Clang Toolchain for BazelA fully hermetic Clang/LLVM toolchain for Bazel that produces completely
self-contained, statically linked binaries with zero host system dependencies.
musl libc: c/c++ standard libraries fetched from Alpine repolibstdc++ 14.2.0: Alpine's C++ standard library built for musl-nostdinc and -nostdinc++ flags to prevent host header inclusionsysroot (musl and Alpine libstdc++)-nostdlib flag to prevent host library linking-static flag to force static linkingmusl libc, libstdc++, libunwind) come from the toolchain's sysrootx86-64 system without requiring any host librariesSupported versions with prebuilt binaries:
The clang compiler binary does require host libraries to run, but this only
affects the build environment, not the produced binaries. The toolchain
provides libtinfo5 to minimize host dependencies for the compiler.
The toolchain achieves hermeticity through several mechanisms:
lib/: Contains libraries needed by Clang itself to run (Ubuntu/LLVM libraries)sysroot/: Contains musl, libstdc++ libraries used for compiling-nostdinc and -nostdinc++: Prevents using host system headers-nostdlib: Prevents linking against host system libraries-static: Forces static linking of all dependenciesmusl from Alpine Linux (for static linking)libstdc++ from Alpine Linux (built against musl)libunwind from LLVM (for exception handling)LLD from LLVMAdd this to your MODULE.bazel:
bazel_dep(name = "hermetic_clang_toolchain", version = "1.0.0")
hermetic_clang = use_extension("@hermetic_clang_toolchain//clang_toolchain:hermetic_clang.bzl", "hermetic_clang_extension")
hermetic_clang.use(version = "21.1.0")
use_repo(hermetic_clang, "hermetic_clang")
register_toolchains("@hermetic_clang_toolchain//clang_toolchain:hermetic_clang_toolchain")
Add this to your .bazelrc:
# Disable default C++ toolchain detection
build --incompatible_enable_cc_toolchain_resolution
build --action_env=BAZEL_DO_NOT_DETECT_CPP_TOOLCHAIN=1
# Use hermetic clang toolchain
build --extra_toolchains=@hermetic_clang//:toolchain
See the example/ directory for a working example:
bazel build //example:simple_test
# Run the test
./bazel-bin/example/simple_test
# Verify it's hermetic (should show "not a dynamic executable")
ldd bazel-bin/example/simple_test
# Check the binary info
file bazel-bin/example/simple_test
# Output: ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked
readelf -p .comment bazel-bin/example/simple_test
# String dump of section '.comment':
# [ 0] clang version 18.1.8
# [ 16] Linker: LLD 18.1.8
# [ 29] GCC: (Alpine 14.2.0) 14.2.0
LLVM/Clang 18.1.8: Pre-built compiler toolchain from LLVM projectclang, clang++, lld, llvm-ar, and other LLVM toolsmusl-dev: C standard librarylibstdc++: C++ standard librarylibstdc++-dev: C++ headersClang runtime only):libtinfo5: Terminal info library needed by ClangClang with hermetic headers from sysrootmusl, libstdc++, libunwind)1.0.1 +4d2025-09-08 | |
1.0.02025-09-03 |