4 ms·
Yes, very much so. In fact, our goal is to have NixOS based containers. Right now, we're using Debian as the base image, and there's /no/ guarantee that the ver
by seppalala 12y ago
Yes, very much so. In fact, our goal is to have NixOS based containers. Right now, we're using Debian as the base image, and there's /no/ guarantee that the versions of software installed are consistent (since Docker caches based on the line in a Dockerfile, rather than what's actually installed).
With Nix, we can have version guarantees in all of our Docker images--including the cached images.
- indygreg2 12y agoI blogged about this the other day and would love to hear about your experience! http://gregoryszorc.com/blog/2014/10/13/deterministic-and-minimal-docker-images/ http://gregoryszorc.com/blog/2014/10/13/deterministic-and-mi...
- seppalala 12y agoThis is spot-on what I'd like to do, and I have the exact same concerns. Thanks for sharing!
- cpuguy83 12y agoWell sure there can be a guarantee. `RUN apt-get install some_package=<version>` If you want a newer version, update the Dockerfile with the version you want.
- joevandyk 12y agoThat package could install some other dependencies, and those dependencies aren't pinned down.
- mentat 12y agoThat depends on how the package is specified doesn't it? You can snapshot the full chain of versions with dpkg and explicitly specify them all. It should be too hard to wrap this into something like Gemfile.lock
- deleted 12y ago[deleted]
- nextos 12y agoGreat. I have a major complaint about Nix. Their packages are built with all sorts of dependencies included. So you install mutt and you end up getting python. Or you install git and you also get subversion. I understand all their philosophy, but they should allow for flexible runtime dependencies without the need for rebuilding packages. Perhaps with a second hash or something, to sign dependencies.