build.go 19 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642
  1. /*
  2. Copyright 2020 Docker Compose CLI authors
  3. Licensed under the Apache License, Version 2.0 (the "License");
  4. you may not use this file except in compliance with the License.
  5. You may obtain a copy of the License at
  6. http://www.apache.org/licenses/LICENSE-2.0
  7. Unless required by applicable law or agreed to in writing, software
  8. distributed under the License is distributed on an "AS IS" BASIS,
  9. WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  10. See the License for the specific language governing permissions and
  11. limitations under the License.
  12. */
  13. package compose
  14. import (
  15. "context"
  16. "errors"
  17. "fmt"
  18. "os"
  19. "strings"
  20. "sync"
  21. "time"
  22. "github.com/compose-spec/compose-go/v2/types"
  23. "github.com/containerd/platforms"
  24. "github.com/docker/buildx/build"
  25. "github.com/docker/buildx/builder"
  26. "github.com/docker/buildx/controller/pb"
  27. "github.com/docker/buildx/store/storeutil"
  28. "github.com/docker/buildx/util/buildflags"
  29. xprogress "github.com/docker/buildx/util/progress"
  30. "github.com/docker/cli/cli/command"
  31. "github.com/docker/cli/cli/hints"
  32. cliopts "github.com/docker/cli/opts"
  33. "github.com/docker/compose/v2/internal/tracing"
  34. "github.com/docker/compose/v2/pkg/api"
  35. "github.com/docker/compose/v2/pkg/progress"
  36. "github.com/docker/compose/v2/pkg/utils"
  37. "github.com/docker/docker/api/types/container"
  38. bclient "github.com/moby/buildkit/client"
  39. "github.com/moby/buildkit/session"
  40. "github.com/moby/buildkit/session/auth/authprovider"
  41. "github.com/moby/buildkit/session/secrets/secretsprovider"
  42. "github.com/moby/buildkit/session/sshforward/sshprovider"
  43. "github.com/moby/buildkit/util/entitlements"
  44. "github.com/moby/buildkit/util/progress/progressui"
  45. specs "github.com/opencontainers/image-spec/specs-go/v1"
  46. "github.com/sirupsen/logrus"
  47. "go.opentelemetry.io/otel/attribute"
  48. "go.opentelemetry.io/otel/trace"
  49. // required to get default driver registered
  50. _ "github.com/docker/buildx/driver/docker"
  51. )
  52. func (s *composeService) Build(ctx context.Context, project *types.Project, options api.BuildOptions) error {
  53. err := options.Apply(project)
  54. if err != nil {
  55. return err
  56. }
  57. return progress.RunWithTitle(ctx, func(ctx context.Context) error {
  58. return tracing.SpanWrapFunc("project/build", tracing.ProjectOptions(ctx, project),
  59. func(ctx context.Context) error {
  60. _, err := s.build(ctx, project, options, nil)
  61. return err
  62. })(ctx)
  63. }, s.stdinfo(), "Building")
  64. }
  65. const bakeSuggest = "Compose can now delegate builds to bake for better performance.\n To do so, set COMPOSE_BAKE=true."
  66. var suggest sync.Once
  67. //nolint:gocyclo
  68. func (s *composeService) build(ctx context.Context, project *types.Project, options api.BuildOptions, localImages map[string]api.ImageSummary) (map[string]string, error) {
  69. imageIDs := map[string]string{}
  70. serviceToBuild := types.Services{}
  71. var policy types.DependencyOption = types.IgnoreDependencies
  72. if options.Deps {
  73. policy = types.IncludeDependencies
  74. }
  75. if len(options.Services) > 0 {
  76. // As user requested some services to be built, also include those used as additional_contexts
  77. options.Services = addBuildDependencies(options.Services, project)
  78. }
  79. project, err := project.WithSelectedServices(options.Services)
  80. if err != nil {
  81. return nil, err
  82. }
  83. err = project.ForEachService(options.Services, func(serviceName string, service *types.ServiceConfig) error {
  84. if service.Build == nil {
  85. return nil
  86. }
  87. image := api.GetImageNameOrDefault(*service, project.Name)
  88. _, localImagePresent := localImages[image]
  89. if localImagePresent && service.PullPolicy != types.PullPolicyBuild {
  90. return nil
  91. }
  92. serviceToBuild[serviceName] = *service
  93. return nil
  94. }, policy)
  95. if err != nil || len(serviceToBuild) == 0 {
  96. return imageIDs, err
  97. }
  98. bake, err := buildWithBake(s.dockerCli)
  99. if err != nil {
  100. return nil, err
  101. }
  102. if bake || options.Print {
  103. trace.SpanFromContext(ctx).SetAttributes(attribute.String("builder", "bake"))
  104. return s.doBuildBake(ctx, project, serviceToBuild, options)
  105. }
  106. // Not using bake, additional_context: service:xx is implemented by building images in dependency order
  107. project, err = project.WithServicesTransform(func(serviceName string, service types.ServiceConfig) (types.ServiceConfig, error) {
  108. if service.Build != nil {
  109. for _, c := range service.Build.AdditionalContexts {
  110. if t, found := strings.CutPrefix(c, types.ServicePrefix); found {
  111. if service.DependsOn == nil {
  112. service.DependsOn = map[string]types.ServiceDependency{}
  113. }
  114. service.DependsOn[t] = types.ServiceDependency{
  115. Condition: "build", // non-canonical, but will force dependency graph ordering
  116. }
  117. }
  118. }
  119. }
  120. return service, nil
  121. })
  122. if err != nil {
  123. return imageIDs, err
  124. }
  125. // Initialize buildkit nodes
  126. buildkitEnabled, err := s.dockerCli.BuildKitEnabled()
  127. if err != nil {
  128. return nil, err
  129. }
  130. var (
  131. b *builder.Builder
  132. nodes []builder.Node
  133. w *xprogress.Printer
  134. )
  135. if buildkitEnabled {
  136. if hints.Enabled() && progress.Mode != progress.ModeQuiet && progress.Mode != progress.ModeJSON {
  137. suggest.Do(func() {
  138. fmt.Fprintln(s.dockerCli.Out(), bakeSuggest) //nolint:errcheck
  139. })
  140. }
  141. builderName := options.Builder
  142. if builderName == "" {
  143. builderName = os.Getenv("BUILDX_BUILDER")
  144. }
  145. b, err = builder.New(s.dockerCli, builder.WithName(builderName))
  146. if err != nil {
  147. return nil, err
  148. }
  149. nodes, err = b.LoadNodes(ctx)
  150. if err != nil {
  151. return nil, err
  152. }
  153. // Progress needs its own context that lives longer than the
  154. // build one otherwise it won't read all the messages from
  155. // build and will lock
  156. progressCtx, cancel := context.WithCancel(context.Background())
  157. defer cancel()
  158. if options.Quiet {
  159. options.Progress = progress.ModeQuiet
  160. }
  161. if options.Progress == "" {
  162. options.Progress = os.Getenv("BUILDKIT_PROGRESS")
  163. }
  164. w, err = xprogress.NewPrinter(progressCtx, os.Stdout, progressui.DisplayMode(options.Progress),
  165. xprogress.WithDesc(
  166. fmt.Sprintf("building with %q instance using %s driver", b.Name, b.Driver),
  167. fmt.Sprintf("%s:%s", b.Driver, b.Name),
  168. ))
  169. if err != nil {
  170. return nil, err
  171. }
  172. }
  173. // we use a pre-allocated []string to collect build digest by service index while running concurrent goroutines
  174. builtDigests := make([]string, len(project.Services))
  175. names := project.ServiceNames()
  176. getServiceIndex := func(name string) int {
  177. for idx, n := range names {
  178. if n == name {
  179. return idx
  180. }
  181. }
  182. return -1
  183. }
  184. cw := progress.ContextWriter(ctx)
  185. err = InDependencyOrder(ctx, project, func(ctx context.Context, name string) error {
  186. service, ok := serviceToBuild[name]
  187. if !ok {
  188. return nil
  189. }
  190. serviceName := fmt.Sprintf("Service %s", name)
  191. if !buildkitEnabled {
  192. trace.SpanFromContext(ctx).SetAttributes(attribute.String("builder", "classic"))
  193. cw.Event(progress.BuildingEvent(serviceName))
  194. id, err := s.doBuildClassic(ctx, project, service, options)
  195. if err != nil {
  196. return err
  197. }
  198. cw.Event(progress.BuiltEvent(serviceName))
  199. builtDigests[getServiceIndex(name)] = id
  200. if options.Push {
  201. return s.push(ctx, project, api.PushOptions{})
  202. }
  203. return nil
  204. }
  205. if options.Memory != 0 {
  206. _, _ = fmt.Fprintln(s.stderr(), "WARNING: --memory is not supported by BuildKit and will be ignored")
  207. }
  208. buildOptions, err := s.toBuildOptions(project, service, options)
  209. if err != nil {
  210. return err
  211. }
  212. trace.SpanFromContext(ctx).SetAttributes(attribute.String("builder", "buildkit"))
  213. digest, err := s.doBuildBuildkit(ctx, name, buildOptions, w, nodes)
  214. if err != nil {
  215. return err
  216. }
  217. builtDigests[getServiceIndex(name)] = digest
  218. return nil
  219. }, func(traversal *graphTraversal) {
  220. traversal.maxConcurrency = s.maxConcurrency
  221. })
  222. // enforce all build event get consumed
  223. if buildkitEnabled {
  224. if errw := w.Wait(); errw != nil {
  225. return nil, errw
  226. }
  227. }
  228. if err != nil {
  229. return nil, err
  230. }
  231. for i, imageDigest := range builtDigests {
  232. if imageDigest != "" {
  233. service := project.Services[names[i]]
  234. imageRef := api.GetImageNameOrDefault(service, project.Name)
  235. imageIDs[imageRef] = imageDigest
  236. cw.Event(progress.BuiltEvent(names[i]))
  237. }
  238. }
  239. return imageIDs, err
  240. }
  241. func (s *composeService) ensureImagesExists(ctx context.Context, project *types.Project, buildOpts *api.BuildOptions, quietPull bool) error {
  242. for name, service := range project.Services {
  243. if service.Provider == nil && service.Image == "" && service.Build == nil {
  244. return fmt.Errorf("invalid service %q. Must specify either image or build", name)
  245. }
  246. }
  247. images, err := s.getLocalImagesDigests(ctx, project)
  248. if err != nil {
  249. return err
  250. }
  251. err = tracing.SpanWrapFunc("project/pull", tracing.ProjectOptions(ctx, project),
  252. func(ctx context.Context) error {
  253. return s.pullRequiredImages(ctx, project, images, quietPull)
  254. },
  255. )(ctx)
  256. if err != nil {
  257. return err
  258. }
  259. if buildOpts != nil {
  260. err = tracing.SpanWrapFunc("project/build", tracing.ProjectOptions(ctx, project),
  261. func(ctx context.Context) error {
  262. builtImages, err := s.build(ctx, project, *buildOpts, images)
  263. if err != nil {
  264. return err
  265. }
  266. for name, digest := range builtImages {
  267. images[name] = api.ImageSummary{
  268. Repository: name,
  269. ID: digest,
  270. LastTagTime: time.Now(),
  271. }
  272. }
  273. return nil
  274. },
  275. )(ctx)
  276. if err != nil {
  277. return err
  278. }
  279. }
  280. // set digest as com.docker.compose.image label so we can detect outdated containers
  281. for name, service := range project.Services {
  282. image := api.GetImageNameOrDefault(service, project.Name)
  283. img, ok := images[image]
  284. if ok {
  285. service.CustomLabels.Add(api.ImageDigestLabel, img.ID)
  286. }
  287. project.Services[name] = service
  288. }
  289. return nil
  290. }
  291. func (s *composeService) getLocalImagesDigests(ctx context.Context, project *types.Project) (map[string]api.ImageSummary, error) {
  292. imageNames := utils.Set[string]{}
  293. for _, s := range project.Services {
  294. imageNames.Add(api.GetImageNameOrDefault(s, project.Name))
  295. for _, volume := range s.Volumes {
  296. if volume.Type == types.VolumeTypeImage {
  297. imageNames.Add(volume.Source)
  298. }
  299. }
  300. }
  301. imgs, err := s.getImageSummaries(ctx, imageNames.Elements())
  302. if err != nil {
  303. return nil, err
  304. }
  305. for i, service := range project.Services {
  306. imgName := api.GetImageNameOrDefault(service, project.Name)
  307. img, ok := imgs[imgName]
  308. if !ok {
  309. continue
  310. }
  311. if service.Platform != "" {
  312. platform, err := platforms.Parse(service.Platform)
  313. if err != nil {
  314. return nil, err
  315. }
  316. inspect, err := s.apiClient().ImageInspect(ctx, img.ID)
  317. if err != nil {
  318. return nil, err
  319. }
  320. actual := specs.Platform{
  321. Architecture: inspect.Architecture,
  322. OS: inspect.Os,
  323. Variant: inspect.Variant,
  324. }
  325. if !platforms.NewMatcher(platform).Match(actual) {
  326. // there is a local image, but it's for the wrong platform, so
  327. // pretend it doesn't exist so that we can pull/build an image
  328. // for the correct platform instead
  329. delete(imgs, imgName)
  330. }
  331. }
  332. project.Services[i].CustomLabels.Add(api.ImageDigestLabel, img.ID)
  333. }
  334. return imgs, nil
  335. }
  336. // resolveAndMergeBuildArgs returns the final set of build arguments to use for the service image build.
  337. //
  338. // First, args directly defined via `build.args` in YAML are considered.
  339. // Then, any explicitly passed args in opts (e.g. via `--build-arg` on the CLI) are merged, overwriting any
  340. // keys that already exist.
  341. // Next, any keys without a value are resolved using the project environment.
  342. //
  343. // Finally, standard proxy variables based on the Docker client configuration are added, but will not overwrite
  344. // any values if already present.
  345. func resolveAndMergeBuildArgs(dockerCli command.Cli, project *types.Project, service types.ServiceConfig, opts api.BuildOptions) types.MappingWithEquals {
  346. result := make(types.MappingWithEquals).
  347. OverrideBy(service.Build.Args).
  348. OverrideBy(opts.Args).
  349. Resolve(envResolver(project.Environment))
  350. // proxy arguments do NOT override and should NOT have env resolution applied,
  351. // so they're handled last
  352. for k, v := range storeutil.GetProxyConfig(dockerCli) {
  353. if _, ok := result[k]; !ok {
  354. v := v
  355. result[k] = &v
  356. }
  357. }
  358. return result
  359. }
  360. func (s *composeService) toBuildOptions(project *types.Project, service types.ServiceConfig, options api.BuildOptions) (build.Options, error) {
  361. plats, err := parsePlatforms(service)
  362. if err != nil {
  363. return build.Options{}, err
  364. }
  365. cacheFrom, err := buildflags.ParseCacheEntry(service.Build.CacheFrom)
  366. if err != nil {
  367. return build.Options{}, err
  368. }
  369. cacheTo, err := buildflags.ParseCacheEntry(service.Build.CacheTo)
  370. if err != nil {
  371. return build.Options{}, err
  372. }
  373. sessionConfig := []session.Attachable{
  374. authprovider.NewDockerAuthProvider(authprovider.DockerAuthProviderConfig{
  375. ConfigFile: s.configFile(),
  376. }),
  377. }
  378. if len(options.SSHs) > 0 || len(service.Build.SSH) > 0 {
  379. sshAgentProvider, err := sshAgentProvider(append(service.Build.SSH, options.SSHs...))
  380. if err != nil {
  381. return build.Options{}, err
  382. }
  383. sessionConfig = append(sessionConfig, sshAgentProvider)
  384. }
  385. if len(service.Build.Secrets) > 0 {
  386. secretsProvider, err := addSecretsConfig(project, service)
  387. if err != nil {
  388. return build.Options{}, err
  389. }
  390. sessionConfig = append(sessionConfig, secretsProvider)
  391. }
  392. tags := []string{api.GetImageNameOrDefault(service, project.Name)}
  393. if len(service.Build.Tags) > 0 {
  394. tags = append(tags, service.Build.Tags...)
  395. }
  396. allow, err := buildflags.ParseEntitlements(service.Build.Entitlements)
  397. if err != nil {
  398. return build.Options{}, err
  399. }
  400. if service.Build.Privileged {
  401. allow = append(allow, entitlements.EntitlementSecurityInsecure.String())
  402. }
  403. imageLabels := getImageBuildLabels(project, service)
  404. push := options.Push && service.Image != ""
  405. exports := []bclient.ExportEntry{{
  406. Type: "docker",
  407. Attrs: map[string]string{
  408. "load": "true",
  409. "push": fmt.Sprint(push),
  410. },
  411. }}
  412. if len(service.Build.Platforms) > 1 {
  413. exports = []bclient.ExportEntry{{
  414. Type: "image",
  415. Attrs: map[string]string{
  416. "push": fmt.Sprint(push),
  417. },
  418. }}
  419. }
  420. sp, err := build.ReadSourcePolicy()
  421. if err != nil {
  422. return build.Options{}, err
  423. }
  424. return build.Options{
  425. Inputs: build.Inputs{
  426. ContextPath: service.Build.Context,
  427. DockerfileInline: service.Build.DockerfileInline,
  428. DockerfilePath: dockerFilePath(service.Build.Context, service.Build.Dockerfile),
  429. NamedContexts: toBuildContexts(service, project),
  430. },
  431. CacheFrom: pb.CreateCaches(cacheFrom.ToPB()),
  432. CacheTo: pb.CreateCaches(cacheTo.ToPB()),
  433. NoCache: service.Build.NoCache,
  434. Pull: service.Build.Pull,
  435. BuildArgs: flatten(resolveAndMergeBuildArgs(s.dockerCli, project, service, options)),
  436. Tags: tags,
  437. Target: service.Build.Target,
  438. Exports: exports,
  439. Platforms: plats,
  440. Labels: imageLabels,
  441. NetworkMode: service.Build.Network,
  442. ExtraHosts: service.Build.ExtraHosts.AsList(":"),
  443. Ulimits: toUlimitOpt(service.Build.Ulimits),
  444. Session: sessionConfig,
  445. Allow: allow,
  446. SourcePolicy: sp,
  447. }, nil
  448. }
  449. func toUlimitOpt(ulimits map[string]*types.UlimitsConfig) *cliopts.UlimitOpt {
  450. ref := map[string]*container.Ulimit{}
  451. for _, limit := range toUlimits(ulimits) {
  452. ref[limit.Name] = &container.Ulimit{
  453. Name: limit.Name,
  454. Hard: limit.Hard,
  455. Soft: limit.Soft,
  456. }
  457. }
  458. return cliopts.NewUlimitOpt(&ref)
  459. }
  460. func flatten(in types.MappingWithEquals) types.Mapping {
  461. out := types.Mapping{}
  462. if len(in) == 0 {
  463. return out
  464. }
  465. for k, v := range in {
  466. if v == nil {
  467. continue
  468. }
  469. out[k] = *v
  470. }
  471. return out
  472. }
  473. func sshAgentProvider(sshKeys types.SSHConfig) (session.Attachable, error) {
  474. sshConfig := make([]sshprovider.AgentConfig, 0, len(sshKeys))
  475. for _, sshKey := range sshKeys {
  476. sshConfig = append(sshConfig, sshprovider.AgentConfig{
  477. ID: sshKey.ID,
  478. Paths: []string{sshKey.Path},
  479. })
  480. }
  481. return sshprovider.NewSSHAgentProvider(sshConfig)
  482. }
  483. func addSecretsConfig(project *types.Project, service types.ServiceConfig) (session.Attachable, error) {
  484. var sources []secretsprovider.Source
  485. for _, secret := range service.Build.Secrets {
  486. config := project.Secrets[secret.Source]
  487. id := secret.Source
  488. if secret.Target != "" {
  489. id = secret.Target
  490. }
  491. switch {
  492. case config.File != "":
  493. sources = append(sources, secretsprovider.Source{
  494. ID: id,
  495. FilePath: config.File,
  496. })
  497. case config.Environment != "":
  498. sources = append(sources, secretsprovider.Source{
  499. ID: id,
  500. Env: config.Environment,
  501. })
  502. default:
  503. return nil, fmt.Errorf("build.secrets only supports environment or file-based secrets: %q", secret.Source)
  504. }
  505. if secret.UID != "" || secret.GID != "" || secret.Mode != nil {
  506. logrus.Warn("secrets `uid`, `gid` and `mode` are not supported by BuildKit, they will be ignored")
  507. }
  508. }
  509. store, err := secretsprovider.NewStore(sources)
  510. if err != nil {
  511. return nil, err
  512. }
  513. return secretsprovider.NewSecretProvider(store), nil
  514. }
  515. func getImageBuildLabels(project *types.Project, service types.ServiceConfig) types.Labels {
  516. ret := make(types.Labels)
  517. if service.Build != nil {
  518. for k, v := range service.Build.Labels {
  519. ret.Add(k, v)
  520. }
  521. }
  522. ret.Add(api.VersionLabel, api.ComposeVersion)
  523. ret.Add(api.ProjectLabel, project.Name)
  524. ret.Add(api.ServiceLabel, service.Name)
  525. return ret
  526. }
  527. func toBuildContexts(service types.ServiceConfig, project *types.Project) map[string]build.NamedContext {
  528. namedContexts := map[string]build.NamedContext{}
  529. for name, contextPath := range service.Build.AdditionalContexts {
  530. if strings.HasPrefix(contextPath, types.ServicePrefix) {
  531. // image we depend on has been built previously, as we run in dependency order.
  532. // so we convert the service reference into an image reference
  533. target := contextPath[len(types.ServicePrefix):]
  534. image := api.GetImageNameOrDefault(project.Services[target], project.Name)
  535. contextPath = "docker-image://" + image
  536. }
  537. namedContexts[name] = build.NamedContext{Path: contextPath}
  538. }
  539. return namedContexts
  540. }
  541. func parsePlatforms(service types.ServiceConfig) ([]specs.Platform, error) {
  542. if service.Build == nil || len(service.Build.Platforms) == 0 {
  543. return nil, nil
  544. }
  545. var errs []error
  546. ret := make([]specs.Platform, len(service.Build.Platforms))
  547. for i := range service.Build.Platforms {
  548. p, err := platforms.Parse(service.Build.Platforms[i])
  549. if err != nil {
  550. errs = append(errs, err)
  551. } else {
  552. ret[i] = p
  553. }
  554. }
  555. if err := errors.Join(errs...); err != nil {
  556. return nil, err
  557. }
  558. return ret, nil
  559. }
  560. func addBuildDependencies(services []string, project *types.Project) []string {
  561. servicesWithDependencies := utils.NewSet(services...)
  562. for _, service := range services {
  563. b := project.Services[service].Build
  564. if b != nil {
  565. for _, target := range b.AdditionalContexts {
  566. if s, found := strings.CutPrefix(target, types.ServicePrefix); found {
  567. servicesWithDependencies.Add(s)
  568. }
  569. }
  570. }
  571. }
  572. if len(servicesWithDependencies) > len(services) {
  573. return addBuildDependencies(servicesWithDependencies.Elements(), project)
  574. }
  575. return servicesWithDependencies.Elements()
  576. }