build_bake.go 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490
  1. /*
  2. Copyright 2020 Docker Compose CLI authors
  3. Licensed under the Apache License, Version 2.0 (the "License");
  4. you may not use this file except in compliance with the License.
  5. You may obtain a copy of the License at
  6. http://www.apache.org/licenses/LICENSE-2.0
  7. Unless required by applicable law or agreed to in writing, software
  8. distributed under the License is distributed on an "AS IS" BASIS,
  9. WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  10. See the License for the specific language governing permissions and
  11. limitations under the License.
  12. */
  13. package compose
  14. import (
  15. "bufio"
  16. "bytes"
  17. "context"
  18. "crypto/sha1"
  19. "encoding/json"
  20. "errors"
  21. "fmt"
  22. "io"
  23. "math/rand"
  24. "os"
  25. "os/exec"
  26. "path/filepath"
  27. "slices"
  28. "strconv"
  29. "strings"
  30. "github.com/compose-spec/compose-go/v2/types"
  31. "github.com/docker/cli/cli-plugins/manager"
  32. "github.com/docker/cli/cli/command"
  33. "github.com/docker/compose/v2/pkg/api"
  34. "github.com/docker/compose/v2/pkg/progress"
  35. "github.com/docker/docker/api/types/versions"
  36. "github.com/docker/docker/builder/remotecontext/urlutil"
  37. "github.com/moby/buildkit/client"
  38. "github.com/moby/buildkit/util/gitutil"
  39. "github.com/moby/buildkit/util/progress/progressui"
  40. "github.com/sirupsen/logrus"
  41. "github.com/spf13/cobra"
  42. "golang.org/x/sync/errgroup"
  43. )
  44. func buildWithBake(dockerCli command.Cli) (bool, error) {
  45. b, ok := os.LookupEnv("COMPOSE_BAKE")
  46. if !ok {
  47. b = "true"
  48. }
  49. bake, err := strconv.ParseBool(b)
  50. if err != nil {
  51. return false, err
  52. }
  53. if !bake {
  54. if ok {
  55. logrus.Warnf("COMPOSE_BAKE=false is deprecated, support for internal compose builder will be removed in next release")
  56. }
  57. return false, nil
  58. }
  59. enabled, err := dockerCli.BuildKitEnabled()
  60. if err != nil {
  61. return false, err
  62. }
  63. if !enabled {
  64. logrus.Warnf("Docker Compose is configured to build using Bake, but buildkit isn't enabled")
  65. return false, nil
  66. }
  67. _, err = manager.GetPlugin("buildx", dockerCli, &cobra.Command{})
  68. if err != nil {
  69. if manager.IsNotFound(err) {
  70. logrus.Warnf("Docker Compose is configured to build using Bake, but buildx isn't installed")
  71. return false, nil
  72. }
  73. return false, err
  74. }
  75. return true, err
  76. }
  77. // We _could_ use bake.* types from github.com/docker/buildx but long term plan is to remove buildx as a dependency
  78. type bakeConfig struct {
  79. Groups map[string]bakeGroup `json:"group"`
  80. Targets map[string]bakeTarget `json:"target"`
  81. }
  82. type bakeGroup struct {
  83. Targets []string `json:"targets"`
  84. }
  85. type bakeTarget struct {
  86. Context string `json:"context,omitempty"`
  87. Contexts map[string]string `json:"contexts,omitempty"`
  88. Dockerfile string `json:"dockerfile,omitempty"`
  89. DockerfileInline string `json:"dockerfile-inline,omitempty"`
  90. Args map[string]string `json:"args,omitempty"`
  91. Labels map[string]string `json:"labels,omitempty"`
  92. Tags []string `json:"tags,omitempty"`
  93. CacheFrom []string `json:"cache-from,omitempty"`
  94. CacheTo []string `json:"cache-to,omitempty"`
  95. Target string `json:"target,omitempty"`
  96. Secrets []string `json:"secret,omitempty"`
  97. SSH []string `json:"ssh,omitempty"`
  98. Platforms []string `json:"platforms,omitempty"`
  99. Pull bool `json:"pull,omitempty"`
  100. NoCache bool `json:"no-cache,omitempty"`
  101. NetworkMode string `json:"network,omitempty"`
  102. NoCacheFilter []string `json:"no-cache-filter,omitempty"`
  103. ShmSize types.UnitBytes `json:"shm-size,omitempty"`
  104. Ulimits []string `json:"ulimits,omitempty"`
  105. Call string `json:"call,omitempty"`
  106. Entitlements []string `json:"entitlements,omitempty"`
  107. ExtraHosts map[string]string `json:"extra-hosts,omitempty"`
  108. Outputs []string `json:"output,omitempty"`
  109. }
  110. type bakeMetadata map[string]buildStatus
  111. type buildStatus struct {
  112. Digest string `json:"containerimage.digest"`
  113. Image string `json:"image.name"`
  114. }
  115. func (s *composeService) doBuildBake(ctx context.Context, project *types.Project, serviceToBeBuild types.Services, options api.BuildOptions) (map[string]string, error) { //nolint:gocyclo
  116. eg := errgroup.Group{}
  117. ch := make(chan *client.SolveStatus)
  118. out := s.dockerCli.Out()
  119. displayMode := progressui.DisplayMode(options.Progress)
  120. if !out.IsTerminal() {
  121. displayMode = progressui.PlainMode
  122. }
  123. display, err := progressui.NewDisplay(out, displayMode)
  124. if err != nil {
  125. return nil, err
  126. }
  127. eg.Go(func() error {
  128. _, err := display.UpdateFrom(ctx, ch)
  129. return err
  130. })
  131. cfg := bakeConfig{
  132. Groups: map[string]bakeGroup{},
  133. Targets: map[string]bakeTarget{},
  134. }
  135. var (
  136. group bakeGroup
  137. privileged bool
  138. read []string
  139. expectedImages = make(map[string]string, len(serviceToBeBuild)) // service name -> expected image
  140. targets = make(map[string]string, len(serviceToBeBuild)) // service name -> build target
  141. )
  142. // produce a unique ID for service used as bake target
  143. for serviceName := range project.Services {
  144. t := strings.ReplaceAll(serviceName, ".", "_")
  145. for {
  146. if _, ok := targets[serviceName]; !ok {
  147. targets[serviceName] = t
  148. break
  149. }
  150. t += "_"
  151. }
  152. }
  153. for serviceName, service := range project.Services {
  154. if service.Build == nil {
  155. continue
  156. }
  157. build := *service.Build
  158. labels := getImageBuildLabels(project, service)
  159. args := types.Mapping{}
  160. for k, v := range resolveAndMergeBuildArgs(s.dockerCli, project, service, options) {
  161. if v == nil {
  162. continue
  163. }
  164. args[k] = *v
  165. }
  166. entitlements := build.Entitlements
  167. if slices.Contains(build.Entitlements, "security.insecure") {
  168. privileged = true
  169. }
  170. if build.Privileged {
  171. entitlements = append(entitlements, "security.insecure")
  172. privileged = true
  173. }
  174. var outputs []string
  175. var call string
  176. push := options.Push && service.Image != ""
  177. switch {
  178. case options.Check:
  179. call = "lint"
  180. case len(service.Build.Platforms) > 1:
  181. outputs = []string{fmt.Sprintf("type=image,push=%t", push)}
  182. default:
  183. outputs = []string{fmt.Sprintf("type=docker,load=true,push=%t", push)}
  184. }
  185. read = append(read, build.Context)
  186. for _, path := range build.AdditionalContexts {
  187. _, err := gitutil.ParseGitRef(path)
  188. if !strings.Contains(path, "://") && err != nil {
  189. read = append(read, path)
  190. }
  191. }
  192. image := api.GetImageNameOrDefault(service, project.Name)
  193. expectedImages[serviceName] = image
  194. target := targets[serviceName]
  195. cfg.Targets[target] = bakeTarget{
  196. Context: build.Context,
  197. Contexts: additionalContexts(build.AdditionalContexts, targets),
  198. Dockerfile: dockerFilePath(build.Context, build.Dockerfile),
  199. DockerfileInline: strings.ReplaceAll(build.DockerfileInline, "${", "$${"),
  200. Args: args,
  201. Labels: labels,
  202. Tags: append(build.Tags, image),
  203. CacheFrom: build.CacheFrom,
  204. CacheTo: build.CacheTo,
  205. NetworkMode: build.Network,
  206. Platforms: build.Platforms,
  207. Target: build.Target,
  208. Secrets: toBakeSecrets(project, build.Secrets),
  209. SSH: toBakeSSH(append(build.SSH, options.SSHs...)),
  210. Pull: options.Pull,
  211. NoCache: options.NoCache,
  212. ShmSize: build.ShmSize,
  213. Ulimits: toBakeUlimits(build.Ulimits),
  214. Entitlements: entitlements,
  215. ExtraHosts: toBakeExtraHosts(build.ExtraHosts),
  216. Outputs: outputs,
  217. Call: call,
  218. }
  219. }
  220. // create a bake group with targets for services to build
  221. for serviceName, service := range serviceToBeBuild {
  222. if service.Build == nil {
  223. continue
  224. }
  225. group.Targets = append(group.Targets, targets[serviceName])
  226. }
  227. cfg.Groups["default"] = group
  228. b, err := json.MarshalIndent(cfg, "", " ")
  229. if err != nil {
  230. return nil, err
  231. }
  232. if options.Print {
  233. _, err = fmt.Fprintln(s.stdout(), string(b))
  234. return nil, err
  235. }
  236. logrus.Debugf("bake build config:\n%s", string(b))
  237. var metadataFile string
  238. for {
  239. // we don't use os.CreateTemp here as we need a temporary file name, but don't want it actually created
  240. // as bake relies on atomicwriter and this creates conflict during rename
  241. metadataFile = filepath.Join(os.TempDir(), fmt.Sprintf("compose-build-metadataFile-%d.json", rand.Int31()))
  242. if _, err = os.Stat(metadataFile); os.IsNotExist(err) {
  243. break
  244. }
  245. }
  246. defer func() {
  247. _ = os.Remove(metadataFile)
  248. }()
  249. buildx, err := manager.GetPlugin("buildx", s.dockerCli, &cobra.Command{})
  250. if err != nil {
  251. return nil, err
  252. }
  253. args := []string{"bake", "--file", "-", "--progress", "rawjson", "--metadata-file", metadataFile}
  254. mustAllow := buildx.Version != "" && versions.GreaterThanOrEqualTo(buildx.Version[1:], "0.17.0")
  255. if mustAllow {
  256. // FIXME we should prompt user about this, but this is a breaking change in UX
  257. for _, path := range read {
  258. args = append(args, "--allow", "fs.read="+path)
  259. }
  260. if privileged {
  261. args = append(args, "--allow", "security.insecure")
  262. }
  263. }
  264. if options.Builder != "" {
  265. args = append(args, "--builder", options.Builder)
  266. }
  267. if options.Quiet {
  268. args = append(args, "--progress=quiet")
  269. }
  270. logrus.Debugf("Executing bake with args: %v", args)
  271. if s.dryRun {
  272. return dryRunBake(ctx, cfg), nil
  273. }
  274. cmd := exec.CommandContext(ctx, buildx.Path, args...)
  275. err = s.prepareShellOut(ctx, project.Environment, cmd)
  276. if err != nil {
  277. return nil, err
  278. }
  279. cmd.Stdout = s.stdout()
  280. cmd.Stdin = bytes.NewBuffer(b)
  281. pipe, err := cmd.StderrPipe()
  282. if err != nil {
  283. return nil, err
  284. }
  285. var errMessage []string
  286. reader := bufio.NewReader(pipe)
  287. err = cmd.Start()
  288. if err != nil {
  289. return nil, err
  290. }
  291. eg.Go(cmd.Wait)
  292. for {
  293. line, readErr := reader.ReadString('\n')
  294. if readErr != nil {
  295. if readErr == io.EOF {
  296. break
  297. } else {
  298. return nil, fmt.Errorf("failed to execute bake: %w", readErr)
  299. }
  300. }
  301. decoder := json.NewDecoder(strings.NewReader(line))
  302. var status client.SolveStatus
  303. err := decoder.Decode(&status)
  304. if err != nil {
  305. if strings.HasPrefix(line, "ERROR: ") {
  306. errMessage = append(errMessage, line[7:])
  307. } else {
  308. errMessage = append(errMessage, line)
  309. }
  310. continue
  311. }
  312. ch <- &status
  313. }
  314. close(ch) // stop build progress UI
  315. err = eg.Wait()
  316. if err != nil {
  317. if len(errMessage) > 0 {
  318. return nil, errors.New(strings.Join(errMessage, "\n"))
  319. }
  320. return nil, fmt.Errorf("failed to execute bake: %w", err)
  321. }
  322. b, err = os.ReadFile(metadataFile)
  323. if err != nil {
  324. return nil, err
  325. }
  326. var md bakeMetadata
  327. err = json.Unmarshal(b, &md)
  328. if err != nil {
  329. return nil, err
  330. }
  331. cw := progress.ContextWriter(ctx)
  332. results := map[string]string{}
  333. for name := range serviceToBeBuild {
  334. image := expectedImages[name]
  335. target := targets[name]
  336. built, ok := md[target]
  337. if !ok {
  338. return nil, fmt.Errorf("build result not found in Bake metadata for service %s", name)
  339. }
  340. results[image] = built.Digest
  341. cw.Event(progress.BuiltEvent(image))
  342. }
  343. return results, nil
  344. }
  345. func toBakeExtraHosts(hosts types.HostsList) map[string]string {
  346. m := make(map[string]string)
  347. for k, v := range hosts {
  348. m[k] = strings.Join(v, ",")
  349. }
  350. return m
  351. }
  352. func additionalContexts(contexts types.Mapping, targets map[string]string) map[string]string {
  353. ac := map[string]string{}
  354. for k, v := range contexts {
  355. if target, found := strings.CutPrefix(v, types.ServicePrefix); found {
  356. v = "target:" + targets[target]
  357. }
  358. ac[k] = v
  359. }
  360. return ac
  361. }
  362. func toBakeUlimits(ulimits map[string]*types.UlimitsConfig) []string {
  363. s := []string{}
  364. for u, l := range ulimits {
  365. if l.Single > 0 {
  366. s = append(s, fmt.Sprintf("%s=%d", u, l.Single))
  367. } else {
  368. s = append(s, fmt.Sprintf("%s=%d:%d", u, l.Soft, l.Hard))
  369. }
  370. }
  371. return s
  372. }
  373. func toBakeSSH(ssh types.SSHConfig) []string {
  374. var s []string
  375. for _, key := range ssh {
  376. s = append(s, fmt.Sprintf("%s=%s", key.ID, key.Path))
  377. }
  378. return s
  379. }
  380. func toBakeSecrets(project *types.Project, secrets []types.ServiceSecretConfig) []string {
  381. var s []string
  382. for _, ref := range secrets {
  383. def := project.Secrets[ref.Source]
  384. target := ref.Target
  385. if target == "" {
  386. target = ref.Source
  387. }
  388. switch {
  389. case def.Environment != "":
  390. s = append(s, fmt.Sprintf("id=%s,type=env,env=%s", target, def.Environment))
  391. case def.File != "":
  392. s = append(s, fmt.Sprintf("id=%s,type=file,src=%s", target, def.File))
  393. }
  394. }
  395. return s
  396. }
  397. func dockerFilePath(ctxName string, dockerfile string) string {
  398. if dockerfile == "" {
  399. return ""
  400. }
  401. if urlutil.IsGitURL(ctxName) {
  402. return dockerfile
  403. }
  404. if !filepath.IsAbs(dockerfile) {
  405. dockerfile = filepath.Join(ctxName, dockerfile)
  406. }
  407. dir := filepath.Dir(dockerfile)
  408. symlinks, err := filepath.EvalSymlinks(dir)
  409. if err == nil {
  410. return filepath.Join(symlinks, filepath.Base(dockerfile))
  411. }
  412. return dockerfile
  413. }
  414. func dryRunBake(ctx context.Context, cfg bakeConfig) map[string]string {
  415. w := progress.ContextWriter(ctx)
  416. bakeResponse := map[string]string{}
  417. for name, target := range cfg.Targets {
  418. dryRunUUID := fmt.Sprintf("dryRun-%x", sha1.Sum([]byte(name)))
  419. displayDryRunBuildEvent(w, name, dryRunUUID, target.Tags[0])
  420. bakeResponse[name] = dryRunUUID
  421. }
  422. for name := range bakeResponse {
  423. w.Event(progress.BuiltEvent(name))
  424. }
  425. return bakeResponse
  426. }
  427. func displayDryRunBuildEvent(w progress.Writer, name string, dryRunUUID, tag string) {
  428. w.Event(progress.Event{
  429. ID: name + " ==>",
  430. Status: progress.Done,
  431. Text: fmt.Sprintf("==> writing image %s", dryRunUUID),
  432. })
  433. w.Event(progress.Event{
  434. ID: name + " ==> ==>",
  435. Status: progress.Done,
  436. Text: fmt.Sprintf(`naming to %s`, tag),
  437. })
  438. }