layer-nerdctl
Recipe card from the charly-distros plugin (Images — the deployable catalog).
layer-nerdctl
Section titled “layer-nerdctl”nerdctl (the containerd CLI) plus the rootless containerd + buildkit + CNI
stack, as ONE candy. Composed by a box that wants the opt-in engine: nerdctl
engine.
What it installs
Section titled “What it installs”- Native packages on Arch/CachyOS/Omarchy and Alpine:
nerdctl,cni-plugins,rootlesskit,slirp4netns,buildkit,fuse-overlayfs,crun,iptables-nft(arch) /iptables(alpine). - Non-native distros (Fedora/Debian/Ubuntu) install the pinned,
sha256-verified
nerdctl-fulltarball (stepnerdctl-full-tarball), which supplies nerdctl + containerd +containerd-fuse-overlayfs-grpc+ CNI + buildkit + rootlesskit in one archive. /etc/nerdctl/nerdctl.toml(charly namespace + rootless buildkit host) and thecharlyCNI network conflist at/etc/cni/net.d/charly.conflist.- The nested-pod posture: userns-scoped
cap_add: ALL,/dev/fuse,/dev/net/tun,unmask=/proc/*.
Engine capability
Section titled “Engine capability”The engine: nerdctl word is served by opencharly/plugin-nerdctl
(out-of-process) or compiled in; every engine op delegates to
container.InvokeEngineOp("nerdctl", …) in the spec module. nerdctl has no
--keep-id, so the start-plan runs the workload as --user 0:0 (uid 0 == the
host user under rootless), guaranteeing uid-identical sharing; a non-zero uid
needs the subuid caveat.
Use when
Section titled “Use when”Working with the nerdctl engine, the layer-nerdctl candy, or an
engine: nerdctl deploy.