build_bake.go 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576
  1. /*
  2. Copyright 2020 Docker Compose CLI authors
  3. Licensed under the Apache License, Version 2.0 (the "License");
  4. you may not use this file except in compliance with the License.
  5. You may obtain a copy of the License at
  6. http://www.apache.org/licenses/LICENSE-2.0
  7. Unless required by applicable law or agreed to in writing, software
  8. distributed under the License is distributed on an "AS IS" BASIS,
  9. WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  10. See the License for the specific language governing permissions and
  11. limitations under the License.
  12. */
  13. package compose
  14. import (
  15. "bufio"
  16. "bytes"
  17. "context"
  18. "crypto/sha1"
  19. "encoding/json"
  20. "errors"
  21. "fmt"
  22. "io"
  23. "io/fs"
  24. "os"
  25. "os/exec"
  26. "path/filepath"
  27. "slices"
  28. "strings"
  29. "github.com/compose-spec/compose-go/v2/types"
  30. "github.com/containerd/console"
  31. "github.com/containerd/errdefs"
  32. "github.com/docker/cli/cli-plugins/manager"
  33. "github.com/docker/cli/cli/command"
  34. "github.com/docker/cli/cli/command/image/build"
  35. "github.com/docker/cli/cli/streams"
  36. "github.com/docker/compose/v2/pkg/api"
  37. "github.com/docker/compose/v2/pkg/progress"
  38. "github.com/docker/docker/api/types/versions"
  39. "github.com/google/uuid"
  40. "github.com/moby/buildkit/client"
  41. gitutil "github.com/moby/buildkit/frontend/dockerfile/dfgitutil"
  42. "github.com/moby/buildkit/util/progress/progressui"
  43. "github.com/sirupsen/logrus"
  44. "github.com/spf13/cobra"
  45. "golang.org/x/sync/errgroup"
  46. )
  47. func buildWithBake(dockerCli command.Cli) (bool, error) {
  48. enabled, err := dockerCli.BuildKitEnabled()
  49. if err != nil {
  50. return false, err
  51. }
  52. if !enabled {
  53. return false, nil
  54. }
  55. _, err = manager.GetPlugin("buildx", dockerCli, &cobra.Command{})
  56. if err != nil {
  57. if errdefs.IsNotFound(err) {
  58. logrus.Warnf("Docker Compose requires buildx plugin to be installed")
  59. return false, nil
  60. }
  61. return false, err
  62. }
  63. return true, err
  64. }
  65. // We _could_ use bake.* types from github.com/docker/buildx but long term plan is to remove buildx as a dependency
  66. type bakeConfig struct {
  67. Groups map[string]bakeGroup `json:"group"`
  68. Targets map[string]bakeTarget `json:"target"`
  69. }
  70. type bakeGroup struct {
  71. Targets []string `json:"targets"`
  72. }
  73. type bakeTarget struct {
  74. Context string `json:"context,omitempty"`
  75. Contexts map[string]string `json:"contexts,omitempty"`
  76. Dockerfile string `json:"dockerfile,omitempty"`
  77. DockerfileInline string `json:"dockerfile-inline,omitempty"`
  78. Args map[string]string `json:"args,omitempty"`
  79. Labels map[string]string `json:"labels,omitempty"`
  80. Tags []string `json:"tags,omitempty"`
  81. CacheFrom []string `json:"cache-from,omitempty"`
  82. CacheTo []string `json:"cache-to,omitempty"`
  83. Target string `json:"target,omitempty"`
  84. Secrets []string `json:"secret,omitempty"`
  85. SSH []string `json:"ssh,omitempty"`
  86. Platforms []string `json:"platforms,omitempty"`
  87. Pull bool `json:"pull,omitempty"`
  88. NoCache bool `json:"no-cache,omitempty"`
  89. NetworkMode string `json:"network,omitempty"`
  90. NoCacheFilter []string `json:"no-cache-filter,omitempty"`
  91. ShmSize types.UnitBytes `json:"shm-size,omitempty"`
  92. Ulimits []string `json:"ulimits,omitempty"`
  93. Call string `json:"call,omitempty"`
  94. Entitlements []string `json:"entitlements,omitempty"`
  95. ExtraHosts map[string]string `json:"extra-hosts,omitempty"`
  96. Outputs []string `json:"output,omitempty"`
  97. Attest []string `json:"attest,omitempty"`
  98. }
  99. type bakeMetadata map[string]buildStatus
  100. type buildStatus struct {
  101. Digest string `json:"containerimage.digest"`
  102. Image string `json:"image.name"`
  103. }
  104. func (s *composeService) doBuildBake(ctx context.Context, project *types.Project, serviceToBeBuild types.Services, options api.BuildOptions) (map[string]string, error) { //nolint:gocyclo
  105. eg := errgroup.Group{}
  106. ch := make(chan *client.SolveStatus)
  107. if options.Progress == progress.ModeAuto {
  108. options.Progress = os.Getenv("BUILDKIT_PROGRESS")
  109. }
  110. displayMode := progressui.DisplayMode(options.Progress)
  111. out := options.Out
  112. if out == nil {
  113. if displayMode == progress.ModeAuto && !s.stdout().IsTerminal() {
  114. displayMode = progressui.PlainMode
  115. }
  116. out = s.stdout()
  117. }
  118. display, err := progressui.NewDisplay(makeConsole(out), displayMode)
  119. if err != nil {
  120. return nil, err
  121. }
  122. eg.Go(func() error {
  123. _, err := display.UpdateFrom(ctx, ch)
  124. return err
  125. })
  126. cfg := bakeConfig{
  127. Groups: map[string]bakeGroup{},
  128. Targets: map[string]bakeTarget{},
  129. }
  130. var (
  131. group bakeGroup
  132. privileged bool
  133. read []string
  134. expectedImages = make(map[string]string, len(serviceToBeBuild)) // service name -> expected image
  135. targets = make(map[string]string, len(serviceToBeBuild)) // service name -> build target
  136. )
  137. // produce a unique ID for service used as bake target
  138. for serviceName := range project.Services {
  139. t := strings.ReplaceAll(serviceName, ".", "_")
  140. for {
  141. if _, ok := targets[serviceName]; !ok {
  142. targets[serviceName] = t
  143. break
  144. }
  145. t += "_"
  146. }
  147. }
  148. var secretsEnv []string
  149. for serviceName, service := range project.Services {
  150. if service.Build == nil {
  151. continue
  152. }
  153. buildConfig := *service.Build
  154. labels := getImageBuildLabels(project, service)
  155. args := resolveAndMergeBuildArgs(s.getProxyConfig(), project, service, options).ToMapping()
  156. for k, v := range args {
  157. args[k] = strings.ReplaceAll(v, "${", "$${")
  158. }
  159. entitlements := buildConfig.Entitlements
  160. if slices.Contains(buildConfig.Entitlements, "security.insecure") {
  161. privileged = true
  162. }
  163. if buildConfig.Privileged {
  164. entitlements = append(entitlements, "security.insecure")
  165. privileged = true
  166. }
  167. var outputs []string
  168. var call string
  169. push := options.Push && service.Image != ""
  170. switch {
  171. case options.Check:
  172. call = "lint"
  173. case len(service.Build.Platforms) > 1:
  174. outputs = []string{fmt.Sprintf("type=image,push=%t", push)}
  175. default:
  176. if push {
  177. outputs = []string{"type=registry"}
  178. } else {
  179. outputs = []string{"type=docker"}
  180. }
  181. }
  182. read = append(read, buildConfig.Context)
  183. for _, path := range buildConfig.AdditionalContexts {
  184. _, _, err := gitutil.ParseGitRef(path)
  185. if !strings.Contains(path, "://") && err != nil {
  186. read = append(read, path)
  187. }
  188. }
  189. image := api.GetImageNameOrDefault(service, project.Name)
  190. s.events.On(progress.BuildingEvent(image))
  191. expectedImages[serviceName] = image
  192. pull := service.Build.Pull || options.Pull
  193. noCache := service.Build.NoCache || options.NoCache
  194. target := targets[serviceName]
  195. secrets, env := toBakeSecrets(project, buildConfig.Secrets)
  196. secretsEnv = append(secretsEnv, env...)
  197. cfg.Targets[target] = bakeTarget{
  198. Context: buildConfig.Context,
  199. Contexts: additionalContexts(buildConfig.AdditionalContexts, targets),
  200. Dockerfile: dockerFilePath(buildConfig.Context, buildConfig.Dockerfile),
  201. DockerfileInline: strings.ReplaceAll(buildConfig.DockerfileInline, "${", "$${"),
  202. Args: args,
  203. Labels: labels,
  204. Tags: append(buildConfig.Tags, image),
  205. CacheFrom: buildConfig.CacheFrom,
  206. CacheTo: buildConfig.CacheTo,
  207. NetworkMode: buildConfig.Network,
  208. Platforms: buildConfig.Platforms,
  209. Target: buildConfig.Target,
  210. Secrets: secrets,
  211. SSH: toBakeSSH(append(buildConfig.SSH, options.SSHs...)),
  212. Pull: pull,
  213. NoCache: noCache,
  214. ShmSize: buildConfig.ShmSize,
  215. Ulimits: toBakeUlimits(buildConfig.Ulimits),
  216. Entitlements: entitlements,
  217. ExtraHosts: toBakeExtraHosts(buildConfig.ExtraHosts),
  218. Outputs: outputs,
  219. Call: call,
  220. Attest: toBakeAttest(buildConfig),
  221. }
  222. }
  223. // create a bake group with targets for services to build
  224. for serviceName, service := range serviceToBeBuild {
  225. if service.Build == nil {
  226. continue
  227. }
  228. group.Targets = append(group.Targets, targets[serviceName])
  229. }
  230. cfg.Groups["default"] = group
  231. b, err := json.MarshalIndent(cfg, "", " ")
  232. if err != nil {
  233. return nil, err
  234. }
  235. if options.Print {
  236. _, err = fmt.Fprintln(s.stdout(), string(b))
  237. return nil, err
  238. }
  239. logrus.Debugf("bake build config:\n%s", string(b))
  240. tmpdir := os.TempDir()
  241. var metadataFile string
  242. for {
  243. // we don't use os.CreateTemp here as we need a temporary file name, but don't want it actually created
  244. // as bake relies on atomicwriter and this creates conflict during rename
  245. metadataFile = filepath.Join(tmpdir, fmt.Sprintf("compose-build-metadataFile-%s.json", uuid.New().String()))
  246. if _, err = os.Stat(metadataFile); err != nil {
  247. if os.IsNotExist(err) {
  248. break
  249. }
  250. var pathError *fs.PathError
  251. if errors.As(err, &pathError) {
  252. return nil, fmt.Errorf("can't access os.tempDir %s: %w", tmpdir, pathError.Err)
  253. }
  254. }
  255. }
  256. defer func() {
  257. _ = os.Remove(metadataFile)
  258. }()
  259. buildx, err := manager.GetPlugin("buildx", s.dockerCli, &cobra.Command{})
  260. if err != nil {
  261. return nil, err
  262. }
  263. if versions.LessThan(buildx.Version[1:], "0.17.0") {
  264. return nil, fmt.Errorf("compose build requires buildx 0.17 or later")
  265. }
  266. args := []string{"bake", "--file", "-", "--progress", "rawjson", "--metadata-file", metadataFile}
  267. // FIXME we should prompt user about this, but this is a breaking change in UX
  268. for _, path := range read {
  269. args = append(args, "--allow", "fs.read="+path)
  270. }
  271. if privileged {
  272. args = append(args, "--allow", "security.insecure")
  273. }
  274. if options.SBOM != "" {
  275. args = append(args, "--sbom="+options.SBOM)
  276. }
  277. if options.Provenance != "" {
  278. args = append(args, "--provenance="+options.Provenance)
  279. }
  280. if options.Builder != "" {
  281. args = append(args, "--builder", options.Builder)
  282. }
  283. if options.Quiet {
  284. args = append(args, "--progress=quiet")
  285. }
  286. logrus.Debugf("Executing bake with args: %v", args)
  287. if s.dryRun {
  288. return s.dryRunBake(cfg), nil
  289. }
  290. cmd := exec.CommandContext(ctx, buildx.Path, args...)
  291. err = s.prepareShellOut(ctx, types.NewMapping(os.Environ()), cmd)
  292. if err != nil {
  293. return nil, err
  294. }
  295. endpoint, cleanup, err := s.propagateDockerEndpoint()
  296. if err != nil {
  297. return nil, err
  298. }
  299. cmd.Env = append(cmd.Env, endpoint...)
  300. cmd.Env = append(cmd.Env, secretsEnv...)
  301. defer cleanup()
  302. cmd.Stdout = s.stdout()
  303. cmd.Stdin = bytes.NewBuffer(b)
  304. pipe, err := cmd.StderrPipe()
  305. if err != nil {
  306. return nil, err
  307. }
  308. var errMessage []string
  309. reader := bufio.NewReader(pipe)
  310. err = cmd.Start()
  311. if err != nil {
  312. return nil, err
  313. }
  314. eg.Go(cmd.Wait)
  315. for {
  316. line, readErr := reader.ReadString('\n')
  317. if readErr != nil {
  318. if readErr == io.EOF {
  319. break
  320. }
  321. if errors.Is(readErr, os.ErrClosed) {
  322. logrus.Debugf("bake stopped")
  323. break
  324. }
  325. return nil, fmt.Errorf("failed to execute bake: %w", readErr)
  326. }
  327. decoder := json.NewDecoder(strings.NewReader(line))
  328. var status client.SolveStatus
  329. err := decoder.Decode(&status)
  330. if err != nil {
  331. if strings.HasPrefix(line, "ERROR: ") {
  332. errMessage = append(errMessage, line[7:])
  333. } else {
  334. errMessage = append(errMessage, line)
  335. }
  336. continue
  337. }
  338. ch <- &status
  339. }
  340. close(ch) // stop build progress UI
  341. err = eg.Wait()
  342. if err != nil {
  343. if len(errMessage) > 0 {
  344. return nil, errors.New(strings.Join(errMessage, "\n"))
  345. }
  346. return nil, fmt.Errorf("failed to execute bake: %w", err)
  347. }
  348. b, err = os.ReadFile(metadataFile)
  349. if err != nil {
  350. return nil, err
  351. }
  352. var md bakeMetadata
  353. err = json.Unmarshal(b, &md)
  354. if err != nil {
  355. return nil, err
  356. }
  357. results := map[string]string{}
  358. for name := range serviceToBeBuild {
  359. image := expectedImages[name]
  360. target := targets[name]
  361. built, ok := md[target]
  362. if !ok {
  363. return nil, fmt.Errorf("build result not found in Bake metadata for service %s", name)
  364. }
  365. results[image] = built.Digest
  366. s.events.On(progress.BuiltEvent(image))
  367. }
  368. return results, nil
  369. }
  370. // makeConsole wraps the provided writer to match [containerd.File] interface if it is of type *streams.Out.
  371. // buildkit's NewDisplay doesn't actually require a [io.Reader], it only uses the [containerd.Console] type to
  372. // benefits from ANSI capabilities, but only does writes.
  373. func makeConsole(out io.Writer) io.Writer {
  374. if s, ok := out.(*streams.Out); ok {
  375. return &_console{s}
  376. }
  377. return out
  378. }
  379. var _ console.File = &_console{}
  380. type _console struct {
  381. *streams.Out
  382. }
  383. func (c _console) Read(p []byte) (n int, err error) {
  384. return 0, errors.New("not implemented")
  385. }
  386. func (c _console) Close() error {
  387. return nil
  388. }
  389. func (c _console) Fd() uintptr {
  390. return c.FD()
  391. }
  392. func (c _console) Name() string {
  393. return "compose"
  394. }
  395. func toBakeExtraHosts(hosts types.HostsList) map[string]string {
  396. m := make(map[string]string)
  397. for k, v := range hosts {
  398. m[k] = strings.Join(v, ",")
  399. }
  400. return m
  401. }
  402. func additionalContexts(contexts types.Mapping, targets map[string]string) map[string]string {
  403. ac := map[string]string{}
  404. for k, v := range contexts {
  405. if target, found := strings.CutPrefix(v, types.ServicePrefix); found {
  406. v = "target:" + targets[target]
  407. }
  408. ac[k] = v
  409. }
  410. return ac
  411. }
  412. func toBakeUlimits(ulimits map[string]*types.UlimitsConfig) []string {
  413. s := []string{}
  414. for u, l := range ulimits {
  415. if l.Single > 0 {
  416. s = append(s, fmt.Sprintf("%s=%d", u, l.Single))
  417. } else {
  418. s = append(s, fmt.Sprintf("%s=%d:%d", u, l.Soft, l.Hard))
  419. }
  420. }
  421. return s
  422. }
  423. func toBakeSSH(ssh types.SSHConfig) []string {
  424. var s []string
  425. for _, key := range ssh {
  426. s = append(s, fmt.Sprintf("%s=%s", key.ID, key.Path))
  427. }
  428. return s
  429. }
  430. func toBakeSecrets(project *types.Project, secrets []types.ServiceSecretConfig) ([]string, []string) {
  431. var s []string
  432. var env []string
  433. for _, ref := range secrets {
  434. def := project.Secrets[ref.Source]
  435. target := ref.Target
  436. if target == "" {
  437. target = ref.Source
  438. }
  439. switch {
  440. case def.Environment != "":
  441. env = append(env, fmt.Sprintf("%s=%s", def.Environment, project.Environment[def.Environment]))
  442. s = append(s, fmt.Sprintf("id=%s,type=env,env=%s", target, def.Environment))
  443. case def.File != "":
  444. s = append(s, fmt.Sprintf("id=%s,type=file,src=%s", target, def.File))
  445. }
  446. }
  447. return s, env
  448. }
  449. func toBakeAttest(buildConfig types.BuildConfig) []string {
  450. var attests []string
  451. // Handle per-service provenance configuration (only from build config, not global options)
  452. if buildConfig.Provenance != "" {
  453. if buildConfig.Provenance == "true" {
  454. attests = append(attests, "type=provenance")
  455. } else if buildConfig.Provenance != "false" {
  456. attests = append(attests, fmt.Sprintf("type=provenance,%s", buildConfig.Provenance))
  457. }
  458. }
  459. // Handle per-service SBOM configuration (only from build config, not global options)
  460. if buildConfig.SBOM != "" {
  461. if buildConfig.SBOM == "true" {
  462. attests = append(attests, "type=sbom")
  463. } else if buildConfig.SBOM != "false" {
  464. attests = append(attests, fmt.Sprintf("type=sbom,%s", buildConfig.SBOM))
  465. }
  466. }
  467. return attests
  468. }
  469. func dockerFilePath(ctxName string, dockerfile string) string {
  470. if dockerfile == "" {
  471. return ""
  472. }
  473. if contextType, _ := build.DetectContextType(ctxName); contextType == build.ContextTypeGit {
  474. return dockerfile
  475. }
  476. if !filepath.IsAbs(dockerfile) {
  477. dockerfile = filepath.Join(ctxName, dockerfile)
  478. }
  479. dir := filepath.Dir(dockerfile)
  480. symlinks, err := filepath.EvalSymlinks(dir)
  481. if err == nil {
  482. return filepath.Join(symlinks, filepath.Base(dockerfile))
  483. }
  484. return dockerfile
  485. }
  486. func (s composeService) dryRunBake(cfg bakeConfig) map[string]string {
  487. bakeResponse := map[string]string{}
  488. for name, target := range cfg.Targets {
  489. dryRunUUID := fmt.Sprintf("dryRun-%x", sha1.Sum([]byte(name)))
  490. s.displayDryRunBuildEvent(name, dryRunUUID, target.Tags[0])
  491. bakeResponse[name] = dryRunUUID
  492. }
  493. for name := range bakeResponse {
  494. s.events.On(progress.BuiltEvent(name))
  495. }
  496. return bakeResponse
  497. }
  498. func (s composeService) displayDryRunBuildEvent(name, dryRunUUID, tag string) {
  499. s.events.On(progress.Event{
  500. ID: name + " ==>",
  501. Status: progress.Done,
  502. Text: fmt.Sprintf("==> writing image %s", dryRunUUID),
  503. })
  504. s.events.On(progress.Event{
  505. ID: name + " ==> ==>",
  506. Status: progress.Done,
  507. Text: fmt.Sprintf(`naming to %s`, tag),
  508. })
  509. }