3 ms·
I'd give this article a read, as it can explain it more clearly than I can: https://serokell.io/blog/what-is-nix https://serokell.io/blog/what-is-nix But to br
by operator-name 3y ago
I'd give this article a read, as it can explain it more clearly than I can: https://serokell.io/blog/what-is-nix https://serokell.io/blog/what-is-nix
But to briefly answer your specific questions: Docker files are commonly not reproducible because they contain arbitary stateful commands like `apt-get update`, `curl`, etc. For a layer with these kinds of commands to be reproducible you would need a mechanism to version and verify the result.
Nix provides such a mechanism, and a community package repository with versioned dependancies between packages. These are defined in a domain specific language called Nix (text files) and kept into a git repository. This should be familiar if you've used a package manager with lock files before.
You can guarentee the package version will stay in the repository by pinning your build to an exact commit hash in the repository.