#!/usr/bin/env bash # ============================================================================= # 30-nvidia — NVIDIA driver + container toolkit for the GTX 1070 # # WHY THIS IS NOT IN late-commands: # The driver is a DKMS module. It must build against the kernel that is # actually running on the installed system, with that kernel's headers, on a # real boot. Building it inside the installer environment produces a module # for the installer's kernel, which is not the kernel that boots. # # DRIVER BRANCH — this is the part that will bite later: # The GTX 1070 is Pascal. NVIDIA's 580 branch is the LAST branch that supports # Maxwell, Pascal and Volta; it is now a frozen legacy branch receiving # security fixes only. There will be no 590 for this card. Two consequences: # 1. We install nvidia-driver-580 explicitly. Never `ubuntu-drivers autoinstall`, # which will happily pick a newer branch that does not support the card. # 2. We install the PROPRIETARY module, not `-open`. The open kernel modules # require Turing or newer. On Pascal they will not load at all. # # Secure Boot must be OFF (verified 2026-07-27). With it on, the DKMS module is # unsigned as far as the firmware is concerned and requires interactive MOK # enrollment at a physical console — on a box with no keyboard. # # Plex is targeted at Quick Sync, not NVENC, so this stage failing does NOT # block Plex. It fails soft. # ============================================================================= set -uo pipefail DRIVER_BRANCH=580 if ! lspci -nn | grep -qi nvidia; then echo " no NVIDIA device on the PCI bus — skipping" exit 0 fi if command -v nvidia-smi >/dev/null 2>&1 && nvidia-smi >/dev/null 2>&1; then echo " driver already working:" nvidia-smi --query-gpu=name,driver_version --format=csv,noheader | sed 's/^/ /' else echo " installing nvidia-driver-${DRIVER_BRANCH} (proprietary; Pascal cannot use -open)" export DEBIAN_FRONTEND=noninteractive apt-get update -qq # Explicit branch, explicit proprietary flavour. No ubuntu-drivers autoinstall. if ! apt-get install -y \ "nvidia-driver-${DRIVER_BRANCH}" \ "nvidia-utils-${DRIVER_BRANCH}" \ "linux-headers-$(uname -r)" \ dkms; then echo " [FAIL] driver install failed — Plex/Quick Sync is unaffected, fix later" exit 1 fi # Persistence mode avoids a multi-second GPU init on every container start. systemctl enable --now nvidia-persistenced 2>/dev/null || true echo " driver installed — a REBOOT is required before nvidia-smi will work" fi # --- NVIDIA Container Toolkit ------------------------------------------------ if [ -f /etc/apt/sources.list.d/nvidia-container-toolkit.list ] \ && command -v nvidia-ctk >/dev/null 2>&1; then echo " container toolkit already present" else echo " installing NVIDIA container toolkit" install -m 0755 -d /usr/share/keyrings curl -fsSL https://nvidia.github.io/libnvidia-container/gpgkey \ | gpg --dearmor -o /usr/share/keyrings/nvidia-container-toolkit-keyring.gpg curl -fsSL https://nvidia.github.io/libnvidia-container/stable/deb/nvidia-container-toolkit.list \ | sed 's#deb https://#deb [signed-by=/usr/share/keyrings/nvidia-container-toolkit-keyring.gpg] https://#g' \ > /etc/apt/sources.list.d/nvidia-container-toolkit.list apt-get update -qq apt-get install -y nvidia-container-toolkit || { echo " [FAIL] container toolkit install failed"; exit 1; } nvidia-ctk runtime configure --runtime=docker systemctl restart docker fi # --- guard rail -------------------------------------------------------------- # If a newer driver branch is ever pulled in, it will silently drop this card. cat > /etc/apt/preferences.d/nvidia-pascal.pref <