build_bake.go 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444
  1. /*
  2. Copyright 2020 Docker Compose CLI authors
  3. Licensed under the Apache License, Version 2.0 (the "License");
  4. you may not use this file except in compliance with the License.
  5. You may obtain a copy of the License at
  6. http://www.apache.org/licenses/LICENSE-2.0
  7. Unless required by applicable law or agreed to in writing, software
  8. distributed under the License is distributed on an "AS IS" BASIS,
  9. WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  10. See the License for the specific language governing permissions and
  11. limitations under the License.
  12. */
  13. package compose
  14. import (
  15. "bufio"
  16. "bytes"
  17. "context"
  18. "encoding/json"
  19. "errors"
  20. "fmt"
  21. "io"
  22. "math/rand"
  23. "os"
  24. "os/exec"
  25. "path/filepath"
  26. "slices"
  27. "strconv"
  28. "strings"
  29. "github.com/compose-spec/compose-go/v2/types"
  30. "github.com/docker/cli/cli-plugins/manager"
  31. "github.com/docker/cli/cli/command"
  32. "github.com/docker/compose/v2/pkg/api"
  33. "github.com/docker/compose/v2/pkg/progress"
  34. "github.com/docker/docker/api/types/versions"
  35. "github.com/docker/docker/builder/remotecontext/urlutil"
  36. "github.com/moby/buildkit/client"
  37. "github.com/moby/buildkit/util/gitutil"
  38. "github.com/moby/buildkit/util/progress/progressui"
  39. "github.com/sirupsen/logrus"
  40. "github.com/spf13/cobra"
  41. "golang.org/x/sync/errgroup"
  42. )
  43. func buildWithBake(dockerCli command.Cli) (bool, error) {
  44. b, ok := os.LookupEnv("COMPOSE_BAKE")
  45. if !ok {
  46. b = "true"
  47. }
  48. bake, err := strconv.ParseBool(b)
  49. if err != nil {
  50. return false, err
  51. }
  52. if !bake {
  53. return false, nil
  54. }
  55. enabled, err := dockerCli.BuildKitEnabled()
  56. if err != nil {
  57. return false, err
  58. }
  59. if !enabled {
  60. logrus.Warnf("Docker Compose is configured to build using Bake, but buildkit isn't enabled")
  61. return false, nil
  62. }
  63. _, err = manager.GetPlugin("buildx", dockerCli, &cobra.Command{})
  64. if err != nil {
  65. if manager.IsNotFound(err) {
  66. logrus.Warnf("Docker Compose is configured to build using Bake, but buildx isn't installed")
  67. return false, nil
  68. }
  69. return false, err
  70. }
  71. return true, err
  72. }
  73. // We _could_ use bake.* types from github.com/docker/buildx but long term plan is to remove buildx as a dependency
  74. type bakeConfig struct {
  75. Groups map[string]bakeGroup `json:"group"`
  76. Targets map[string]bakeTarget `json:"target"`
  77. }
  78. type bakeGroup struct {
  79. Targets []string `json:"targets"`
  80. }
  81. type bakeTarget struct {
  82. Context string `json:"context,omitempty"`
  83. Contexts map[string]string `json:"contexts,omitempty"`
  84. Dockerfile string `json:"dockerfile,omitempty"`
  85. DockerfileInline string `json:"dockerfile-inline,omitempty"`
  86. Args map[string]string `json:"args,omitempty"`
  87. Labels map[string]string `json:"labels,omitempty"`
  88. Tags []string `json:"tags,omitempty"`
  89. CacheFrom []string `json:"cache-from,omitempty"`
  90. CacheTo []string `json:"cache-to,omitempty"`
  91. Target string `json:"target,omitempty"`
  92. Secrets []string `json:"secret,omitempty"`
  93. SSH []string `json:"ssh,omitempty"`
  94. Platforms []string `json:"platforms,omitempty"`
  95. Pull bool `json:"pull,omitempty"`
  96. NoCache bool `json:"no-cache,omitempty"`
  97. NetworkMode string `json:"network,omitempty"`
  98. NoCacheFilter []string `json:"no-cache-filter,omitempty"`
  99. ShmSize types.UnitBytes `json:"shm-size,omitempty"`
  100. Ulimits []string `json:"ulimits,omitempty"`
  101. Call string `json:"call,omitempty"`
  102. Entitlements []string `json:"entitlements,omitempty"`
  103. ExtraHosts map[string]string `json:"extra-hosts,omitempty"`
  104. Outputs []string `json:"output,omitempty"`
  105. }
  106. type bakeMetadata map[string]buildStatus
  107. type buildStatus struct {
  108. Digest string `json:"containerimage.digest"`
  109. Image string `json:"image.name"`
  110. }
  111. func (s *composeService) doBuildBake(ctx context.Context, project *types.Project, serviceToBeBuild types.Services, options api.BuildOptions) (map[string]string, error) { //nolint:gocyclo
  112. eg := errgroup.Group{}
  113. ch := make(chan *client.SolveStatus)
  114. display, err := progressui.NewDisplay(os.Stdout, progressui.DisplayMode(options.Progress))
  115. if err != nil {
  116. return nil, err
  117. }
  118. eg.Go(func() error {
  119. _, err := display.UpdateFrom(ctx, ch)
  120. return err
  121. })
  122. cfg := bakeConfig{
  123. Groups: map[string]bakeGroup{},
  124. Targets: map[string]bakeTarget{},
  125. }
  126. var (
  127. group bakeGroup
  128. privileged bool
  129. read []string
  130. targets = make(map[string]string, len(serviceToBeBuild)) // service name -> build target
  131. )
  132. // produce a unique ID for service used as bake target
  133. for serviceName := range project.Services {
  134. t := strings.ReplaceAll(serviceName, ".", "_")
  135. for {
  136. if _, ok := targets[serviceName]; !ok {
  137. targets[serviceName] = t
  138. break
  139. }
  140. t += "_"
  141. }
  142. }
  143. for serviceName, service := range project.Services {
  144. if service.Build == nil {
  145. continue
  146. }
  147. build := *service.Build
  148. args := types.Mapping{}
  149. for k, v := range resolveAndMergeBuildArgs(s.dockerCli, project, service, options) {
  150. if v == nil {
  151. continue
  152. }
  153. args[k] = *v
  154. }
  155. entitlements := build.Entitlements
  156. if slices.Contains(build.Entitlements, "security.insecure") {
  157. privileged = true
  158. }
  159. if build.Privileged {
  160. entitlements = append(entitlements, "security.insecure")
  161. privileged = true
  162. }
  163. var outputs []string
  164. var call string
  165. push := options.Push && service.Image != ""
  166. switch {
  167. case options.Check:
  168. call = "lint"
  169. case len(service.Build.Platforms) > 1:
  170. outputs = []string{fmt.Sprintf("type=image,push=%t", push)}
  171. default:
  172. outputs = []string{fmt.Sprintf("type=docker,load=true,push=%t", push)}
  173. }
  174. read = append(read, build.Context)
  175. for _, path := range build.AdditionalContexts {
  176. _, err := gitutil.ParseGitRef(path)
  177. if !strings.Contains(path, "://") && err != nil {
  178. read = append(read, path)
  179. }
  180. }
  181. target := targets[serviceName]
  182. cfg.Targets[target] = bakeTarget{
  183. Context: build.Context,
  184. Contexts: additionalContexts(build.AdditionalContexts, targets),
  185. Dockerfile: dockerFilePath(build.Context, build.Dockerfile),
  186. DockerfileInline: strings.ReplaceAll(build.DockerfileInline, "${", "$${"),
  187. Args: args,
  188. Labels: build.Labels,
  189. Tags: append(build.Tags, api.GetImageNameOrDefault(service, project.Name)),
  190. CacheFrom: build.CacheFrom,
  191. CacheTo: build.CacheTo,
  192. NetworkMode: build.Network,
  193. Platforms: build.Platforms,
  194. Target: build.Target,
  195. Secrets: toBakeSecrets(project, build.Secrets),
  196. SSH: toBakeSSH(append(build.SSH, options.SSHs...)),
  197. Pull: options.Pull,
  198. NoCache: options.NoCache,
  199. ShmSize: build.ShmSize,
  200. Ulimits: toBakeUlimits(build.Ulimits),
  201. Entitlements: entitlements,
  202. ExtraHosts: toBakeExtraHosts(build.ExtraHosts),
  203. Outputs: outputs,
  204. Call: call,
  205. }
  206. }
  207. // create a bake group with targets for services to build
  208. for serviceName, service := range serviceToBeBuild {
  209. if service.Build == nil {
  210. continue
  211. }
  212. group.Targets = append(group.Targets, targets[serviceName])
  213. }
  214. cfg.Groups["default"] = group
  215. b, err := json.MarshalIndent(cfg, "", " ")
  216. if err != nil {
  217. return nil, err
  218. }
  219. if options.Print {
  220. _, err = fmt.Fprintln(s.stdout(), string(b))
  221. return nil, err
  222. }
  223. logrus.Debugf("bake build config:\n%s", string(b))
  224. var metadataFile string
  225. for {
  226. // we don't use os.CreateTemp here as we need a temporary file name, but don't want it actually created
  227. // as bake relies on atomicwriter and this creates conflict during rename
  228. metadataFile = filepath.Join(os.TempDir(), fmt.Sprintf("compose-build-metadataFile-%d.json", rand.Int31()))
  229. if _, err = os.Stat(metadataFile); os.IsNotExist(err) {
  230. break
  231. }
  232. }
  233. defer func() {
  234. _ = os.Remove(metadataFile)
  235. }()
  236. buildx, err := manager.GetPlugin("buildx", s.dockerCli, &cobra.Command{})
  237. if err != nil {
  238. return nil, err
  239. }
  240. args := []string{"bake", "--file", "-", "--progress", "rawjson", "--metadata-file", metadataFile}
  241. mustAllow := buildx.Version != "" && versions.GreaterThanOrEqualTo(buildx.Version[1:], "0.17.0")
  242. if mustAllow {
  243. // FIXME we should prompt user about this, but this is a breaking change in UX
  244. for _, path := range read {
  245. args = append(args, "--allow", "fs.read="+path)
  246. }
  247. if privileged {
  248. args = append(args, "--allow", "security.insecure")
  249. }
  250. }
  251. if options.Builder != "" {
  252. args = append(args, "--builder", options.Builder)
  253. }
  254. if options.Quiet {
  255. args = append(args, "--progress=quiet")
  256. }
  257. logrus.Debugf("Executing bake with args: %v", args)
  258. cmd := exec.CommandContext(ctx, buildx.Path, args...)
  259. err = s.prepareShellOut(ctx, project, cmd)
  260. if err != nil {
  261. return nil, err
  262. }
  263. cmd.Stdout = s.stdout()
  264. cmd.Stdin = bytes.NewBuffer(b)
  265. pipe, err := cmd.StderrPipe()
  266. if err != nil {
  267. return nil, err
  268. }
  269. var errMessage []string
  270. reader := bufio.NewReader(pipe)
  271. err = cmd.Start()
  272. if err != nil {
  273. return nil, err
  274. }
  275. eg.Go(cmd.Wait)
  276. for {
  277. line, readErr := reader.ReadString('\n')
  278. if readErr != nil {
  279. if readErr == io.EOF {
  280. break
  281. } else {
  282. return nil, fmt.Errorf("failed to execute bake: %w", readErr)
  283. }
  284. }
  285. decoder := json.NewDecoder(strings.NewReader(line))
  286. var status client.SolveStatus
  287. err := decoder.Decode(&status)
  288. if err != nil {
  289. if strings.HasPrefix(line, "ERROR: ") {
  290. errMessage = append(errMessage, line[7:])
  291. } else {
  292. errMessage = append(errMessage, line)
  293. }
  294. continue
  295. }
  296. ch <- &status
  297. }
  298. close(ch) // stop build progress UI
  299. err = eg.Wait()
  300. if err != nil {
  301. if len(errMessage) > 0 {
  302. return nil, errors.New(strings.Join(errMessage, "\n"))
  303. }
  304. return nil, fmt.Errorf("failed to execute bake: %w", err)
  305. }
  306. b, err = os.ReadFile(metadataFile)
  307. if err != nil {
  308. return nil, err
  309. }
  310. var md bakeMetadata
  311. err = json.Unmarshal(b, &md)
  312. if err != nil {
  313. return nil, err
  314. }
  315. cw := progress.ContextWriter(ctx)
  316. results := map[string]string{}
  317. for name := range serviceToBeBuild {
  318. target := targets[name]
  319. built, ok := md[target]
  320. if !ok {
  321. return nil, fmt.Errorf("build result not found in Bake metadata for service %s", name)
  322. }
  323. results[name] = built.Digest
  324. cw.Event(progress.BuiltEvent(name))
  325. }
  326. return results, nil
  327. }
  328. func toBakeExtraHosts(hosts types.HostsList) map[string]string {
  329. m := make(map[string]string)
  330. for k, v := range hosts {
  331. m[k] = strings.Join(v, ",")
  332. }
  333. return m
  334. }
  335. func additionalContexts(contexts types.Mapping, targets map[string]string) map[string]string {
  336. ac := map[string]string{}
  337. for k, v := range contexts {
  338. if target, found := strings.CutPrefix(v, types.ServicePrefix); found {
  339. v = "target:" + targets[target]
  340. }
  341. ac[k] = v
  342. }
  343. return ac
  344. }
  345. func toBakeUlimits(ulimits map[string]*types.UlimitsConfig) []string {
  346. s := []string{}
  347. for u, l := range ulimits {
  348. if l.Single > 0 {
  349. s = append(s, fmt.Sprintf("%s=%d", u, l.Single))
  350. } else {
  351. s = append(s, fmt.Sprintf("%s=%d:%d", u, l.Soft, l.Hard))
  352. }
  353. }
  354. return s
  355. }
  356. func toBakeSSH(ssh types.SSHConfig) []string {
  357. var s []string
  358. for _, key := range ssh {
  359. s = append(s, fmt.Sprintf("%s=%s", key.ID, key.Path))
  360. }
  361. return s
  362. }
  363. func toBakeSecrets(project *types.Project, secrets []types.ServiceSecretConfig) []string {
  364. var s []string
  365. for _, ref := range secrets {
  366. def := project.Secrets[ref.Source]
  367. target := ref.Target
  368. if target == "" {
  369. target = ref.Source
  370. }
  371. switch {
  372. case def.Environment != "":
  373. s = append(s, fmt.Sprintf("id=%s,type=env,env=%s", target, def.Environment))
  374. case def.File != "":
  375. s = append(s, fmt.Sprintf("id=%s,type=file,src=%s", target, def.File))
  376. }
  377. }
  378. return s
  379. }
  380. func dockerFilePath(ctxName string, dockerfile string) string {
  381. if dockerfile == "" {
  382. return ""
  383. }
  384. if urlutil.IsGitURL(ctxName) {
  385. return dockerfile
  386. }
  387. if !filepath.IsAbs(dockerfile) {
  388. dockerfile = filepath.Join(ctxName, dockerfile)
  389. }
  390. symlinks, err := filepath.EvalSymlinks(dockerfile)
  391. if err == nil {
  392. return symlinks
  393. }
  394. return dockerfile
  395. }