Skip to content PULSAR
Docs Install
DocsThemesReleases Install Source on GitHub
Docs Provenance

Every image has a paper trail

Each image is built on a single-night build machine, with its full package list attached. The signing keys never touch it.

One night’s build

a change lands in the public repo; that night’s build picks it upboth images, on a build machine created for the night and destroyed afterthe NVIDIA kernel module, with the key Secure Boot is told to trust, and each image, with Pulsar’s release keya full package list (SPDX SBOM), attached to the image and diffed against last night’syour machine switches to the new image, and rolls back on its own if it fails its boot checks

Don’t take the page’s word for it.

Check it yourself

Each image has an SPDX SBOM attached in the registry (oras discover lists it). Images and ISOs are signed with Pulsar’s cosign release key. Image signatures are also logged in Rekor, Sigstore’s public transparency log; ISO signatures are not logged yet.

Each nightly is diffed against the previous one from the SBOMs: the changelog, changelog.json, and pulsar changelog. None of it is hand-written.

the night’s diff, as the build wrote it the image’s baked manifest the release key that signs images and ISOs

Check an image’s signature and its log entry:

On a Pulsar machine, pulsar verify prints the same check for the exact image you booted, by digest, and runs it if cosign is installed.

Verify an ISO · NVIDIA module signing

One key for both images

  • The NVIDIA variant builds nvidia-open for the image’s exact kernel and signs it.
  • Containerfile needs no secrets. Containerfile.nvidia sends each module to the signing host with a bearer token and attaches the returned signature; neither key nor token reaches an image layer.
  • Both images ship the public cert, so it can be enrolled before switching to NVIDIA. The build fails if the module’s signer doesn’t match it.
  • Building your own? Fork and use your own key: enrolling this cert means trusting modules Pulsar signs. The standard image needs no keys.

Builds started by hand

Only the scheduled nightly is published. Hand-started builds are tagged -dev: they don’t move :latest, the SBOM baseline or the site, and the boot menu labels them.

MIT-licensed. Source.

Written with help from AI and reviewed by a person before publishing. Spotted a mistake? Let us know.

PULSAR

Your lighthouse in the sky.

Site

Machine

Arclight

Theme

Dark only Light only

Recolors the whole site, like pulsar theme set does your desktop.

Light and dark

One look picks light or dark for you

Saved in this browser Back to Pulsar