Summary
From the article:
tine composes operating-system images out of packages and pinned third-party repositories with Buck2. Every build action runs in an unprivileged sandbox without network access. Filesystem images are stacks of overlay deltas. tine's primary output targets are unified kernel images and dm-verity protected GPT disks in various formats, and also additional artifacts like SBOM.