Chainguard has successfully doubled its production of container build manifests within the past six months, reaching over 1 billion. This achievement also includes surpassing 3,000 unique container images and 675,000 image versions. These figures, however, represent more than just numbers; they reflect a fundamental overhaul of Chainguard’s system that enabled such growth.
Understanding Build Manifests
A build manifest is essentially the result of the Chainguard Factory producing a new, verifiable artifact. This could include a fresh image for a new software version, a rebuild prompted by a security patch, or a newly generated SBOM after a dependency update. At the scale Chainguard operates, a single project might support numerous versions and architectures, necessitating frequent rebuilds as changes occur upstream or as security enhancements are made.
Unlike traditional approaches, Chainguard’s method ensures the catalog remains secure not only at the time of image retrieval but continuously, reflecting the company’s commitment to ongoing vulnerability management and security enhancement.
The Innovative Approach to Building
Central to Chainguard’s success is its specialized operating system, Chainguard OS, which is tailored for cloud-native workloads. This system allows for continuous integration, rapid updates, and real-time artifact delivery, diverging from the slower release cycles of traditional Linux distributions. The Chainguard Factory, the infrastructure behind this process, ensures each artifact is secure and verified, featuring SLSA Level 3 provenance and full SBOMs.
The Factory’s architecture supports high-volume rebuilding through declarative and reproducible builds, enabling rapid regeneration of images without data drift. But speed alone wasn’t enough; the system needed to know precisely when to initiate these rebuilds, acting swiftly on those signals without constant human intervention.
Introducing Factory 2.0
To overcome the limitations of its initial event-driven system, Chainguard developed Factory 2.0, powered by DriftlessAF. This self-correcting system integrates AI-driven reconciliation with deterministic automation, allowing for continuous comparison of desired and actual states, and adjusting accordingly.
DriftlessAF employs AI to tackle complex tasks, like evaluating new components in minor releases or backporting security fixes, enabling the system to learn from previous successes and become more autonomous over time. This advancement reduces the operational burden on engineers, allowing them to focus on improving the factory infrastructure and the quality of outputs.
The Importance of Speed in Security
In today’s rapidly evolving threat landscape, the speed of rebuilding is crucial. Attackers are utilizing AI to discover vulnerabilities and create exploits faster than ever before. By halving the time needed for upstream changes to transform into secure, verified images, Chainguard enhances its defenses, keeping pace with potential threats.
The automated and agentic nature of Chainguard Factory enables engineers to act as experts, arbitrating changes and continuously improving the system. With DriftlessAF as an open-source framework, other organizations can leverage Chainguard’s innovations for their own automation challenges, fostering a collaborative environment for tackling large-scale problems.
Chainguard remains committed to advancing its infrastructure, expanding DriftlessAF, and ensuring its catalog’s security and efficiency. For more insights into Chainguard’s offerings, explore their container image catalog or delve into DriftlessAF’s documentation.
