github.com/pwn-term/docker@v0.0.0-20210616085119-6e977cce2565/moby/builder/builder-next/controller.go (about) 1 package buildkit 2 3 import ( 4 "context" 5 "net/http" 6 "os" 7 "path/filepath" 8 9 "github.com/containerd/containerd/content/local" 10 ctdmetadata "github.com/containerd/containerd/metadata" 11 "github.com/containerd/containerd/platforms" 12 "github.com/containerd/containerd/snapshots" 13 "github.com/docker/docker/api/types" 14 "github.com/docker/docker/api/types/filters" 15 "github.com/docker/docker/builder/builder-next/adapters/containerimage" 16 "github.com/docker/docker/builder/builder-next/adapters/localinlinecache" 17 "github.com/docker/docker/builder/builder-next/adapters/snapshot" 18 containerimageexp "github.com/docker/docker/builder/builder-next/exporter" 19 "github.com/docker/docker/builder/builder-next/imagerefchecker" 20 mobyworker "github.com/docker/docker/builder/builder-next/worker" 21 "github.com/docker/docker/daemon/config" 22 "github.com/docker/docker/daemon/graphdriver" 23 units "github.com/docker/go-units" 24 "github.com/moby/buildkit/cache" 25 "github.com/moby/buildkit/cache/metadata" 26 "github.com/moby/buildkit/cache/remotecache" 27 inlineremotecache "github.com/moby/buildkit/cache/remotecache/inline" 28 localremotecache "github.com/moby/buildkit/cache/remotecache/local" 29 "github.com/moby/buildkit/client" 30 "github.com/moby/buildkit/control" 31 "github.com/moby/buildkit/frontend" 32 dockerfile "github.com/moby/buildkit/frontend/dockerfile/builder" 33 "github.com/moby/buildkit/frontend/gateway" 34 "github.com/moby/buildkit/frontend/gateway/forwarder" 35 containerdsnapshot "github.com/moby/buildkit/snapshot/containerd" 36 "github.com/moby/buildkit/solver/bboltcachestorage" 37 "github.com/moby/buildkit/util/archutil" 38 "github.com/moby/buildkit/util/entitlements" 39 "github.com/moby/buildkit/util/leaseutil" 40 "github.com/moby/buildkit/worker" 41 specs "github.com/opencontainers/image-spec/specs-go/v1" 42 "github.com/pkg/errors" 43 bolt "go.etcd.io/bbolt" 44 ) 45 46 func newController(rt http.RoundTripper, opt Opt) (*control.Controller, error) { 47 if err := os.MkdirAll(opt.Root, 0711); err != nil { 48 return nil, err 49 } 50 51 dist := opt.Dist 52 root := opt.Root 53 54 var driver graphdriver.Driver 55 if ls, ok := dist.LayerStore.(interface { 56 Driver() graphdriver.Driver 57 }); ok { 58 driver = ls.Driver() 59 } else { 60 return nil, errors.Errorf("could not access graphdriver") 61 } 62 63 store, err := local.NewStore(filepath.Join(root, "content")) 64 if err != nil { 65 return nil, err 66 } 67 68 db, err := bolt.Open(filepath.Join(root, "containerdmeta.db"), 0644, nil) 69 if err != nil { 70 return nil, errors.WithStack(err) 71 } 72 73 mdb := ctdmetadata.NewDB(db, store, map[string]snapshots.Snapshotter{}) 74 75 store = containerdsnapshot.NewContentStore(mdb.ContentStore(), "buildkit") 76 77 lm := leaseutil.WithNamespace(ctdmetadata.NewLeaseManager(mdb), "buildkit") 78 79 snapshotter, lm, err := snapshot.NewSnapshotter(snapshot.Opt{ 80 GraphDriver: driver, 81 LayerStore: dist.LayerStore, 82 Root: root, 83 IdentityMapping: opt.IdentityMapping, 84 }, lm) 85 if err != nil { 86 return nil, err 87 } 88 89 if err := cache.MigrateV2(context.Background(), filepath.Join(root, "metadata.db"), filepath.Join(root, "metadata_v2.db"), store, snapshotter, lm); err != nil { 90 return nil, err 91 } 92 93 md, err := metadata.NewStore(filepath.Join(root, "metadata_v2.db")) 94 if err != nil { 95 return nil, err 96 } 97 98 layerGetter, ok := snapshotter.(imagerefchecker.LayerGetter) 99 if !ok { 100 return nil, errors.Errorf("snapshotter does not implement layergetter") 101 } 102 103 refChecker := imagerefchecker.New(imagerefchecker.Opt{ 104 ImageStore: dist.ImageStore, 105 LayerGetter: layerGetter, 106 }) 107 108 cm, err := cache.NewManager(cache.ManagerOpt{ 109 Snapshotter: snapshotter, 110 MetadataStore: md, 111 PruneRefChecker: refChecker, 112 LeaseManager: lm, 113 ContentStore: store, 114 }) 115 if err != nil { 116 return nil, err 117 } 118 119 src, err := containerimage.NewSource(containerimage.SourceOpt{ 120 CacheAccessor: cm, 121 ContentStore: store, 122 DownloadManager: dist.DownloadManager, 123 MetadataStore: dist.V2MetadataService, 124 ImageStore: dist.ImageStore, 125 ReferenceStore: dist.ReferenceStore, 126 RegistryHosts: opt.RegistryHosts, 127 LayerStore: dist.LayerStore, 128 }) 129 if err != nil { 130 return nil, err 131 } 132 133 dns := getDNSConfig(opt.DNSConfig) 134 135 exec, err := newExecutor(root, opt.DefaultCgroupParent, opt.NetworkController, dns, opt.Rootless, opt.IdentityMapping) 136 if err != nil { 137 return nil, err 138 } 139 140 differ, ok := snapshotter.(containerimageexp.Differ) 141 if !ok { 142 return nil, errors.Errorf("snapshotter doesn't support differ") 143 } 144 145 exp, err := containerimageexp.New(containerimageexp.Opt{ 146 ImageStore: dist.ImageStore, 147 ReferenceStore: dist.ReferenceStore, 148 Differ: differ, 149 }) 150 if err != nil { 151 return nil, err 152 } 153 154 cacheStorage, err := bboltcachestorage.NewStore(filepath.Join(opt.Root, "cache.db")) 155 if err != nil { 156 return nil, err 157 } 158 159 gcPolicy, err := getGCPolicy(opt.BuilderConfig, root) 160 if err != nil { 161 return nil, errors.Wrap(err, "could not get builder GC policy") 162 } 163 164 layers, ok := snapshotter.(mobyworker.LayerAccess) 165 if !ok { 166 return nil, errors.Errorf("snapshotter doesn't support differ") 167 } 168 169 p, err := parsePlatforms(archutil.SupportedPlatforms(true)) 170 if err != nil { 171 return nil, err 172 } 173 174 leases, err := lm.List(context.TODO(), "labels.\"buildkit/lease.temporary\"") 175 if err != nil { 176 return nil, err 177 } 178 for _, l := range leases { 179 lm.Delete(context.TODO(), l) 180 } 181 182 wopt := mobyworker.Opt{ 183 ID: "moby", 184 MetadataStore: md, 185 ContentStore: store, 186 CacheManager: cm, 187 GCPolicy: gcPolicy, 188 Snapshotter: snapshotter, 189 Executor: exec, 190 ImageSource: src, 191 DownloadManager: dist.DownloadManager, 192 V2MetadataService: dist.V2MetadataService, 193 Exporter: exp, 194 Transport: rt, 195 Layers: layers, 196 Platforms: p, 197 } 198 199 wc := &worker.Controller{} 200 w, err := mobyworker.NewWorker(wopt) 201 if err != nil { 202 return nil, err 203 } 204 wc.Add(w) 205 206 frontends := map[string]frontend.Frontend{ 207 "dockerfile.v0": forwarder.NewGatewayForwarder(wc, dockerfile.Build), 208 "gateway.v0": gateway.NewGatewayFrontend(wc), 209 } 210 211 return control.NewController(control.Opt{ 212 SessionManager: opt.SessionManager, 213 WorkerController: wc, 214 Frontends: frontends, 215 CacheKeyStorage: cacheStorage, 216 ResolveCacheImporterFuncs: map[string]remotecache.ResolveCacheImporterFunc{ 217 "registry": localinlinecache.ResolveCacheImporterFunc(opt.SessionManager, opt.RegistryHosts, store, dist.ReferenceStore, dist.ImageStore), 218 "local": localremotecache.ResolveCacheImporterFunc(opt.SessionManager), 219 }, 220 ResolveCacheExporterFuncs: map[string]remotecache.ResolveCacheExporterFunc{ 221 "inline": inlineremotecache.ResolveCacheExporterFunc(), 222 }, 223 Entitlements: getEntitlements(opt.BuilderConfig), 224 }) 225 } 226 227 func getGCPolicy(conf config.BuilderConfig, root string) ([]client.PruneInfo, error) { 228 var gcPolicy []client.PruneInfo 229 if conf.GC.Enabled { 230 var ( 231 defaultKeepStorage int64 232 err error 233 ) 234 235 if conf.GC.DefaultKeepStorage != "" { 236 defaultKeepStorage, err = units.RAMInBytes(conf.GC.DefaultKeepStorage) 237 if err != nil { 238 return nil, errors.Wrapf(err, "could not parse '%s' as Builder.GC.DefaultKeepStorage config", conf.GC.DefaultKeepStorage) 239 } 240 } 241 242 if conf.GC.Policy == nil { 243 gcPolicy = mobyworker.DefaultGCPolicy(root, defaultKeepStorage) 244 } else { 245 gcPolicy = make([]client.PruneInfo, len(conf.GC.Policy)) 246 for i, p := range conf.GC.Policy { 247 b, err := units.RAMInBytes(p.KeepStorage) 248 if err != nil { 249 return nil, err 250 } 251 if b == 0 { 252 b = defaultKeepStorage 253 } 254 gcPolicy[i], err = toBuildkitPruneInfo(types.BuildCachePruneOptions{ 255 All: p.All, 256 KeepStorage: b, 257 Filters: filters.Args(p.Filter), 258 }) 259 if err != nil { 260 return nil, err 261 } 262 } 263 } 264 } 265 return gcPolicy, nil 266 } 267 268 func parsePlatforms(platformsStr []string) ([]specs.Platform, error) { 269 out := make([]specs.Platform, 0, len(platformsStr)) 270 for _, s := range platformsStr { 271 p, err := platforms.Parse(s) 272 if err != nil { 273 return nil, err 274 } 275 out = append(out, platforms.Normalize(p)) 276 } 277 return out, nil 278 } 279 280 func getEntitlements(conf config.BuilderConfig) []string { 281 var ents []string 282 // Incase of no config settings, NetworkHost should be enabled & SecurityInsecure must be disabled. 283 if conf.Entitlements.NetworkHost == nil || *conf.Entitlements.NetworkHost { 284 ents = append(ents, string(entitlements.EntitlementNetworkHost)) 285 } 286 if conf.Entitlements.SecurityInsecure != nil && *conf.Entitlements.SecurityInsecure { 287 ents = append(ents, string(entitlements.EntitlementSecurityInsecure)) 288 } 289 return ents 290 }