3 ms·
> As long as I can rebuild and get a system that works the same way as before, I'm happy. Bit-for-bit identical packages is the only way to guarantee it works
by matrss 2y ago
> As long as I can rebuild and get a system that works the same way as before, I'm happy.
Bit-for-bit identical packages is the only way to guarantee it works the same way (in the absence of differences in hardware behaviour, otherwise reproducibility can't help you either).
Yes, building in a functionally identical environment will probably be good enough even if the result isn't bit-for-bit identical, but then you still have to be able to rebuild said environment, and nix gives you the tools to at least get such a repeatable environment. Outside of nix and guix I am not aware of any tool that can do the same from source. So:
> And I don't even need Nix to do that; there are much simpler ways to do so.
Genuinely curious, what simpler ways are you referring to?
- lostmsu 2y agoNot the parent, but you can have a base image + set of offline only setup scripts.
- matrss 2y agoThat doesn't satisfy the requirement "from source". Sure, you can build on a large binary blob that already contains everything you need, but then you are just moving the issue into the build process of that blob. Also, 99% of container image build scripts (Dockerfiles, etc.) probably don't pin an exact base image and don't avoid pulling in external resources (e.g. packages from the base image distro's repositories). I wouldn't call a system that makes it very easy to break reproducible build environments easier than just using nix to achieve that reproducibility.