nix/docker: use copyToRoot to add configs
instead of `runAsRoot` which requires virtualization which is not available for GH Actions.