github.com/demonoid81/moby@v0.0.0-20200517203328-62dd8e17c460/builder/builder-next/controller.go (about) 1 package buildkit 2 3 import ( 4 "context" 5 "net/http" 6 "os" 7 "path/filepath" 8 9 "github.com/containerd/containerd/content/local" 10 ctdmetadata "github.com/containerd/containerd/metadata" 11 "github.com/containerd/containerd/platforms" 12 "github.com/containerd/containerd/snapshots" 13 "github.com/demonoid81/moby/api/types" 14 "github.com/demonoid81/moby/api/types/filters" 15 "github.com/demonoid81/moby/builder/builder-next/adapters/containerimage" 16 "github.com/demonoid81/moby/builder/builder-next/adapters/localinlinecache" 17 "github.com/demonoid81/moby/builder/builder-next/adapters/snapshot" 18 containerimageexp "github.com/demonoid81/moby/builder/builder-next/exporter" 19 "github.com/demonoid81/moby/builder/builder-next/imagerefchecker" 20 mobyworker "github.com/demonoid81/moby/builder/builder-next/worker" 21 "github.com/demonoid81/moby/daemon/config" 22 "github.com/demonoid81/moby/daemon/graphdriver" 23 units "github.com/docker/go-units" 24 "github.com/moby/buildkit/cache" 25 "github.com/moby/buildkit/cache/metadata" 26 "github.com/moby/buildkit/cache/remotecache" 27 inlineremotecache "github.com/moby/buildkit/cache/remotecache/inline" 28 localremotecache "github.com/moby/buildkit/cache/remotecache/local" 29 "github.com/moby/buildkit/client" 30 "github.com/moby/buildkit/control" 31 "github.com/moby/buildkit/frontend" 32 dockerfile "github.com/moby/buildkit/frontend/dockerfile/builder" 33 "github.com/moby/buildkit/frontend/gateway" 34 "github.com/moby/buildkit/frontend/gateway/forwarder" 35 containerdsnapshot "github.com/moby/buildkit/snapshot/containerd" 36 "github.com/moby/buildkit/solver/bboltcachestorage" 37 "github.com/moby/buildkit/util/binfmt_misc" 38 "github.com/moby/buildkit/util/entitlements" 39 "github.com/moby/buildkit/util/leaseutil" 40 "github.com/moby/buildkit/worker" 41 specs "github.com/opencontainers/image-spec/specs-go/v1" 42 "github.com/pkg/errors" 43 bolt "go.etcd.io/bbolt" 44 ) 45 46 func newController(rt http.RoundTripper, opt Opt) (*control.Controller, error) { 47 if err := os.MkdirAll(opt.Root, 0711); err != nil { 48 return nil, err 49 } 50 51 dist := opt.Dist 52 root := opt.Root 53 54 var driver graphdriver.Driver 55 if ls, ok := dist.LayerStore.(interface { 56 Driver() graphdriver.Driver 57 }); ok { 58 driver = ls.Driver() 59 } else { 60 return nil, errors.Errorf("could not access graphdriver") 61 } 62 63 store, err := local.NewStore(filepath.Join(root, "content")) 64 if err != nil { 65 return nil, err 66 } 67 68 db, err := bolt.Open(filepath.Join(root, "containerdmeta.db"), 0644, nil) 69 if err != nil { 70 return nil, errors.WithStack(err) 71 } 72 73 mdb := ctdmetadata.NewDB(db, store, map[string]snapshots.Snapshotter{}) 74 75 store = containerdsnapshot.NewContentStore(mdb.ContentStore(), "buildkit") 76 77 lm := leaseutil.WithNamespace(ctdmetadata.NewLeaseManager(mdb), "buildkit") 78 79 snapshotter, lm, err := snapshot.NewSnapshotter(snapshot.Opt{ 80 GraphDriver: driver, 81 LayerStore: dist.LayerStore, 82 Root: root, 83 IdentityMapping: opt.IdentityMapping, 84 }, lm) 85 if err != nil { 86 return nil, err 87 } 88 89 md, err := metadata.NewStore(filepath.Join(root, "metadata.db")) 90 if err != nil { 91 return nil, err 92 } 93 94 layerGetter, ok := snapshotter.(imagerefchecker.LayerGetter) 95 if !ok { 96 return nil, errors.Errorf("snapshotter does not implement layergetter") 97 } 98 99 refChecker := imagerefchecker.New(imagerefchecker.Opt{ 100 ImageStore: dist.ImageStore, 101 LayerGetter: layerGetter, 102 }) 103 104 cm, err := cache.NewManager(cache.ManagerOpt{ 105 Snapshotter: snapshotter, 106 MetadataStore: md, 107 PruneRefChecker: refChecker, 108 LeaseManager: lm, 109 ContentStore: store, 110 }) 111 if err != nil { 112 return nil, err 113 } 114 115 src, err := containerimage.NewSource(containerimage.SourceOpt{ 116 CacheAccessor: cm, 117 ContentStore: store, 118 DownloadManager: dist.DownloadManager, 119 MetadataStore: dist.V2MetadataService, 120 ImageStore: dist.ImageStore, 121 ReferenceStore: dist.ReferenceStore, 122 RegistryHosts: opt.RegistryHosts, 123 LayerStore: dist.LayerStore, 124 }) 125 if err != nil { 126 return nil, err 127 } 128 129 dns := getDNSConfig(opt.DNSConfig) 130 131 exec, err := newExecutor(root, opt.DefaultCgroupParent, opt.NetworkController, dns, opt.Rootless, opt.IdentityMapping) 132 if err != nil { 133 return nil, err 134 } 135 136 differ, ok := snapshotter.(containerimageexp.Differ) 137 if !ok { 138 return nil, errors.Errorf("snapshotter doesn't support differ") 139 } 140 141 exp, err := containerimageexp.New(containerimageexp.Opt{ 142 ImageStore: dist.ImageStore, 143 ReferenceStore: dist.ReferenceStore, 144 Differ: differ, 145 }) 146 if err != nil { 147 return nil, err 148 } 149 150 cacheStorage, err := bboltcachestorage.NewStore(filepath.Join(opt.Root, "cache.db")) 151 if err != nil { 152 return nil, err 153 } 154 155 gcPolicy, err := getGCPolicy(opt.BuilderConfig, root) 156 if err != nil { 157 return nil, errors.Wrap(err, "could not get builder GC policy") 158 } 159 160 layers, ok := snapshotter.(mobyworker.LayerAccess) 161 if !ok { 162 return nil, errors.Errorf("snapshotter doesn't support differ") 163 } 164 165 p, err := parsePlatforms(binfmt_misc.SupportedPlatforms(true)) 166 if err != nil { 167 return nil, err 168 } 169 170 leases, err := lm.List(context.TODO(), "labels.\"buildkit/lease.temporary\"") 171 if err != nil { 172 return nil, err 173 } 174 for _, l := range leases { 175 lm.Delete(context.TODO(), l) 176 } 177 178 wopt := mobyworker.Opt{ 179 ID: "moby", 180 MetadataStore: md, 181 ContentStore: store, 182 CacheManager: cm, 183 GCPolicy: gcPolicy, 184 Snapshotter: snapshotter, 185 Executor: exec, 186 ImageSource: src, 187 DownloadManager: dist.DownloadManager, 188 V2MetadataService: dist.V2MetadataService, 189 Exporter: exp, 190 Transport: rt, 191 Layers: layers, 192 Platforms: p, 193 } 194 195 wc := &worker.Controller{} 196 w, err := mobyworker.NewWorker(wopt) 197 if err != nil { 198 return nil, err 199 } 200 wc.Add(w) 201 202 frontends := map[string]frontend.Frontend{ 203 "dockerfile.v0": forwarder.NewGatewayForwarder(wc, dockerfile.Build), 204 "gateway.v0": gateway.NewGatewayFrontend(wc), 205 } 206 207 return control.NewController(control.Opt{ 208 SessionManager: opt.SessionManager, 209 WorkerController: wc, 210 Frontends: frontends, 211 CacheKeyStorage: cacheStorage, 212 ResolveCacheImporterFuncs: map[string]remotecache.ResolveCacheImporterFunc{ 213 "registry": localinlinecache.ResolveCacheImporterFunc(opt.SessionManager, opt.RegistryHosts, store, dist.ReferenceStore, dist.ImageStore), 214 "local": localremotecache.ResolveCacheImporterFunc(opt.SessionManager), 215 }, 216 ResolveCacheExporterFuncs: map[string]remotecache.ResolveCacheExporterFunc{ 217 "inline": inlineremotecache.ResolveCacheExporterFunc(), 218 }, 219 Entitlements: getEntitlements(opt.BuilderConfig), 220 }) 221 } 222 223 func getGCPolicy(conf config.BuilderConfig, root string) ([]client.PruneInfo, error) { 224 var gcPolicy []client.PruneInfo 225 if conf.GC.Enabled { 226 var ( 227 defaultKeepStorage int64 228 err error 229 ) 230 231 if conf.GC.DefaultKeepStorage != "" { 232 defaultKeepStorage, err = units.RAMInBytes(conf.GC.DefaultKeepStorage) 233 if err != nil { 234 return nil, errors.Wrapf(err, "could not parse '%s' as Builder.GC.DefaultKeepStorage config", conf.GC.DefaultKeepStorage) 235 } 236 } 237 238 if conf.GC.Policy == nil { 239 gcPolicy = mobyworker.DefaultGCPolicy(root, defaultKeepStorage) 240 } else { 241 gcPolicy = make([]client.PruneInfo, len(conf.GC.Policy)) 242 for i, p := range conf.GC.Policy { 243 b, err := units.RAMInBytes(p.KeepStorage) 244 if err != nil { 245 return nil, err 246 } 247 if b == 0 { 248 b = defaultKeepStorage 249 } 250 gcPolicy[i], err = toBuildkitPruneInfo(types.BuildCachePruneOptions{ 251 All: p.All, 252 KeepStorage: b, 253 Filters: filters.Args(p.Filter), 254 }) 255 if err != nil { 256 return nil, err 257 } 258 } 259 } 260 } 261 return gcPolicy, nil 262 } 263 264 func parsePlatforms(platformsStr []string) ([]specs.Platform, error) { 265 out := make([]specs.Platform, 0, len(platformsStr)) 266 for _, s := range platformsStr { 267 p, err := platforms.Parse(s) 268 if err != nil { 269 return nil, err 270 } 271 out = append(out, platforms.Normalize(p)) 272 } 273 return out, nil 274 } 275 276 func getEntitlements(conf config.BuilderConfig) []string { 277 var ents []string 278 // Incase of no config settings, NetworkHost should be enabled & SecurityInsecure must be disabled. 279 if conf.Entitlements.NetworkHost == nil || *conf.Entitlements.NetworkHost { 280 ents = append(ents, string(entitlements.EntitlementNetworkHost)) 281 } 282 if conf.Entitlements.SecurityInsecure != nil && *conf.Entitlements.SecurityInsecure { 283 ents = append(ents, string(entitlements.EntitlementSecurityInsecure)) 284 } 285 return ents 286 }