Really depends on what you want to accomplish. Virtualization does have some overheads and general complexity that cgroups don’t, but since the tech has been used for this kind of use case for 30-ish years now it’s much better integrated.
Actually, I'm not *sure* virtualization has much of an overhead compared to cgroups for this use case...
The overheads are usually overstated quite significantly, same-architecture virtualization does not require any form of tranlation and is hence very performant; the instructions are executed directly on the CPU, just in a different address space. The overhead is purely in the same kind of virtual in/output stuff these docker alternatives do, except the virtualization world has been doing it for decades so I wouldn’t be surprised if they’re better at it… And docker images for this kind of use case are probably not much smaller.
The main overheads would be in bootup speed and disk space, because each VM needs a kernel that takes up ~200MB of disk space and about that much memory, on top of having to boot, and well, the overhead of running an extra kernel (which I want to note is small). You can alternatively tinker with smaller kernels if memory size a problem for your use case.
I’m honestly really curious how the technologies compare for really fat use cases like this. I feel like an extra kernel is easily amortized by the size of most modern games.
In theory nixpkgs’ dockertools should be able to create any docker image you want though. It’s not only designed for “small” images or anything. Copying stuff without understanding why and how it works is more likely the issue you’re running into.
There are also nixos-containers, which are probably much easier to configure for this kind of thing since they’re written with NixOS module definitions. They can’t be deployed to generic OCI runtimes, though, they’re executed with systemd-nspawn instead.
But yes, NixOS can also be used to create more general OS images.
Anyway, that project looks like it’s geared around setting up homebrew game streaming services. If that’s not your use case, you’re barking up the entirely wrong tree.
If that is your use case, you’ll have to evaluate hosting costs across various cloud infrastructure providers to see if fat VMs make more or less sense for your use case.
If this is for personal use you’re almost certainly better off with a beefy VPS and moonshine, flexible cloud infra tends to have overhead costs that are difficult to manage for small scales (and frankly even large scales).
If you’re thinking of setting up some kind of game streaming company, I think you have a lot of learning to do before you should embark on that. I’m not certain containerizing with nix is the right way to go, since you’ll be dealing with a lot of proprietary software that probably doesn’t mesh well with NixOS’ lack of a global /usr and other idiosyncracies.
If all you’re trying to do is sandbox your games, well, that’s what flatpak is for. If you’re doing this because the default permissions are too lax for you, flatseal helps with that.
If you’re just toying around and learning, well, have fun.