5 ms·
Docker is a nice runtime, but you cannot reproduce the build of a docker container. What if you want to make a small change to the image? You need to rebuild it
by bennofs 9y ago
Docker is a nice runtime, but you cannot reproduce the build of a docker container. What if you want to make a small change to the image? You need to rebuild it, but if it's years later, the versions of packages in the ubuntu repository may have changed and a lot of other things (if you're not careful, tarballs downloaded during the building of the image may have disappeared/changed/...). While you can try to avoid these through careful scripting and pinning things, this is what Nix makes really easy: just pin your nixpkgs version, and you can almost guarrante that you'll get the exact same build years later and you can still change parts of it if you need to.
- jrs95 9y agoCould reproducible Docker builds be achieved through adding Nix, then? Maybe that really ought to be the best practice for people doing this on a large scale.
- willtim 9y agoAbsolutely! From my point-of-view, Nix is complementary to Docker. Nix is a deterministic replacement for the apt-get commands used in the parent post.
- Filligree 9y agoIt already has all the needed infrastructure, in fact. See for example http://lethalman.blogspot.ie/2016/04/cheap-docker-images-with-nix_15.html http://lethalman.blogspot.ie/2016/04/cheap-docker-images-wit...
- notmymain 9y ago> Docker is a nice runtime, but you cannot reproduce the build of a docker container This is a common misconception but there's plenty of info out there if you want to find out how to do it. https://duckduckgo.com/?q=reproducible+builds+in+docker&atb=v88-6_g&ia=web https://duckduckgo.com/?q=reproducible+builds+in+docker&atb=... In essence, you can make reproducible builds in docker by controlling the build environment and then specifying particlar versions when installing dependencies. It's a bit more work but it's eminently doable. You control the build environment by building your reproducible docker containers within an environment (eg a reproducible docker container) that is itself reproducible (ie with specified versions of everything). This seems like a bootstrapping problem, but actually it works. So: 1. Make a "Build container" with a specified base image version and specified versions of the transitive deps of everything it needs to build your thing 2. Use this container to build your actual container, specifiying a version of the base image and all dependencies. Pretty sure you don't need more than these two layers of the onion to make bitwise-identical builds as long as your package build recipe is itself reproducible (eg the toolchain supports it and you don't do anything like embedding timestamps etc in the binaries). Package managers provide mechanisms to get the version list in force so generally the way to do this is to start with your preferred base image, install all the packages you want/need, use the package manager to give you the version list, then change the Dockerfile to install specifically those versions.
- willtim 9y ago> In essence, you can make reproducible builds in docker by controlling the build environment and then specifying particular versions when installing dependencies. Nix would be an excellent way to achieve this.
- Filligree 9y agoNixpkgs has a function for creating Docker images as derivations, in fact.
- Filligree 9y ago> Just pin your nixpkgs version, and you can almost guarrante that you'll get the exact same build years later and you can still change parts of it if you need to. In theory. In practice, anything that doesn't hit the NixOS cache server will likely have been removed; it doesn't cache the build inputs, and links break all the time. On smaller timescales it's brilliant, though.