build_bake.go 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500
  1. /*
  2. Copyright 2020 Docker Compose CLI authors
  3. Licensed under the Apache License, Version 2.0 (the "License");
  4. you may not use this file except in compliance with the License.
  5. You may obtain a copy of the License at
  6. http://www.apache.org/licenses/LICENSE-2.0
  7. Unless required by applicable law or agreed to in writing, software
  8. distributed under the License is distributed on an "AS IS" BASIS,
  9. WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  10. See the License for the specific language governing permissions and
  11. limitations under the License.
  12. */
  13. package compose
  14. import (
  15. "bufio"
  16. "bytes"
  17. "context"
  18. "crypto/sha1"
  19. "encoding/json"
  20. "errors"
  21. "fmt"
  22. "io"
  23. "math/rand"
  24. "os"
  25. "os/exec"
  26. "path/filepath"
  27. "slices"
  28. "strconv"
  29. "strings"
  30. "github.com/compose-spec/compose-go/v2/types"
  31. "github.com/docker/cli/cli-plugins/manager"
  32. "github.com/docker/cli/cli/command"
  33. "github.com/docker/compose/v2/pkg/api"
  34. "github.com/docker/compose/v2/pkg/progress"
  35. "github.com/docker/docker/api/types/versions"
  36. "github.com/docker/docker/builder/remotecontext/urlutil"
  37. "github.com/moby/buildkit/client"
  38. "github.com/moby/buildkit/util/gitutil"
  39. "github.com/moby/buildkit/util/progress/progressui"
  40. "github.com/sirupsen/logrus"
  41. "github.com/spf13/cobra"
  42. "golang.org/x/sync/errgroup"
  43. )
  44. func buildWithBake(dockerCli command.Cli) (bool, error) {
  45. b, ok := os.LookupEnv("COMPOSE_BAKE")
  46. if !ok {
  47. b = "true"
  48. }
  49. bake, err := strconv.ParseBool(b)
  50. if err != nil {
  51. return false, err
  52. }
  53. if !bake {
  54. if ok {
  55. logrus.Warnf("COMPOSE_BAKE=false is deprecated, support for internal compose builder will be removed in next release")
  56. }
  57. return false, nil
  58. }
  59. enabled, err := dockerCli.BuildKitEnabled()
  60. if err != nil {
  61. return false, err
  62. }
  63. if !enabled {
  64. logrus.Warnf("Docker Compose is configured to build using Bake, but buildkit isn't enabled")
  65. return false, nil
  66. }
  67. _, err = manager.GetPlugin("buildx", dockerCli, &cobra.Command{})
  68. if err != nil {
  69. if manager.IsNotFound(err) {
  70. logrus.Warnf("Docker Compose is configured to build using Bake, but buildx isn't installed")
  71. return false, nil
  72. }
  73. return false, err
  74. }
  75. return true, err
  76. }
  77. // We _could_ use bake.* types from github.com/docker/buildx but long term plan is to remove buildx as a dependency
  78. type bakeConfig struct {
  79. Groups map[string]bakeGroup `json:"group"`
  80. Targets map[string]bakeTarget `json:"target"`
  81. }
  82. type bakeGroup struct {
  83. Targets []string `json:"targets"`
  84. }
  85. type bakeTarget struct {
  86. Context string `json:"context,omitempty"`
  87. Contexts map[string]string `json:"contexts,omitempty"`
  88. Dockerfile string `json:"dockerfile,omitempty"`
  89. DockerfileInline string `json:"dockerfile-inline,omitempty"`
  90. Args map[string]string `json:"args,omitempty"`
  91. Labels map[string]string `json:"labels,omitempty"`
  92. Tags []string `json:"tags,omitempty"`
  93. CacheFrom []string `json:"cache-from,omitempty"`
  94. CacheTo []string `json:"cache-to,omitempty"`
  95. Target string `json:"target,omitempty"`
  96. Secrets []string `json:"secret,omitempty"`
  97. SSH []string `json:"ssh,omitempty"`
  98. Platforms []string `json:"platforms,omitempty"`
  99. Pull bool `json:"pull,omitempty"`
  100. NoCache bool `json:"no-cache,omitempty"`
  101. NetworkMode string `json:"network,omitempty"`
  102. NoCacheFilter []string `json:"no-cache-filter,omitempty"`
  103. ShmSize types.UnitBytes `json:"shm-size,omitempty"`
  104. Ulimits []string `json:"ulimits,omitempty"`
  105. Call string `json:"call,omitempty"`
  106. Entitlements []string `json:"entitlements,omitempty"`
  107. ExtraHosts map[string]string `json:"extra-hosts,omitempty"`
  108. Outputs []string `json:"output,omitempty"`
  109. }
  110. type bakeMetadata map[string]buildStatus
  111. type buildStatus struct {
  112. Digest string `json:"containerimage.digest"`
  113. Image string `json:"image.name"`
  114. }
  115. func (s *composeService) doBuildBake(ctx context.Context, project *types.Project, serviceToBeBuild types.Services, options api.BuildOptions) (map[string]string, error) { //nolint:gocyclo
  116. eg := errgroup.Group{}
  117. ch := make(chan *client.SolveStatus)
  118. if options.Progress == progress.ModeAuto {
  119. options.Progress = os.Getenv("BUILDKIT_PROGRESS")
  120. }
  121. displayMode := progressui.DisplayMode(options.Progress)
  122. out := options.Out
  123. if out == nil {
  124. if !s.dockerCli.Out().IsTerminal() {
  125. displayMode = progressui.PlainMode
  126. }
  127. out = os.Stdout // should be s.dockerCli.Out(), but NewDisplay require access to the underlying *File
  128. }
  129. display, err := progressui.NewDisplay(out, displayMode)
  130. if err != nil {
  131. return nil, err
  132. }
  133. eg.Go(func() error {
  134. _, err := display.UpdateFrom(ctx, ch)
  135. return err
  136. })
  137. cfg := bakeConfig{
  138. Groups: map[string]bakeGroup{},
  139. Targets: map[string]bakeTarget{},
  140. }
  141. var (
  142. group bakeGroup
  143. privileged bool
  144. read []string
  145. expectedImages = make(map[string]string, len(serviceToBeBuild)) // service name -> expected image
  146. targets = make(map[string]string, len(serviceToBeBuild)) // service name -> build target
  147. )
  148. // produce a unique ID for service used as bake target
  149. for serviceName := range project.Services {
  150. t := strings.ReplaceAll(serviceName, ".", "_")
  151. for {
  152. if _, ok := targets[serviceName]; !ok {
  153. targets[serviceName] = t
  154. break
  155. }
  156. t += "_"
  157. }
  158. }
  159. for serviceName, service := range project.Services {
  160. if service.Build == nil {
  161. continue
  162. }
  163. build := *service.Build
  164. labels := getImageBuildLabels(project, service)
  165. args := types.Mapping{}
  166. for k, v := range resolveAndMergeBuildArgs(s.dockerCli, project, service, options) {
  167. if v == nil {
  168. continue
  169. }
  170. args[k] = *v
  171. }
  172. entitlements := build.Entitlements
  173. if slices.Contains(build.Entitlements, "security.insecure") {
  174. privileged = true
  175. }
  176. if build.Privileged {
  177. entitlements = append(entitlements, "security.insecure")
  178. privileged = true
  179. }
  180. var outputs []string
  181. var call string
  182. push := options.Push && service.Image != ""
  183. switch {
  184. case options.Check:
  185. call = "lint"
  186. case len(service.Build.Platforms) > 1:
  187. outputs = []string{fmt.Sprintf("type=image,push=%t", push)}
  188. default:
  189. if push {
  190. outputs = []string{"type=registry"}
  191. } else {
  192. outputs = []string{"type=docker"}
  193. }
  194. }
  195. read = append(read, build.Context)
  196. for _, path := range build.AdditionalContexts {
  197. _, err := gitutil.ParseGitRef(path)
  198. if !strings.Contains(path, "://") && err != nil {
  199. read = append(read, path)
  200. }
  201. }
  202. image := api.GetImageNameOrDefault(service, project.Name)
  203. expectedImages[serviceName] = image
  204. target := targets[serviceName]
  205. cfg.Targets[target] = bakeTarget{
  206. Context: build.Context,
  207. Contexts: additionalContexts(build.AdditionalContexts, targets),
  208. Dockerfile: dockerFilePath(build.Context, build.Dockerfile),
  209. DockerfileInline: strings.ReplaceAll(build.DockerfileInline, "${", "$${"),
  210. Args: args,
  211. Labels: labels,
  212. Tags: append(build.Tags, image),
  213. CacheFrom: build.CacheFrom,
  214. CacheTo: build.CacheTo,
  215. NetworkMode: build.Network,
  216. Platforms: build.Platforms,
  217. Target: build.Target,
  218. Secrets: toBakeSecrets(project, build.Secrets),
  219. SSH: toBakeSSH(append(build.SSH, options.SSHs...)),
  220. Pull: options.Pull,
  221. NoCache: options.NoCache,
  222. ShmSize: build.ShmSize,
  223. Ulimits: toBakeUlimits(build.Ulimits),
  224. Entitlements: entitlements,
  225. ExtraHosts: toBakeExtraHosts(build.ExtraHosts),
  226. Outputs: outputs,
  227. Call: call,
  228. }
  229. }
  230. // create a bake group with targets for services to build
  231. for serviceName, service := range serviceToBeBuild {
  232. if service.Build == nil {
  233. continue
  234. }
  235. group.Targets = append(group.Targets, targets[serviceName])
  236. }
  237. cfg.Groups["default"] = group
  238. b, err := json.MarshalIndent(cfg, "", " ")
  239. if err != nil {
  240. return nil, err
  241. }
  242. if options.Print {
  243. _, err = fmt.Fprintln(s.stdout(), string(b))
  244. return nil, err
  245. }
  246. logrus.Debugf("bake build config:\n%s", string(b))
  247. var metadataFile string
  248. for {
  249. // we don't use os.CreateTemp here as we need a temporary file name, but don't want it actually created
  250. // as bake relies on atomicwriter and this creates conflict during rename
  251. metadataFile = filepath.Join(os.TempDir(), fmt.Sprintf("compose-build-metadataFile-%d.json", rand.Int31()))
  252. if _, err = os.Stat(metadataFile); os.IsNotExist(err) {
  253. break
  254. }
  255. }
  256. defer func() {
  257. _ = os.Remove(metadataFile)
  258. }()
  259. buildx, err := manager.GetPlugin("buildx", s.dockerCli, &cobra.Command{})
  260. if err != nil {
  261. return nil, err
  262. }
  263. args := []string{"bake", "--file", "-", "--progress", "rawjson", "--metadata-file", metadataFile}
  264. mustAllow := buildx.Version != "" && versions.GreaterThanOrEqualTo(buildx.Version[1:], "0.17.0")
  265. if mustAllow {
  266. // FIXME we should prompt user about this, but this is a breaking change in UX
  267. for _, path := range read {
  268. args = append(args, "--allow", "fs.read="+path)
  269. }
  270. if privileged {
  271. args = append(args, "--allow", "security.insecure")
  272. }
  273. }
  274. if options.Builder != "" {
  275. args = append(args, "--builder", options.Builder)
  276. }
  277. if options.Quiet {
  278. args = append(args, "--progress=quiet")
  279. }
  280. logrus.Debugf("Executing bake with args: %v", args)
  281. if s.dryRun {
  282. return dryRunBake(ctx, cfg), nil
  283. }
  284. cmd := exec.CommandContext(ctx, buildx.Path, args...)
  285. err = s.prepareShellOut(ctx, project.Environment, cmd)
  286. if err != nil {
  287. return nil, err
  288. }
  289. cmd.Stdout = s.stdout()
  290. cmd.Stdin = bytes.NewBuffer(b)
  291. pipe, err := cmd.StderrPipe()
  292. if err != nil {
  293. return nil, err
  294. }
  295. var errMessage []string
  296. reader := bufio.NewReader(pipe)
  297. err = cmd.Start()
  298. if err != nil {
  299. return nil, err
  300. }
  301. eg.Go(cmd.Wait)
  302. for {
  303. line, readErr := reader.ReadString('\n')
  304. if readErr != nil {
  305. if readErr == io.EOF {
  306. break
  307. } else {
  308. return nil, fmt.Errorf("failed to execute bake: %w", readErr)
  309. }
  310. }
  311. decoder := json.NewDecoder(strings.NewReader(line))
  312. var status client.SolveStatus
  313. err := decoder.Decode(&status)
  314. if err != nil {
  315. if strings.HasPrefix(line, "ERROR: ") {
  316. errMessage = append(errMessage, line[7:])
  317. } else {
  318. errMessage = append(errMessage, line)
  319. }
  320. continue
  321. }
  322. ch <- &status
  323. }
  324. close(ch) // stop build progress UI
  325. err = eg.Wait()
  326. if err != nil {
  327. if len(errMessage) > 0 {
  328. return nil, errors.New(strings.Join(errMessage, "\n"))
  329. }
  330. return nil, fmt.Errorf("failed to execute bake: %w", err)
  331. }
  332. b, err = os.ReadFile(metadataFile)
  333. if err != nil {
  334. return nil, err
  335. }
  336. var md bakeMetadata
  337. err = json.Unmarshal(b, &md)
  338. if err != nil {
  339. return nil, err
  340. }
  341. cw := progress.ContextWriter(ctx)
  342. results := map[string]string{}
  343. for name := range serviceToBeBuild {
  344. image := expectedImages[name]
  345. target := targets[name]
  346. built, ok := md[target]
  347. if !ok {
  348. return nil, fmt.Errorf("build result not found in Bake metadata for service %s", name)
  349. }
  350. results[image] = built.Digest
  351. cw.Event(progress.BuiltEvent(image))
  352. }
  353. return results, nil
  354. }
  355. func toBakeExtraHosts(hosts types.HostsList) map[string]string {
  356. m := make(map[string]string)
  357. for k, v := range hosts {
  358. m[k] = strings.Join(v, ",")
  359. }
  360. return m
  361. }
  362. func additionalContexts(contexts types.Mapping, targets map[string]string) map[string]string {
  363. ac := map[string]string{}
  364. for k, v := range contexts {
  365. if target, found := strings.CutPrefix(v, types.ServicePrefix); found {
  366. v = "target:" + targets[target]
  367. }
  368. ac[k] = v
  369. }
  370. return ac
  371. }
  372. func toBakeUlimits(ulimits map[string]*types.UlimitsConfig) []string {
  373. s := []string{}
  374. for u, l := range ulimits {
  375. if l.Single > 0 {
  376. s = append(s, fmt.Sprintf("%s=%d", u, l.Single))
  377. } else {
  378. s = append(s, fmt.Sprintf("%s=%d:%d", u, l.Soft, l.Hard))
  379. }
  380. }
  381. return s
  382. }
  383. func toBakeSSH(ssh types.SSHConfig) []string {
  384. var s []string
  385. for _, key := range ssh {
  386. s = append(s, fmt.Sprintf("%s=%s", key.ID, key.Path))
  387. }
  388. return s
  389. }
  390. func toBakeSecrets(project *types.Project, secrets []types.ServiceSecretConfig) []string {
  391. var s []string
  392. for _, ref := range secrets {
  393. def := project.Secrets[ref.Source]
  394. target := ref.Target
  395. if target == "" {
  396. target = ref.Source
  397. }
  398. switch {
  399. case def.Environment != "":
  400. s = append(s, fmt.Sprintf("id=%s,type=env,env=%s", target, def.Environment))
  401. case def.File != "":
  402. s = append(s, fmt.Sprintf("id=%s,type=file,src=%s", target, def.File))
  403. }
  404. }
  405. return s
  406. }
  407. func dockerFilePath(ctxName string, dockerfile string) string {
  408. if dockerfile == "" {
  409. return ""
  410. }
  411. if urlutil.IsGitURL(ctxName) {
  412. return dockerfile
  413. }
  414. if !filepath.IsAbs(dockerfile) {
  415. dockerfile = filepath.Join(ctxName, dockerfile)
  416. }
  417. dir := filepath.Dir(dockerfile)
  418. symlinks, err := filepath.EvalSymlinks(dir)
  419. if err == nil {
  420. return filepath.Join(symlinks, filepath.Base(dockerfile))
  421. }
  422. return dockerfile
  423. }
  424. func dryRunBake(ctx context.Context, cfg bakeConfig) map[string]string {
  425. w := progress.ContextWriter(ctx)
  426. bakeResponse := map[string]string{}
  427. for name, target := range cfg.Targets {
  428. dryRunUUID := fmt.Sprintf("dryRun-%x", sha1.Sum([]byte(name)))
  429. displayDryRunBuildEvent(w, name, dryRunUUID, target.Tags[0])
  430. bakeResponse[name] = dryRunUUID
  431. }
  432. for name := range bakeResponse {
  433. w.Event(progress.BuiltEvent(name))
  434. }
  435. return bakeResponse
  436. }
  437. func displayDryRunBuildEvent(w progress.Writer, name string, dryRunUUID, tag string) {
  438. w.Event(progress.Event{
  439. ID: name + " ==>",
  440. Status: progress.Done,
  441. Text: fmt.Sprintf("==> writing image %s", dryRunUUID),
  442. })
  443. w.Event(progress.Event{
  444. ID: name + " ==> ==>",
  445. Status: progress.Done,
  446. Text: fmt.Sprintf(`naming to %s`, tag),
  447. })
  448. }