build_bake.go 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564
  1. /*
  2. Copyright 2020 Docker Compose CLI authors
  3. Licensed under the Apache License, Version 2.0 (the "License");
  4. you may not use this file except in compliance with the License.
  5. You may obtain a copy of the License at
  6. http://www.apache.org/licenses/LICENSE-2.0
  7. Unless required by applicable law or agreed to in writing, software
  8. distributed under the License is distributed on an "AS IS" BASIS,
  9. WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  10. See the License for the specific language governing permissions and
  11. limitations under the License.
  12. */
  13. package compose
  14. import (
  15. "bufio"
  16. "bytes"
  17. "context"
  18. "crypto/sha1"
  19. "encoding/json"
  20. "errors"
  21. "fmt"
  22. "io"
  23. "math/rand"
  24. "os"
  25. "os/exec"
  26. "path/filepath"
  27. "slices"
  28. "strconv"
  29. "strings"
  30. "github.com/compose-spec/compose-go/v2/types"
  31. "github.com/containerd/errdefs"
  32. "github.com/docker/cli/cli-plugins/manager"
  33. "github.com/docker/cli/cli/command"
  34. "github.com/docker/compose/v2/pkg/api"
  35. "github.com/docker/compose/v2/pkg/progress"
  36. "github.com/docker/docker/api/types/versions"
  37. "github.com/docker/docker/builder/remotecontext/urlutil"
  38. "github.com/moby/buildkit/client"
  39. gitutil "github.com/moby/buildkit/frontend/dockerfile/dfgitutil"
  40. "github.com/moby/buildkit/util/progress/progressui"
  41. "github.com/sirupsen/logrus"
  42. "github.com/spf13/cobra"
  43. "golang.org/x/sync/errgroup"
  44. )
  45. func buildWithBake(dockerCli command.Cli) (bool, error) {
  46. b, ok := os.LookupEnv("COMPOSE_BAKE")
  47. if !ok {
  48. b = "true"
  49. }
  50. bake, err := strconv.ParseBool(b)
  51. if err != nil {
  52. return false, err
  53. }
  54. if !bake {
  55. if ok {
  56. logrus.Warnf("COMPOSE_BAKE=false is deprecated, support for internal compose builder will be removed in next release")
  57. }
  58. return false, nil
  59. }
  60. enabled, err := dockerCli.BuildKitEnabled()
  61. if err != nil {
  62. return false, err
  63. }
  64. if !enabled {
  65. logrus.Warnf("Docker Compose is configured to build using Bake, but buildkit isn't enabled")
  66. return false, nil
  67. }
  68. _, err = manager.GetPlugin("buildx", dockerCli, &cobra.Command{})
  69. if err != nil {
  70. if errdefs.IsNotFound(err) {
  71. logrus.Warnf("Docker Compose is configured to build using Bake, but buildx isn't installed")
  72. return false, nil
  73. }
  74. return false, err
  75. }
  76. return true, err
  77. }
  78. // We _could_ use bake.* types from github.com/docker/buildx but long term plan is to remove buildx as a dependency
  79. type bakeConfig struct {
  80. Groups map[string]bakeGroup `json:"group"`
  81. Targets map[string]bakeTarget `json:"target"`
  82. }
  83. type bakeGroup struct {
  84. Targets []string `json:"targets"`
  85. }
  86. type bakeTarget struct {
  87. Context string `json:"context,omitempty"`
  88. Contexts map[string]string `json:"contexts,omitempty"`
  89. Dockerfile string `json:"dockerfile,omitempty"`
  90. DockerfileInline string `json:"dockerfile-inline,omitempty"`
  91. Args map[string]string `json:"args,omitempty"`
  92. Labels map[string]string `json:"labels,omitempty"`
  93. Tags []string `json:"tags,omitempty"`
  94. CacheFrom []string `json:"cache-from,omitempty"`
  95. CacheTo []string `json:"cache-to,omitempty"`
  96. Target string `json:"target,omitempty"`
  97. Secrets []string `json:"secret,omitempty"`
  98. SSH []string `json:"ssh,omitempty"`
  99. Platforms []string `json:"platforms,omitempty"`
  100. Pull bool `json:"pull,omitempty"`
  101. NoCache bool `json:"no-cache,omitempty"`
  102. NetworkMode string `json:"network,omitempty"`
  103. NoCacheFilter []string `json:"no-cache-filter,omitempty"`
  104. ShmSize types.UnitBytes `json:"shm-size,omitempty"`
  105. Ulimits []string `json:"ulimits,omitempty"`
  106. Call string `json:"call,omitempty"`
  107. Entitlements []string `json:"entitlements,omitempty"`
  108. ExtraHosts map[string]string `json:"extra-hosts,omitempty"`
  109. Outputs []string `json:"output,omitempty"`
  110. Attest []string `json:"attest,omitempty"`
  111. }
  112. type bakeMetadata map[string]buildStatus
  113. type buildStatus struct {
  114. Digest string `json:"containerimage.digest"`
  115. Image string `json:"image.name"`
  116. }
  117. func (s *composeService) doBuildBake(ctx context.Context, project *types.Project, serviceToBeBuild types.Services, options api.BuildOptions) (map[string]string, error) { //nolint:gocyclo
  118. eg := errgroup.Group{}
  119. ch := make(chan *client.SolveStatus)
  120. if options.Progress == progress.ModeAuto {
  121. options.Progress = os.Getenv("BUILDKIT_PROGRESS")
  122. }
  123. displayMode := progressui.DisplayMode(options.Progress)
  124. out := options.Out
  125. if out == nil {
  126. if displayMode == progress.ModeAuto && !s.dockerCli.Out().IsTerminal() {
  127. displayMode = progressui.PlainMode
  128. }
  129. out = os.Stdout // should be s.dockerCli.Out(), but NewDisplay require access to the underlying *File
  130. }
  131. display, err := progressui.NewDisplay(out, displayMode)
  132. if err != nil {
  133. return nil, err
  134. }
  135. eg.Go(func() error {
  136. _, err := display.UpdateFrom(ctx, ch)
  137. return err
  138. })
  139. cfg := bakeConfig{
  140. Groups: map[string]bakeGroup{},
  141. Targets: map[string]bakeTarget{},
  142. }
  143. var (
  144. group bakeGroup
  145. privileged bool
  146. read []string
  147. expectedImages = make(map[string]string, len(serviceToBeBuild)) // service name -> expected image
  148. targets = make(map[string]string, len(serviceToBeBuild)) // service name -> build target
  149. )
  150. // produce a unique ID for service used as bake target
  151. for serviceName := range project.Services {
  152. t := strings.ReplaceAll(serviceName, ".", "_")
  153. for {
  154. if _, ok := targets[serviceName]; !ok {
  155. targets[serviceName] = t
  156. break
  157. }
  158. t += "_"
  159. }
  160. }
  161. // tmpSecrets stores secret set by environment variables, so we don't have to "pollute" bake process's environment
  162. tmpSecrets, err := os.MkdirTemp("", "secrets")
  163. if err != nil {
  164. return nil, err
  165. }
  166. defer func() {
  167. rerr := os.RemoveAll(tmpSecrets)
  168. if rerr != nil {
  169. logrus.Warnf("Failed to removed temporary secrets directory %s: %s", tmpSecrets, rerr.Error())
  170. }
  171. }()
  172. for serviceName, service := range project.Services {
  173. if service.Build == nil {
  174. continue
  175. }
  176. build := *service.Build
  177. labels := getImageBuildLabels(project, service)
  178. args := types.Mapping{}
  179. for k, v := range resolveAndMergeBuildArgs(s.dockerCli, project, service, options) {
  180. if v == nil {
  181. continue
  182. }
  183. args[k] = *v
  184. }
  185. entitlements := build.Entitlements
  186. if slices.Contains(build.Entitlements, "security.insecure") {
  187. privileged = true
  188. }
  189. if build.Privileged {
  190. entitlements = append(entitlements, "security.insecure")
  191. privileged = true
  192. }
  193. var outputs []string
  194. var call string
  195. push := options.Push && service.Image != ""
  196. switch {
  197. case options.Check:
  198. call = "lint"
  199. case len(service.Build.Platforms) > 1:
  200. outputs = []string{fmt.Sprintf("type=image,push=%t", push)}
  201. default:
  202. if push {
  203. outputs = []string{"type=registry"}
  204. } else {
  205. outputs = []string{"type=docker"}
  206. }
  207. }
  208. read = append(read, build.Context)
  209. for _, path := range build.AdditionalContexts {
  210. _, _, err := gitutil.ParseGitRef(path)
  211. if !strings.Contains(path, "://") && err != nil {
  212. read = append(read, path)
  213. }
  214. }
  215. image := api.GetImageNameOrDefault(service, project.Name)
  216. expectedImages[serviceName] = image
  217. pull := service.Build.Pull || options.Pull
  218. noCache := service.Build.NoCache || options.NoCache
  219. target := targets[serviceName]
  220. secrets, err := toBakeSecrets(project, build.Secrets, tmpSecrets)
  221. if err != nil {
  222. return nil, err
  223. }
  224. cfg.Targets[target] = bakeTarget{
  225. Context: build.Context,
  226. Contexts: additionalContexts(build.AdditionalContexts, targets),
  227. Dockerfile: dockerFilePath(build.Context, build.Dockerfile),
  228. DockerfileInline: strings.ReplaceAll(build.DockerfileInline, "${", "$${"),
  229. Args: args,
  230. Labels: labels,
  231. Tags: append(build.Tags, image),
  232. CacheFrom: build.CacheFrom,
  233. CacheTo: build.CacheTo,
  234. NetworkMode: build.Network,
  235. Platforms: build.Platforms,
  236. Target: build.Target,
  237. Secrets: secrets,
  238. SSH: toBakeSSH(append(build.SSH, options.SSHs...)),
  239. Pull: pull,
  240. NoCache: noCache,
  241. ShmSize: build.ShmSize,
  242. Ulimits: toBakeUlimits(build.Ulimits),
  243. Entitlements: entitlements,
  244. ExtraHosts: toBakeExtraHosts(build.ExtraHosts),
  245. Outputs: outputs,
  246. Call: call,
  247. Attest: toBakeAttest(build),
  248. }
  249. }
  250. // create a bake group with targets for services to build
  251. for serviceName, service := range serviceToBeBuild {
  252. if service.Build == nil {
  253. continue
  254. }
  255. group.Targets = append(group.Targets, targets[serviceName])
  256. }
  257. cfg.Groups["default"] = group
  258. b, err := json.MarshalIndent(cfg, "", " ")
  259. if err != nil {
  260. return nil, err
  261. }
  262. if options.Print {
  263. _, err = fmt.Fprintln(s.stdout(), string(b))
  264. return nil, err
  265. }
  266. logrus.Debugf("bake build config:\n%s", string(b))
  267. var metadataFile string
  268. for {
  269. // we don't use os.CreateTemp here as we need a temporary file name, but don't want it actually created
  270. // as bake relies on atomicwriter and this creates conflict during rename
  271. metadataFile = filepath.Join(os.TempDir(), fmt.Sprintf("compose-build-metadataFile-%d.json", rand.Int31()))
  272. if _, err = os.Stat(metadataFile); os.IsNotExist(err) {
  273. break
  274. }
  275. }
  276. defer func() {
  277. _ = os.Remove(metadataFile)
  278. }()
  279. buildx, err := manager.GetPlugin("buildx", s.dockerCli, &cobra.Command{})
  280. if err != nil {
  281. return nil, err
  282. }
  283. args := []string{"bake", "--file", "-", "--progress", "rawjson", "--metadata-file", metadataFile}
  284. mustAllow := buildx.Version != "" && versions.GreaterThanOrEqualTo(buildx.Version[1:], "0.17.0")
  285. if mustAllow {
  286. // FIXME we should prompt user about this, but this is a breaking change in UX
  287. for _, path := range read {
  288. args = append(args, "--allow", "fs.read="+path)
  289. }
  290. if privileged {
  291. args = append(args, "--allow", "security.insecure")
  292. }
  293. }
  294. if options.SBOM != "" {
  295. args = append(args, "--sbom="+options.SBOM)
  296. }
  297. if options.Provenance != "" {
  298. args = append(args, "--provenance="+options.Provenance)
  299. }
  300. if options.Builder != "" {
  301. args = append(args, "--builder", options.Builder)
  302. }
  303. if options.Quiet {
  304. args = append(args, "--progress=quiet")
  305. }
  306. logrus.Debugf("Executing bake with args: %v", args)
  307. if s.dryRun {
  308. return dryRunBake(ctx, cfg), nil
  309. }
  310. cmd := exec.CommandContext(ctx, buildx.Path, args...)
  311. err = s.prepareShellOut(ctx, types.NewMapping(os.Environ()), cmd)
  312. if err != nil {
  313. return nil, err
  314. }
  315. endpoint, cleanup, err := s.propagateDockerEndpoint()
  316. if err != nil {
  317. return nil, err
  318. }
  319. cmd.Env = append(cmd.Env, endpoint...)
  320. defer cleanup()
  321. cmd.Stdout = s.stdout()
  322. cmd.Stdin = bytes.NewBuffer(b)
  323. pipe, err := cmd.StderrPipe()
  324. if err != nil {
  325. return nil, err
  326. }
  327. var errMessage []string
  328. reader := bufio.NewReader(pipe)
  329. err = cmd.Start()
  330. if err != nil {
  331. return nil, err
  332. }
  333. eg.Go(cmd.Wait)
  334. for {
  335. line, readErr := reader.ReadString('\n')
  336. if readErr != nil {
  337. if readErr == io.EOF {
  338. break
  339. } else {
  340. return nil, fmt.Errorf("failed to execute bake: %w", readErr)
  341. }
  342. }
  343. decoder := json.NewDecoder(strings.NewReader(line))
  344. var status client.SolveStatus
  345. err := decoder.Decode(&status)
  346. if err != nil {
  347. if strings.HasPrefix(line, "ERROR: ") {
  348. errMessage = append(errMessage, line[7:])
  349. } else {
  350. errMessage = append(errMessage, line)
  351. }
  352. continue
  353. }
  354. ch <- &status
  355. }
  356. close(ch) // stop build progress UI
  357. err = eg.Wait()
  358. if err != nil {
  359. if len(errMessage) > 0 {
  360. return nil, errors.New(strings.Join(errMessage, "\n"))
  361. }
  362. return nil, fmt.Errorf("failed to execute bake: %w", err)
  363. }
  364. b, err = os.ReadFile(metadataFile)
  365. if err != nil {
  366. return nil, err
  367. }
  368. var md bakeMetadata
  369. err = json.Unmarshal(b, &md)
  370. if err != nil {
  371. return nil, err
  372. }
  373. cw := progress.ContextWriter(ctx)
  374. results := map[string]string{}
  375. for name := range serviceToBeBuild {
  376. image := expectedImages[name]
  377. target := targets[name]
  378. built, ok := md[target]
  379. if !ok {
  380. return nil, fmt.Errorf("build result not found in Bake metadata for service %s", name)
  381. }
  382. results[image] = built.Digest
  383. cw.Event(progress.BuiltEvent(image))
  384. }
  385. return results, nil
  386. }
  387. func toBakeExtraHosts(hosts types.HostsList) map[string]string {
  388. m := make(map[string]string)
  389. for k, v := range hosts {
  390. m[k] = strings.Join(v, ",")
  391. }
  392. return m
  393. }
  394. func additionalContexts(contexts types.Mapping, targets map[string]string) map[string]string {
  395. ac := map[string]string{}
  396. for k, v := range contexts {
  397. if target, found := strings.CutPrefix(v, types.ServicePrefix); found {
  398. v = "target:" + targets[target]
  399. }
  400. ac[k] = v
  401. }
  402. return ac
  403. }
  404. func toBakeUlimits(ulimits map[string]*types.UlimitsConfig) []string {
  405. s := []string{}
  406. for u, l := range ulimits {
  407. if l.Single > 0 {
  408. s = append(s, fmt.Sprintf("%s=%d", u, l.Single))
  409. } else {
  410. s = append(s, fmt.Sprintf("%s=%d:%d", u, l.Soft, l.Hard))
  411. }
  412. }
  413. return s
  414. }
  415. func toBakeSSH(ssh types.SSHConfig) []string {
  416. var s []string
  417. for _, key := range ssh {
  418. s = append(s, fmt.Sprintf("%s=%s", key.ID, key.Path))
  419. }
  420. return s
  421. }
  422. func toBakeSecrets(project *types.Project, secrets []types.ServiceSecretConfig, tmpSecrets string) ([]string, error) {
  423. var s []string
  424. for _, ref := range secrets {
  425. def := project.Secrets[ref.Source]
  426. target := ref.Target
  427. if target == "" {
  428. target = ref.Source
  429. }
  430. switch {
  431. case def.Environment != "":
  432. sf := filepath.Join(tmpSecrets, def.Environment)
  433. err := os.WriteFile(sf, []byte(project.Environment[def.Environment]), 0o600)
  434. if err != nil {
  435. return nil, err
  436. }
  437. s = append(s, fmt.Sprintf("id=%s,type=file,src=%s", target, sf))
  438. case def.File != "":
  439. s = append(s, fmt.Sprintf("id=%s,type=file,src=%s", target, def.File))
  440. }
  441. }
  442. return s, nil
  443. }
  444. func toBakeAttest(build types.BuildConfig) []string {
  445. var attests []string
  446. // Handle per-service provenance configuration (only from build config, not global options)
  447. if build.Provenance != "" {
  448. if build.Provenance == "true" {
  449. attests = append(attests, "type=provenance")
  450. } else if build.Provenance != "false" {
  451. attests = append(attests, fmt.Sprintf("type=provenance,%s", build.Provenance))
  452. }
  453. }
  454. // Handle per-service SBOM configuration (only from build config, not global options)
  455. if build.SBOM != "" {
  456. if build.SBOM == "true" {
  457. attests = append(attests, "type=sbom")
  458. } else if build.SBOM != "false" {
  459. attests = append(attests, fmt.Sprintf("type=sbom,%s", build.SBOM))
  460. }
  461. }
  462. return attests
  463. }
  464. func dockerFilePath(ctxName string, dockerfile string) string {
  465. if dockerfile == "" {
  466. return ""
  467. }
  468. if urlutil.IsGitURL(ctxName) {
  469. return dockerfile
  470. }
  471. if !filepath.IsAbs(dockerfile) {
  472. dockerfile = filepath.Join(ctxName, dockerfile)
  473. }
  474. dir := filepath.Dir(dockerfile)
  475. symlinks, err := filepath.EvalSymlinks(dir)
  476. if err == nil {
  477. return filepath.Join(symlinks, filepath.Base(dockerfile))
  478. }
  479. return dockerfile
  480. }
  481. func dryRunBake(ctx context.Context, cfg bakeConfig) map[string]string {
  482. w := progress.ContextWriter(ctx)
  483. bakeResponse := map[string]string{}
  484. for name, target := range cfg.Targets {
  485. dryRunUUID := fmt.Sprintf("dryRun-%x", sha1.Sum([]byte(name)))
  486. displayDryRunBuildEvent(w, name, dryRunUUID, target.Tags[0])
  487. bakeResponse[name] = dryRunUUID
  488. }
  489. for name := range bakeResponse {
  490. w.Event(progress.BuiltEvent(name))
  491. }
  492. return bakeResponse
  493. }
  494. func displayDryRunBuildEvent(w progress.Writer, name string, dryRunUUID, tag string) {
  495. w.Event(progress.Event{
  496. ID: name + " ==>",
  497. Status: progress.Done,
  498. Text: fmt.Sprintf("==> writing image %s", dryRunUUID),
  499. })
  500. w.Event(progress.Event{
  501. ID: name + " ==> ==>",
  502. Status: progress.Done,
  503. Text: fmt.Sprintf(`naming to %s`, tag),
  504. })
  505. }