Learning path

Full curriculum

Full curriculum

Unit content

Reproducible builds and immutable artifacts

A build is reproducible when the same declared source and build inputs produce the same artifact rather than depending on accidental machine state.

Reproducibility requires controlling inputs such as dependency versions, toolchains, generated files and relevant environment settings. Timestamps, nondeterministic file ordering or undeclared local tools can otherwise change the output.

Once an artifact has passed verification, deployment should identify that exact artifact rather than rebuilding “the same source” later under potentially different conditions.

An immutable artifact is published once under an identity such as a version or content digest and is not silently replaced with different bytes. Promotion can then move the same artifact from test to staging to production.

This separates two questions: whether source can be built, and whether the exact thing being deployed is the thing that was tested.

Reproducible builds make artifacts explainable; immutable promotion keeps verification attached to the artifact that actually reaches users.