-
-
Notifications
You must be signed in to change notification settings - Fork 13.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
dockerTools: Allow separately specifying metadata and filesystem timestamps #327579
Merged
tomberek
merged 2 commits into
NixOS:master
from
the-sun-will-rise-tomorrow:separate-created-mtime
Sep 25, 2024
Merged
dockerTools: Allow separately specifying metadata and filesystem timestamps #327579
tomberek
merged 2 commits into
NixOS:master
from
the-sun-will-rise-tomorrow:separate-created-mtime
Sep 25, 2024
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
the-sun-will-rise-tomorrow
force-pushed
the
separate-created-mtime
branch
from
July 16, 2024 07:27
cd4a942
to
0291147
Compare
the-sun-will-rise-tomorrow
force-pushed
the
separate-created-mtime
branch
from
July 16, 2024 10:26
0291147
to
b75c43d
Compare
Some considerations:
|
This was referenced Jul 22, 2024
Reconciling buildImage and buildLayeredImage seems like a good idea. I'll take a look at this and review. |
tomberek
force-pushed
the
separate-created-mtime
branch
from
September 25, 2024 00:23
6c852fa
to
2681c5b
Compare
…stamps Setting the image creation timestamp in the image metadata to a constant date can cause problems with self-hosted container registries, that need to e.g. prune old images. This timestamp is also useful for debugging. However, it is almost never useful to set the filesystem timestamp to a constant value. Doing so not only causes the image to possibly no longer be reproducible, but also removes any possibility of deduplicating layers with other images, causing unnecessary storage space usage. Therefore, this commit introduces "mtime", a new parameter to streamLayeredImage, which allows specifying the filesystem timestamps separately from "created". For backwards compatibility, "mtime" defaults to the value of "created".
tomberek
force-pushed
the
separate-created-mtime
branch
from
September 25, 2024 04:23
2681c5b
to
847b473
Compare
Added a change to the default such that mtime will be epoch more often, unless someone overrides it. |
tomberek
force-pushed
the
separate-created-mtime
branch
from
September 25, 2024 04:31
c2c1f3c
to
d0b3364
Compare
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description of changes
Setting the image creation timestamp in the image metadata to a constant date can cause problems with self-hosted container registries, that need to e.g. prune old images. This timestamp is also useful for debugging.
However, it is almost never useful to set the filesystem timestamp to a non-constant value. Doing so not only causes the image to possibly no longer be reproducible, but also removes any possibility of deduplicating layers with other images, causing unnecessary storage space usage.
Therefore, this commit introduces
mtime
, a new parameter tostreamLayeredImage
, which allows specifying the filesystem timestamps separately fromcreated
. For backwards compatibility,mtime
defaults to the value ofcreated
.Things done
nix.conf
? (See Nix manual)sandbox = relaxed
sandbox = true
nix-shell -p nixpkgs-review --run "nixpkgs-review rev HEAD"
. Note: all changes have to be committed, also see nixpkgs-review usage./result/bin/
)Add a 👍 reaction to pull requests you find important.