feat: cleanup the houdini image setup
This commit is contained in:
68
README.md
68
README.md
@@ -1,35 +1,40 @@
|
||||
# distrobox-images
|
||||
|
||||
Dockerfiles pour les softs lourds (Houdini, ...) lancés via [distrobox](https://github.com/89luca89/distrobox),
|
||||
buildés une fois et poussés sur un registry privé plutôt que rebuild à chaque
|
||||
`distrobox create`.
|
||||
Dockerfiles for heavy software (Houdini, ...) run via
|
||||
[distrobox](https://github.com/89luca89/distrobox), built once and pushed to
|
||||
a private registry instead of rebuilding on every `distrobox create`.
|
||||
|
||||
## Convention
|
||||
|
||||
Un dossier par soft, autonome :
|
||||
One self-contained folder per app:
|
||||
|
||||
```
|
||||
<soft>/
|
||||
Dockerfile # souvent multi-stage: base commune + variante amd / nvidia
|
||||
build-and-push.sh # build + push vers le registry
|
||||
<soft>-run # launcher installé dans l'image (entrypoint applicatif)
|
||||
README.md # specifics: prérequis, licence, distrobox create, gotchas
|
||||
Dockerfile # often multi-stage: shared base + amd / nvidia variant
|
||||
build-and-push.sh # build + push to the registry
|
||||
<soft>-run # launcher installed in the image (app entrypoint)
|
||||
README.md # specifics: prerequisites, licensing, distrobox create, gotchas
|
||||
```
|
||||
|
||||
Pas de base image partagée entre softs différents — chacun a ses propres
|
||||
dépendances système, ça n'apporte rien de mutualiser au-delà du dossier.
|
||||
No shared base image across different apps — each has its own system
|
||||
dependencies, sharing more than the folder structure doesn't buy anything.
|
||||
|
||||
Deux variantes GPU par soft quand le rendu OpenGL/Vulkan compte (viewport,
|
||||
préview) :
|
||||
- `<soft>-amd` — Mesa embarqué dans l'image (radeonsi / RADV), marche aussi
|
||||
pour Intel.
|
||||
- `<soft>-nvidia` — rien embarqué; le driver NVIDIA de l'hôte est monté au
|
||||
runtime par `distrobox --nvidia`.
|
||||
Two GPU variants per app when OpenGL/Vulkan rendering matters (viewport,
|
||||
preview):
|
||||
- `<soft>-amd` — Mesa baked into the image (radeonsi / RADV), also works for
|
||||
Intel.
|
||||
- `<soft>-nvidia` — nothing baked in; the host's NVIDIA driver is mounted at
|
||||
runtime by `distrobox --nvidia`.
|
||||
|
||||
Si le rendu GPU n'a pas d'importance pour un soft donné, une seule image
|
||||
suffit — ne pas dupliquer par principe.
|
||||
If GPU rendering doesn't matter for a given app, one image is enough — don't
|
||||
duplicate on principle.
|
||||
|
||||
## Registry privé
|
||||
## Private registry
|
||||
|
||||
Registry: `docker.slambin.fr`. If it's a real domain with TLS (reverse proxy
|
||||
+ cert) in front, nothing to configure on the container engine side —
|
||||
`push`/`pull` just work. Only if the registry runs plain HTTP (e.g. a local
|
||||
test without TLS) does it need to be declared "insecure":
|
||||
|
||||
```bash
|
||||
podman run -d --name registry --restart=always \
|
||||
@@ -37,32 +42,27 @@ podman run -d --name registry --restart=always \
|
||||
registry:2
|
||||
```
|
||||
|
||||
HTTP en clair, donc à déclarer en "insecure" côté moteur de conteneurs.
|
||||
|
||||
**podman** — `/etc/containers/registries.conf.d/local.conf` :
|
||||
**podman** — `/etc/containers/registries.conf.d/local.conf`:
|
||||
|
||||
```toml
|
||||
[[registry]]
|
||||
location = "registry.lan:5000"
|
||||
location = "docker.slambin.fr"
|
||||
insecure = true
|
||||
```
|
||||
|
||||
**docker** — `/etc/docker/daemon.json`, puis restart docker :
|
||||
**docker** — `/etc/docker/daemon.json`, then restart docker:
|
||||
|
||||
```json
|
||||
{ "insecure-registries": ["registry.lan:5000"] }
|
||||
{ "insecure-registries": ["docker.slambin.fr"] }
|
||||
```
|
||||
|
||||
Au-delà d'un LAN de confiance, mettre TLS + auth devant plutôt que
|
||||
`insecure`.
|
||||
## Licensing / EULA
|
||||
|
||||
## Licences / EULA
|
||||
Several of these apps (Houdini included) are installed from a proprietary
|
||||
binary downloaded with a personal account, and the EULA generally forbids
|
||||
redistribution. The registry must stay **private** — never push an image
|
||||
containing one of these binaries to a public registry.
|
||||
|
||||
Plusieurs de ces softs (Houdini compris) sont installés depuis un binaire
|
||||
propriétaire téléchargé avec un compte perso, et l'EULA interdit en général
|
||||
la redistribution. Le registry doit rester **privé** — jamais de push d'une
|
||||
image contenant un de ces binaires vers un registry public.
|
||||
|
||||
## Softs
|
||||
## Apps
|
||||
|
||||
- [`houdini/`](houdini/README.md) — Houdini Apprentice
|
||||
|
||||
Reference in New Issue
Block a user