Support reproducible builds with SOURCE_DATE_EPOCH
I maintainer di solito rispondono entro 1 giorno
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 52/100
- Tipo di issue
- Funzionalità
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Attiva
- Stack tecnologico
- docker, github-actions
- Ambito
- build-system, ci-cd
Direzione di ricerca
Start with .github/workflows/build.yml, especially the output construction at the referenced v1.17.0 line 803, and inspect the corresponding bake.yml workflow and metadata-action inputs. Trace how workflow inputs reach the build step, image/local outputs, and metadata labels or annotations. Done means both workflows support the proposed epoch behavior, including commit, and builds use consistent timestamps for layers and created metadata.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Description
Problem
Docker's reproducible builds guide for GitHub Actions recommends setting SOURCE_DATE_EPOCH, for example to the commit time (git log -1 --pretty=%ct), on the build step. With the build reusable workflow, there's currently no way to get a reproducible image:
- No input sets
SOURCE_DATE_EPOCHfor the build step. Passing it throughbuild-argsworks for the image config and history timestamps, because BuildKit reads it as a build arg too. But the caller has to compute the commit time in a separate job, since the reusable workflow builds from the Git context without a checkout. - File timestamps inside the layers aren't rewritten. That needs
rewrite-timestamp=trueon the image exporter (BuildKit docs). The workflow builds the output string itself (build.yml#L803 at v1.17.0), so callers can't add it. - With
set-meta-labels/set-meta-annotations,org.opencontainers.image.createdgets the build time, because metadata-action uses the current date, even whenSOURCE_DATE_EPOCHis set.
So two builds of the same commit always end up with different layer and image digests.
Proposal
A source-date-epoch input for build.yml (and bake.yml) that:
- sets
SOURCE_DATE_EPOCHfor the build step; - adds
rewrite-timestamp=trueto theimage(andlocal) output; - uses the same time for the
org.opencontainers.image.createdlabel and annotation whenset-meta-labels/set-meta-annotationsare on.
It would help most if the input could also take the commit time directly, for example source-date-epoch: commit, since the workflow already knows which commit it builds and callers wouldn't need an extra job for it.
Alternatives considered
build-args: SOURCE_DATE_EPOCH=…plus overridingmeta-labels/meta-annotations: fixes the metadata timestamps, but not the layer contents, so the digests still differ.- Using
docker/build-push-actiondirectly: works, but gives up what the reusable workflow provides (distributed native builds, signed cache, signed provenance).
- Lingua principale
- Nessun dato sulla lingua
- Stelle
- 86
- Fork
- 23
- Merge medio
- 5g 47m
- PR unite (30g)
- 17
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Nessun modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di docker/github-builder
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 52/100
docker/github-builder#251 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 68/100
docker/github-builder#209 ·
I maintainer di solito rispondono entro 1 giorno
-
kind/enhancement
Difficoltà 3/5 1-2 giorni Idoneità per principianti 65/100
docker/github-builder#207 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
kind/enhancement status/triage
Difficoltà 5/5 Più di una settimana Idoneità per principianti 25/100
docker/github-builder#203 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
status/triage
Difficoltà 4/5 3-5 giorni Idoneità per principianti 45/100
docker/github-builder#193 · 2 commenti ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di docker/github-builder
Issue simili
-
0.kind: enhancement 9.needs: package (update)
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
I maintainer di solito rispondono entro 1 giorno
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 62/100
hpi-swa-teaching/AutoTDD#135 ·
-
bug pixi-build-r
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
prefix-dev/pixi#7229 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
mesonbuild/wrapdb#2961 ·
I maintainer di solito rispondono entro 1 giorno
-
package-update
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
oSoWoSo/vOid_Community_repOsitory#330 ·
I maintainer di solito rispondono entro 1 giorno