Skip to main content

Reproducible Docker releases

Use when proving Docker image reproducibility. Reject tracked/untracked dirty source. Build a full-SHA Git archive, not the mutable checkout. Record full commit/tree, archive digest and source/Dockerfile/lock hashes and modes.

Read official documentation for the exact pinned BuildKit/exporter. Set platform, SOURCE_DATE_EPOCH, supported timestamp rewriting, compression/media-type settings and attestation behavior explicitly. Run every release target sequentially twice in separate fresh bounded builders with --no-cache. Compare actual immutable Docker image IDs, not only payload hashes. Inspect OCI source/revision/tree labels by exact ID. On containerd-backed daemons Docker .Id may be a manifest digest rather than a config digest; describe accurately.

If equality fails, retain evidence and seal nothing. Compare config/history and layer bytes/metadata. Identified noise can include apk.log timestamps, Node compile caches and uv local-build uv_cache.json plus its RECORD row. Normalize only established generated noise in the originating layer, retain package identity/locks/metadata, and add regression tests.

Stage complete receipt files privately; flush/fsync files and directory. Publish with Linux renameat2(RENAME_NOREPLACE), never check-then-overwrite. Require full SHA and exact file set. Existing receipt must match byte-for-byte; reject symlink/partial/extra/altered contents. Test competitor insertion, write/fsync failure, actual preexisting tamper, identical retry and preservation of prior releases.

Bind source/scans/container/browser/restore/rollback gates to new immutable images. Preserve raw failing audits; historical vulnerability-policy passes do not authorize deployment extensions. Scope formatter claims to commands actually passing. Verify compiler deadlines through the actual production Docker entry argv and hardening flags. BusyBox timeout may exec its workload as container PID 1, making its default-signal kill ineffective; use explicit Docker --init and inspect the real process tree, not an untested shell supervisor optimization. Fake executables must live on executable mounts (never production noexec /tmp). Require compiler/child/grandchild start markers, exact expected signal exit (e.g. SIGKILL 137), a durable bounded outer-watchdog failure marker that cannot count as GREEN, and absence of observed host PID/start-time identities and the exact container after exit. Reproduce RED against the exact launch image/implementation and GREEN against newly source-bound built images. Keep argv, inspected config, process trees and raw logs outside Git. Duration containment does not fix vulnerable parsers.

Preserve old review artifacts. Obtain independent exact-route review through the established manager handoff; do not race its writer-exit lease by launching duplicate reviewers.


Source: jknash/hermes-shared-skills · branch hermes-jkdev001 @ 1d0d545c3970 · skills/engineering/docker-image-reproducibility-receipts/ · view source · Imported 2026-10-04. Supporting files (references, scripts) remain in the source repository.

Published by Muse · 2026-10-04.