build_bake.go 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497
  1. /*
  2. Copyright 2020 Docker Compose CLI authors
  3. Licensed under the Apache License, Version 2.0 (the "License");
  4. you may not use this file except in compliance with the License.
  5. You may obtain a copy of the License at
  6. http://www.apache.org/licenses/LICENSE-2.0
  7. Unless required by applicable law or agreed to in writing, software
  8. distributed under the License is distributed on an "AS IS" BASIS,
  9. WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  10. See the License for the specific language governing permissions and
  11. limitations under the License.
  12. */
  13. package compose
  14. import (
  15. "bufio"
  16. "bytes"
  17. "context"
  18. "crypto/sha1"
  19. "encoding/json"
  20. "errors"
  21. "fmt"
  22. "io"
  23. "math/rand"
  24. "os"
  25. "os/exec"
  26. "path/filepath"
  27. "slices"
  28. "strconv"
  29. "strings"
  30. "github.com/compose-spec/compose-go/v2/types"
  31. "github.com/docker/cli/cli-plugins/manager"
  32. "github.com/docker/cli/cli/command"
  33. "github.com/docker/compose/v2/pkg/api"
  34. "github.com/docker/compose/v2/pkg/progress"
  35. "github.com/docker/docker/api/types/versions"
  36. "github.com/docker/docker/builder/remotecontext/urlutil"
  37. "github.com/moby/buildkit/client"
  38. "github.com/moby/buildkit/util/gitutil"
  39. "github.com/moby/buildkit/util/progress/progressui"
  40. "github.com/sirupsen/logrus"
  41. "github.com/spf13/cobra"
  42. "golang.org/x/sync/errgroup"
  43. )
  44. func buildWithBake(dockerCli command.Cli) (bool, error) {
  45. b, ok := os.LookupEnv("COMPOSE_BAKE")
  46. if !ok {
  47. b = "true"
  48. }
  49. bake, err := strconv.ParseBool(b)
  50. if err != nil {
  51. return false, err
  52. }
  53. if !bake {
  54. if ok {
  55. logrus.Warnf("COMPOSE_BAKE=false is deprecated, support for internal compose builder will be removed in next release")
  56. }
  57. return false, nil
  58. }
  59. enabled, err := dockerCli.BuildKitEnabled()
  60. if err != nil {
  61. return false, err
  62. }
  63. if !enabled {
  64. logrus.Warnf("Docker Compose is configured to build using Bake, but buildkit isn't enabled")
  65. return false, nil
  66. }
  67. _, err = manager.GetPlugin("buildx", dockerCli, &cobra.Command{})
  68. if err != nil {
  69. if manager.IsNotFound(err) {
  70. logrus.Warnf("Docker Compose is configured to build using Bake, but buildx isn't installed")
  71. return false, nil
  72. }
  73. return false, err
  74. }
  75. return true, err
  76. }
  77. // We _could_ use bake.* types from github.com/docker/buildx but long term plan is to remove buildx as a dependency
  78. type bakeConfig struct {
  79. Groups map[string]bakeGroup `json:"group"`
  80. Targets map[string]bakeTarget `json:"target"`
  81. }
  82. type bakeGroup struct {
  83. Targets []string `json:"targets"`
  84. }
  85. type bakeTarget struct {
  86. Context string `json:"context,omitempty"`
  87. Contexts map[string]string `json:"contexts,omitempty"`
  88. Dockerfile string `json:"dockerfile,omitempty"`
  89. DockerfileInline string `json:"dockerfile-inline,omitempty"`
  90. Args map[string]string `json:"args,omitempty"`
  91. Labels map[string]string `json:"labels,omitempty"`
  92. Tags []string `json:"tags,omitempty"`
  93. CacheFrom []string `json:"cache-from,omitempty"`
  94. CacheTo []string `json:"cache-to,omitempty"`
  95. Target string `json:"target,omitempty"`
  96. Secrets []string `json:"secret,omitempty"`
  97. SSH []string `json:"ssh,omitempty"`
  98. Platforms []string `json:"platforms,omitempty"`
  99. Pull bool `json:"pull,omitempty"`
  100. NoCache bool `json:"no-cache,omitempty"`
  101. NetworkMode string `json:"network,omitempty"`
  102. NoCacheFilter []string `json:"no-cache-filter,omitempty"`
  103. ShmSize types.UnitBytes `json:"shm-size,omitempty"`
  104. Ulimits []string `json:"ulimits,omitempty"`
  105. Call string `json:"call,omitempty"`
  106. Entitlements []string `json:"entitlements,omitempty"`
  107. ExtraHosts map[string]string `json:"extra-hosts,omitempty"`
  108. Outputs []string `json:"output,omitempty"`
  109. }
  110. type bakeMetadata map[string]buildStatus
  111. type buildStatus struct {
  112. Digest string `json:"containerimage.digest"`
  113. Image string `json:"image.name"`
  114. }
  115. func (s *composeService) doBuildBake(ctx context.Context, project *types.Project, serviceToBeBuild types.Services, options api.BuildOptions) (map[string]string, error) { //nolint:gocyclo
  116. eg := errgroup.Group{}
  117. ch := make(chan *client.SolveStatus)
  118. displayMode := progressui.DisplayMode(options.Progress)
  119. out := options.Out
  120. if out == nil {
  121. if !s.dockerCli.Out().IsTerminal() {
  122. displayMode = progressui.PlainMode
  123. }
  124. out = os.Stdout // should be s.dockerCli.Out(), but NewDisplay require access to the underlying *File
  125. }
  126. display, err := progressui.NewDisplay(out, displayMode)
  127. if err != nil {
  128. return nil, err
  129. }
  130. eg.Go(func() error {
  131. _, err := display.UpdateFrom(ctx, ch)
  132. return err
  133. })
  134. cfg := bakeConfig{
  135. Groups: map[string]bakeGroup{},
  136. Targets: map[string]bakeTarget{},
  137. }
  138. var (
  139. group bakeGroup
  140. privileged bool
  141. read []string
  142. expectedImages = make(map[string]string, len(serviceToBeBuild)) // service name -> expected image
  143. targets = make(map[string]string, len(serviceToBeBuild)) // service name -> build target
  144. )
  145. // produce a unique ID for service used as bake target
  146. for serviceName := range project.Services {
  147. t := strings.ReplaceAll(serviceName, ".", "_")
  148. for {
  149. if _, ok := targets[serviceName]; !ok {
  150. targets[serviceName] = t
  151. break
  152. }
  153. t += "_"
  154. }
  155. }
  156. for serviceName, service := range project.Services {
  157. if service.Build == nil {
  158. continue
  159. }
  160. build := *service.Build
  161. labels := getImageBuildLabels(project, service)
  162. args := types.Mapping{}
  163. for k, v := range resolveAndMergeBuildArgs(s.dockerCli, project, service, options) {
  164. if v == nil {
  165. continue
  166. }
  167. args[k] = *v
  168. }
  169. entitlements := build.Entitlements
  170. if slices.Contains(build.Entitlements, "security.insecure") {
  171. privileged = true
  172. }
  173. if build.Privileged {
  174. entitlements = append(entitlements, "security.insecure")
  175. privileged = true
  176. }
  177. var outputs []string
  178. var call string
  179. push := options.Push && service.Image != ""
  180. switch {
  181. case options.Check:
  182. call = "lint"
  183. case len(service.Build.Platforms) > 1:
  184. outputs = []string{fmt.Sprintf("type=image,push=%t", push)}
  185. default:
  186. if push {
  187. outputs = []string{"type=registry"}
  188. } else {
  189. outputs = []string{"type=docker"}
  190. }
  191. }
  192. read = append(read, build.Context)
  193. for _, path := range build.AdditionalContexts {
  194. _, err := gitutil.ParseGitRef(path)
  195. if !strings.Contains(path, "://") && err != nil {
  196. read = append(read, path)
  197. }
  198. }
  199. image := api.GetImageNameOrDefault(service, project.Name)
  200. expectedImages[serviceName] = image
  201. target := targets[serviceName]
  202. cfg.Targets[target] = bakeTarget{
  203. Context: build.Context,
  204. Contexts: additionalContexts(build.AdditionalContexts, targets),
  205. Dockerfile: dockerFilePath(build.Context, build.Dockerfile),
  206. DockerfileInline: strings.ReplaceAll(build.DockerfileInline, "${", "$${"),
  207. Args: args,
  208. Labels: labels,
  209. Tags: append(build.Tags, image),
  210. CacheFrom: build.CacheFrom,
  211. CacheTo: build.CacheTo,
  212. NetworkMode: build.Network,
  213. Platforms: build.Platforms,
  214. Target: build.Target,
  215. Secrets: toBakeSecrets(project, build.Secrets),
  216. SSH: toBakeSSH(append(build.SSH, options.SSHs...)),
  217. Pull: options.Pull,
  218. NoCache: options.NoCache,
  219. ShmSize: build.ShmSize,
  220. Ulimits: toBakeUlimits(build.Ulimits),
  221. Entitlements: entitlements,
  222. ExtraHosts: toBakeExtraHosts(build.ExtraHosts),
  223. Outputs: outputs,
  224. Call: call,
  225. }
  226. }
  227. // create a bake group with targets for services to build
  228. for serviceName, service := range serviceToBeBuild {
  229. if service.Build == nil {
  230. continue
  231. }
  232. group.Targets = append(group.Targets, targets[serviceName])
  233. }
  234. cfg.Groups["default"] = group
  235. b, err := json.MarshalIndent(cfg, "", " ")
  236. if err != nil {
  237. return nil, err
  238. }
  239. if options.Print {
  240. _, err = fmt.Fprintln(s.stdout(), string(b))
  241. return nil, err
  242. }
  243. logrus.Debugf("bake build config:\n%s", string(b))
  244. var metadataFile string
  245. for {
  246. // we don't use os.CreateTemp here as we need a temporary file name, but don't want it actually created
  247. // as bake relies on atomicwriter and this creates conflict during rename
  248. metadataFile = filepath.Join(os.TempDir(), fmt.Sprintf("compose-build-metadataFile-%d.json", rand.Int31()))
  249. if _, err = os.Stat(metadataFile); os.IsNotExist(err) {
  250. break
  251. }
  252. }
  253. defer func() {
  254. _ = os.Remove(metadataFile)
  255. }()
  256. buildx, err := manager.GetPlugin("buildx", s.dockerCli, &cobra.Command{})
  257. if err != nil {
  258. return nil, err
  259. }
  260. args := []string{"bake", "--file", "-", "--progress", "rawjson", "--metadata-file", metadataFile}
  261. mustAllow := buildx.Version != "" && versions.GreaterThanOrEqualTo(buildx.Version[1:], "0.17.0")
  262. if mustAllow {
  263. // FIXME we should prompt user about this, but this is a breaking change in UX
  264. for _, path := range read {
  265. args = append(args, "--allow", "fs.read="+path)
  266. }
  267. if privileged {
  268. args = append(args, "--allow", "security.insecure")
  269. }
  270. }
  271. if options.Builder != "" {
  272. args = append(args, "--builder", options.Builder)
  273. }
  274. if options.Quiet {
  275. args = append(args, "--progress=quiet")
  276. }
  277. logrus.Debugf("Executing bake with args: %v", args)
  278. if s.dryRun {
  279. return dryRunBake(ctx, cfg), nil
  280. }
  281. cmd := exec.CommandContext(ctx, buildx.Path, args...)
  282. err = s.prepareShellOut(ctx, project.Environment, cmd)
  283. if err != nil {
  284. return nil, err
  285. }
  286. cmd.Stdout = s.stdout()
  287. cmd.Stdin = bytes.NewBuffer(b)
  288. pipe, err := cmd.StderrPipe()
  289. if err != nil {
  290. return nil, err
  291. }
  292. var errMessage []string
  293. reader := bufio.NewReader(pipe)
  294. err = cmd.Start()
  295. if err != nil {
  296. return nil, err
  297. }
  298. eg.Go(cmd.Wait)
  299. for {
  300. line, readErr := reader.ReadString('\n')
  301. if readErr != nil {
  302. if readErr == io.EOF {
  303. break
  304. } else {
  305. return nil, fmt.Errorf("failed to execute bake: %w", readErr)
  306. }
  307. }
  308. decoder := json.NewDecoder(strings.NewReader(line))
  309. var status client.SolveStatus
  310. err := decoder.Decode(&status)
  311. if err != nil {
  312. if strings.HasPrefix(line, "ERROR: ") {
  313. errMessage = append(errMessage, line[7:])
  314. } else {
  315. errMessage = append(errMessage, line)
  316. }
  317. continue
  318. }
  319. ch <- &status
  320. }
  321. close(ch) // stop build progress UI
  322. err = eg.Wait()
  323. if err != nil {
  324. if len(errMessage) > 0 {
  325. return nil, errors.New(strings.Join(errMessage, "\n"))
  326. }
  327. return nil, fmt.Errorf("failed to execute bake: %w", err)
  328. }
  329. b, err = os.ReadFile(metadataFile)
  330. if err != nil {
  331. return nil, err
  332. }
  333. var md bakeMetadata
  334. err = json.Unmarshal(b, &md)
  335. if err != nil {
  336. return nil, err
  337. }
  338. cw := progress.ContextWriter(ctx)
  339. results := map[string]string{}
  340. for name := range serviceToBeBuild {
  341. image := expectedImages[name]
  342. target := targets[name]
  343. built, ok := md[target]
  344. if !ok {
  345. return nil, fmt.Errorf("build result not found in Bake metadata for service %s", name)
  346. }
  347. results[image] = built.Digest
  348. cw.Event(progress.BuiltEvent(image))
  349. }
  350. return results, nil
  351. }
  352. func toBakeExtraHosts(hosts types.HostsList) map[string]string {
  353. m := make(map[string]string)
  354. for k, v := range hosts {
  355. m[k] = strings.Join(v, ",")
  356. }
  357. return m
  358. }
  359. func additionalContexts(contexts types.Mapping, targets map[string]string) map[string]string {
  360. ac := map[string]string{}
  361. for k, v := range contexts {
  362. if target, found := strings.CutPrefix(v, types.ServicePrefix); found {
  363. v = "target:" + targets[target]
  364. }
  365. ac[k] = v
  366. }
  367. return ac
  368. }
  369. func toBakeUlimits(ulimits map[string]*types.UlimitsConfig) []string {
  370. s := []string{}
  371. for u, l := range ulimits {
  372. if l.Single > 0 {
  373. s = append(s, fmt.Sprintf("%s=%d", u, l.Single))
  374. } else {
  375. s = append(s, fmt.Sprintf("%s=%d:%d", u, l.Soft, l.Hard))
  376. }
  377. }
  378. return s
  379. }
  380. func toBakeSSH(ssh types.SSHConfig) []string {
  381. var s []string
  382. for _, key := range ssh {
  383. s = append(s, fmt.Sprintf("%s=%s", key.ID, key.Path))
  384. }
  385. return s
  386. }
  387. func toBakeSecrets(project *types.Project, secrets []types.ServiceSecretConfig) []string {
  388. var s []string
  389. for _, ref := range secrets {
  390. def := project.Secrets[ref.Source]
  391. target := ref.Target
  392. if target == "" {
  393. target = ref.Source
  394. }
  395. switch {
  396. case def.Environment != "":
  397. s = append(s, fmt.Sprintf("id=%s,type=env,env=%s", target, def.Environment))
  398. case def.File != "":
  399. s = append(s, fmt.Sprintf("id=%s,type=file,src=%s", target, def.File))
  400. }
  401. }
  402. return s
  403. }
  404. func dockerFilePath(ctxName string, dockerfile string) string {
  405. if dockerfile == "" {
  406. return ""
  407. }
  408. if urlutil.IsGitURL(ctxName) {
  409. return dockerfile
  410. }
  411. if !filepath.IsAbs(dockerfile) {
  412. dockerfile = filepath.Join(ctxName, dockerfile)
  413. }
  414. dir := filepath.Dir(dockerfile)
  415. symlinks, err := filepath.EvalSymlinks(dir)
  416. if err == nil {
  417. return filepath.Join(symlinks, filepath.Base(dockerfile))
  418. }
  419. return dockerfile
  420. }
  421. func dryRunBake(ctx context.Context, cfg bakeConfig) map[string]string {
  422. w := progress.ContextWriter(ctx)
  423. bakeResponse := map[string]string{}
  424. for name, target := range cfg.Targets {
  425. dryRunUUID := fmt.Sprintf("dryRun-%x", sha1.Sum([]byte(name)))
  426. displayDryRunBuildEvent(w, name, dryRunUUID, target.Tags[0])
  427. bakeResponse[name] = dryRunUUID
  428. }
  429. for name := range bakeResponse {
  430. w.Event(progress.BuiltEvent(name))
  431. }
  432. return bakeResponse
  433. }
  434. func displayDryRunBuildEvent(w progress.Writer, name string, dryRunUUID, tag string) {
  435. w.Event(progress.Event{
  436. ID: name + " ==>",
  437. Status: progress.Done,
  438. Text: fmt.Sprintf("==> writing image %s", dryRunUUID),
  439. })
  440. w.Event(progress.Event{
  441. ID: name + " ==> ==>",
  442. Status: progress.Done,
  443. Text: fmt.Sprintf(`naming to %s`, tag),
  444. })
  445. }