69 lines
2.1 KiB
Markdown
69 lines
2.1 KiB
Markdown
# distrobox-images
|
|
|
|
Dockerfiles for heavy software (Houdini, ...) run via
|
|
[distrobox](https://github.com/89luca89/distrobox), built once and pushed to
|
|
a private registry instead of rebuilding on every `distrobox create`.
|
|
|
|
## Convention
|
|
|
|
One self-contained folder per app:
|
|
|
|
```
|
|
<soft>/
|
|
Dockerfile # often multi-stage: shared base + amd / nvidia variant
|
|
build-and-push.sh # build + push to the registry
|
|
<soft>-run # launcher installed in the image (app entrypoint)
|
|
README.md # specifics: prerequisites, licensing, distrobox create, gotchas
|
|
```
|
|
|
|
No shared base image across different apps — each has its own system
|
|
dependencies, sharing more than the folder structure doesn't buy anything.
|
|
|
|
Two GPU variants per app when OpenGL/Vulkan rendering matters (viewport,
|
|
preview):
|
|
- `<soft>-amd` — Mesa baked into the image (radeonsi / RADV), also works for
|
|
Intel.
|
|
- `<soft>-nvidia` — nothing baked in; the host's NVIDIA driver is mounted at
|
|
runtime by `distrobox --nvidia`.
|
|
|
|
If GPU rendering doesn't matter for a given app, one image is enough — don't
|
|
duplicate on principle.
|
|
|
|
## Private registry
|
|
|
|
Registry: `docker.slambin.fr`. If it's a real domain with TLS (reverse proxy
|
|
+ cert) in front, nothing to configure on the container engine side —
|
|
`push`/`pull` just work. Only if the registry runs plain HTTP (e.g. a local
|
|
test without TLS) does it need to be declared "insecure":
|
|
|
|
```bash
|
|
podman run -d --name registry --restart=always \
|
|
-p 5000:5000 -v registry-data:/var/lib/registry \
|
|
registry:2
|
|
```
|
|
|
|
**podman** — `/etc/containers/registries.conf.d/local.conf`:
|
|
|
|
```toml
|
|
[[registry]]
|
|
location = "docker.slambin.fr"
|
|
insecure = true
|
|
```
|
|
|
|
**docker** — `/etc/docker/daemon.json`, then restart docker:
|
|
|
|
```json
|
|
{ "insecure-registries": ["docker.slambin.fr"] }
|
|
```
|
|
|
|
## Licensing / EULA
|
|
|
|
Several of these apps (Houdini included) are installed from a proprietary
|
|
binary downloaded with a personal account, and the EULA generally forbids
|
|
redistribution. The registry must stay **private** — never push an image
|
|
containing one of these binaries to a public registry.
|
|
|
|
## Apps
|
|
|
|
- [`houdini/`](houdini/README.md) — Houdini Apprentice
|