build.go 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526
  1. /*
  2. Copyright 2020 Docker Compose CLI authors
  3. Licensed under the Apache License, Version 2.0 (the "License");
  4. you may not use this file except in compliance with the License.
  5. You may obtain a copy of the License at
  6. http://www.apache.org/licenses/LICENSE-2.0
  7. Unless required by applicable law or agreed to in writing, software
  8. distributed under the License is distributed on an "AS IS" BASIS,
  9. WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  10. See the License for the specific language governing permissions and
  11. limitations under the License.
  12. */
  13. package compose
  14. import (
  15. "context"
  16. "errors"
  17. "fmt"
  18. "os"
  19. "path/filepath"
  20. "github.com/compose-spec/compose-go/types"
  21. "github.com/containerd/containerd/platforms"
  22. "github.com/docker/buildx/build"
  23. "github.com/docker/buildx/builder"
  24. "github.com/docker/buildx/controller/pb"
  25. "github.com/docker/buildx/store/storeutil"
  26. "github.com/docker/buildx/util/buildflags"
  27. xprogress "github.com/docker/buildx/util/progress"
  28. "github.com/docker/cli/cli/command"
  29. "github.com/docker/compose/v2/internal/tracing"
  30. "github.com/docker/compose/v2/pkg/api"
  31. "github.com/docker/compose/v2/pkg/progress"
  32. "github.com/docker/compose/v2/pkg/utils"
  33. "github.com/docker/docker/builder/remotecontext/urlutil"
  34. bclient "github.com/moby/buildkit/client"
  35. "github.com/moby/buildkit/session"
  36. "github.com/moby/buildkit/session/auth/authprovider"
  37. "github.com/moby/buildkit/session/secrets/secretsprovider"
  38. "github.com/moby/buildkit/session/sshforward/sshprovider"
  39. "github.com/moby/buildkit/util/entitlements"
  40. specs "github.com/opencontainers/image-spec/specs-go/v1"
  41. "github.com/sirupsen/logrus"
  42. // required to get default driver registered
  43. _ "github.com/docker/buildx/driver/docker"
  44. )
  45. func (s *composeService) Build(ctx context.Context, project *types.Project, options api.BuildOptions) error {
  46. err := options.Apply(project)
  47. if err != nil {
  48. return err
  49. }
  50. return progress.RunWithTitle(ctx, func(ctx context.Context) error {
  51. _, err := s.build(ctx, project, options, nil)
  52. return err
  53. }, s.stdinfo(), "Building")
  54. }
  55. //nolint:gocyclo
  56. func (s *composeService) build(ctx context.Context, project *types.Project, options api.BuildOptions, localImages map[string]string) (map[string]string, error) {
  57. buildkitEnabled, err := s.dockerCli.BuildKitEnabled()
  58. if err != nil {
  59. return nil, err
  60. }
  61. // Initialize buildkit nodes
  62. var (
  63. b *builder.Builder
  64. nodes []builder.Node
  65. w *xprogress.Printer
  66. )
  67. if buildkitEnabled {
  68. builderName := options.Builder
  69. if builderName == "" {
  70. builderName = os.Getenv("BUILDX_BUILDER")
  71. }
  72. b, err = builder.New(s.dockerCli, builder.WithName(builderName))
  73. if err != nil {
  74. return nil, err
  75. }
  76. nodes, err = b.LoadNodes(ctx, false)
  77. if err != nil {
  78. return nil, err
  79. }
  80. // Progress needs its own context that lives longer than the
  81. // build one otherwise it won't read all the messages from
  82. // build and will lock
  83. progressCtx, cancel := context.WithCancel(context.Background())
  84. defer cancel()
  85. w, err = xprogress.NewPrinter(progressCtx, s.stdout(), os.Stdout, options.Progress,
  86. xprogress.WithDesc(
  87. fmt.Sprintf("building with %q instance using %s driver", b.Name, b.Driver),
  88. fmt.Sprintf("%s:%s", b.Driver, b.Name),
  89. ))
  90. if err != nil {
  91. return nil, err
  92. }
  93. }
  94. builtDigests := make([]string, len(project.Services))
  95. err = InDependencyOrder(ctx, project, func(ctx context.Context, name string) error {
  96. if len(options.Services) > 0 && !utils.Contains(options.Services, name) {
  97. return nil
  98. }
  99. service, idx := getServiceIndex(project, name)
  100. if service.Build == nil {
  101. return nil
  102. }
  103. image := api.GetImageNameOrDefault(service, project.Name)
  104. _, localImagePresent := localImages[image]
  105. if localImagePresent && service.PullPolicy != types.PullPolicyBuild {
  106. return nil
  107. }
  108. if !buildkitEnabled {
  109. id, err := s.doBuildClassic(ctx, project, service, options)
  110. if err != nil {
  111. return err
  112. }
  113. builtDigests[idx] = id
  114. if options.Push {
  115. return s.push(ctx, project, api.PushOptions{})
  116. }
  117. return nil
  118. }
  119. if options.Memory != 0 {
  120. fmt.Fprintln(s.stderr(), "WARNING: --memory is not supported by BuildKit and will be ignored.")
  121. }
  122. buildOptions, err := s.toBuildOptions(project, service, options)
  123. if err != nil {
  124. return err
  125. }
  126. digest, err := s.doBuildBuildkit(ctx, service.Name, buildOptions, w, nodes)
  127. if err != nil {
  128. return err
  129. }
  130. builtDigests[idx] = digest
  131. return nil
  132. }, func(traversal *graphTraversal) {
  133. traversal.maxConcurrency = s.maxConcurrency
  134. })
  135. // enforce all build event get consumed
  136. if buildkitEnabled {
  137. if errw := w.Wait(); errw != nil {
  138. return nil, errw
  139. }
  140. }
  141. if err != nil {
  142. return nil, err
  143. }
  144. imageIDs := map[string]string{}
  145. for i, imageDigest := range builtDigests {
  146. if imageDigest != "" {
  147. imageRef := api.GetImageNameOrDefault(project.Services[i], project.Name)
  148. imageIDs[imageRef] = imageDigest
  149. }
  150. }
  151. return imageIDs, err
  152. }
  153. func getServiceIndex(project *types.Project, name string) (types.ServiceConfig, int) {
  154. var service types.ServiceConfig
  155. var idx int
  156. for i, s := range project.Services {
  157. if s.Name == name {
  158. idx, service = i, s
  159. break
  160. }
  161. }
  162. return service, idx
  163. }
  164. func (s *composeService) ensureImagesExists(ctx context.Context, project *types.Project, buildOpts *api.BuildOptions, quietPull bool) error {
  165. for _, service := range project.Services {
  166. if service.Image == "" && service.Build == nil {
  167. return fmt.Errorf("invalid service %q. Must specify either image or build", service.Name)
  168. }
  169. }
  170. images, err := s.getLocalImagesDigests(ctx, project)
  171. if err != nil {
  172. return err
  173. }
  174. err = tracing.SpanWrapFunc("project/pull", tracing.ProjectOptions(project),
  175. func(ctx context.Context) error {
  176. return s.pullRequiredImages(ctx, project, images, quietPull)
  177. },
  178. )(ctx)
  179. if err != nil {
  180. return err
  181. }
  182. if buildOpts != nil {
  183. err = tracing.SpanWrapFunc("project/build", tracing.ProjectOptions(project),
  184. func(ctx context.Context) error {
  185. builtImages, err := s.build(ctx, project, *buildOpts, images)
  186. if err != nil {
  187. return err
  188. }
  189. for name, digest := range builtImages {
  190. images[name] = digest
  191. }
  192. return nil
  193. },
  194. )(ctx)
  195. if err != nil {
  196. return err
  197. }
  198. }
  199. // set digest as com.docker.compose.image label so we can detect outdated containers
  200. for i, service := range project.Services {
  201. image := api.GetImageNameOrDefault(service, project.Name)
  202. digest, ok := images[image]
  203. if ok {
  204. if project.Services[i].Labels == nil {
  205. project.Services[i].Labels = types.Labels{}
  206. }
  207. project.Services[i].CustomLabels.Add(api.ImageDigestLabel, digest)
  208. }
  209. }
  210. return nil
  211. }
  212. func (s *composeService) getLocalImagesDigests(ctx context.Context, project *types.Project) (map[string]string, error) {
  213. var imageNames []string
  214. for _, s := range project.Services {
  215. imgName := api.GetImageNameOrDefault(s, project.Name)
  216. if !utils.StringContains(imageNames, imgName) {
  217. imageNames = append(imageNames, imgName)
  218. }
  219. }
  220. imgs, err := s.getImages(ctx, imageNames)
  221. if err != nil {
  222. return nil, err
  223. }
  224. images := map[string]string{}
  225. for name, info := range imgs {
  226. images[name] = info.ID
  227. }
  228. for i, service := range project.Services {
  229. imgName := api.GetImageNameOrDefault(service, project.Name)
  230. digest, ok := images[imgName]
  231. if !ok {
  232. continue
  233. }
  234. if service.Platform != "" {
  235. platform, err := platforms.Parse(service.Platform)
  236. if err != nil {
  237. return nil, err
  238. }
  239. inspect, _, err := s.apiClient().ImageInspectWithRaw(ctx, digest)
  240. if err != nil {
  241. return nil, err
  242. }
  243. actual := specs.Platform{
  244. Architecture: inspect.Architecture,
  245. OS: inspect.Os,
  246. Variant: inspect.Variant,
  247. }
  248. if !platforms.NewMatcher(platform).Match(actual) {
  249. // there is a local image, but it's for the wrong platform, so
  250. // pretend it doesn't exist so that we can pull/build an image
  251. // for the correct platform instead
  252. delete(images, imgName)
  253. }
  254. }
  255. project.Services[i].CustomLabels.Add(api.ImageDigestLabel, digest)
  256. }
  257. return images, nil
  258. }
  259. // resolveAndMergeBuildArgs returns the final set of build arguments to use for the service image build.
  260. //
  261. // First, args directly defined via `build.args` in YAML are considered.
  262. // Then, any explicitly passed args in opts (e.g. via `--build-arg` on the CLI) are merged, overwriting any
  263. // keys that already exist.
  264. // Next, any keys without a value are resolved using the project environment.
  265. //
  266. // Finally, standard proxy variables based on the Docker client configuration are added, but will not overwrite
  267. // any values if already present.
  268. func resolveAndMergeBuildArgs(
  269. dockerCli command.Cli,
  270. project *types.Project,
  271. service types.ServiceConfig,
  272. opts api.BuildOptions,
  273. ) types.MappingWithEquals {
  274. result := make(types.MappingWithEquals).
  275. OverrideBy(service.Build.Args).
  276. OverrideBy(opts.Args).
  277. Resolve(envResolver(project.Environment))
  278. // proxy arguments do NOT override and should NOT have env resolution applied,
  279. // so they're handled last
  280. for k, v := range storeutil.GetProxyConfig(dockerCli) {
  281. if _, ok := result[k]; !ok {
  282. v := v
  283. result[k] = &v
  284. }
  285. }
  286. return result
  287. }
  288. func (s *composeService) toBuildOptions(project *types.Project, service types.ServiceConfig, options api.BuildOptions) (build.Options, error) {
  289. plats, err := parsePlatforms(service)
  290. if err != nil {
  291. return build.Options{}, err
  292. }
  293. cacheFrom, err := buildflags.ParseCacheEntry(service.Build.CacheFrom)
  294. if err != nil {
  295. return build.Options{}, err
  296. }
  297. cacheTo, err := buildflags.ParseCacheEntry(service.Build.CacheTo)
  298. if err != nil {
  299. return build.Options{}, err
  300. }
  301. sessionConfig := []session.Attachable{
  302. authprovider.NewDockerAuthProvider(s.configFile()),
  303. }
  304. if len(options.SSHs) > 0 || len(service.Build.SSH) > 0 {
  305. sshAgentProvider, err := sshAgentProvider(append(service.Build.SSH, options.SSHs...))
  306. if err != nil {
  307. return build.Options{}, err
  308. }
  309. sessionConfig = append(sessionConfig, sshAgentProvider)
  310. }
  311. if len(service.Build.Secrets) > 0 {
  312. secretsProvider, err := addSecretsConfig(project, service)
  313. if err != nil {
  314. return build.Options{}, err
  315. }
  316. sessionConfig = append(sessionConfig, secretsProvider)
  317. }
  318. tags := []string{api.GetImageNameOrDefault(service, project.Name)}
  319. if len(service.Build.Tags) > 0 {
  320. tags = append(tags, service.Build.Tags...)
  321. }
  322. var allow []entitlements.Entitlement
  323. if service.Build.Privileged {
  324. allow = append(allow, entitlements.EntitlementSecurityInsecure)
  325. }
  326. imageLabels := getImageBuildLabels(project, service)
  327. push := options.Push && service.Image != ""
  328. exports := []bclient.ExportEntry{{
  329. Type: "docker",
  330. Attrs: map[string]string{
  331. "load": "true",
  332. "push": fmt.Sprint(push),
  333. },
  334. }}
  335. if len(service.Build.Platforms) > 1 {
  336. exports = []bclient.ExportEntry{{
  337. Type: "image",
  338. Attrs: map[string]string{
  339. "push": fmt.Sprint(push),
  340. },
  341. }}
  342. }
  343. return build.Options{
  344. Inputs: build.Inputs{
  345. ContextPath: service.Build.Context,
  346. DockerfileInline: service.Build.DockerfileInline,
  347. DockerfilePath: dockerFilePath(service.Build.Context, service.Build.Dockerfile),
  348. NamedContexts: toBuildContexts(service.Build.AdditionalContexts),
  349. },
  350. CacheFrom: pb.CreateCaches(cacheFrom),
  351. CacheTo: pb.CreateCaches(cacheTo),
  352. NoCache: service.Build.NoCache,
  353. Pull: service.Build.Pull,
  354. BuildArgs: flatten(resolveAndMergeBuildArgs(s.dockerCli, project, service, options)),
  355. Tags: tags,
  356. Target: service.Build.Target,
  357. Exports: exports,
  358. Platforms: plats,
  359. Labels: imageLabels,
  360. NetworkMode: service.Build.Network,
  361. ExtraHosts: service.Build.ExtraHosts.AsList(),
  362. Session: sessionConfig,
  363. Allow: allow,
  364. }, nil
  365. }
  366. func flatten(in types.MappingWithEquals) types.Mapping {
  367. out := types.Mapping{}
  368. if len(in) == 0 {
  369. return out
  370. }
  371. for k, v := range in {
  372. if v == nil {
  373. continue
  374. }
  375. out[k] = *v
  376. }
  377. return out
  378. }
  379. func dockerFilePath(ctxName string, dockerfile string) string {
  380. if dockerfile == "" {
  381. return ""
  382. }
  383. if urlutil.IsGitURL(ctxName) || filepath.IsAbs(dockerfile) {
  384. return dockerfile
  385. }
  386. return filepath.Join(ctxName, dockerfile)
  387. }
  388. func sshAgentProvider(sshKeys types.SSHConfig) (session.Attachable, error) {
  389. sshConfig := make([]sshprovider.AgentConfig, 0, len(sshKeys))
  390. for _, sshKey := range sshKeys {
  391. sshConfig = append(sshConfig, sshprovider.AgentConfig{
  392. ID: sshKey.ID,
  393. Paths: []string{sshKey.Path},
  394. })
  395. }
  396. return sshprovider.NewSSHAgentProvider(sshConfig)
  397. }
  398. func addSecretsConfig(project *types.Project, service types.ServiceConfig) (session.Attachable, error) {
  399. var sources []secretsprovider.Source
  400. for _, secret := range service.Build.Secrets {
  401. config := project.Secrets[secret.Source]
  402. id := secret.Source
  403. if secret.Target != "" {
  404. id = secret.Target
  405. }
  406. switch {
  407. case config.File != "":
  408. sources = append(sources, secretsprovider.Source{
  409. ID: id,
  410. FilePath: config.File,
  411. })
  412. case config.Environment != "":
  413. sources = append(sources, secretsprovider.Source{
  414. ID: id,
  415. Env: config.Environment,
  416. })
  417. default:
  418. return nil, fmt.Errorf("build.secrets only supports environment or file-based secrets: %q", secret.Source)
  419. }
  420. if secret.UID != "" || secret.GID != "" || secret.Mode != nil {
  421. logrus.Warn("secrets `uid`, `gid` and `mode` are not supported by BuildKit, they will be ignored")
  422. }
  423. }
  424. store, err := secretsprovider.NewStore(sources)
  425. if err != nil {
  426. return nil, err
  427. }
  428. return secretsprovider.NewSecretProvider(store), nil
  429. }
  430. func getImageBuildLabels(project *types.Project, service types.ServiceConfig) types.Labels {
  431. ret := make(types.Labels)
  432. if service.Build != nil {
  433. for k, v := range service.Build.Labels {
  434. ret.Add(k, v)
  435. }
  436. }
  437. ret.Add(api.VersionLabel, api.ComposeVersion)
  438. ret.Add(api.ProjectLabel, project.Name)
  439. ret.Add(api.ServiceLabel, service.Name)
  440. return ret
  441. }
  442. func toBuildContexts(additionalContexts types.Mapping) map[string]build.NamedContext {
  443. namedContexts := map[string]build.NamedContext{}
  444. for name, context := range additionalContexts {
  445. namedContexts[name] = build.NamedContext{Path: context}
  446. }
  447. return namedContexts
  448. }
  449. func parsePlatforms(service types.ServiceConfig) ([]specs.Platform, error) {
  450. if service.Build == nil || len(service.Build.Platforms) == 0 {
  451. return nil, nil
  452. }
  453. var errs []error
  454. ret := make([]specs.Platform, len(service.Build.Platforms))
  455. for i := range service.Build.Platforms {
  456. p, err := platforms.Parse(service.Build.Platforms[i])
  457. if err != nil {
  458. errs = append(errs, err)
  459. } else {
  460. ret[i] = p
  461. }
  462. }
  463. if err := errors.Join(errs...); err != nil {
  464. return nil, err
  465. }
  466. return ret, nil
  467. }