6 ms·
This is based on bootc (bootable containers), so note that the OS build is described in a normal Dockerfile: https://github.com/pocketblue/pocketblue/blob/main/
by nikodunk 7mo ago
This is based on bootc (bootable containers), so note that the OS build is described in a normal Dockerfile: https://github.com/pocketblue/pocketblue/blob/main/Containerfile https://github.com/pocketblue/pocketblue/blob/main/Container... which is then run by the Github action (or locally).
Very similar to how Universal Blue, Bazzite, Bluefin etc. build at https://github.com/ublue-os/bazzite https://github.com/ublue-os/bazzite (see their Containerfile), but for mobile.
Has a similar mission to https://postmarketos.org https://postmarketos.org, but with a different build system AFAICT
- arianvanp 7mo agoAre we really bringing OCI to freaking OS builds? Nothing about OCI is pleasant. A list of Tarballs is the most backwards boot format I can think of. Terrible for reproducibility. Terrible for security. Boot images should be Dm-verity protected EROFS images. We should not be building new things on OCI. It's really mind-blowing to me that this is a new direction people who are supposed to be top of class OS builders are moving to as a direction. They took the CoreOS dream and threw everything in the trash
- exceptione 7mo ago> Dm-verity protected EROFS images First time I hear about it. Playing the devils advocate: how does it improve over checksums + tarballs?
- curt15 7mo agochecksums + tarballs don't help with runtime integrity verification. You'll need additional technologies for that like dm-verity or fs-verity; see composefs.
- looperhacks 7mo agoHow is OCI terrible for reproducibility and security? They are certainly more reproducible than what we had before. I haven't heard "Works on my machine for a long time". If you're talking about reproducible builds, there aren't any hard issues either that are directly caused by OCI images - except setting the clock correctly. > Boot images should be Dm-verity protected EROFS images Maybe I'm misunderstanding you - I gather that you think the boot images are distributed as OCI images? That's not the case, bootc is more about building the image, updating it and the overall structure. Booting an image built with bootc does not involve any container infrastructure (unless you start services that depend on containers, I guess - but that's deep in userspace). There's technically nothing preventing this from using verified read-only images.
- saltamimi 7mo agoFor the record, bootc supports and has workflows for verity images.
- arianvanp 7mo ago> I gather that you think the boot images are distributed as OCI image Yes? That's literally the sales pitch on the website. Am I missing something? Quote from https://bootc-dev.github.io/ https://bootc-dev.github.io/ tells me that bootc is using OCI as a delivery format for bootable images. Transactional, in-place operating system updates using OCI/Docker container images. Motivation The original Docker container model of using "layers" to model applications has been extremely successful. This project aims to apply the same technique for bootable host systems - using standard OCI/Docker containers as a transport and delivery format for base operating system updates
- exceptione 7mo ago> Dockerfile nitpick: Containerfile. I mention it because people still think container==docker. I am sure the Fedora people focus on podman, as part of the Red Hat ecosystem. For a better dev experience they offer podman-bootc¹, which you will miss when using Docker. Personally I am convinced that we should steer people to podman instead of Docker. 1. https://docs.fedoraproject.org/en-US/bootc/getting-started/ https://docs.fedoraproject.org/en-US/bootc/getting-started/
- curt15 7mo agoRed Hat obviously wants to change people's vocabulary but "Dockerfile" is basically an industry-standard generic term by this point.
- exceptione 7mo agoThat is true, the same for "to google" if people mean "to search". It does bury the generality of the concept though. Like I said, a nitpick.
- Conan_Kudo 7mo agoI think it's also worth noting that the Dockerfile format is still driven by Docker, and there have been zero extensions to the format by Podman folks, so Containerfile==Dockerfile.
- traverseda 7mo agoIf you're thinking about actually using it, please not it only supports redhat distros. https://github.com/bootc-dev/bootc/issues/865 https://github.com/bootc-dev/bootc/issues/865