build_bake.go 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501
  1. /*
  2. Copyright 2020 Docker Compose CLI authors
  3. Licensed under the Apache License, Version 2.0 (the "License");
  4. you may not use this file except in compliance with the License.
  5. You may obtain a copy of the License at
  6. http://www.apache.org/licenses/LICENSE-2.0
  7. Unless required by applicable law or agreed to in writing, software
  8. distributed under the License is distributed on an "AS IS" BASIS,
  9. WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  10. See the License for the specific language governing permissions and
  11. limitations under the License.
  12. */
  13. package compose
  14. import (
  15. "bufio"
  16. "bytes"
  17. "context"
  18. "crypto/sha1"
  19. "encoding/json"
  20. "errors"
  21. "fmt"
  22. "io"
  23. "math/rand"
  24. "os"
  25. "os/exec"
  26. "path/filepath"
  27. "slices"
  28. "strconv"
  29. "strings"
  30. "github.com/compose-spec/compose-go/v2/types"
  31. "github.com/containerd/errdefs"
  32. "github.com/docker/cli/cli-plugins/manager"
  33. "github.com/docker/cli/cli/command"
  34. "github.com/docker/compose/v2/pkg/api"
  35. "github.com/docker/compose/v2/pkg/progress"
  36. "github.com/docker/docker/api/types/versions"
  37. "github.com/docker/docker/builder/remotecontext/urlutil"
  38. "github.com/moby/buildkit/client"
  39. "github.com/moby/buildkit/util/gitutil"
  40. "github.com/moby/buildkit/util/progress/progressui"
  41. "github.com/sirupsen/logrus"
  42. "github.com/spf13/cobra"
  43. "golang.org/x/sync/errgroup"
  44. )
  45. func buildWithBake(dockerCli command.Cli) (bool, error) {
  46. b, ok := os.LookupEnv("COMPOSE_BAKE")
  47. if !ok {
  48. b = "true"
  49. }
  50. bake, err := strconv.ParseBool(b)
  51. if err != nil {
  52. return false, err
  53. }
  54. if !bake {
  55. if ok {
  56. logrus.Warnf("COMPOSE_BAKE=false is deprecated, support for internal compose builder will be removed in next release")
  57. }
  58. return false, nil
  59. }
  60. enabled, err := dockerCli.BuildKitEnabled()
  61. if err != nil {
  62. return false, err
  63. }
  64. if !enabled {
  65. logrus.Warnf("Docker Compose is configured to build using Bake, but buildkit isn't enabled")
  66. return false, nil
  67. }
  68. _, err = manager.GetPlugin("buildx", dockerCli, &cobra.Command{})
  69. if err != nil {
  70. if errdefs.IsNotFound(err) {
  71. logrus.Warnf("Docker Compose is configured to build using Bake, but buildx isn't installed")
  72. return false, nil
  73. }
  74. return false, err
  75. }
  76. return true, err
  77. }
  78. // We _could_ use bake.* types from github.com/docker/buildx but long term plan is to remove buildx as a dependency
  79. type bakeConfig struct {
  80. Groups map[string]bakeGroup `json:"group"`
  81. Targets map[string]bakeTarget `json:"target"`
  82. }
  83. type bakeGroup struct {
  84. Targets []string `json:"targets"`
  85. }
  86. type bakeTarget struct {
  87. Context string `json:"context,omitempty"`
  88. Contexts map[string]string `json:"contexts,omitempty"`
  89. Dockerfile string `json:"dockerfile,omitempty"`
  90. DockerfileInline string `json:"dockerfile-inline,omitempty"`
  91. Args map[string]string `json:"args,omitempty"`
  92. Labels map[string]string `json:"labels,omitempty"`
  93. Tags []string `json:"tags,omitempty"`
  94. CacheFrom []string `json:"cache-from,omitempty"`
  95. CacheTo []string `json:"cache-to,omitempty"`
  96. Target string `json:"target,omitempty"`
  97. Secrets []string `json:"secret,omitempty"`
  98. SSH []string `json:"ssh,omitempty"`
  99. Platforms []string `json:"platforms,omitempty"`
  100. Pull bool `json:"pull,omitempty"`
  101. NoCache bool `json:"no-cache,omitempty"`
  102. NetworkMode string `json:"network,omitempty"`
  103. NoCacheFilter []string `json:"no-cache-filter,omitempty"`
  104. ShmSize types.UnitBytes `json:"shm-size,omitempty"`
  105. Ulimits []string `json:"ulimits,omitempty"`
  106. Call string `json:"call,omitempty"`
  107. Entitlements []string `json:"entitlements,omitempty"`
  108. ExtraHosts map[string]string `json:"extra-hosts,omitempty"`
  109. Outputs []string `json:"output,omitempty"`
  110. }
  111. type bakeMetadata map[string]buildStatus
  112. type buildStatus struct {
  113. Digest string `json:"containerimage.digest"`
  114. Image string `json:"image.name"`
  115. }
  116. func (s *composeService) doBuildBake(ctx context.Context, project *types.Project, serviceToBeBuild types.Services, options api.BuildOptions) (map[string]string, error) { //nolint:gocyclo
  117. eg := errgroup.Group{}
  118. ch := make(chan *client.SolveStatus)
  119. if options.Progress == progress.ModeAuto {
  120. options.Progress = os.Getenv("BUILDKIT_PROGRESS")
  121. }
  122. displayMode := progressui.DisplayMode(options.Progress)
  123. out := options.Out
  124. if out == nil {
  125. if !s.dockerCli.Out().IsTerminal() {
  126. displayMode = progressui.PlainMode
  127. }
  128. out = os.Stdout // should be s.dockerCli.Out(), but NewDisplay require access to the underlying *File
  129. }
  130. display, err := progressui.NewDisplay(out, displayMode)
  131. if err != nil {
  132. return nil, err
  133. }
  134. eg.Go(func() error {
  135. _, err := display.UpdateFrom(ctx, ch)
  136. return err
  137. })
  138. cfg := bakeConfig{
  139. Groups: map[string]bakeGroup{},
  140. Targets: map[string]bakeTarget{},
  141. }
  142. var (
  143. group bakeGroup
  144. privileged bool
  145. read []string
  146. expectedImages = make(map[string]string, len(serviceToBeBuild)) // service name -> expected image
  147. targets = make(map[string]string, len(serviceToBeBuild)) // service name -> build target
  148. )
  149. // produce a unique ID for service used as bake target
  150. for serviceName := range project.Services {
  151. t := strings.ReplaceAll(serviceName, ".", "_")
  152. for {
  153. if _, ok := targets[serviceName]; !ok {
  154. targets[serviceName] = t
  155. break
  156. }
  157. t += "_"
  158. }
  159. }
  160. for serviceName, service := range project.Services {
  161. if service.Build == nil {
  162. continue
  163. }
  164. build := *service.Build
  165. labels := getImageBuildLabels(project, service)
  166. args := types.Mapping{}
  167. for k, v := range resolveAndMergeBuildArgs(s.dockerCli, project, service, options) {
  168. if v == nil {
  169. continue
  170. }
  171. args[k] = *v
  172. }
  173. entitlements := build.Entitlements
  174. if slices.Contains(build.Entitlements, "security.insecure") {
  175. privileged = true
  176. }
  177. if build.Privileged {
  178. entitlements = append(entitlements, "security.insecure")
  179. privileged = true
  180. }
  181. var outputs []string
  182. var call string
  183. push := options.Push && service.Image != ""
  184. switch {
  185. case options.Check:
  186. call = "lint"
  187. case len(service.Build.Platforms) > 1:
  188. outputs = []string{fmt.Sprintf("type=image,push=%t", push)}
  189. default:
  190. if push {
  191. outputs = []string{"type=registry"}
  192. } else {
  193. outputs = []string{"type=docker"}
  194. }
  195. }
  196. read = append(read, build.Context)
  197. for _, path := range build.AdditionalContexts {
  198. _, err := gitutil.ParseGitRef(path)
  199. if !strings.Contains(path, "://") && err != nil {
  200. read = append(read, path)
  201. }
  202. }
  203. image := api.GetImageNameOrDefault(service, project.Name)
  204. expectedImages[serviceName] = image
  205. target := targets[serviceName]
  206. cfg.Targets[target] = bakeTarget{
  207. Context: build.Context,
  208. Contexts: additionalContexts(build.AdditionalContexts, targets),
  209. Dockerfile: dockerFilePath(build.Context, build.Dockerfile),
  210. DockerfileInline: strings.ReplaceAll(build.DockerfileInline, "${", "$${"),
  211. Args: args,
  212. Labels: labels,
  213. Tags: append(build.Tags, image),
  214. CacheFrom: build.CacheFrom,
  215. CacheTo: build.CacheTo,
  216. NetworkMode: build.Network,
  217. Platforms: build.Platforms,
  218. Target: build.Target,
  219. Secrets: toBakeSecrets(project, build.Secrets),
  220. SSH: toBakeSSH(append(build.SSH, options.SSHs...)),
  221. Pull: options.Pull,
  222. NoCache: options.NoCache,
  223. ShmSize: build.ShmSize,
  224. Ulimits: toBakeUlimits(build.Ulimits),
  225. Entitlements: entitlements,
  226. ExtraHosts: toBakeExtraHosts(build.ExtraHosts),
  227. Outputs: outputs,
  228. Call: call,
  229. }
  230. }
  231. // create a bake group with targets for services to build
  232. for serviceName, service := range serviceToBeBuild {
  233. if service.Build == nil {
  234. continue
  235. }
  236. group.Targets = append(group.Targets, targets[serviceName])
  237. }
  238. cfg.Groups["default"] = group
  239. b, err := json.MarshalIndent(cfg, "", " ")
  240. if err != nil {
  241. return nil, err
  242. }
  243. if options.Print {
  244. _, err = fmt.Fprintln(s.stdout(), string(b))
  245. return nil, err
  246. }
  247. logrus.Debugf("bake build config:\n%s", string(b))
  248. var metadataFile string
  249. for {
  250. // we don't use os.CreateTemp here as we need a temporary file name, but don't want it actually created
  251. // as bake relies on atomicwriter and this creates conflict during rename
  252. metadataFile = filepath.Join(os.TempDir(), fmt.Sprintf("compose-build-metadataFile-%d.json", rand.Int31()))
  253. if _, err = os.Stat(metadataFile); os.IsNotExist(err) {
  254. break
  255. }
  256. }
  257. defer func() {
  258. _ = os.Remove(metadataFile)
  259. }()
  260. buildx, err := manager.GetPlugin("buildx", s.dockerCli, &cobra.Command{})
  261. if err != nil {
  262. return nil, err
  263. }
  264. args := []string{"bake", "--file", "-", "--progress", "rawjson", "--metadata-file", metadataFile}
  265. mustAllow := buildx.Version != "" && versions.GreaterThanOrEqualTo(buildx.Version[1:], "0.17.0")
  266. if mustAllow {
  267. // FIXME we should prompt user about this, but this is a breaking change in UX
  268. for _, path := range read {
  269. args = append(args, "--allow", "fs.read="+path)
  270. }
  271. if privileged {
  272. args = append(args, "--allow", "security.insecure")
  273. }
  274. }
  275. if options.Builder != "" {
  276. args = append(args, "--builder", options.Builder)
  277. }
  278. if options.Quiet {
  279. args = append(args, "--progress=quiet")
  280. }
  281. logrus.Debugf("Executing bake with args: %v", args)
  282. if s.dryRun {
  283. return dryRunBake(ctx, cfg), nil
  284. }
  285. cmd := exec.CommandContext(ctx, buildx.Path, args...)
  286. err = s.prepareShellOut(ctx, project.Environment, cmd)
  287. if err != nil {
  288. return nil, err
  289. }
  290. cmd.Stdout = s.stdout()
  291. cmd.Stdin = bytes.NewBuffer(b)
  292. pipe, err := cmd.StderrPipe()
  293. if err != nil {
  294. return nil, err
  295. }
  296. var errMessage []string
  297. reader := bufio.NewReader(pipe)
  298. err = cmd.Start()
  299. if err != nil {
  300. return nil, err
  301. }
  302. eg.Go(cmd.Wait)
  303. for {
  304. line, readErr := reader.ReadString('\n')
  305. if readErr != nil {
  306. if readErr == io.EOF {
  307. break
  308. } else {
  309. return nil, fmt.Errorf("failed to execute bake: %w", readErr)
  310. }
  311. }
  312. decoder := json.NewDecoder(strings.NewReader(line))
  313. var status client.SolveStatus
  314. err := decoder.Decode(&status)
  315. if err != nil {
  316. if strings.HasPrefix(line, "ERROR: ") {
  317. errMessage = append(errMessage, line[7:])
  318. } else {
  319. errMessage = append(errMessage, line)
  320. }
  321. continue
  322. }
  323. ch <- &status
  324. }
  325. close(ch) // stop build progress UI
  326. err = eg.Wait()
  327. if err != nil {
  328. if len(errMessage) > 0 {
  329. return nil, errors.New(strings.Join(errMessage, "\n"))
  330. }
  331. return nil, fmt.Errorf("failed to execute bake: %w", err)
  332. }
  333. b, err = os.ReadFile(metadataFile)
  334. if err != nil {
  335. return nil, err
  336. }
  337. var md bakeMetadata
  338. err = json.Unmarshal(b, &md)
  339. if err != nil {
  340. return nil, err
  341. }
  342. cw := progress.ContextWriter(ctx)
  343. results := map[string]string{}
  344. for name := range serviceToBeBuild {
  345. image := expectedImages[name]
  346. target := targets[name]
  347. built, ok := md[target]
  348. if !ok {
  349. return nil, fmt.Errorf("build result not found in Bake metadata for service %s", name)
  350. }
  351. results[image] = built.Digest
  352. cw.Event(progress.BuiltEvent(image))
  353. }
  354. return results, nil
  355. }
  356. func toBakeExtraHosts(hosts types.HostsList) map[string]string {
  357. m := make(map[string]string)
  358. for k, v := range hosts {
  359. m[k] = strings.Join(v, ",")
  360. }
  361. return m
  362. }
  363. func additionalContexts(contexts types.Mapping, targets map[string]string) map[string]string {
  364. ac := map[string]string{}
  365. for k, v := range contexts {
  366. if target, found := strings.CutPrefix(v, types.ServicePrefix); found {
  367. v = "target:" + targets[target]
  368. }
  369. ac[k] = v
  370. }
  371. return ac
  372. }
  373. func toBakeUlimits(ulimits map[string]*types.UlimitsConfig) []string {
  374. s := []string{}
  375. for u, l := range ulimits {
  376. if l.Single > 0 {
  377. s = append(s, fmt.Sprintf("%s=%d", u, l.Single))
  378. } else {
  379. s = append(s, fmt.Sprintf("%s=%d:%d", u, l.Soft, l.Hard))
  380. }
  381. }
  382. return s
  383. }
  384. func toBakeSSH(ssh types.SSHConfig) []string {
  385. var s []string
  386. for _, key := range ssh {
  387. s = append(s, fmt.Sprintf("%s=%s", key.ID, key.Path))
  388. }
  389. return s
  390. }
  391. func toBakeSecrets(project *types.Project, secrets []types.ServiceSecretConfig) []string {
  392. var s []string
  393. for _, ref := range secrets {
  394. def := project.Secrets[ref.Source]
  395. target := ref.Target
  396. if target == "" {
  397. target = ref.Source
  398. }
  399. switch {
  400. case def.Environment != "":
  401. s = append(s, fmt.Sprintf("id=%s,type=env,env=%s", target, def.Environment))
  402. case def.File != "":
  403. s = append(s, fmt.Sprintf("id=%s,type=file,src=%s", target, def.File))
  404. }
  405. }
  406. return s
  407. }
  408. func dockerFilePath(ctxName string, dockerfile string) string {
  409. if dockerfile == "" {
  410. return ""
  411. }
  412. if urlutil.IsGitURL(ctxName) {
  413. return dockerfile
  414. }
  415. if !filepath.IsAbs(dockerfile) {
  416. dockerfile = filepath.Join(ctxName, dockerfile)
  417. }
  418. dir := filepath.Dir(dockerfile)
  419. symlinks, err := filepath.EvalSymlinks(dir)
  420. if err == nil {
  421. return filepath.Join(symlinks, filepath.Base(dockerfile))
  422. }
  423. return dockerfile
  424. }
  425. func dryRunBake(ctx context.Context, cfg bakeConfig) map[string]string {
  426. w := progress.ContextWriter(ctx)
  427. bakeResponse := map[string]string{}
  428. for name, target := range cfg.Targets {
  429. dryRunUUID := fmt.Sprintf("dryRun-%x", sha1.Sum([]byte(name)))
  430. displayDryRunBuildEvent(w, name, dryRunUUID, target.Tags[0])
  431. bakeResponse[name] = dryRunUUID
  432. }
  433. for name := range bakeResponse {
  434. w.Event(progress.BuiltEvent(name))
  435. }
  436. return bakeResponse
  437. }
  438. func displayDryRunBuildEvent(w progress.Writer, name string, dryRunUUID, tag string) {
  439. w.Event(progress.Event{
  440. ID: name + " ==>",
  441. Status: progress.Done,
  442. Text: fmt.Sprintf("==> writing image %s", dryRunUUID),
  443. })
  444. w.Event(progress.Event{
  445. ID: name + " ==> ==>",
  446. Status: progress.Done,
  447. Text: fmt.Sprintf(`naming to %s`, tag),
  448. })
  449. }