build_bake.go 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498
  1. /*
  2. Copyright 2020 Docker Compose CLI authors
  3. Licensed under the Apache License, Version 2.0 (the "License");
  4. you may not use this file except in compliance with the License.
  5. You may obtain a copy of the License at
  6. http://www.apache.org/licenses/LICENSE-2.0
  7. Unless required by applicable law or agreed to in writing, software
  8. distributed under the License is distributed on an "AS IS" BASIS,
  9. WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  10. See the License for the specific language governing permissions and
  11. limitations under the License.
  12. */
  13. package compose
  14. import (
  15. "bufio"
  16. "bytes"
  17. "context"
  18. "crypto/sha1"
  19. "encoding/json"
  20. "errors"
  21. "fmt"
  22. "io"
  23. "math/rand"
  24. "os"
  25. "os/exec"
  26. "path/filepath"
  27. "slices"
  28. "strconv"
  29. "strings"
  30. "github.com/compose-spec/compose-go/v2/types"
  31. "github.com/docker/cli/cli-plugins/manager"
  32. "github.com/docker/cli/cli/command"
  33. "github.com/docker/compose/v2/pkg/api"
  34. "github.com/docker/compose/v2/pkg/progress"
  35. "github.com/docker/docker/api/types/versions"
  36. "github.com/docker/docker/builder/remotecontext/urlutil"
  37. "github.com/moby/buildkit/client"
  38. "github.com/moby/buildkit/util/gitutil"
  39. "github.com/moby/buildkit/util/progress/progressui"
  40. "github.com/sirupsen/logrus"
  41. "github.com/spf13/cobra"
  42. "golang.org/x/sync/errgroup"
  43. )
  44. func buildWithBake(dockerCli command.Cli) (bool, error) {
  45. b, ok := os.LookupEnv("COMPOSE_BAKE")
  46. if !ok {
  47. b = "true"
  48. }
  49. bake, err := strconv.ParseBool(b)
  50. if err != nil {
  51. return false, err
  52. }
  53. if !bake {
  54. if ok {
  55. logrus.Warnf("COMPOSE_BAKE=false is deprecated, support for internal compose builder will be removed in next release")
  56. }
  57. return false, nil
  58. }
  59. enabled, err := dockerCli.BuildKitEnabled()
  60. if err != nil {
  61. return false, err
  62. }
  63. if !enabled {
  64. logrus.Warnf("Docker Compose is configured to build using Bake, but buildkit isn't enabled")
  65. return false, nil
  66. }
  67. _, err = manager.GetPlugin("buildx", dockerCli, &cobra.Command{})
  68. if err != nil {
  69. if manager.IsNotFound(err) {
  70. logrus.Warnf("Docker Compose is configured to build using Bake, but buildx isn't installed")
  71. return false, nil
  72. }
  73. return false, err
  74. }
  75. return true, err
  76. }
  77. // We _could_ use bake.* types from github.com/docker/buildx but long term plan is to remove buildx as a dependency
  78. type bakeConfig struct {
  79. Groups map[string]bakeGroup `json:"group"`
  80. Targets map[string]bakeTarget `json:"target"`
  81. }
  82. type bakeGroup struct {
  83. Targets []string `json:"targets"`
  84. }
  85. type bakeTarget struct {
  86. Context string `json:"context,omitempty"`
  87. Contexts map[string]string `json:"contexts,omitempty"`
  88. Dockerfile string `json:"dockerfile,omitempty"`
  89. DockerfileInline string `json:"dockerfile-inline,omitempty"`
  90. Args map[string]string `json:"args,omitempty"`
  91. Labels map[string]string `json:"labels,omitempty"`
  92. Tags []string `json:"tags,omitempty"`
  93. CacheFrom []string `json:"cache-from,omitempty"`
  94. CacheTo []string `json:"cache-to,omitempty"`
  95. Target string `json:"target,omitempty"`
  96. Secrets []string `json:"secret,omitempty"`
  97. SSH []string `json:"ssh,omitempty"`
  98. Platforms []string `json:"platforms,omitempty"`
  99. Pull bool `json:"pull,omitempty"`
  100. NoCache bool `json:"no-cache,omitempty"`
  101. NetworkMode string `json:"network,omitempty"`
  102. NoCacheFilter []string `json:"no-cache-filter,omitempty"`
  103. ShmSize types.UnitBytes `json:"shm-size,omitempty"`
  104. Ulimits []string `json:"ulimits,omitempty"`
  105. Call string `json:"call,omitempty"`
  106. Entitlements []string `json:"entitlements,omitempty"`
  107. ExtraHosts map[string]string `json:"extra-hosts,omitempty"`
  108. Outputs []string `json:"output,omitempty"`
  109. }
  110. type bakeMetadata map[string]buildStatus
  111. type buildStatus struct {
  112. Digest string `json:"containerimage.digest"`
  113. Image string `json:"image.name"`
  114. }
  115. func (s *composeService) doBuildBake(ctx context.Context, project *types.Project, serviceToBeBuild types.Services, options api.BuildOptions) (map[string]string, error) { //nolint:gocyclo
  116. eg := errgroup.Group{}
  117. ch := make(chan *client.SolveStatus)
  118. displayMode := progressui.DisplayMode(options.Progress)
  119. out := options.Out
  120. if out == nil {
  121. cout := s.dockerCli.Out()
  122. if !cout.IsTerminal() {
  123. displayMode = progressui.PlainMode
  124. }
  125. out = cout
  126. }
  127. display, err := progressui.NewDisplay(out, displayMode)
  128. if err != nil {
  129. return nil, err
  130. }
  131. eg.Go(func() error {
  132. _, err := display.UpdateFrom(ctx, ch)
  133. return err
  134. })
  135. cfg := bakeConfig{
  136. Groups: map[string]bakeGroup{},
  137. Targets: map[string]bakeTarget{},
  138. }
  139. var (
  140. group bakeGroup
  141. privileged bool
  142. read []string
  143. expectedImages = make(map[string]string, len(serviceToBeBuild)) // service name -> expected image
  144. targets = make(map[string]string, len(serviceToBeBuild)) // service name -> build target
  145. )
  146. // produce a unique ID for service used as bake target
  147. for serviceName := range project.Services {
  148. t := strings.ReplaceAll(serviceName, ".", "_")
  149. for {
  150. if _, ok := targets[serviceName]; !ok {
  151. targets[serviceName] = t
  152. break
  153. }
  154. t += "_"
  155. }
  156. }
  157. for serviceName, service := range project.Services {
  158. if service.Build == nil {
  159. continue
  160. }
  161. build := *service.Build
  162. labels := getImageBuildLabels(project, service)
  163. args := types.Mapping{}
  164. for k, v := range resolveAndMergeBuildArgs(s.dockerCli, project, service, options) {
  165. if v == nil {
  166. continue
  167. }
  168. args[k] = *v
  169. }
  170. entitlements := build.Entitlements
  171. if slices.Contains(build.Entitlements, "security.insecure") {
  172. privileged = true
  173. }
  174. if build.Privileged {
  175. entitlements = append(entitlements, "security.insecure")
  176. privileged = true
  177. }
  178. var outputs []string
  179. var call string
  180. push := options.Push && service.Image != ""
  181. switch {
  182. case options.Check:
  183. call = "lint"
  184. case len(service.Build.Platforms) > 1:
  185. outputs = []string{fmt.Sprintf("type=image,push=%t", push)}
  186. default:
  187. if push {
  188. outputs = []string{"type=registry"}
  189. } else {
  190. outputs = []string{"type=docker"}
  191. }
  192. }
  193. read = append(read, build.Context)
  194. for _, path := range build.AdditionalContexts {
  195. _, err := gitutil.ParseGitRef(path)
  196. if !strings.Contains(path, "://") && err != nil {
  197. read = append(read, path)
  198. }
  199. }
  200. image := api.GetImageNameOrDefault(service, project.Name)
  201. expectedImages[serviceName] = image
  202. target := targets[serviceName]
  203. cfg.Targets[target] = bakeTarget{
  204. Context: build.Context,
  205. Contexts: additionalContexts(build.AdditionalContexts, targets),
  206. Dockerfile: dockerFilePath(build.Context, build.Dockerfile),
  207. DockerfileInline: strings.ReplaceAll(build.DockerfileInline, "${", "$${"),
  208. Args: args,
  209. Labels: labels,
  210. Tags: append(build.Tags, image),
  211. CacheFrom: build.CacheFrom,
  212. CacheTo: build.CacheTo,
  213. NetworkMode: build.Network,
  214. Platforms: build.Platforms,
  215. Target: build.Target,
  216. Secrets: toBakeSecrets(project, build.Secrets),
  217. SSH: toBakeSSH(append(build.SSH, options.SSHs...)),
  218. Pull: options.Pull,
  219. NoCache: options.NoCache,
  220. ShmSize: build.ShmSize,
  221. Ulimits: toBakeUlimits(build.Ulimits),
  222. Entitlements: entitlements,
  223. ExtraHosts: toBakeExtraHosts(build.ExtraHosts),
  224. Outputs: outputs,
  225. Call: call,
  226. }
  227. }
  228. // create a bake group with targets for services to build
  229. for serviceName, service := range serviceToBeBuild {
  230. if service.Build == nil {
  231. continue
  232. }
  233. group.Targets = append(group.Targets, targets[serviceName])
  234. }
  235. cfg.Groups["default"] = group
  236. b, err := json.MarshalIndent(cfg, "", " ")
  237. if err != nil {
  238. return nil, err
  239. }
  240. if options.Print {
  241. _, err = fmt.Fprintln(s.stdout(), string(b))
  242. return nil, err
  243. }
  244. logrus.Debugf("bake build config:\n%s", string(b))
  245. var metadataFile string
  246. for {
  247. // we don't use os.CreateTemp here as we need a temporary file name, but don't want it actually created
  248. // as bake relies on atomicwriter and this creates conflict during rename
  249. metadataFile = filepath.Join(os.TempDir(), fmt.Sprintf("compose-build-metadataFile-%d.json", rand.Int31()))
  250. if _, err = os.Stat(metadataFile); os.IsNotExist(err) {
  251. break
  252. }
  253. }
  254. defer func() {
  255. _ = os.Remove(metadataFile)
  256. }()
  257. buildx, err := manager.GetPlugin("buildx", s.dockerCli, &cobra.Command{})
  258. if err != nil {
  259. return nil, err
  260. }
  261. args := []string{"bake", "--file", "-", "--progress", "rawjson", "--metadata-file", metadataFile}
  262. mustAllow := buildx.Version != "" && versions.GreaterThanOrEqualTo(buildx.Version[1:], "0.17.0")
  263. if mustAllow {
  264. // FIXME we should prompt user about this, but this is a breaking change in UX
  265. for _, path := range read {
  266. args = append(args, "--allow", "fs.read="+path)
  267. }
  268. if privileged {
  269. args = append(args, "--allow", "security.insecure")
  270. }
  271. }
  272. if options.Builder != "" {
  273. args = append(args, "--builder", options.Builder)
  274. }
  275. if options.Quiet {
  276. args = append(args, "--progress=quiet")
  277. }
  278. logrus.Debugf("Executing bake with args: %v", args)
  279. if s.dryRun {
  280. return dryRunBake(ctx, cfg), nil
  281. }
  282. cmd := exec.CommandContext(ctx, buildx.Path, args...)
  283. err = s.prepareShellOut(ctx, project.Environment, cmd)
  284. if err != nil {
  285. return nil, err
  286. }
  287. cmd.Stdout = s.stdout()
  288. cmd.Stdin = bytes.NewBuffer(b)
  289. pipe, err := cmd.StderrPipe()
  290. if err != nil {
  291. return nil, err
  292. }
  293. var errMessage []string
  294. reader := bufio.NewReader(pipe)
  295. err = cmd.Start()
  296. if err != nil {
  297. return nil, err
  298. }
  299. eg.Go(cmd.Wait)
  300. for {
  301. line, readErr := reader.ReadString('\n')
  302. if readErr != nil {
  303. if readErr == io.EOF {
  304. break
  305. } else {
  306. return nil, fmt.Errorf("failed to execute bake: %w", readErr)
  307. }
  308. }
  309. decoder := json.NewDecoder(strings.NewReader(line))
  310. var status client.SolveStatus
  311. err := decoder.Decode(&status)
  312. if err != nil {
  313. if strings.HasPrefix(line, "ERROR: ") {
  314. errMessage = append(errMessage, line[7:])
  315. } else {
  316. errMessage = append(errMessage, line)
  317. }
  318. continue
  319. }
  320. ch <- &status
  321. }
  322. close(ch) // stop build progress UI
  323. err = eg.Wait()
  324. if err != nil {
  325. if len(errMessage) > 0 {
  326. return nil, errors.New(strings.Join(errMessage, "\n"))
  327. }
  328. return nil, fmt.Errorf("failed to execute bake: %w", err)
  329. }
  330. b, err = os.ReadFile(metadataFile)
  331. if err != nil {
  332. return nil, err
  333. }
  334. var md bakeMetadata
  335. err = json.Unmarshal(b, &md)
  336. if err != nil {
  337. return nil, err
  338. }
  339. cw := progress.ContextWriter(ctx)
  340. results := map[string]string{}
  341. for name := range serviceToBeBuild {
  342. image := expectedImages[name]
  343. target := targets[name]
  344. built, ok := md[target]
  345. if !ok {
  346. return nil, fmt.Errorf("build result not found in Bake metadata for service %s", name)
  347. }
  348. results[image] = built.Digest
  349. cw.Event(progress.BuiltEvent(image))
  350. }
  351. return results, nil
  352. }
  353. func toBakeExtraHosts(hosts types.HostsList) map[string]string {
  354. m := make(map[string]string)
  355. for k, v := range hosts {
  356. m[k] = strings.Join(v, ",")
  357. }
  358. return m
  359. }
  360. func additionalContexts(contexts types.Mapping, targets map[string]string) map[string]string {
  361. ac := map[string]string{}
  362. for k, v := range contexts {
  363. if target, found := strings.CutPrefix(v, types.ServicePrefix); found {
  364. v = "target:" + targets[target]
  365. }
  366. ac[k] = v
  367. }
  368. return ac
  369. }
  370. func toBakeUlimits(ulimits map[string]*types.UlimitsConfig) []string {
  371. s := []string{}
  372. for u, l := range ulimits {
  373. if l.Single > 0 {
  374. s = append(s, fmt.Sprintf("%s=%d", u, l.Single))
  375. } else {
  376. s = append(s, fmt.Sprintf("%s=%d:%d", u, l.Soft, l.Hard))
  377. }
  378. }
  379. return s
  380. }
  381. func toBakeSSH(ssh types.SSHConfig) []string {
  382. var s []string
  383. for _, key := range ssh {
  384. s = append(s, fmt.Sprintf("%s=%s", key.ID, key.Path))
  385. }
  386. return s
  387. }
  388. func toBakeSecrets(project *types.Project, secrets []types.ServiceSecretConfig) []string {
  389. var s []string
  390. for _, ref := range secrets {
  391. def := project.Secrets[ref.Source]
  392. target := ref.Target
  393. if target == "" {
  394. target = ref.Source
  395. }
  396. switch {
  397. case def.Environment != "":
  398. s = append(s, fmt.Sprintf("id=%s,type=env,env=%s", target, def.Environment))
  399. case def.File != "":
  400. s = append(s, fmt.Sprintf("id=%s,type=file,src=%s", target, def.File))
  401. }
  402. }
  403. return s
  404. }
  405. func dockerFilePath(ctxName string, dockerfile string) string {
  406. if dockerfile == "" {
  407. return ""
  408. }
  409. if urlutil.IsGitURL(ctxName) {
  410. return dockerfile
  411. }
  412. if !filepath.IsAbs(dockerfile) {
  413. dockerfile = filepath.Join(ctxName, dockerfile)
  414. }
  415. dir := filepath.Dir(dockerfile)
  416. symlinks, err := filepath.EvalSymlinks(dir)
  417. if err == nil {
  418. return filepath.Join(symlinks, filepath.Base(dockerfile))
  419. }
  420. return dockerfile
  421. }
  422. func dryRunBake(ctx context.Context, cfg bakeConfig) map[string]string {
  423. w := progress.ContextWriter(ctx)
  424. bakeResponse := map[string]string{}
  425. for name, target := range cfg.Targets {
  426. dryRunUUID := fmt.Sprintf("dryRun-%x", sha1.Sum([]byte(name)))
  427. displayDryRunBuildEvent(w, name, dryRunUUID, target.Tags[0])
  428. bakeResponse[name] = dryRunUUID
  429. }
  430. for name := range bakeResponse {
  431. w.Event(progress.BuiltEvent(name))
  432. }
  433. return bakeResponse
  434. }
  435. func displayDryRunBuildEvent(w progress.Writer, name string, dryRunUUID, tag string) {
  436. w.Event(progress.Event{
  437. ID: name + " ==>",
  438. Status: progress.Done,
  439. Text: fmt.Sprintf("==> writing image %s", dryRunUUID),
  440. })
  441. w.Event(progress.Event{
  442. ID: name + " ==> ==>",
  443. Status: progress.Done,
  444. Text: fmt.Sprintf(`naming to %s`, tag),
  445. })
  446. }