3 ms·
Nix (and by extension Guix) has had remote builds and signed build provenance for nearly 2 decades. It has also had a story to deal with both content-addrrssed
by tomberek 3y ago
Nix (and by extension Guix) has had remote builds and signed build provenance for nearly 2 decades. It has also had a story to deal with both content-addrrssed and input-addressed (this is our term for the "stable identifier" for a workflow mentioned above).
I can understand not using Nix, but please take a look at how we've solved some of these problems, and our mistakes. There is no need to reinvent the wheel blindly. Feel free to reach out if interested.
- woodruffw 3y ago> Nix (and by extension Guix) has had remote builds and signed build provenance for nearly 2 decades. Where is this documented? When I search for "Nix code signing" I mostly get issue reports for people experiencing breakage due to macOS's (separate) code signing requirements. Edit: To be clear, I like Nix, and I find many of its properties appealing. At the same time, it's not clear to me that Homebrew has too much to glean here: Homebrew isn't trying to be a totalizing package/system state management solution, and has historically leaned heavily on automation and external services (GHA, GHCR, etc.). These are design decisions with tradeoffs; they've also informed the proposed build provenance design substantially.
- tomberek 3y agoThere is a naming problem here where "Nix" is often easily confused with the state management pieces (home-manager, NixOS, etc). The underlying Store abstraction provides the concepts of various kinds of addressing. This is independent of the Nix language and we are currently trying to expose each of these layers more directly so it can be re-used in other contexts. The piece that might be of interest to you is the interaction between content-addressed and input-addressed content in light of build systems+software+compilers that are not bit-reproducible. There is also the bookkeeping to ensure auditability by third-parties; anyone else can run the same builds and expect the same outcome, or close enough that the differences become easy to find and report upstream (https://r13y.com/ https://r13y.com/), but the system doesn't require bit-reproducibility from day1 because that would be impractical. Of course substituting from a cache is exact, made possible by the signatures. Remote builds: https://nixos.org/manual/nix/stable/advanced-topics/distributed-builds.html https://nixos.org/manual/nix/stable/advanced-topics/distribu... Signing (i'll amend my claim above to be only 1 decade). These are either signatures of a CA path, or for input-addressed things it can be seen as a claim by the signer that the producing build recipe (we call it "derivation") has this particular binary output. - https://nixos.org/manual/nix/stable/command-ref/nix-store/generate-binary-cache-key.html https://nixos.org/manual/nix/stable/command-ref/nix-store/ge... - https://nixos.org/manual/nix/stable/advanced-topics/post-build-hook.html?highlight=keys#set-up-a-signing-key https://nixos.org/manual/nix/stable/advanced-topics/post-bui... - https://nixos.org/manual/nix/stable/command-ref/conf-file.html?highlight=trusted-public-keys#conf-require-sigs https://nixos.org/manual/nix/stable/command-ref/conf-file.ht... - https://nixos.org/manual/nix/stable/command-ref/conf-file.html?highlight=trusted-public-keys#conf-trusted-public-keys https://nixos.org/manual/nix/stable/command-ref/conf-file.ht... - example: see the Signatures line for an example that this this specific provenance produced this specific binary output: https://trusted-friendly-sesame.glitch.me/view.html?cache_base=https%3A%2F%2Fcache.nixos.org&hash=7ghhnlwla2mddkg7hgqa5v0sr8g5hga8 https://trusted-friendly-sesame.glitch.me/view.html?cache_ba... or https://cache.nixos.org/7ghhnlwla2mddkg7hgqa5v0sr8g5hga8.narinfo https://cache.nixos.org/7ghhnlwla2mddkg7hgqa5v0sr8g5hga8.nar...