Skip to main content
podbox/docs/baked-in-packages.md
On this page

Base packages

Custom builds get a curated toolset injected automatically. You don't list these in your TOML — they just show up.

Prebuilt images (image.image set) ship complete and skip this entirely. Extend either kind under [image.packages].

What's included

GroupPackages
Privilege escalationsudo
Downloadingcurl, wget
Archivestar, unzip
Locatorswhich
Core toolscoreutils, diffutils, findutils, grep, sed, gawk
Shell completionbash-completion (plus zsh-completions on Arch)
Your shellfish, bash, or zsh — whichever $SHELL points at on the host
Localeslocales (Debian), glibc-all-langpacks (Fedora), glibc (Arch), musl-locales (Alpine)
Host $SHELLInjected
/usr/bin/fishfish
/bin/bashbash, bash-completion
/usr/bin/zshzsh (+ zsh-completions on Arch, zsh-common on Debian)
/bin/sh, /bin/dashdash

Prebuilt images skip this — their shell comes from the image itself.

Distro detection

The base image name picks the package manager:

FamilyMatched byManager
Debiandebian, ubuntu, mint, kali, pop, elementaryapt
Fedorafedora, rhel, centos, rocky, alma, nobaradnf
Archarch, cachy, manjaro, endeavouros, garudapacman
Alpinealpineapk
Anything else—dnf

Wrong guess? Pin it:

toml
[image.packages]
manager = "apk" # dnf, apt, pacman, apk, zypper

Anything else is ignored and detection applies.

Add or remove packages

toml
[image.packages]
install = ["neovim", "git", "ripgrep"] # added on top, duplicates removed
remove = ["vim-minimal"] # strip what the base image ships

Leave install empty for a lean image — you still get the base set.

Passwordless sudo

sudo dnf install … just works, no prompt. The rule regenerates on every start:

bash
bet ALL=(ALL) NOPASSWD: ALL

Locale and timezone

WhatHow
LANG, LC_ALL, LC_CTYPECopied from your host environment
/etc/localtimeMounted read-only, if it exists on the host
/etc/timezoneMounted read-only, if it exists (Debian/Ubuntu)

Missing files are skipped, not errors. Arch and Fedora don't have /etc/timezone — that's normal.

Theme, icon, and font paths

With sync_themes, sync_icons, or sync_fonts on, podbox mounts both the old and new locations (when they exist on the host), so themed apps don't look broken:

OldNew
~/.themes~/.local/share/themes
~/.icons~/.local/share/icons
~/.fonts~/.local/share/fonts
podbox — declarative Linux container environments
Licensed under MIT. Open Source by bethropolis.