Skip to content

layer-nerdctl

Recipe card from the charly-distros plugin (Images — the deployable catalog).

nerdctl (the containerd CLI) plus the rootless containerd + buildkit + CNI stack, as ONE candy. Composed by a box that wants the opt-in engine: nerdctl engine.

  • Native packages on Arch/CachyOS/Omarchy and Alpine: nerdctl, cni-plugins, rootlesskit, slirp4netns, buildkit, fuse-overlayfs, crun, iptables-nft (arch) / iptables (alpine).
  • Non-native distros (Fedora/Debian/Ubuntu) install the pinned, sha256-verified nerdctl-full tarball (step nerdctl-full-tarball), which supplies nerdctl + containerd + containerd-fuse-overlayfs-grpc + CNI + buildkit + rootlesskit in one archive.
  • /etc/nerdctl/nerdctl.toml (charly namespace + rootless buildkit host) and the charly CNI network conflist at /etc/cni/net.d/charly.conflist.
  • The nested-pod posture: userns-scoped cap_add: ALL, /dev/fuse, /dev/net/tun, unmask=/proc/*.

The engine: nerdctl word is served by opencharly/plugin-nerdctl (out-of-process) or compiled in; every engine op delegates to container.InvokeEngineOp("nerdctl", …) in the spec module. nerdctl has no --keep-id, so the start-plan runs the workload as --user 0:0 (uid 0 == the host user under rootless), guaranteeing uid-identical sharing; a non-zero uid needs the subuid caveat.

Working with the nerdctl engine, the layer-nerdctl candy, or an engine: nerdctl deploy.