build_bake.go 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466
  1. /*
  2. Copyright 2020 Docker Compose CLI authors
  3. Licensed under the Apache License, Version 2.0 (the "License");
  4. you may not use this file except in compliance with the License.
  5. You may obtain a copy of the License at
  6. http://www.apache.org/licenses/LICENSE-2.0
  7. Unless required by applicable law or agreed to in writing, software
  8. distributed under the License is distributed on an "AS IS" BASIS,
  9. WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  10. See the License for the specific language governing permissions and
  11. limitations under the License.
  12. */
  13. package compose
  14. import (
  15. "bufio"
  16. "bytes"
  17. "context"
  18. "encoding/json"
  19. "errors"
  20. "fmt"
  21. "math/rand"
  22. "os"
  23. "os/exec"
  24. "path/filepath"
  25. "slices"
  26. "strconv"
  27. "strings"
  28. "github.com/compose-spec/compose-go/v2/types"
  29. "github.com/docker/cli/cli-plugins/manager"
  30. "github.com/docker/cli/cli-plugins/socket"
  31. "github.com/docker/cli/cli/command"
  32. "github.com/docker/compose/v2/pkg/api"
  33. "github.com/docker/compose/v2/pkg/progress"
  34. "github.com/docker/docker/api/types/versions"
  35. "github.com/docker/docker/builder/remotecontext/urlutil"
  36. "github.com/moby/buildkit/client"
  37. "github.com/moby/buildkit/util/gitutil"
  38. "github.com/moby/buildkit/util/progress/progressui"
  39. "github.com/sirupsen/logrus"
  40. "github.com/spf13/cobra"
  41. "go.opentelemetry.io/otel"
  42. "go.opentelemetry.io/otel/propagation"
  43. "golang.org/x/sync/errgroup"
  44. )
  45. func buildWithBake(dockerCli command.Cli) (bool, error) {
  46. b, ok := os.LookupEnv("COMPOSE_BAKE")
  47. if !ok {
  48. b = "true"
  49. }
  50. bake, err := strconv.ParseBool(b)
  51. if err != nil {
  52. return false, err
  53. }
  54. if !bake {
  55. return false, nil
  56. }
  57. enabled, err := dockerCli.BuildKitEnabled()
  58. if err != nil {
  59. return false, err
  60. }
  61. if !enabled {
  62. logrus.Warnf("Docker Compose is configured to build using Bake, but buildkit isn't enabled")
  63. return false, nil
  64. }
  65. _, err = manager.GetPlugin("buildx", dockerCli, &cobra.Command{})
  66. if err != nil {
  67. if manager.IsNotFound(err) {
  68. logrus.Warnf("Docker Compose is configured to build using Bake, but buildx isn't installed")
  69. return false, nil
  70. }
  71. return false, err
  72. }
  73. return true, err
  74. }
  75. // We _could_ use bake.* types from github.com/docker/buildx but long term plan is to remove buildx as a dependency
  76. type bakeConfig struct {
  77. Groups map[string]bakeGroup `json:"group"`
  78. Targets map[string]bakeTarget `json:"target"`
  79. }
  80. type bakeGroup struct {
  81. Targets []string `json:"targets"`
  82. }
  83. type bakeTarget struct {
  84. Context string `json:"context,omitempty"`
  85. Contexts map[string]string `json:"contexts,omitempty"`
  86. Dockerfile string `json:"dockerfile,omitempty"`
  87. DockerfileInline string `json:"dockerfile-inline,omitempty"`
  88. Args map[string]string `json:"args,omitempty"`
  89. Labels map[string]string `json:"labels,omitempty"`
  90. Tags []string `json:"tags,omitempty"`
  91. CacheFrom []string `json:"cache-from,omitempty"`
  92. CacheTo []string `json:"cache-to,omitempty"`
  93. Target string `json:"target,omitempty"`
  94. Secrets []string `json:"secret,omitempty"`
  95. SSH []string `json:"ssh,omitempty"`
  96. Platforms []string `json:"platforms,omitempty"`
  97. Pull bool `json:"pull,omitempty"`
  98. NoCache bool `json:"no-cache,omitempty"`
  99. NetworkMode string `json:"network,omitempty"`
  100. NoCacheFilter []string `json:"no-cache-filter,omitempty"`
  101. ShmSize types.UnitBytes `json:"shm-size,omitempty"`
  102. Ulimits []string `json:"ulimits,omitempty"`
  103. Call string `json:"call,omitempty"`
  104. Entitlements []string `json:"entitlements,omitempty"`
  105. ExtraHosts map[string]string `json:"extra-hosts,omitempty"`
  106. Outputs []string `json:"output,omitempty"`
  107. }
  108. type bakeMetadata map[string]buildStatus
  109. type buildStatus struct {
  110. Digest string `json:"containerimage.digest"`
  111. Image string `json:"image.name"`
  112. }
  113. func (s *composeService) doBuildBake(ctx context.Context, project *types.Project, serviceToBeBuild types.Services, options api.BuildOptions) (map[string]string, error) { //nolint:gocyclo
  114. eg := errgroup.Group{}
  115. ch := make(chan *client.SolveStatus)
  116. display, err := progressui.NewDisplay(os.Stdout, progressui.DisplayMode(options.Progress))
  117. if err != nil {
  118. return nil, err
  119. }
  120. eg.Go(func() error {
  121. _, err := display.UpdateFrom(ctx, ch)
  122. return err
  123. })
  124. cfg := bakeConfig{
  125. Groups: map[string]bakeGroup{},
  126. Targets: map[string]bakeTarget{},
  127. }
  128. var (
  129. group bakeGroup
  130. privileged bool
  131. read []string
  132. targets = make(map[string]string, len(serviceToBeBuild)) // service name -> build target
  133. )
  134. // produce a unique ID for service used as bake target
  135. for serviceName := range project.Services {
  136. t := strings.ReplaceAll(serviceName, ".", "_")
  137. for {
  138. if _, ok := targets[serviceName]; !ok {
  139. targets[serviceName] = t
  140. break
  141. }
  142. t += "_"
  143. }
  144. }
  145. for serviceName, service := range project.Services {
  146. if service.Build == nil {
  147. continue
  148. }
  149. build := *service.Build
  150. args := types.Mapping{}
  151. for k, v := range resolveAndMergeBuildArgs(s.dockerCli, project, service, options) {
  152. if v == nil {
  153. continue
  154. }
  155. args[k] = *v
  156. }
  157. entitlements := build.Entitlements
  158. if slices.Contains(build.Entitlements, "security.insecure") {
  159. privileged = true
  160. }
  161. if build.Privileged {
  162. entitlements = append(entitlements, "security.insecure")
  163. privileged = true
  164. }
  165. var outputs []string
  166. var call string
  167. push := options.Push && service.Image != ""
  168. switch {
  169. case options.Check:
  170. call = "lint"
  171. case len(service.Build.Platforms) > 1:
  172. outputs = []string{fmt.Sprintf("type=image,push=%t", push)}
  173. default:
  174. outputs = []string{fmt.Sprintf("type=docker,load=true,push=%t", push)}
  175. }
  176. read = append(read, build.Context)
  177. for _, path := range build.AdditionalContexts {
  178. _, err := gitutil.ParseGitRef(path)
  179. if !strings.Contains(path, "://") && err != nil {
  180. read = append(read, path)
  181. }
  182. }
  183. target := targets[serviceName]
  184. cfg.Targets[target] = bakeTarget{
  185. Context: build.Context,
  186. Contexts: additionalContexts(build.AdditionalContexts, targets),
  187. Dockerfile: dockerFilePath(build.Context, build.Dockerfile),
  188. DockerfileInline: strings.ReplaceAll(build.DockerfileInline, "${", "$${"),
  189. Args: args,
  190. Labels: build.Labels,
  191. Tags: append(build.Tags, api.GetImageNameOrDefault(service, project.Name)),
  192. CacheFrom: build.CacheFrom,
  193. // CacheTo: TODO
  194. Platforms: build.Platforms,
  195. Target: build.Target,
  196. Secrets: toBakeSecrets(project, build.Secrets),
  197. SSH: toBakeSSH(append(build.SSH, options.SSHs...)),
  198. Pull: options.Pull,
  199. NoCache: options.NoCache,
  200. ShmSize: build.ShmSize,
  201. Ulimits: toBakeUlimits(build.Ulimits),
  202. Entitlements: entitlements,
  203. ExtraHosts: toBakeExtraHosts(build.ExtraHosts),
  204. Outputs: outputs,
  205. Call: call,
  206. }
  207. }
  208. // create a bake group with targets for services to build
  209. for serviceName, service := range serviceToBeBuild {
  210. if service.Build == nil {
  211. continue
  212. }
  213. group.Targets = append(group.Targets, targets[serviceName])
  214. }
  215. cfg.Groups["default"] = group
  216. b, err := json.MarshalIndent(cfg, "", " ")
  217. if err != nil {
  218. return nil, err
  219. }
  220. if options.Print {
  221. _, err = fmt.Fprintln(s.stdout(), string(b))
  222. return nil, err
  223. }
  224. logrus.Debugf("bake build config:\n%s", string(b))
  225. var metadataFile string
  226. for {
  227. // we don't use os.CreateTemp here as we need a temporary file name, but don't want it actually created
  228. // as bake relies on atomicwriter and this creates conflict during rename
  229. metadataFile = filepath.Join(os.TempDir(), fmt.Sprintf("compose-build-metadataFile-%d.json", rand.Int31()))
  230. if _, err = os.Stat(metadataFile); os.IsNotExist(err) {
  231. break
  232. }
  233. }
  234. defer func() {
  235. _ = os.Remove(metadataFile)
  236. }()
  237. buildx, err := manager.GetPlugin("buildx", s.dockerCli, &cobra.Command{})
  238. if err != nil {
  239. return nil, err
  240. }
  241. args := []string{"bake", "--file", "-", "--progress", "rawjson", "--metadata-file", metadataFile}
  242. mustAllow := buildx.Version != "" && versions.GreaterThanOrEqualTo(buildx.Version[1:], "0.17.0")
  243. if mustAllow {
  244. // FIXME we should prompt user about this, but this is a breaking change in UX
  245. for _, path := range read {
  246. args = append(args, "--allow", "fs.read="+path)
  247. }
  248. if privileged {
  249. args = append(args, "--allow", "security.insecure")
  250. }
  251. }
  252. if options.Builder != "" {
  253. args = append(args, "--builder", options.Builder)
  254. }
  255. if options.Quiet {
  256. args = append(args, "--progress=quiet")
  257. }
  258. logrus.Debugf("Executing bake with args: %v", args)
  259. cmd := exec.CommandContext(ctx, buildx.Path, args...)
  260. // Remove DOCKER_CLI_PLUGIN... variable so buildx can detect it run standalone
  261. cmd.Env = filter(os.Environ(), manager.ReexecEnvvar)
  262. // Use docker/cli mechanism to propagate termination signal to child process
  263. server, err := socket.NewPluginServer(nil)
  264. if err == nil {
  265. defer server.Close() //nolint:errcheck
  266. cmd.Env = replace(cmd.Env, socket.EnvKey, server.Addr().String())
  267. }
  268. cmd.Env = append(cmd.Env, fmt.Sprintf("DOCKER_CONTEXT=%s", s.dockerCli.CurrentContext()))
  269. // propagate opentelemetry context to child process, see https://github.com/open-telemetry/oteps/blob/main/text/0258-env-context-baggage-carriers.md
  270. carrier := propagation.MapCarrier{}
  271. otel.GetTextMapPropagator().Inject(ctx, &carrier)
  272. cmd.Env = append(cmd.Env, types.Mapping(carrier).Values()...)
  273. cmd.Stdout = s.stdout()
  274. cmd.Stdin = bytes.NewBuffer(b)
  275. pipe, err := cmd.StderrPipe()
  276. if err != nil {
  277. return nil, err
  278. }
  279. var errMessage []string
  280. scanner := bufio.NewScanner(pipe)
  281. scanner.Split(bufio.ScanLines)
  282. err = cmd.Start()
  283. if err != nil {
  284. return nil, err
  285. }
  286. eg.Go(cmd.Wait)
  287. for scanner.Scan() {
  288. line := scanner.Text()
  289. decoder := json.NewDecoder(strings.NewReader(line))
  290. var status client.SolveStatus
  291. err := decoder.Decode(&status)
  292. if err != nil {
  293. if strings.HasPrefix(line, "ERROR: ") {
  294. errMessage = append(errMessage, line[7:])
  295. } else {
  296. errMessage = append(errMessage, line)
  297. }
  298. continue
  299. }
  300. ch <- &status
  301. }
  302. close(ch) // stop build progress UI
  303. err = eg.Wait()
  304. if err != nil {
  305. if len(errMessage) > 0 {
  306. return nil, errors.New(strings.Join(errMessage, "\n"))
  307. }
  308. return nil, fmt.Errorf("failed to execute bake: %w", err)
  309. }
  310. b, err = os.ReadFile(metadataFile)
  311. if err != nil {
  312. return nil, err
  313. }
  314. var md bakeMetadata
  315. err = json.Unmarshal(b, &md)
  316. if err != nil {
  317. return nil, err
  318. }
  319. cw := progress.ContextWriter(ctx)
  320. results := map[string]string{}
  321. for name := range serviceToBeBuild {
  322. target := targets[name]
  323. built, ok := md[target]
  324. if !ok {
  325. return nil, fmt.Errorf("build result not found in Bake metadata for service %s", name)
  326. }
  327. results[name] = built.Digest
  328. cw.Event(progress.BuiltEvent(name))
  329. }
  330. return results, nil
  331. }
  332. func toBakeExtraHosts(hosts types.HostsList) map[string]string {
  333. m := make(map[string]string)
  334. for k, v := range hosts {
  335. m[k] = strings.Join(v, ",")
  336. }
  337. return m
  338. }
  339. func additionalContexts(contexts types.Mapping, targets map[string]string) map[string]string {
  340. ac := map[string]string{}
  341. for k, v := range contexts {
  342. if target, found := strings.CutPrefix(v, types.ServicePrefix); found {
  343. v = "target:" + targets[target]
  344. }
  345. ac[k] = v
  346. }
  347. return ac
  348. }
  349. func toBakeUlimits(ulimits map[string]*types.UlimitsConfig) []string {
  350. s := []string{}
  351. for u, l := range ulimits {
  352. if l.Single > 0 {
  353. s = append(s, fmt.Sprintf("%s=%d", u, l.Single))
  354. } else {
  355. s = append(s, fmt.Sprintf("%s=%d:%d", u, l.Soft, l.Hard))
  356. }
  357. }
  358. return s
  359. }
  360. func toBakeSSH(ssh types.SSHConfig) []string {
  361. var s []string
  362. for _, key := range ssh {
  363. s = append(s, fmt.Sprintf("%s=%s", key.ID, key.Path))
  364. }
  365. return s
  366. }
  367. func toBakeSecrets(project *types.Project, secrets []types.ServiceSecretConfig) []string {
  368. var s []string
  369. for _, ref := range secrets {
  370. def := project.Secrets[ref.Source]
  371. target := ref.Target
  372. if target == "" {
  373. target = ref.Source
  374. }
  375. switch {
  376. case def.Environment != "":
  377. s = append(s, fmt.Sprintf("id=%s,type=env,env=%s", target, def.Environment))
  378. case def.File != "":
  379. s = append(s, fmt.Sprintf("id=%s,type=file,src=%s", target, def.File))
  380. }
  381. }
  382. return s
  383. }
  384. func filter(environ []string, variable string) []string {
  385. prefix := variable + "="
  386. filtered := make([]string, 0, len(environ))
  387. for _, val := range environ {
  388. if !strings.HasPrefix(val, prefix) {
  389. filtered = append(filtered, val)
  390. }
  391. }
  392. return filtered
  393. }
  394. func replace(environ []string, variable, value string) []string {
  395. filtered := filter(environ, variable)
  396. return append(filtered, fmt.Sprintf("%s=%s", variable, value))
  397. }
  398. func dockerFilePath(ctxName string, dockerfile string) string {
  399. if dockerfile == "" {
  400. return ""
  401. }
  402. if urlutil.IsGitURL(ctxName) {
  403. return dockerfile
  404. }
  405. if !filepath.IsAbs(dockerfile) {
  406. dockerfile = filepath.Join(ctxName, dockerfile)
  407. }
  408. symlinks, err := filepath.EvalSymlinks(dockerfile)
  409. if err == nil {
  410. return symlinks
  411. }
  412. return dockerfile
  413. }