build.go 19 KB


  1. /*
  2. Copyright 2020 Docker Compose CLI authors
  3. Licensed under the Apache License, Version 2.0 (the "License");
  4. you may not use this file except in compliance with the License.
  5. You may obtain a copy of the License at
  6. http://www.apache.org/licenses/LICENSE-2.0
  7. Unless required by applicable law or agreed to in writing, software
  8. distributed under the License is distributed on an "AS IS" BASIS,
  9. WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  10. See the License for the specific language governing permissions and
  11. limitations under the License.
  12. */
  13. package compose
  14. import (
  15. "context"
  16. "errors"
  17. "fmt"
  18. "os"
  19. "strconv"
  20. "strings"
  21. "time"
  22. "github.com/compose-spec/compose-go/v2/types"
  23. "github.com/containerd/platforms"
  24. "github.com/docker/buildx/build"
  25. "github.com/docker/buildx/builder"
  26. "github.com/docker/buildx/store/storeutil"
  27. "github.com/docker/buildx/util/buildflags"
  28. xprogress "github.com/docker/buildx/util/progress"
  29. "github.com/docker/cli/cli/command"
  30. cliopts "github.com/docker/cli/opts"
  31. "github.com/docker/compose/v2/internal/tracing"
  32. "github.com/docker/compose/v2/pkg/api"
  33. "github.com/docker/compose/v2/pkg/progress"
  34. "github.com/docker/compose/v2/pkg/utils"
  35. "github.com/docker/docker/api/types/container"
  36. bclient "github.com/moby/buildkit/client"
  37. "github.com/moby/buildkit/session"
  38. "github.com/moby/buildkit/session/auth/authprovider"
  39. "github.com/moby/buildkit/session/secrets/secretsprovider"
  40. "github.com/moby/buildkit/session/sshforward/sshprovider"
  41. "github.com/moby/buildkit/util/entitlements"
  42. "github.com/moby/buildkit/util/progress/progressui"
  43. specs "github.com/opencontainers/image-spec/specs-go/v1"
  44. "github.com/sirupsen/logrus"
  45. "go.opentelemetry.io/otel/attribute"
  46. "go.opentelemetry.io/otel/trace"
  47. // required to get default driver registered
  48. _ "github.com/docker/buildx/driver/docker"
  49. )
  50. func (s *composeService) Build(ctx context.Context, project *types.Project, options api.BuildOptions) error {
  51. err := options.Apply(project)
  52. if err != nil {
  53. return err
  54. }
  55. return progress.RunWithTitle(ctx, func(ctx context.Context) error {
  56. return tracing.SpanWrapFunc("project/build", tracing.ProjectOptions(ctx, project),
  57. func(ctx context.Context) error {
  58. _, err := s.build(ctx, project, options, nil)
  59. return err
  60. })(ctx)
  61. }, s.stdinfo(), "Building")
  62. }
  63. //nolint:gocyclo
  64. func (s *composeService) build(ctx context.Context, project *types.Project, options api.BuildOptions, localImages map[string]api.ImageSummary) (map[string]string, error) {
  65. imageIDs := map[string]string{}
  66. serviceToBuild := types.Services{}
  67. var policy types.DependencyOption = types.IgnoreDependencies
  68. if options.Deps {
  69. policy = types.IncludeDependencies
  70. }
  71. if len(options.Services) == 0 {
  72. options.Services = project.ServiceNames()
  73. }
  74. // also include services used as additional_contexts with service: prefix
  75. options.Services = addBuildDependencies(options.Services, project)
  76. // Some build dependencies we just introduced may not be enabled
  77. var err error
  78. project, err = project.WithServicesEnabled(options.Services...)
  79. if err != nil {
  80. return nil, err
  81. }
  82. project, err = project.WithSelectedServices(options.Services)
  83. if err != nil {
  84. return nil, err
  85. }
  86. err = project.ForEachService(options.Services, func(serviceName string, service *types.ServiceConfig) error {
  87. if service.Build == nil {
  88. return nil
  89. }
  90. image := api.GetImageNameOrDefault(*service, project.Name)
  91. _, localImagePresent := localImages[image]
  92. if localImagePresent && service.PullPolicy != types.PullPolicyBuild {
  93. return nil
  94. }
  95. serviceToBuild[serviceName] = *service
  96. return nil
  97. }, policy)
  98. if err != nil || len(serviceToBuild) == 0 {
  99. return imageIDs, err
  100. }
  101. bake, err := buildWithBake(s.dockerCli)
  102. if err != nil {
  103. return nil, err
  104. }
  105. if bake || options.Print {
  106. trace.SpanFromContext(ctx).SetAttributes(attribute.String("builder", "bake"))
  107. return s.doBuildBake(ctx, project, serviceToBuild, options)
  108. }
  109. // Not using bake, additional_context: service:xx is implemented by building images in dependency order
  110. project, err = project.WithServicesTransform(func(serviceName string, service types.ServiceConfig) (types.ServiceConfig, error) {
  111. if service.Build != nil {
  112. for _, c := range service.Build.AdditionalContexts {
  113. if t, found := strings.CutPrefix(c, types.ServicePrefix); found {
  114. if service.DependsOn == nil {
  115. service.DependsOn = map[string]types.ServiceDependency{}
  116. }
  117. service.DependsOn[t] = types.ServiceDependency{
  118. Condition: "build", // non-canonical, but will force dependency graph ordering
  119. }
  120. }
  121. }
  122. }
  123. return service, nil
  124. })
  125. if err != nil {
  126. return imageIDs, err
  127. }
  128. // Initialize buildkit nodes
  129. buildkitEnabled, err := s.dockerCli.BuildKitEnabled()
  130. if err != nil {
  131. return nil, err
  132. }
  133. var (
  134. b *builder.Builder
  135. nodes []builder.Node
  136. w *xprogress.Printer
  137. )
  138. if buildkitEnabled {
  139. builderName := options.Builder
  140. if builderName == "" {
  141. builderName = os.Getenv("BUILDX_BUILDER")
  142. }
  143. b, err = builder.New(s.dockerCli, builder.WithName(builderName))
  144. if err != nil {
  145. return nil, err
  146. }
  147. nodes, err = b.LoadNodes(ctx)
  148. if err != nil {
  149. return nil, err
  150. }
  151. // Progress needs its own context that lives longer than the
  152. // build one otherwise it won't read all the messages from
  153. // build and will lock
  154. progressCtx, cancel := context.WithCancel(context.Background())
  155. defer cancel()
  156. if options.Quiet {
  157. options.Progress = progress.ModeQuiet
  158. }
  159. if options.Progress == progress.ModeAuto {
  160. options.Progress = os.Getenv("BUILDKIT_PROGRESS")
  161. }
  162. w, err = xprogress.NewPrinter(progressCtx, os.Stdout, progressui.DisplayMode(options.Progress),
  163. xprogress.WithDesc(
  164. fmt.Sprintf("building with %q instance using %s driver", b.Name, b.Driver),
  165. fmt.Sprintf("%s:%s", b.Driver, b.Name),
  166. ))
  167. if err != nil {
  168. return nil, err
  169. }
  170. }
  171. // we use a pre-allocated []string to collect build digest by service index while running concurrent goroutines
  172. builtDigests := make([]string, len(project.Services))
  173. names := project.ServiceNames()
  174. getServiceIndex := func(name string) int {
  175. for idx, n := range names {
  176. if n == name {
  177. return idx
  178. }
  179. }
  180. return -1
  181. }
  182. cw := progress.ContextWriter(ctx)
  183. err = InDependencyOrder(ctx, project, func(ctx context.Context, name string) error {
  184. service, ok := serviceToBuild[name]
  185. if !ok {
  186. return nil
  187. }
  188. serviceName := fmt.Sprintf("Service %s", name)
  189. if !buildkitEnabled {
  190. trace.SpanFromContext(ctx).SetAttributes(attribute.String("builder", "classic"))
  191. cw.Event(progress.BuildingEvent(serviceName))
  192. id, err := s.doBuildClassic(ctx, project, service, options)
  193. if err != nil {
  194. return err
  195. }
  196. cw.Event(progress.BuiltEvent(serviceName))
  197. builtDigests[getServiceIndex(name)] = id
  198. if options.Push {
  199. return s.push(ctx, project, api.PushOptions{})
  200. }
  201. return nil
  202. }
  203. if options.Memory != 0 {
  204. _, _ = fmt.Fprintln(s.stderr(), "WARNING: --memory is not supported by BuildKit and will be ignored")
  205. }
  206. buildOptions, err := s.toBuildOptions(project, service, options)
  207. if err != nil {
  208. return err
  209. }
  210. trace.SpanFromContext(ctx).SetAttributes(attribute.String("builder", "buildkit"))
  211. digest, err := s.doBuildBuildkit(ctx, name, buildOptions, w, nodes)
  212. if err != nil {
  213. return err
  214. }
  215. builtDigests[getServiceIndex(name)] = digest
  216. return nil
  217. }, func(traversal *graphTraversal) {
  218. traversal.maxConcurrency = s.maxConcurrency
  219. })
  220. // enforce all build event get consumed
  221. if buildkitEnabled {
  222. if errw := w.Wait(); errw != nil {
  223. return nil, errw
  224. }
  225. }
  226. if err != nil {
  227. return nil, err
  228. }
  229. for i, imageDigest := range builtDigests {
  230. if imageDigest != "" {
  231. service := project.Services[names[i]]
  232. imageRef := api.GetImageNameOrDefault(service, project.Name)
  233. imageIDs[imageRef] = imageDigest
  234. cw.Event(progress.BuiltEvent(names[i]))
  235. }
  236. }
  237. return imageIDs, err
  238. }
  239. func (s *composeService) ensureImagesExists(ctx context.Context, project *types.Project, buildOpts *api.BuildOptions, quietPull bool) error {
  240. for name, service := range project.Services {
  241. if service.Provider == nil && service.Image == "" && service.Build == nil {
  242. return fmt.Errorf("invalid service %q. Must specify either image or build", name)
  243. }
  244. }
  245. images, err := s.getLocalImagesDigests(ctx, project)
  246. if err != nil {
  247. return err
  248. }
  249. err = tracing.SpanWrapFunc("project/pull", tracing.ProjectOptions(ctx, project),
  250. func(ctx context.Context) error {
  251. return s.pullRequiredImages(ctx, project, images, quietPull)
  252. },
  253. )(ctx)
  254. if err != nil {
  255. return err
  256. }
  257. if buildOpts != nil {
  258. err = tracing.SpanWrapFunc("project/build", tracing.ProjectOptions(ctx, project),
  259. func(ctx context.Context) error {
  260. builtImages, err := s.build(ctx, project, *buildOpts, images)
  261. if err != nil {
  262. return err
  263. }
  264. for name, digest := range builtImages {
  265. images[name] = api.ImageSummary{
  266. Repository: name,
  267. ID: digest,
  268. LastTagTime: time.Now(),
  269. }
  270. }
  271. return nil
  272. },
  273. )(ctx)
  274. if err != nil {
  275. return err
  276. }
  277. }
  278. // set digest as com.docker.compose.image label so we can detect outdated containers
  279. for name, service := range project.Services {
  280. image := api.GetImageNameOrDefault(service, project.Name)
  281. img, ok := images[image]
  282. if ok {
  283. service.CustomLabels.Add(api.ImageDigestLabel, img.ID)
  284. }
  285. project.Services[name] = service
  286. }
  287. return nil
  288. }
  289. func (s *composeService) getLocalImagesDigests(ctx context.Context, project *types.Project) (map[string]api.ImageSummary, error) {
  290. imageNames := utils.Set[string]{}
  291. for _, s := range project.Services {
  292. imageNames.Add(api.GetImageNameOrDefault(s, project.Name))
  293. for _, volume := range s.Volumes {
  294. if volume.Type == types.VolumeTypeImage {
  295. imageNames.Add(volume.Source)
  296. }
  297. }
  298. }
  299. imgs, err := s.getImageSummaries(ctx, imageNames.Elements())
  300. if err != nil {
  301. return nil, err
  302. }
  303. for i, service := range project.Services {
  304. imgName := api.GetImageNameOrDefault(service, project.Name)
  305. img, ok := imgs[imgName]
  306. if !ok {
  307. continue
  308. }
  309. if service.Platform != "" {
  310. platform, err := platforms.Parse(service.Platform)
  311. if err != nil {
  312. return nil, err
  313. }
  314. inspect, err := s.apiClient().ImageInspect(ctx, img.ID)
  315. if err != nil {
  316. return nil, err
  317. }
  318. actual := specs.Platform{
  319. Architecture: inspect.Architecture,
  320. OS: inspect.Os,
  321. Variant: inspect.Variant,
  322. }
  323. if !platforms.NewMatcher(platform).Match(actual) {
  324. logrus.Debugf("local image %s doesn't match expected platform %s", service.Image, service.Platform)
  325. // there is a local image, but it's for the wrong platform, so
  326. // pretend it doesn't exist so that we can pull/build an image
  327. // for the correct platform instead
  328. delete(imgs, imgName)
  329. }
  330. }
  331. project.Services[i].CustomLabels.Add(api.ImageDigestLabel, img.ID)
  332. }
  333. return imgs, nil
  334. }
  335. // resolveAndMergeBuildArgs returns the final set of build arguments to use for the service image build.
  336. //
  337. // First, args directly defined via `build.args` in YAML are considered.
  338. // Then, any explicitly passed args in opts (e.g. via `--build-arg` on the CLI) are merged, overwriting any
  339. // keys that already exist.
  340. // Next, any keys without a value are resolved using the project environment.
  341. //
  342. // Finally, standard proxy variables based on the Docker client configuration are added, but will not overwrite
  343. // any values if already present.
  344. func resolveAndMergeBuildArgs(dockerCli command.Cli, project *types.Project, service types.ServiceConfig, opts api.BuildOptions) types.MappingWithEquals {
  345. result := make(types.MappingWithEquals).
  346. OverrideBy(service.Build.Args).
  347. OverrideBy(opts.Args).
  348. Resolve(envResolver(project.Environment))
  349. // proxy arguments do NOT override and should NOT have env resolution applied,
  350. // so they're handled last
  351. for k, v := range storeutil.GetProxyConfig(dockerCli) {
  352. if _, ok := result[k]; !ok {
  353. v := v
  354. result[k] = &v
  355. }
  356. }
  357. return result
  358. }
  359. //nolint:gocyclo
  360. func (s *composeService) toBuildOptions(project *types.Project, service types.ServiceConfig, options api.BuildOptions) (build.Options, error) {
  361. plats, err := parsePlatforms(service)
  362. if err != nil {
  363. return build.Options{}, err
  364. }
  365. cacheFrom, err := buildflags.ParseCacheEntry(service.Build.CacheFrom)
  366. if err != nil {
  367. return build.Options{}, err
  368. }
  369. cacheTo, err := buildflags.ParseCacheEntry(service.Build.CacheTo)
  370. if err != nil {
  371. return build.Options{}, err
  372. }
  373. sessionConfig := []session.Attachable{
  374. authprovider.NewDockerAuthProvider(authprovider.DockerAuthProviderConfig{
  375. ConfigFile: s.configFile(),
  376. }),
  377. }
  378. if len(options.SSHs) > 0 || len(service.Build.SSH) > 0 {
  379. sshAgentProvider, err := sshAgentProvider(append(service.Build.SSH, options.SSHs...))
  380. if err != nil {
  381. return build.Options{}, err
  382. }
  383. sessionConfig = append(sessionConfig, sshAgentProvider)
  384. }
  385. if len(service.Build.Secrets) > 0 {
  386. secretsProvider, err := addSecretsConfig(project, service)
  387. if err != nil {
  388. return build.Options{}, err
  389. }
  390. sessionConfig = append(sessionConfig, secretsProvider)
  391. }
  392. tags := []string{api.GetImageNameOrDefault(service, project.Name)}
  393. if len(service.Build.Tags) > 0 {
  394. tags = append(tags, service.Build.Tags...)
  395. }
  396. allow, err := buildflags.ParseEntitlements(service.Build.Entitlements)
  397. if err != nil {
  398. return build.Options{}, err
  399. }
  400. if service.Build.Privileged {
  401. allow = append(allow, entitlements.EntitlementSecurityInsecure.String())
  402. }
  403. imageLabels := getImageBuildLabels(project, service)
  404. push := options.Push && service.Image != ""
  405. exports := []bclient.ExportEntry{{
  406. Type: "docker",
  407. Attrs: map[string]string{
  408. "load": "true",
  409. "push": fmt.Sprint(push),
  410. },
  411. }}
  412. if len(service.Build.Platforms) > 1 {
  413. exports = []bclient.ExportEntry{{
  414. Type: "image",
  415. Attrs: map[string]string{
  416. "push": fmt.Sprint(push),
  417. },
  418. }}
  419. }
  420. sp, err := build.ReadSourcePolicy()
  421. if err != nil {
  422. return build.Options{}, err
  423. }
  424. attests := map[string]*string{}
  425. if options.Attestations {
  426. if service.Build.Provenance != "" {
  427. attests["provenance"] = attestation(service.Build.Provenance, "provenance")
  428. }
  429. if service.Build.SBOM != "" {
  430. attests["sbom"] = attestation(service.Build.SBOM, "sbom")
  431. }
  432. }
  433. if options.Provenance != "" {
  434. attests["provenance"] = attestation(options.Provenance, "provenance")
  435. }
  436. if options.SBOM != "" {
  437. attests["sbom"] = attestation(options.SBOM, "sbom")
  438. }
  439. return build.Options{
  440. Inputs: build.Inputs{
  441. ContextPath: service.Build.Context,
  442. DockerfileInline: service.Build.DockerfileInline,
  443. DockerfilePath: dockerFilePath(service.Build.Context, service.Build.Dockerfile),
  444. NamedContexts: toBuildContexts(service, project),
  445. },
  446. CacheFrom: build.CreateCaches(cacheFrom),
  447. CacheTo: build.CreateCaches(cacheTo),
  448. NoCache: service.Build.NoCache,
  449. Pull: service.Build.Pull,
  450. BuildArgs: flatten(resolveAndMergeBuildArgs(s.dockerCli, project, service, options)),
  451. Tags: tags,
  452. Target: service.Build.Target,
  453. Exports: exports,
  454. Platforms: plats,
  455. Labels: imageLabels,
  456. NetworkMode: service.Build.Network,
  457. ExtraHosts: service.Build.ExtraHosts.AsList(":"),
  458. Ulimits: toUlimitOpt(service.Build.Ulimits),
  459. Session: sessionConfig,
  460. Allow: allow,
  461. SourcePolicy: sp,
  462. Attests: attests,
  463. }, nil
  464. }
  465. func attestation(attest string, val string) *string {
  466. if b, err := strconv.ParseBool(val); err == nil {
  467. s := fmt.Sprintf("type=%s,disabled=%t", attest, b)
  468. return &s
  469. } else {
  470. s := fmt.Sprintf("type=%s,%s", attest, val)
  471. return &s
  472. }
  473. }
  474. func toUlimitOpt(ulimits map[string]*types.UlimitsConfig) *cliopts.UlimitOpt {
  475. ref := map[string]*container.Ulimit{}
  476. for _, limit := range toUlimits(ulimits) {
  477. ref[limit.Name] = &container.Ulimit{
  478. Name: limit.Name,
  479. Hard: limit.Hard,
  480. Soft: limit.Soft,
  481. }
  482. }
  483. return cliopts.NewUlimitOpt(&ref)
  484. }
  485. func flatten(in types.MappingWithEquals) types.Mapping {
  486. out := types.Mapping{}
  487. if len(in) == 0 {
  488. return out
  489. }
  490. for k, v := range in {
  491. if v == nil {
  492. continue
  493. }
  494. out[k] = *v
  495. }
  496. return out
  497. }
  498. func sshAgentProvider(sshKeys types.SSHConfig) (session.Attachable, error) {
  499. sshConfig := make([]sshprovider.AgentConfig, 0, len(sshKeys))
  500. for _, sshKey := range sshKeys {
  501. sshConfig = append(sshConfig, sshprovider.AgentConfig{
  502. ID: sshKey.ID,
  503. Paths: []string{sshKey.Path},
  504. })
  505. }
  506. return sshprovider.NewSSHAgentProvider(sshConfig)
  507. }
  508. func addSecretsConfig(project *types.Project, service types.ServiceConfig) (session.Attachable, error) {
  509. var sources []secretsprovider.Source
  510. for _, secret := range service.Build.Secrets {
  511. config := project.Secrets[secret.Source]
  512. id := secret.Source
  513. if secret.Target != "" {
  514. id = secret.Target
  515. }
  516. switch {
  517. case config.File != "":
  518. sources = append(sources, secretsprovider.Source{
  519. ID: id,
  520. FilePath: config.File,
  521. })
  522. case config.Environment != "":
  523. sources = append(sources, secretsprovider.Source{
  524. ID: id,
  525. Env: config.Environment,
  526. })
  527. default:
  528. return nil, fmt.Errorf("build.secrets only supports environment or file-based secrets: %q", secret.Source)
  529. }
  530. if secret.UID != "" || secret.GID != "" || secret.Mode != nil {
  531. logrus.Warn("secrets `uid`, `gid` and `mode` are not supported by BuildKit, they will be ignored")
  532. }
  533. }
  534. store, err := secretsprovider.NewStore(sources)
  535. if err != nil {
  536. return nil, err
  537. }
  538. return secretsprovider.NewSecretProvider(store), nil
  539. }
  540. func getImageBuildLabels(project *types.Project, service types.ServiceConfig) types.Labels {
  541. ret := make(types.Labels)
  542. if service.Build != nil {
  543. for k, v := range service.Build.Labels {
  544. ret.Add(k, v)
  545. }
  546. }
  547. ret.Add(api.VersionLabel, api.ComposeVersion)
  548. ret.Add(api.ProjectLabel, project.Name)
  549. ret.Add(api.ServiceLabel, service.Name)
  550. return ret
  551. }
  552. func toBuildContexts(service types.ServiceConfig, project *types.Project) map[string]build.NamedContext {
  553. namedContexts := map[string]build.NamedContext{}
  554. for name, contextPath := range service.Build.AdditionalContexts {
  555. if strings.HasPrefix(contextPath, types.ServicePrefix) {
  556. // image we depend on has been built previously, as we run in dependency order.
  557. // so we convert the service reference into an image reference
  558. target := contextPath[len(types.ServicePrefix):]
  559. image := api.GetImageNameOrDefault(project.Services[target], project.Name)
  560. contextPath = "docker-image://" + image
  561. }
  562. namedContexts[name] = build.NamedContext{Path: contextPath}
  563. }
  564. return namedContexts
  565. }
  566. func parsePlatforms(service types.ServiceConfig) ([]specs.Platform, error) {
  567. if service.Build == nil || len(service.Build.Platforms) == 0 {
  568. return nil, nil
  569. }
  570. var errs []error
  571. ret := make([]specs.Platform, len(service.Build.Platforms))
  572. for i := range service.Build.Platforms {
  573. p, err := platforms.Parse(service.Build.Platforms[i])
  574. if err != nil {
  575. errs = append(errs, err)
  576. } else {
  577. ret[i] = p
  578. }
  579. }
  580. if err := errors.Join(errs...); err != nil {
  581. return nil, err
  582. }
  583. return ret, nil
  584. }
  585. func addBuildDependencies(services []string, project *types.Project) []string {
  586. servicesWithDependencies := utils.NewSet(services...)
  587. for _, service := range services {
  588. s, ok := project.Services[service]
  589. if !ok {
  590. s = project.DisabledServices[service]
  591. }
  592. b := s.Build
  593. if b != nil {
  594. for _, target := range b.AdditionalContexts {
  595. if s, found := strings.CutPrefix(target, types.ServicePrefix); found {
  596. servicesWithDependencies.Add(s)
  597. }
  598. }
  599. }
  600. }
  601. if len(servicesWithDependencies) > len(services) {
  602. return addBuildDependencies(servicesWithDependencies.Elements(), project)
  603. }
  604. return servicesWithDependencies.Elements()
  605. }