build_bake.go 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482
  1. /*
  2. Copyright 2020 Docker Compose CLI authors
  3. Licensed under the Apache License, Version 2.0 (the "License");
  4. you may not use this file except in compliance with the License.
  5. You may obtain a copy of the License at
  6. http://www.apache.org/licenses/LICENSE-2.0
  7. Unless required by applicable law or agreed to in writing, software
  8. distributed under the License is distributed on an "AS IS" BASIS,
  9. WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  10. See the License for the specific language governing permissions and
  11. limitations under the License.
  12. */
  13. package compose
  14. import (
  15. "bufio"
  16. "bytes"
  17. "context"
  18. "crypto/sha1"
  19. "encoding/json"
  20. "errors"
  21. "fmt"
  22. "io"
  23. "math/rand"
  24. "os"
  25. "os/exec"
  26. "path/filepath"
  27. "slices"
  28. "strconv"
  29. "strings"
  30. "github.com/compose-spec/compose-go/v2/types"
  31. "github.com/docker/cli/cli-plugins/manager"
  32. "github.com/docker/cli/cli/command"
  33. "github.com/docker/compose/v2/pkg/api"
  34. "github.com/docker/compose/v2/pkg/progress"
  35. "github.com/docker/docker/api/types/versions"
  36. "github.com/docker/docker/builder/remotecontext/urlutil"
  37. "github.com/moby/buildkit/client"
  38. "github.com/moby/buildkit/util/gitutil"
  39. "github.com/moby/buildkit/util/progress/progressui"
  40. "github.com/sirupsen/logrus"
  41. "github.com/spf13/cobra"
  42. "golang.org/x/sync/errgroup"
  43. )
  44. func buildWithBake(dockerCli command.Cli) (bool, error) {
  45. b, ok := os.LookupEnv("COMPOSE_BAKE")
  46. if !ok {
  47. b = "true"
  48. }
  49. bake, err := strconv.ParseBool(b)
  50. if err != nil {
  51. return false, err
  52. }
  53. if !bake {
  54. return false, nil
  55. }
  56. enabled, err := dockerCli.BuildKitEnabled()
  57. if err != nil {
  58. return false, err
  59. }
  60. if !enabled {
  61. logrus.Warnf("Docker Compose is configured to build using Bake, but buildkit isn't enabled")
  62. return false, nil
  63. }
  64. _, err = manager.GetPlugin("buildx", dockerCli, &cobra.Command{})
  65. if err != nil {
  66. if manager.IsNotFound(err) {
  67. logrus.Warnf("Docker Compose is configured to build using Bake, but buildx isn't installed")
  68. return false, nil
  69. }
  70. return false, err
  71. }
  72. return true, err
  73. }
  74. // We _could_ use bake.* types from github.com/docker/buildx but long term plan is to remove buildx as a dependency
  75. type bakeConfig struct {
  76. Groups map[string]bakeGroup `json:"group"`
  77. Targets map[string]bakeTarget `json:"target"`
  78. }
  79. type bakeGroup struct {
  80. Targets []string `json:"targets"`
  81. }
  82. type bakeTarget struct {
  83. Context string `json:"context,omitempty"`
  84. Contexts map[string]string `json:"contexts,omitempty"`
  85. Dockerfile string `json:"dockerfile,omitempty"`
  86. DockerfileInline string `json:"dockerfile-inline,omitempty"`
  87. Args map[string]string `json:"args,omitempty"`
  88. Labels map[string]string `json:"labels,omitempty"`
  89. Tags []string `json:"tags,omitempty"`
  90. CacheFrom []string `json:"cache-from,omitempty"`
  91. CacheTo []string `json:"cache-to,omitempty"`
  92. Target string `json:"target,omitempty"`
  93. Secrets []string `json:"secret,omitempty"`
  94. SSH []string `json:"ssh,omitempty"`
  95. Platforms []string `json:"platforms,omitempty"`
  96. Pull bool `json:"pull,omitempty"`
  97. NoCache bool `json:"no-cache,omitempty"`
  98. NetworkMode string `json:"network,omitempty"`
  99. NoCacheFilter []string `json:"no-cache-filter,omitempty"`
  100. ShmSize types.UnitBytes `json:"shm-size,omitempty"`
  101. Ulimits []string `json:"ulimits,omitempty"`
  102. Call string `json:"call,omitempty"`
  103. Entitlements []string `json:"entitlements,omitempty"`
  104. ExtraHosts map[string]string `json:"extra-hosts,omitempty"`
  105. Outputs []string `json:"output,omitempty"`
  106. }
  107. type bakeMetadata map[string]buildStatus
  108. type buildStatus struct {
  109. Digest string `json:"containerimage.digest"`
  110. Image string `json:"image.name"`
  111. }
  112. func (s *composeService) doBuildBake(ctx context.Context, project *types.Project, serviceToBeBuild types.Services, options api.BuildOptions) (map[string]string, error) { //nolint:gocyclo
  113. eg := errgroup.Group{}
  114. ch := make(chan *client.SolveStatus)
  115. display, err := progressui.NewDisplay(os.Stdout, progressui.DisplayMode(options.Progress))
  116. if err != nil {
  117. return nil, err
  118. }
  119. eg.Go(func() error {
  120. _, err := display.UpdateFrom(ctx, ch)
  121. return err
  122. })
  123. cfg := bakeConfig{
  124. Groups: map[string]bakeGroup{},
  125. Targets: map[string]bakeTarget{},
  126. }
  127. var (
  128. group bakeGroup
  129. privileged bool
  130. read []string
  131. expectedImages = make(map[string]string, len(serviceToBeBuild)) // service name -> expected image
  132. targets = make(map[string]string, len(serviceToBeBuild)) // service name -> build target
  133. )
  134. // produce a unique ID for service used as bake target
  135. for serviceName := range project.Services {
  136. t := strings.ReplaceAll(serviceName, ".", "_")
  137. for {
  138. if _, ok := targets[serviceName]; !ok {
  139. targets[serviceName] = t
  140. break
  141. }
  142. t += "_"
  143. }
  144. }
  145. for serviceName, service := range project.Services {
  146. if service.Build == nil {
  147. continue
  148. }
  149. build := *service.Build
  150. labels := getImageBuildLabels(project, service)
  151. args := types.Mapping{}
  152. for k, v := range resolveAndMergeBuildArgs(s.dockerCli, project, service, options) {
  153. if v == nil {
  154. continue
  155. }
  156. args[k] = *v
  157. }
  158. entitlements := build.Entitlements
  159. if slices.Contains(build.Entitlements, "security.insecure") {
  160. privileged = true
  161. }
  162. if build.Privileged {
  163. entitlements = append(entitlements, "security.insecure")
  164. privileged = true
  165. }
  166. var outputs []string
  167. var call string
  168. push := options.Push && service.Image != ""
  169. switch {
  170. case options.Check:
  171. call = "lint"
  172. case len(service.Build.Platforms) > 1:
  173. outputs = []string{fmt.Sprintf("type=image,push=%t", push)}
  174. default:
  175. outputs = []string{fmt.Sprintf("type=docker,load=true,push=%t", push)}
  176. }
  177. read = append(read, build.Context)
  178. for _, path := range build.AdditionalContexts {
  179. _, err := gitutil.ParseGitRef(path)
  180. if !strings.Contains(path, "://") && err != nil {
  181. read = append(read, path)
  182. }
  183. }
  184. image := api.GetImageNameOrDefault(service, project.Name)
  185. expectedImages[serviceName] = image
  186. target := targets[serviceName]
  187. cfg.Targets[target] = bakeTarget{
  188. Context: build.Context,
  189. Contexts: additionalContexts(build.AdditionalContexts, targets),
  190. Dockerfile: dockerFilePath(build.Context, build.Dockerfile),
  191. DockerfileInline: strings.ReplaceAll(build.DockerfileInline, "${", "$${"),
  192. Args: args,
  193. Labels: labels,
  194. Tags: append(build.Tags, image),
  195. CacheFrom: build.CacheFrom,
  196. CacheTo: build.CacheTo,
  197. NetworkMode: build.Network,
  198. Platforms: build.Platforms,
  199. Target: build.Target,
  200. Secrets: toBakeSecrets(project, build.Secrets),
  201. SSH: toBakeSSH(append(build.SSH, options.SSHs...)),
  202. Pull: options.Pull,
  203. NoCache: options.NoCache,
  204. ShmSize: build.ShmSize,
  205. Ulimits: toBakeUlimits(build.Ulimits),
  206. Entitlements: entitlements,
  207. ExtraHosts: toBakeExtraHosts(build.ExtraHosts),
  208. Outputs: outputs,
  209. Call: call,
  210. }
  211. }
  212. // create a bake group with targets for services to build
  213. for serviceName, service := range serviceToBeBuild {
  214. if service.Build == nil {
  215. continue
  216. }
  217. group.Targets = append(group.Targets, targets[serviceName])
  218. }
  219. cfg.Groups["default"] = group
  220. b, err := json.MarshalIndent(cfg, "", " ")
  221. if err != nil {
  222. return nil, err
  223. }
  224. if options.Print {
  225. _, err = fmt.Fprintln(s.stdout(), string(b))
  226. return nil, err
  227. }
  228. logrus.Debugf("bake build config:\n%s", string(b))
  229. var metadataFile string
  230. for {
  231. // we don't use os.CreateTemp here as we need a temporary file name, but don't want it actually created
  232. // as bake relies on atomicwriter and this creates conflict during rename
  233. metadataFile = filepath.Join(os.TempDir(), fmt.Sprintf("compose-build-metadataFile-%d.json", rand.Int31()))
  234. if _, err = os.Stat(metadataFile); os.IsNotExist(err) {
  235. break
  236. }
  237. }
  238. defer func() {
  239. _ = os.Remove(metadataFile)
  240. }()
  241. buildx, err := manager.GetPlugin("buildx", s.dockerCli, &cobra.Command{})
  242. if err != nil {
  243. return nil, err
  244. }
  245. args := []string{"bake", "--file", "-", "--progress", "rawjson", "--metadata-file", metadataFile}
  246. mustAllow := buildx.Version != "" && versions.GreaterThanOrEqualTo(buildx.Version[1:], "0.17.0")
  247. if mustAllow {
  248. // FIXME we should prompt user about this, but this is a breaking change in UX
  249. for _, path := range read {
  250. args = append(args, "--allow", "fs.read="+path)
  251. }
  252. if privileged {
  253. args = append(args, "--allow", "security.insecure")
  254. }
  255. }
  256. if options.Builder != "" {
  257. args = append(args, "--builder", options.Builder)
  258. }
  259. if options.Quiet {
  260. args = append(args, "--progress=quiet")
  261. }
  262. logrus.Debugf("Executing bake with args: %v", args)
  263. if s.dryRun {
  264. return dryRunBake(ctx, cfg), nil
  265. }
  266. cmd := exec.CommandContext(ctx, buildx.Path, args...)
  267. err = s.prepareShellOut(ctx, project, cmd)
  268. if err != nil {
  269. return nil, err
  270. }
  271. cmd.Stdout = s.stdout()
  272. cmd.Stdin = bytes.NewBuffer(b)
  273. pipe, err := cmd.StderrPipe()
  274. if err != nil {
  275. return nil, err
  276. }
  277. var errMessage []string
  278. reader := bufio.NewReader(pipe)
  279. err = cmd.Start()
  280. if err != nil {
  281. return nil, err
  282. }
  283. eg.Go(cmd.Wait)
  284. for {
  285. line, readErr := reader.ReadString('\n')
  286. if readErr != nil {
  287. if readErr == io.EOF {
  288. break
  289. } else {
  290. return nil, fmt.Errorf("failed to execute bake: %w", readErr)
  291. }
  292. }
  293. decoder := json.NewDecoder(strings.NewReader(line))
  294. var status client.SolveStatus
  295. err := decoder.Decode(&status)
  296. if err != nil {
  297. if strings.HasPrefix(line, "ERROR: ") {
  298. errMessage = append(errMessage, line[7:])
  299. } else {
  300. errMessage = append(errMessage, line)
  301. }
  302. continue
  303. }
  304. ch <- &status
  305. }
  306. close(ch) // stop build progress UI
  307. err = eg.Wait()
  308. if err != nil {
  309. if len(errMessage) > 0 {
  310. return nil, errors.New(strings.Join(errMessage, "\n"))
  311. }
  312. return nil, fmt.Errorf("failed to execute bake: %w", err)
  313. }
  314. b, err = os.ReadFile(metadataFile)
  315. if err != nil {
  316. return nil, err
  317. }
  318. var md bakeMetadata
  319. err = json.Unmarshal(b, &md)
  320. if err != nil {
  321. return nil, err
  322. }
  323. cw := progress.ContextWriter(ctx)
  324. results := map[string]string{}
  325. for name := range serviceToBeBuild {
  326. image := expectedImages[name]
  327. target := targets[name]
  328. built, ok := md[target]
  329. if !ok {
  330. return nil, fmt.Errorf("build result not found in Bake metadata for service %s", name)
  331. }
  332. results[image] = built.Digest
  333. cw.Event(progress.BuiltEvent(image))
  334. }
  335. return results, nil
  336. }
  337. func toBakeExtraHosts(hosts types.HostsList) map[string]string {
  338. m := make(map[string]string)
  339. for k, v := range hosts {
  340. m[k] = strings.Join(v, ",")
  341. }
  342. return m
  343. }
  344. func additionalContexts(contexts types.Mapping, targets map[string]string) map[string]string {
  345. ac := map[string]string{}
  346. for k, v := range contexts {
  347. if target, found := strings.CutPrefix(v, types.ServicePrefix); found {
  348. v = "target:" + targets[target]
  349. }
  350. ac[k] = v
  351. }
  352. return ac
  353. }
  354. func toBakeUlimits(ulimits map[string]*types.UlimitsConfig) []string {
  355. s := []string{}
  356. for u, l := range ulimits {
  357. if l.Single > 0 {
  358. s = append(s, fmt.Sprintf("%s=%d", u, l.Single))
  359. } else {
  360. s = append(s, fmt.Sprintf("%s=%d:%d", u, l.Soft, l.Hard))
  361. }
  362. }
  363. return s
  364. }
  365. func toBakeSSH(ssh types.SSHConfig) []string {
  366. var s []string
  367. for _, key := range ssh {
  368. s = append(s, fmt.Sprintf("%s=%s", key.ID, key.Path))
  369. }
  370. return s
  371. }
  372. func toBakeSecrets(project *types.Project, secrets []types.ServiceSecretConfig) []string {
  373. var s []string
  374. for _, ref := range secrets {
  375. def := project.Secrets[ref.Source]
  376. target := ref.Target
  377. if target == "" {
  378. target = ref.Source
  379. }
  380. switch {
  381. case def.Environment != "":
  382. s = append(s, fmt.Sprintf("id=%s,type=env,env=%s", target, def.Environment))
  383. case def.File != "":
  384. s = append(s, fmt.Sprintf("id=%s,type=file,src=%s", target, def.File))
  385. }
  386. }
  387. return s
  388. }
  389. func dockerFilePath(ctxName string, dockerfile string) string {
  390. if dockerfile == "" {
  391. return ""
  392. }
  393. if urlutil.IsGitURL(ctxName) {
  394. return dockerfile
  395. }
  396. if !filepath.IsAbs(dockerfile) {
  397. dockerfile = filepath.Join(ctxName, dockerfile)
  398. }
  399. dir := filepath.Dir(dockerfile)
  400. symlinks, err := filepath.EvalSymlinks(dir)
  401. if err == nil {
  402. return filepath.Join(symlinks, filepath.Base(dockerfile))
  403. }
  404. return dockerfile
  405. }
  406. func dryRunBake(ctx context.Context, cfg bakeConfig) map[string]string {
  407. w := progress.ContextWriter(ctx)
  408. bakeResponse := map[string]string{}
  409. for name, target := range cfg.Targets {
  410. dryRunUUID := fmt.Sprintf("dryRun-%x", sha1.Sum([]byte(name)))
  411. displayDryRunBuildEvent(w, name, dryRunUUID, target.Tags[0])
  412. bakeResponse[name] = dryRunUUID
  413. }
  414. for name := range bakeResponse {
  415. w.Event(progress.BuiltEvent(name))
  416. }
  417. return bakeResponse
  418. }
  419. func displayDryRunBuildEvent(w progress.Writer, name string, dryRunUUID, tag string) {
  420. w.Event(progress.Event{
  421. ID: name + " ==>",
  422. Status: progress.Done,
  423. Text: fmt.Sprintf("==> writing image %s", dryRunUUID),
  424. })
  425. w.Event(progress.Event{
  426. ID: name + " ==> ==>",
  427. Status: progress.Done,
  428. Text: fmt.Sprintf(`naming to %s`, tag),
  429. })
  430. }