# Secure systems: an alternate use case for PackageCompiler.jl

**URL:** <https://discourse.julialang.org/t/secure-systems-an-alternate-use-case-for-packagecompiler-jl/90955>\
**Category:** General Usage\
**Created:** [November 28, 2022, 3:28pm UTC](https://discourse.julialang.org/t/secure-systems-an-alternate-use-case-for-packagecompiler-jl/90955 "2022-11-28T15:28:12Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ashlin\_Harris](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/ashlin_harris/32/210166_2.png) [@Ashlin\_Harris](https://discourse.julialang.org/u/Ashlin_Harris)\
**Post date:** [November 28, 2022, 3:28pm UTC](https://discourse.julialang.org/t/secure-systems-an-alternate-use-case-for-packagecompiler-jl/90955/1 "2022-11-28T15:28:12Z")

</div>

Julia’s package manager relies on internet access, so it can be challenging to make dependencies available on secure systems. [PackageCompiler.jl](https://github.com/JuliaLang/PackageCompiler.jl) compiles Julia code ahead of time, primarily for [improved performance in certain workflows](https://julialang.github.io/PackageCompiler.jl/dev/index.html#PackageCompiler). In particular, [generating a sysimage](https://julialang.github.io/PackageCompiler.jl/dev/sysimages.html) produces a performant stand-alone Julia session, and since its [main drawback (version locking)](https://julialang.github.io/PackageCompiler.jl/dev/sysimages.html#Drawbacks-to-custom-sysimages) is mitigated on secure systems, it seems to be the best approach for putting a Julia session on a system without internet access or direct `ssh` access.

@dilumaluthge and I have put together a workflow for uploading Julia sessions to our institution’s secure system, and we wanted to make a public version available. [SIEGE](https://github.com/bcbi/SIEGE) takes a Julia project as input and automatically generates a sysimage (using PackageCompiler) for use in secure systems. It also includes a Bash script that starts an offline Julia session with the new sysimage. The script sets environment variables and accepts command-line arguments, so it can be aliased to `julia` by users. The main requirement is an internet-connected build server that has the same architecture as the secure system.

I don’t believe SIEGE is the very first tool for automatically generating sysimages, but I couldn’t find much documentation on using sysimages for secure systems, so sharing our approach should hopefully save other researchers some time and effort.

---

<div class="post-metadata">

**Author:** ![Ashlin\_Harris](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/ashlin_harris/32/210166_2.png) [@Ashlin\_Harris](https://discourse.julialang.org/u/Ashlin_Harris)\
**Post date:** [November 28, 2022, 3:37pm UTC](https://discourse.julialang.org/t/secure-systems-an-alternate-use-case-for-packagecompiler-jl/90955/2 "2022-11-28T15:37:39Z")

</div>

[The repo](https://github.com/bcbi/SIEGE) gives more details. Broadly speaking, we used the following approach:

1. [Build a sysimage with PackageCompiler](https://julialang.github.io/PackageCompiler.jl/dev/sysimages.html)
2. Upload the build and Julia binaries to the secure system
3. Alias a script to `julia`, similar to the following example:

```julia
#!/bin/bash
set -Eeu -o pipefail

unset JULIA_LOAD_PATH

export JULIA_PROJECT=/Path/To/Project
export JULIA_DEPOT_PATH=/Path/To/Depot
export JULIA_PKG_OFFLINE=true

/Path/To/julia -J/Path/To/sysimage.so "$@"

```

---

<div class="post-metadata">

**Author:** ![27rabbitlt](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/27rabbitlt/32/45384_2.png) [@27rabbitlt](https://discourse.julialang.org/u/27rabbitlt)\
**Post date:** [December 30, 2022, 3:57pm UTC](https://discourse.julialang.org/t/secure-systems-an-alternate-use-case-for-packagecompiler-jl/90955/3 "2022-12-30T15:57:27Z")

</div>

Hello, I’m so excited to see a solution for Julia in secure system. I’ve given it a try but something went wrong here, so I guess I must have missed something.

Here is my procedure:

1. git clone SIEGE, and follow the instructions in github README.
2. before running main(“path\_to\_SIEGE”), I typed “using LoopVectorization”, and did some unrelevant calculation with @turbo.
3. Then I ran main(“path\_to\_SIEGE”). After that, I can see a “sysimage.so” in SIEGE/build folder.
4. Then I upload the whole SIEGE folder to the secure system, and edited run\_sysimage.sh to fit my environment (actually what I did is just completing the path).
5. Then I ran “run\_sysimage.sh”, and julia was successfully executed.

Now here is my problem: I thought that now that I wrapped all the running environment into a .so, and I started another julia from that .so, I should natrually have the package “LoopVectorization”. But the fact is that I can’t “using LoopVectorization”, nor use @turbo.

So in a nutshell, what should I do to transfer all my required packages to that secure system? Do I have to edit Manifest.toml or something?

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![Ashlin\_Harris](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/ashlin_harris/32/210166_2.png) [@Ashlin\_Harris](https://discourse.julialang.org/u/Ashlin_Harris)\
**Post date:** [December 30, 2022, 6:05pm UTC](https://discourse.julialang.org/t/secure-systems-an-alternate-use-case-for-packagecompiler-jl/90955/4 "2022-12-30T18:05:41Z")

</div>

SIEGE builds the sysimage and artifacts based on `env/Project.toml`, so you would need to add the package to that environment.

---

<div class="post-metadata">

**Author:** ![27rabbitlt](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/27rabbitlt/32/45384_2.png) [@27rabbitlt](https://discourse.julialang.org/u/27rabbitlt)\
**Post date:** [December 31, 2022, 2:11am UTC](https://discourse.julialang.org/t/secure-systems-an-alternate-use-case-for-packagecompiler-jl/90955/5 "2022-12-31T02:11:40Z")

</div>

So much thanks! It did work.
