From 07991dabafbc7e2a50cc66ce2cfa3ec65a44c2b8 Mon Sep 17 00:00:00 2001 From: tiennm99 Date: Thu, 17 Sep 2026 14:20:57 +0700 Subject: [PATCH] feat(code-server): mount the host docker socket Bind-mount /var/run/docker.sock so the universal-docker mod's CLI has a daemon to talk to, and document the sibling-container and permission caveats in the service README. --- code-server/README.md | 14 ++++++++++++++ code-server/compose.yml | 1 + 2 files changed, 15 insertions(+) diff --git a/code-server/README.md b/code-server/README.md index 827a09e..8ec4895 100644 --- a/code-server/README.md +++ b/code-server/README.md @@ -7,6 +7,20 @@ Comes with Go, Node.js 24, Python 3, pnpm, and zsh via LinuxServer mods, plus `gh`, `git`, `ffmpeg`, `imagemagick`, and other CLI tools through `INSTALL_PACKAGES`. Git author/committer identity is injected from `.env`. +## Docker access + +The `universal-docker` mod installs the Docker CLI but no daemon, so the host +socket is bind-mounted at `/var/run/docker.sock` to give it something to talk +to. Containers started from inside are siblings on the host, not children -- +bind mounts in them resolve against host paths, so a path under `/config` will +not exist unless the same path exists on the host. + +The socket is owned by the host's `docker` group, which the `abc` user inside +the container is not a member of; run `docker` under `sudo` (the `SUDO_PASSWORD` +is the same `PASSWORD`) or add the group by hand. Handing a container the +socket is equivalent to giving it root on the host -- that is accepted here +because this is a single-user dev box. + ## Environment | Variable | Purpose | diff --git a/code-server/compose.yml b/code-server/compose.yml index ba2a916..09f30f4 100644 --- a/code-server/compose.yml +++ b/code-server/compose.yml @@ -19,5 +19,6 @@ services: - GIT_COMMITTER_EMAIL=${GIT_EMAIL} volumes: - 'code-server-config:/config' + - '/var/run/docker.sock:/var/run/docker.sock' volumes: code-server-config: