Support reproducible builds with SOURCE_DATE_EPOCH
Les mainteneurs répondent en général sous 1 jour
Personne n'a encore pris cette issue.
Évaluation
- Difficulté
- 4/5
- Temps estimé
- 3-5 jours
- Accessibilité débutants
- 52/100
- Type d'issue
- Fonctionnalité
- Clarté
- Plutôt claire
- Activité
- Active
- Stack technique
- docker, github-actions
- Domaine
- build-system, ci-cd
Piste de recherche
Start with .github/workflows/build.yml, especially the output construction at the referenced v1.17.0 line 803, and inspect the corresponding bake.yml workflow and metadata-action inputs. Trace how workflow inputs reach the build step, image/local outputs, and metadata labels or annotations. Done means both workflows support the proposed epoch behavior, including commit, and builds use consistent timestamps for layers and created metadata.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Description
Description
Problem
Docker's reproducible builds guide for GitHub Actions recommends setting SOURCE_DATE_EPOCH, for example to the commit time (git log -1 --pretty=%ct), on the build step. With the build reusable workflow, there's currently no way to get a reproducible image:
- No input sets
SOURCE_DATE_EPOCHfor the build step. Passing it throughbuild-argsworks for the image config and history timestamps, because BuildKit reads it as a build arg too. But the caller has to compute the commit time in a separate job, since the reusable workflow builds from the Git context without a checkout. - File timestamps inside the layers aren't rewritten. That needs
rewrite-timestamp=trueon the image exporter (BuildKit docs). The workflow builds the output string itself (build.yml#L803 at v1.17.0), so callers can't add it. - With
set-meta-labels/set-meta-annotations,org.opencontainers.image.createdgets the build time, because metadata-action uses the current date, even whenSOURCE_DATE_EPOCHis set.
So two builds of the same commit always end up with different layer and image digests.
Proposal
A source-date-epoch input for build.yml (and bake.yml) that:
- sets
SOURCE_DATE_EPOCHfor the build step; - adds
rewrite-timestamp=trueto theimage(andlocal) output; - uses the same time for the
org.opencontainers.image.createdlabel and annotation whenset-meta-labels/set-meta-annotationsare on.
It would help most if the input could also take the commit time directly, for example source-date-epoch: commit, since the workflow already knows which commit it builds and callers wouldn't need an extra job for it.
Alternatives considered
build-args: SOURCE_DATE_EPOCH=…plus overridingmeta-labels/meta-annotations: fixes the metadata timestamps, but not the layer contents, so the digests still differ.- Using
docker/build-push-actiondirectly: works, but gives up what the reusable workflow provides (distributed native builds, signed cache, signed provenance).
- Langage dominant
- Aucune donnée de langage
- Étoiles
- 86
- Forks
- 23
- Merge moyen
- 5 j 47 min
- PR mergées (30 j)
- 17
Préparer son environnement
- Aucun Dockerfile ni fichier Docker Compose
- Aucun modèle de pull request
- Lire le guide de contribution
Par où commencer
- Lisez l'issue en entier, puis le guide de contribution du projet.
- Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
- Forkez le dépôt et travaillez sur une branche.
- Ouvrez une pull request qui référence le numéro de l'issue.
Autres issues de docker/github-builder
-
Difficulté 4/5 3-5 jours Accessibilité débutants 52/100
docker/github-builder#251 ·
Les mainteneurs répondent en général sous 1 jour
-
Difficulté 3/5 1-2 jours Accessibilité débutants 68/100
docker/github-builder#209 ·
Les mainteneurs répondent en général sous 1 jour
-
kind/enhancement
Difficulté 3/5 1-2 jours Accessibilité débutants 65/100
docker/github-builder#207 · 1 commentaire ·
Les mainteneurs répondent en général sous 1 jour
-
kind/enhancement status/triage
Difficulté 5/5 Plus d'une semaine Accessibilité débutants 25/100
docker/github-builder#203 · 1 commentaire ·
Les mainteneurs répondent en général sous 1 jour
-
status/triage
Difficulté 4/5 3-5 jours Accessibilité débutants 45/100
docker/github-builder#193 · 2 commentaires ·
Les mainteneurs répondent en général sous 1 jour
Toutes les issues de docker/github-builder
Issues similaires
-
Difficulté 2/5 1-3 heures Accessibilité débutants 65/100
rescript-lang/rescript#8765 ·
Les mainteneurs répondent en général sous 1 jour
-
[request] vsg/1.1.16Ouverteupstream update
Difficulté 2/5 1-3 heures Accessibilité débutants 65/100
conan-io/conan-center-index#31142 ·
Les mainteneurs répondent en général sous 1 jour
-
bot-found documentation priority: P3
Difficulté 2/5 1-3 heures Accessibilité débutants 72/100
madenvel/KalinkaPlayer#313 ·
-
Difficulté 2/5 1-3 heures Accessibilité débutants 62/100
Les mainteneurs répondent en général sous 1 jour
-
setup_intel.py: sycl_version() returns "0", so setup refuses UD-IQ4_XS and UD-Q4_K_XL on IntelOuverte
Difficulté 2/5 1-3 heures Accessibilité débutants 85/100
Les mainteneurs répondent en général sous 1 jour