build_bake.go 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454
  1. /*
  2. Copyright 2020 Docker Compose CLI authors
  3. Licensed under the Apache License, Version 2.0 (the "License");
  4. you may not use this file except in compliance with the License.
  5. You may obtain a copy of the License at
  6. http://www.apache.org/licenses/LICENSE-2.0
  7. Unless required by applicable law or agreed to in writing, software
  8. distributed under the License is distributed on an "AS IS" BASIS,
  9. WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  10. See the License for the specific language governing permissions and
  11. limitations under the License.
  12. */
  13. package compose
  14. import (
  15. "bufio"
  16. "bytes"
  17. "context"
  18. "encoding/json"
  19. "errors"
  20. "fmt"
  21. "os"
  22. "os/exec"
  23. "path/filepath"
  24. "slices"
  25. "strconv"
  26. "strings"
  27. "github.com/compose-spec/compose-go/v2/types"
  28. "github.com/docker/cli/cli-plugins/manager"
  29. "github.com/docker/cli/cli-plugins/socket"
  30. "github.com/docker/cli/cli/command"
  31. "github.com/docker/compose/v2/pkg/api"
  32. "github.com/docker/compose/v2/pkg/progress"
  33. "github.com/docker/docker/api/types/versions"
  34. "github.com/docker/docker/builder/remotecontext/urlutil"
  35. "github.com/moby/buildkit/client"
  36. "github.com/moby/buildkit/util/gitutil"
  37. "github.com/moby/buildkit/util/progress/progressui"
  38. "github.com/sirupsen/logrus"
  39. "github.com/spf13/cobra"
  40. "go.opentelemetry.io/otel"
  41. "go.opentelemetry.io/otel/propagation"
  42. "golang.org/x/sync/errgroup"
  43. )
  44. func buildWithBake(dockerCli command.Cli) (bool, error) {
  45. b, ok := os.LookupEnv("COMPOSE_BAKE")
  46. if !ok {
  47. b = "true"
  48. }
  49. bake, err := strconv.ParseBool(b)
  50. if err != nil {
  51. return false, err
  52. }
  53. if !bake {
  54. return false, nil
  55. }
  56. enabled, err := dockerCli.BuildKitEnabled()
  57. if err != nil {
  58. return false, err
  59. }
  60. if !enabled {
  61. logrus.Warnf("Docker Compose is configured to build using Bake, but buildkit isn't enabled")
  62. return false, nil
  63. }
  64. _, err = manager.GetPlugin("buildx", dockerCli, &cobra.Command{})
  65. if err != nil {
  66. if manager.IsNotFound(err) {
  67. logrus.Warnf("Docker Compose is configured to build using Bake, but buildx isn't installed")
  68. return false, nil
  69. }
  70. return false, err
  71. }
  72. return true, err
  73. }
  74. // We _could_ use bake.* types from github.com/docker/buildx but long term plan is to remove buildx as a dependency
  75. type bakeConfig struct {
  76. Groups map[string]bakeGroup `json:"group"`
  77. Targets map[string]bakeTarget `json:"target"`
  78. }
  79. type bakeGroup struct {
  80. Targets []string `json:"targets"`
  81. }
  82. type bakeTarget struct {
  83. Context string `json:"context,omitempty"`
  84. Contexts map[string]string `json:"contexts,omitempty"`
  85. Dockerfile string `json:"dockerfile,omitempty"`
  86. DockerfileInline string `json:"dockerfile-inline,omitempty"`
  87. Args map[string]string `json:"args,omitempty"`
  88. Labels map[string]string `json:"labels,omitempty"`
  89. Tags []string `json:"tags,omitempty"`
  90. CacheFrom []string `json:"cache-from,omitempty"`
  91. CacheTo []string `json:"cache-to,omitempty"`
  92. Target string `json:"target,omitempty"`
  93. Secrets []string `json:"secret,omitempty"`
  94. SSH []string `json:"ssh,omitempty"`
  95. Platforms []string `json:"platforms,omitempty"`
  96. Pull bool `json:"pull,omitempty"`
  97. NoCache bool `json:"no-cache,omitempty"`
  98. NetworkMode string `json:"network,omitempty"`
  99. NoCacheFilter []string `json:"no-cache-filter,omitempty"`
  100. ShmSize types.UnitBytes `json:"shm-size,omitempty"`
  101. Ulimits []string `json:"ulimits,omitempty"`
  102. Call string `json:"call,omitempty"`
  103. Entitlements []string `json:"entitlements,omitempty"`
  104. Outputs []string `json:"output,omitempty"`
  105. }
  106. type bakeMetadata map[string]buildStatus
  107. type buildStatus struct {
  108. Digest string `json:"containerimage.digest"`
  109. Image string `json:"image.name"`
  110. }
  111. func (s *composeService) doBuildBake(ctx context.Context, project *types.Project, serviceToBeBuild types.Services, options api.BuildOptions) (map[string]string, error) { //nolint:gocyclo
  112. eg := errgroup.Group{}
  113. ch := make(chan *client.SolveStatus)
  114. display, err := progressui.NewDisplay(os.Stdout, progressui.DisplayMode(options.Progress))
  115. if err != nil {
  116. return nil, err
  117. }
  118. eg.Go(func() error {
  119. _, err := display.UpdateFrom(ctx, ch)
  120. return err
  121. })
  122. cfg := bakeConfig{
  123. Groups: map[string]bakeGroup{},
  124. Targets: map[string]bakeTarget{},
  125. }
  126. var (
  127. group bakeGroup
  128. privileged bool
  129. read []string
  130. expectedImages = make(map[string]string, len(serviceToBeBuild)) // service name -> expected image
  131. targets = make(map[string]string, len(serviceToBeBuild)) // service name -> build target
  132. )
  133. // produce a unique ID for service used as bake target
  134. for serviceName := range project.Services {
  135. t := strings.ReplaceAll(serviceName, ".", "_")
  136. for {
  137. if _, ok := targets[serviceName]; !ok {
  138. targets[serviceName] = t
  139. break
  140. }
  141. t += "_"
  142. }
  143. }
  144. for serviceName, service := range project.Services {
  145. if service.Build == nil {
  146. continue
  147. }
  148. build := *service.Build
  149. args := types.Mapping{}
  150. for k, v := range resolveAndMergeBuildArgs(s.dockerCli, project, service, options) {
  151. if v == nil {
  152. continue
  153. }
  154. args[k] = *v
  155. }
  156. image := api.GetImageNameOrDefault(service, project.Name)
  157. expectedImages[serviceName] = image
  158. entitlements := build.Entitlements
  159. if slices.Contains(build.Entitlements, "security.insecure") {
  160. privileged = true
  161. }
  162. if build.Privileged {
  163. entitlements = append(entitlements, "security.insecure")
  164. privileged = true
  165. }
  166. var outputs []string
  167. var call string
  168. push := options.Push && service.Image != ""
  169. switch {
  170. case options.Check:
  171. call = "lint"
  172. case len(service.Build.Platforms) > 1:
  173. outputs = []string{fmt.Sprintf("type=image,push=%t", push)}
  174. default:
  175. outputs = []string{fmt.Sprintf("type=docker,load=true,push=%t", push)}
  176. }
  177. read = append(read, build.Context)
  178. for _, path := range build.AdditionalContexts {
  179. _, err := gitutil.ParseGitRef(path)
  180. if !strings.Contains(path, "://") && err != nil {
  181. read = append(read, path)
  182. }
  183. }
  184. target := targets[serviceName]
  185. cfg.Targets[target] = bakeTarget{
  186. Context: build.Context,
  187. Contexts: additionalContexts(build.AdditionalContexts, targets),
  188. Dockerfile: dockerFilePath(build.Context, build.Dockerfile),
  189. DockerfileInline: strings.ReplaceAll(build.DockerfileInline, "${", "$${"),
  190. Args: args,
  191. Labels: build.Labels,
  192. Tags: append(build.Tags, image),
  193. CacheFrom: build.CacheFrom,
  194. // CacheTo: TODO
  195. Platforms: build.Platforms,
  196. Target: build.Target,
  197. Secrets: toBakeSecrets(project, build.Secrets),
  198. SSH: toBakeSSH(append(build.SSH, options.SSHs...)),
  199. Pull: options.Pull,
  200. NoCache: options.NoCache,
  201. ShmSize: build.ShmSize,
  202. Ulimits: toBakeUlimits(build.Ulimits),
  203. Entitlements: entitlements,
  204. Outputs: outputs,
  205. Call: call,
  206. }
  207. }
  208. // create a bake group with targets for services to build
  209. for serviceName, service := range serviceToBeBuild {
  210. if service.Build == nil {
  211. continue
  212. }
  213. group.Targets = append(group.Targets, targets[serviceName])
  214. }
  215. cfg.Groups["default"] = group
  216. b, err := json.MarshalIndent(cfg, "", " ")
  217. if err != nil {
  218. return nil, err
  219. }
  220. if options.Print {
  221. _, err = fmt.Fprintln(s.stdout(), string(b))
  222. return nil, err
  223. }
  224. logrus.Debugf("bake build config:\n%s", string(b))
  225. metadata, err := os.CreateTemp(os.TempDir(), "compose")
  226. if err != nil {
  227. return nil, err
  228. }
  229. defer func() {
  230. _ = os.Remove(metadata.Name())
  231. }()
  232. buildx, err := manager.GetPlugin("buildx", s.dockerCli, &cobra.Command{})
  233. if err != nil {
  234. return nil, err
  235. }
  236. args := []string{"bake", "--file", "-", "--progress", "rawjson", "--metadata-file", metadata.Name()}
  237. mustAllow := buildx.Version != "" && versions.GreaterThanOrEqualTo(buildx.Version[1:], "0.17.0")
  238. if mustAllow {
  239. // FIXME we should prompt user about this, but this is a breaking change in UX
  240. for _, path := range read {
  241. args = append(args, "--allow", "fs.read="+path)
  242. }
  243. if privileged {
  244. args = append(args, "--allow", "security.insecure")
  245. }
  246. }
  247. if options.Builder != "" {
  248. args = append(args, "--builder", options.Builder)
  249. }
  250. if options.Quiet {
  251. args = append(args, "--progress=quiet")
  252. }
  253. logrus.Debugf("Executing bake with args: %v", args)
  254. cmd := exec.CommandContext(ctx, buildx.Path, args...)
  255. // Remove DOCKER_CLI_PLUGIN... variable so buildx can detect it run standalone
  256. cmd.Env = filter(os.Environ(), manager.ReexecEnvvar)
  257. // Use docker/cli mechanism to propagate termination signal to child process
  258. server, err := socket.NewPluginServer(nil)
  259. if err != nil {
  260. defer server.Close() //nolint:errcheck
  261. cmd.Cancel = server.Close
  262. cmd.Env = replace(cmd.Env, socket.EnvKey, server.Addr().String())
  263. }
  264. cmd.Env = append(cmd.Env, fmt.Sprintf("DOCKER_CONTEXT=%s", s.dockerCli.CurrentContext()))
  265. // propagate opentelemetry context to child process, see https://github.com/open-telemetry/oteps/blob/main/text/0258-env-context-baggage-carriers.md
  266. carrier := propagation.MapCarrier{}
  267. otel.GetTextMapPropagator().Inject(ctx, &carrier)
  268. cmd.Env = append(cmd.Env, types.Mapping(carrier).Values()...)
  269. cmd.Stdout = s.stdout()
  270. cmd.Stdin = bytes.NewBuffer(b)
  271. pipe, err := cmd.StderrPipe()
  272. if err != nil {
  273. return nil, err
  274. }
  275. var errMessage []string
  276. scanner := bufio.NewScanner(pipe)
  277. scanner.Split(bufio.ScanLines)
  278. err = cmd.Start()
  279. if err != nil {
  280. return nil, err
  281. }
  282. eg.Go(cmd.Wait)
  283. for scanner.Scan() {
  284. line := scanner.Text()
  285. decoder := json.NewDecoder(strings.NewReader(line))
  286. var status client.SolveStatus
  287. err := decoder.Decode(&status)
  288. if err != nil {
  289. if strings.HasPrefix(line, "ERROR: ") {
  290. errMessage = append(errMessage, line[7:])
  291. } else {
  292. errMessage = append(errMessage, line)
  293. }
  294. continue
  295. }
  296. ch <- &status
  297. }
  298. close(ch) // stop build progress UI
  299. err = eg.Wait()
  300. if err != nil {
  301. if len(errMessage) > 0 {
  302. return nil, errors.New(strings.Join(errMessage, "\n"))
  303. }
  304. return nil, fmt.Errorf("failed to execute bake: %w", err)
  305. }
  306. b, err = os.ReadFile(metadata.Name())
  307. if err != nil {
  308. return nil, err
  309. }
  310. var md bakeMetadata
  311. err = json.Unmarshal(b, &md)
  312. if err != nil {
  313. return nil, err
  314. }
  315. cw := progress.ContextWriter(ctx)
  316. results := map[string]string{}
  317. for service, name := range expectedImages {
  318. built, ok := md[targets[service]]
  319. if !ok {
  320. return nil, fmt.Errorf("build result not found in Bake metadata for service %s", service)
  321. }
  322. results[name] = built.Digest
  323. cw.Event(progress.BuiltEvent(name))
  324. }
  325. return results, nil
  326. }
  327. func additionalContexts(contexts types.Mapping, targets map[string]string) map[string]string {
  328. ac := map[string]string{}
  329. for k, v := range contexts {
  330. if target, found := strings.CutPrefix(v, types.ServicePrefix); found {
  331. v = "target:" + targets[target]
  332. }
  333. ac[k] = v
  334. }
  335. return ac
  336. }
  337. func toBakeUlimits(ulimits map[string]*types.UlimitsConfig) []string {
  338. s := []string{}
  339. for u, l := range ulimits {
  340. if l.Single > 0 {
  341. s = append(s, fmt.Sprintf("%s=%d", u, l.Single))
  342. } else {
  343. s = append(s, fmt.Sprintf("%s=%d:%d", u, l.Soft, l.Hard))
  344. }
  345. }
  346. return s
  347. }
  348. func toBakeSSH(ssh types.SSHConfig) []string {
  349. var s []string
  350. for _, key := range ssh {
  351. s = append(s, fmt.Sprintf("%s=%s", key.ID, key.Path))
  352. }
  353. return s
  354. }
  355. func toBakeSecrets(project *types.Project, secrets []types.ServiceSecretConfig) []string {
  356. var s []string
  357. for _, ref := range secrets {
  358. def := project.Secrets[ref.Source]
  359. target := ref.Target
  360. if target == "" {
  361. target = ref.Source
  362. }
  363. switch {
  364. case def.Environment != "":
  365. s = append(s, fmt.Sprintf("id=%s,type=env,env=%s", target, def.Environment))
  366. case def.File != "":
  367. s = append(s, fmt.Sprintf("id=%s,type=file,src=%s", target, def.File))
  368. }
  369. }
  370. return s
  371. }
  372. func filter(environ []string, variable string) []string {
  373. prefix := variable + "="
  374. filtered := make([]string, 0, len(environ))
  375. for _, val := range environ {
  376. if !strings.HasPrefix(val, prefix) {
  377. filtered = append(filtered, val)
  378. }
  379. }
  380. return filtered
  381. }
  382. func replace(environ []string, variable, value string) []string {
  383. filtered := filter(environ, variable)
  384. return append(filtered, fmt.Sprintf("%s=%s", variable, value))
  385. }
  386. func dockerFilePath(ctxName string, dockerfile string) string {
  387. if dockerfile == "" {
  388. return ""
  389. }
  390. if urlutil.IsGitURL(ctxName) {
  391. return dockerfile
  392. }
  393. if !filepath.IsAbs(dockerfile) {
  394. dockerfile = filepath.Join(ctxName, dockerfile)
  395. }
  396. symlinks, err := filepath.EvalSymlinks(dockerfile)
  397. if err == nil {
  398. return symlinks
  399. }
  400. return dockerfile
  401. }