Share feedback
Answers are generated based on the documentation.

docker buildx replay

DescriptionReplay a build from its provenance
Usagedocker buildx replay

Experimental

This command is experimental.

Experimental features are intended for testing and feedback as their functionality or design may change between releases without warning or can be removed entirely in a future release.

Description

buildx replay reads the SLSA provenance attestation of an existing build and reproduces the build with the recorded frontend, options, and source digests. Replay runs on the selected builder and requires BuildKit v0.27 or later.

Subjects are accepted in three forms:

  • docker-image://<ref> or a bare <ref> — resolve through the registry.
  • oci-layout://<path>[:<tag>] — read from a local OCI layout.
  • A local attestation file: an in-toto statement (.intoto.jsonl), an unsigned DSSE envelope, a Sigstore bundle, or a bare SLSA provenance predicate.

A build can be replayed when:

  • its provenance was recorded with mode=max (--provenance=mode=max or --attest=type=provenance,mode=max). mode=min provenance omits the build arguments, secrets, and SSH needed for replay;
  • its build context was a Git repository or an HTTP(S) URL. Builds that used local directories, stdin, OCI layouts, or other Bake targets as build contexts cannot be replayed;
  • it did not use --network=host, unless a different --network is passed to replay;
  • the recorded sources are still available.

Replay rebuilds one platform at a time. For a multi-platform image, select the platform with --platform. By default, the only platform of the image or the default platform of the builder is used.

Subcommands

CommandDescription
docker buildx replay buildRebuild an image from provenance and pinned materials