profile-img
Frederic 🧊 Branczyk @[email protected]

@fredbrancz

Founder @PolarSignalsIO 🧊 ❄️ Building @ParcaDev, Prometheus maintainer. BLM (he/him) Mastodon https://t.co/hWq2D5SOOV

calendar_today26-01-2012 21:42:24

6,6K Tweets

4,3K Followers

287 Following

Frederic 🧊 Branczyk @brancz@hachyderm.io(@fredbrancz) 's Twitter Profile Photo

We have byte-by-byte reproducible builds of everything at Polar Signals, including container images. We migrated from podman to buildkit, and it looks like producing provenance information includes build times, ultimately breaking reproducibility. Is there any way to fix this?

account_circle
Frederic 🧊 Branczyk @brancz@hachyderm.io(@fredbrancz) 's Twitter Profile Photo

Frederic 🧊 Branczyk @[email protected] This is a benefit of attaching signed provenance outside the image. We use sigstore and it works great.

Getting reproducible image builds was one of the (many!) reasons we built our own tools for it, more about it here chainguard.dev/unchained/desi…

account_circle