What was necessary for making Arch images reproducible:
The goal is to make a rootfs that’s reproducible
Lots of timestamp cleanup
Handling logs: the output of some build tools can be piped to /dev/null
An archive is needed for bootstrapping: use yesterday’s archive to bootstrap today’s image
Pacman has some non-determinism (key material embedded in the binary), which is stripped from the image. This breaks pacman out of the box; you need to run a command to fix pacman. Pacman also supports redirecting logs (to /dev/null) and using SOURCE_DATE_EPOCH for installed package metadata.
Comment: does apt support this?
For WSL, the rootfs is enough; very little translation is needed after that
For containers, the builder takes the rootfs but needs additional flags to make the container image itself reproducible. One of the major ones is the epoch time; Arch uses the release timestamp
One difficult quirk is that the name of the container is embedded in the file as an annotation. This makes comparing two containers (e.g. with diff) on the same system (in the same registry) impossible, because they need to be named differently.
diffoci helps with this comparison and allows ignoring those differences
Versioning and release process
The version of the image is the current date; the archive date is set to -1 day for consistency of the archive. Rebuilds happen weekly.
Reproducibility is also tested for the userland - if the default packages are reproducible but does not block the release.
Using CI is recommended, along with a pull-through mirror for Docker Hub (or AWS/GCP mirrors as a fallback due to Hub rate limiting).
From the end user’s perspective, archive/snapshot repos can be slow as they don’t have mirrors, and they are a potential SPOF.