about summary refs log tree commit diff
path: root/nixos/doc/manual/administration/containers.chapter.md
diff options
context:
space:
mode:
authorBobby Rong <rjl931189261@126.com>2021-09-08 14:40:26 +0800
committerBobby Rong <rjl931189261@126.com>2021-09-08 14:40:26 +0800
commit5aaeddee5f2da59e5664d5c215ff08cfb6a6f252 (patch)
tree13afe1424844538db241e5ead82a478d4e231ff9 /nixos/doc/manual/administration/containers.chapter.md
parent8882ec6ff968a2f10d9d9ec2ab695791859e0852 (diff)
nixos: nixos/doc/manual/administration/containers.xml to CommonMark
Diffstat (limited to 'nixos/doc/manual/administration/containers.chapter.md')
-rw-r--r--nixos/doc/manual/administration/containers.chapter.md28
1 files changed, 28 insertions, 0 deletions
diff --git a/nixos/doc/manual/administration/containers.chapter.md b/nixos/doc/manual/administration/containers.chapter.md
new file mode 100644
index 0000000000000..ea51f91f698fb
--- /dev/null
+++ b/nixos/doc/manual/administration/containers.chapter.md
@@ -0,0 +1,28 @@
+# Container Management {#ch-containers}
+
+NixOS allows you to easily run other NixOS instances as *containers*.
+Containers are a light-weight approach to virtualisation that runs
+software in the container at the same speed as in the host system. NixOS
+containers share the Nix store of the host, making container creation
+very efficient.
+
+::: {.warning}
+Currently, NixOS containers are not perfectly isolated from the host
+system. This means that a user with root access to the container can do
+things that affect the host. So you should not give container root
+access to untrusted users.
+:::
+
+NixOS containers can be created in two ways: imperatively, using the
+command `nixos-container`, and declaratively, by specifying them in your
+`configuration.nix`. The declarative approach implies that containers
+get upgraded along with your host system when you run `nixos-rebuild`,
+which is often not what you want. By contrast, in the imperative
+approach, containers are configured and updated independently from the
+host system.
+
+```{=docbook}
+<xi:include href="imperative-containers.section.xml" />
+<xi:include href="declarative-containers.section.xml" />
+<xi:include href="container-networking.section.xml" />
+```