[Git][reproducible-builds/reproducible-website][master] 2 commits: d1-imagebuilds: convert to markdown
Bernhard M. Wiedemann (@bmwiedemann-guest)
gitlab at salsa.debian.org
Fri Sep 25 08:54:10 UTC 2026
Bernhard M. Wiedemann pushed to branch master at Reproducible Builds / reproducible-website
Commits:
41f9b7f4 by Bernhard M. Wiedemann at 2026-09-25T10:46:15+02:00
d1-imagebuilds: convert to markdown
- - - - -
112b51f5 by Bernhard M. Wiedemann at 2026-09-25T10:53:16+02:00
d1-imagebuilds: improve grammar
- - - - -
1 changed file:
- _events/gothenburg2026/agenda/d1-imagebuilds.md
Changes:
=====================================
_events/gothenburg2026/agenda/d1-imagebuilds.md
=====================================
@@ -1,24 +1,32 @@
-What was necessary for making arch images reproducible:
-Goal is to make a rootfs that's reproducible
-Lots of timestamp cleanup
-Handling logs, some build tools can be piped to dev null
-Need an archive for bootstrapping, use yesterday's archive to bootstrap today's image
-Pacman has some non-determinism (key material embedded in the binary) which is stripped from the image. This breaks pacman out of the box, you need to run a command to fix pacman. Pacman also supports redirecting logs (to dev null) and use `SOURCE_DATE_EPOCH` for installed package metadata. Comment: does apt support this?
-For WSL the rootfs is enough, very little translation after that
-For containers, the builder takes the rootfs but needs additional flags to make the container image itself reproducible. One of the major ones is epoch time, arch uses the release timestamp
-One difficult quirk is that the name of the container is embedded in the file as annotation, making comparing two containers eg diff on the same system (in the same registry) is impossible because they need to be named differently.
-diffoci helps do this diff, allows ignoring those diffs
-
-Version of the image is the current date, archive date is set to -1 day for consistency of the archive. Weekly rebuilds. Reproducibility is also tested for the userland - if the default packages are reproducible but does not block the release.
-Recommended to use CI, pull-through mirror for docker hub (or AWS/GCP mirrors as fallback due to Hub rate limiting). From end user perspective, archive/snapshot repos can be slow as they don't have mirrors, potential SPOF.
-
+## What was necessary for making Arch images reproducible:
+
+- The goal is to make a rootfs that's reproducible
+- Lots of timestamp cleanup
+- Handling logs: the output of some build tools can be piped to /dev/null
+- An archive is needed for bootstrapping: use yesterday's archive to bootstrap today's image
+- Pacman has some non-determinism (key material embedded in the binary), which is stripped from the image. This breaks pacman out of the box; you need to run a command to fix pacman. Pacman also supports redirecting logs (to /dev/null) and using `SOURCE_DATE_EPOCH` for installed package metadata.
+ - Comment: does apt support this?
+- For WSL, the rootfs is enough; very little translation is needed after that
+- For containers, the builder takes the rootfs but needs additional flags to make the container image itself reproducible. One of the major ones is the epoch time; Arch uses the release timestamp
+- One difficult quirk is that the name of the container is embedded in the file as an annotation. This makes comparing two containers (e.g. with diff) on the same system (in the same registry) impossible, because they need to be named differently.
+ - diffoci helps with this comparison and allows ignoring those differences
+
+## Versioning and release process
+
+- The version of the image is the current date; the archive date is set to -1 day for consistency of the archive. Rebuilds happen weekly.
+- Reproducibility is also tested for the userland - if the default packages are reproducible but does not block the release.
+- Using CI is recommended, along with a pull-through mirror for Docker Hub (or AWS/GCP mirrors as a fallback due to Hub rate limiting).
+- From the end user's perspective, archive/snapshot repos can be slow as they don't have mirrors, and they are a potential SPOF.
+
## Actionable tasks?
-- ?
-
+
+- ?
+
## Resources
-- [https://antiz.fr/blog/the-archlinux-wsl-image-is-now-reproducible/](https://antiz.fr/blog/the-archlinux-wsl-image-is-now-reproducible/)
-- [https://antiz.fr/blog/archlinux-now-has-a-reproducible-docker-image/](https://antiz.fr/blog/archlinux-now-has-a-reproducible-docker-image/)
-- [https://vdwaa.nl/mkosi-reproducible-arch-images.html#mkosi-reproducible-arch-images](https://vdwaa.nl/mkosi-reproducible-arch-images.html#mkosi-reproducible-arch-images)
-- [https://vdwaa.nl/mkosi-reproducible-images.html#mkosi-reproducible-images](https://vdwaa.nl/mkosi-reproducible-images.html#mkosi-reproducible-images)
-- [https://gitlab.archlinux.org/archlinux/archlinux-docker/-/blob/master/REPRO.md](https://gitlab.archlinux.org/archlinux/archlinux-docker/-/blob/master/REPRO.md)
+
+- [https://antiz.fr/blog/the-archlinux-wsl-image-is-now-reproducible/](https://antiz.fr/blog/the-archlinux-wsl-image-is-now-reproducible/)
+- [https://antiz.fr/blog/archlinux-now-has-a-reproducible-docker-image/](https://antiz.fr/blog/archlinux-now-has-a-reproducible-docker-image/)
+- [https://vdwaa.nl/mkosi-reproducible-arch-images.html#mkosi-reproducible-arch-images](https://vdwaa.nl/mkosi-reproducible-arch-images.html#mkosi-reproducible-arch-images)
+- [https://vdwaa.nl/mkosi-reproducible-images.html#mkosi-reproducible-images](https://vdwaa.nl/mkosi-reproducible-images.html#mkosi-reproducible-images)
+- [https://gitlab.archlinux.org/archlinux/archlinux-docker/-/blob/master/REPRO.md](https://gitlab.archlinux.org/archlinux/archlinux-docker/-/blob/master/REPRO.md)
- [https://gitlab.archlinux.org/archlinux/archlinux-wsl/-/blob/main/REPRO.md](https://gitlab.archlinux.org/archlinux/archlinux-wsl/-/blob/main/REPRO.md)
View it on GitLab: https://salsa.debian.org/reproducible-builds/reproducible-website/-/compare/ffb13a43f150f16ce63d96075ec536d791c394d7...112b51f5ec0b81ba4962cd3d481f4e998f597226
--
View it on GitLab: https://salsa.debian.org/reproducible-builds/reproducible-website/-/compare/ffb13a43f150f16ce63d96075ec536d791c394d7...112b51f5ec0b81ba4962cd3d481f4e998f597226
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.reproducible-builds.org/pipermail/rb-commits/attachments/20260925/4e46d809/attachment.htm>
More information about the rb-commits
mailing list