feat(code-server): mount the host docker socket

Bind-mount /var/run/docker.sock so the universal-docker mod's CLI has a
daemon to talk to, and document the sibling-container and permission
caveats in the service README.
This commit is contained in:
tiennm99 committed 2026-09-17 14:20:57 +07:00
1 parent f09325b2fc
commit 07991dabaf
2 files changed
+15

No files matched your search

+14
View File
@@ -7,6 +7,20 @@ Comes with Go, Node.js 24, Python 3, pnpm, and zsh via LinuxServer mods, plus
`gh`, `git`, `ffmpeg`, `imagemagick`, and other CLI tools through
`INSTALL_PACKAGES`. Git author/committer identity is injected from `.env`.
## Docker access
The `universal-docker` mod installs the Docker CLI but no daemon, so the host
socket is bind-mounted at `/var/run/docker.sock` to give it something to talk
to. Containers started from inside are siblings on the host, not children --
bind mounts in them resolve against host paths, so a path under `/config` will
not exist unless the same path exists on the host.
The socket is owned by the host's `docker` group, which the `abc` user inside
the container is not a member of; run `docker` under `sudo` (the `SUDO_PASSWORD`
is the same `PASSWORD`) or add the group by hand. Handing a container the
socket is equivalent to giving it root on the host -- that is accepted here
because this is a single-user dev box.
## Environment
| Variable | Purpose |