vpsAdminOS is a small OS serving as a host for unprivileged Linux system
containers. It is based on [NixOS](https://nixos.org) and
[not-os](https://github.com/cleverca22/not-os/). It is designed to run full
distributions inside unprivileged containers which look and feel as much as
a virtual machine as possible.vpsAdminOS is developed and used in production by [vpsFree.cz](https://vpsfree.cz),
a non-profit organization which provides virtual servers to its members.
See [vpsfree-cz-configuration](https://github.com/vpsfreecz/vpsfree-cz-configuration)
for example cluster configuration.## Links
* IRC: #vpsadminos @ irc.libera.chat
* Documentation:
* Man pages:
* OS and program references:
* ISO images:## Components
vpsAdminOS uses:
- [LTS kernel with a mix of out-of-tree patches](https://github.com/vpsfreecz/linux)
to improve container experience,
- runit as an init system,
- ZFS for storage,
- our own tools for system container management called [osctl](https://man.vpsadminos.org/man8/osctl.8.html),
- LXC is used to run the containers,
- BIRD for network routing.## Building OS
Our kernel live-patch facility requires [ccache](https://wiki.nixos.org/wiki/CCache)
to build the OS.```bash
git clone https://github.com/vpsfreecz/vpsadminos/
cd vpsadminos
```vpsAdminOS is developed on top of the latest NixOS release, so make sure that
the correct version of nixpkgs is in `NIX_PATH`, or set it as follows:```bash
git clone https://github.com/NixOS/nixpkgs --branch nixos-25.05
export NIX_PATH=`pwd`
```vpsAdminOS can now be built and run:
```
# Build the OS
make# Run under qemu
make qemu
```The QEMU runner creates two disk images - `sda.img` and `sdb.img` which are added
as QEMU ATA drives and can be used to create a mirrored ZFS pool that persists
across reboots.## Usage
```bash
# Login via ssh or use qemu terminal with autologin
ssh -p 2222 localhost# Configure osctld:
osctl pool install tank# Create a container:
osctl ct new --distribution alpine myct01# Configure container networking:
# Bridged veth
osctl ct netif new bridge --link lxcbr0 myct01 eth0# Routed veth
osctl ct netif new routed myct01 eth1
osctl ct netif ip add myct01 eth1 1.2.3.4/32# Start the container:
osctl ct start myct01# Work with containers:
osctl ct ls
osctl ct attach myct01
osctl ct console myct01
osctl ct exec myct01 ip addr# More information:
man osctl# https://vpsadminos.org/user-guide/setup/
# https://vpsadminos.org/containers/administration/
```## Binary cache
vpsAdminOS has its own binary cache which contains builds of vpsAdminOS
with the current NixOS stable branch. Using it can save a lot of time building
the kernel.```nix
{ config, ... }:
{
nix.settings = {
substituters = [ "https://cache.vpsadminos.org" ];
trusted-public-keys = [ "cache.vpsadminos.org:wpIJlNZQIhS+0gFf1U3MC9sLZdLW3sh5qakOWGDoDrE=" ];# Enable fallback in case the binary cache is unreachable
fallback = true;
connect-timeout = 15;
};
}
```## Docs
* [vpsAdminOS documentation](https://vpsadminos.org)
* [Manual pages](https://man.vpsadminos.org)
* [Reference documentation](https://ref.vpsadminos.org)
* https://linuxcontainers.org/