Tonis Tiigi
72c3d4a237
bake: make FS entitlements error by default
...
Change FS entitlements checks from warning to error
by default as expressed in initial PR. Users can still
opt-out with environment variable if the choose to.
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2024-12-19 17:14:35 -08:00
Tõnis Tiigi and GitHub
5c5bc510ac
Merge pull request #2848 from jsternberg/bake-composable-attributes-attests
...
bake: implement composable attributes for attestations
2024-12-18 13:11:50 -08:00
Tõnis Tiigi and GitHub
0dfc4a1019
Merge pull request #2871 from jsternberg/bake-empty-variable-tests
...
bake: test empty override
2024-12-18 11:00:49 -08:00
Tõnis Tiigi and GitHub
3771fe2034
Merge pull request #2814 from jsternberg/bake-composable-attributes-phase2
...
bake: various fixes for composable attributes
2024-12-18 09:35:35 -08:00
Tonis Tiigi
a53ed0a354
add additional test coverage for FS entitlement paths
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2024-12-16 22:29:35 -08:00
Tonis Tiigi
737da6959d
bake: change evaluation of entitlement paths
...
Currently, to compare the local path used by bake against the paths allowed
by entitlements, symlinks were evaluated for path normalization so that the
local path used by build was allowed to not exist while the path allowed by
entitlement needed to exist. If the path used by the build did not exist,
then the deepest existing parent path was used instead. This was concistent
with entitlement rules as that parent path would be the actual path access
is needed.
This raised an issue with `--set` if one provides a non-existing path as
an argument, as these paths are supposed to be allowed automatically. With
the above restrictions set to allowed paths, this meant the build would fail
as it can't grant entitlement to the non-existing paths.
This changes the evaluation logic for allowing paths so that they do not
need to exist. If such a case appears, then the path is evaluated to the
last component that exists, and then the rest of the path is appended as is.
This means that for example, if `output = /tmp/out/foo/` is set in HCL
and `/tmp` is the last component that exists then invoking build with
`--allow fs.write=/tmp/out/foo` will not fail with stat error anymore
but will fail in entitlements validation as build would also need to
write `/tmp/out` that is not inside the allowed `/tmp/out/foo` path. The
same would apply to `--set` as well so that if it points to
a non-existing path, then an additional `--allow` rule is needed
providing access to writing to the last existing component of that path.
This may or may not be unexpected.
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2024-12-16 22:29:24 -08:00
Tonis Tiigi
6befa70cc8
update test BuildKit to v0.18.2
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2024-12-16 15:47:45 -08:00
Tõnis Tiigi and GitHub
3e3242cfdd
Merge pull request #2851 from crazy-max/dockerfile-pin-alpine
...
dockerfiles: pin alpine version
2024-12-10 10:47:04 -08:00
Tonis Tiigi
fdac6d5fe7
update xx to v1.6.1
...
Fixes compatibility issues with Alpine 3.21
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2024-12-09 18:48:50 -08:00
Tõnis Tiigi and GitHub
d4eca07af8
Merge pull request #2834 from tonistiigi/bake-entitlements-output-fix
...
bake: fix entitlements path checks for local outputs
2024-12-06 13:52:48 -08:00
Tonis Tiigi
6810a7c69c
update buildkit used for tests
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2024-12-03 17:59:08 -08:00
Tonis Tiigi
dd596d6542
bake: allow entitlements from overrides automatically
...
If override specifies a path, mark it automatically allowed
so there is no need to use duplicate flags for defining the
same feature.
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2024-12-02 17:16:28 -08:00
Tonis Tiigi
c6e403ad7f
bake: fix entitlements path checks for local outputs
...
Previous check based on dest attributes was not correct
as the attributes already get converted before validation happens.
Because the local path is not preserved for single-file
outputs and gets replaced by io.Writer, a temporary array variable
was needed. This value should instead be added to ExportEntry
struct in BuildKit in future revision.
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2024-12-02 15:00:29 -08:00
Tõnis Tiigi and GitHub
71c7889719
Merge pull request #2821 from tonistiigi/update-buildkit-v0.18.0
...
vendor: update buildkit to v0.18.0
2024-11-26 14:49:31 -08:00
Tonis Tiigi
a3418e0178
vendor: update buildkit to v0.18.0
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2024-11-26 13:57:25 -08:00
Tõnis Tiigi and GitHub
6a1cf78879
Merge pull request #2818 from tonistiigi/vendor-buildkit-v0.18.0-rc2
...
vendor: update buildkit to v0.18.0-rc2
2024-11-25 17:52:46 -08:00
Tonis Tiigi
ec1f712328
vendor: update buildkit to v0.18.0-rc2
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2024-11-25 17:42:30 -08:00
Tõnis Tiigi and GitHub
d612139b19
Merge pull request #2811 from crazy-max/update-buildkit
...
dockerfile: update buildkit to v0.17.2
2024-11-25 10:11:09 -08:00
Tõnis Tiigi and GitHub
42f7898c53
Merge pull request #2815 from tonistiigi/entitlements-symlink-tests
...
bake: fix entitlement test when running from symlink temp
2024-11-25 10:08:19 -08:00
Tonis Tiigi
3148c098a2
bake: remove unnecessary GetLongPathName calls
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2024-11-25 08:26:02 -08:00
Tonis Tiigi
f95d574f94
bake: fix entitlement test when running from symlink temp
...
As the paths returned by validator have the symlinks resolved,
the test needs to resolve the symlinks also in the expected
values. Previously this would fail if t.TempDir() or os.GetWd()
returned a path that contained a symlink.
The issue was purely in the test and not in the entitlements
validation logic.
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2024-11-25 00:03:54 -08:00
Tõnis Tiigi and GitHub
17eff25fe5
Merge pull request #2807 from tonistiigi/buildkit-v0.18.0-rc1
...
vendor: update buildkit to v0.18.0-rc1
2024-11-21 14:29:29 -08:00
Tõnis Tiigi and GitHub
9c8ffb77d6
Merge pull request #2806 from tonistiigi/vendor-compose-v2.4.4
...
vendor: update compose to v2.4.4
2024-11-21 14:29:18 -08:00
Tonis Tiigi
13a426fca6
vendor: update buildkit to v0.18.0-rc1
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2024-11-21 12:57:27 -08:00
Tõnis Tiigi and GitHub
1a039115bc
Merge pull request #2758 from jsternberg/bake-composable-attributes
...
bake: initial set of composable bake attributes
2024-11-21 12:54:54 -08:00
Tonis Tiigi
07d58782b8
vendor: update compose to v2.4.4
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2024-11-21 10:32:02 -08:00
Tõnis Tiigi and GitHub
a34c641bc4
Merge pull request #2796 from tonistiigi/fs-entitlements
...
bake: add filesystem entitlements support
2024-11-21 09:51:49 -08:00
Tonis Tiigi and CrazyMax
615f4f6759
bake: windows entitlement path fixes
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2024-11-21 14:05:12 +01:00
Tonis Tiigi and CrazyMax
9a7b028bab
bake: add fs entitlements for context paths
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2024-11-21 14:05:11 +01:00
Tonis Tiigi and CrazyMax
1af4f05ba4
bake: add filesystem entitlements support
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2024-11-21 14:05:11 +01:00
Tonis Tiigi
d2c512a95b
lint: enable testifylint
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2024-11-20 10:53:11 -08:00
Tõnis Tiigi and GitHub
5937ba0e00
Merge pull request #2307 from crazy-max/test-docker-multi-ver
...
tests: handle multiple docker versions
2024-11-20 09:53:57 -08:00
Tõnis Tiigi and GitHub
21fb026aa3
Merge pull request #2775 from crazy-max/openbsd
...
build openbsd
2024-11-20 09:49:49 -08:00
Tonis Tiigi
58fd190c31
lint: enable importas rules from buildkit
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2024-11-19 18:29:04 -08:00
Tonis Tiigi
e7a53fb829
lint: enable forbidigo context rules
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2024-11-19 18:27:25 -08:00
Tonis Tiigi
c0fd64f4f8
lint: enable linters from buildkit
...
Skipping errname and testifylint
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2024-11-19 17:51:24 -08:00
Tonis Tiigi
0c629335ac
lint: sort linters
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2024-11-19 17:40:42 -08:00
Tonis Tiigi
f216b71ad2
lint: enable gosimple
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2024-11-19 17:39:22 -08:00
Tõnis Tiigi and GitHub
a6ef9db84d
Merge pull request #2794 from crazy-max/bake-var-req
...
bake: basic variable validation
2024-11-19 12:23:44 -08:00
Tõnis Tiigi and GitHub
3b943bd4ba
Merge pull request #2790 from crazy-max/fix-network-attr-yaml
...
bake: check for empty build network with compose
2024-11-14 18:55:33 -08:00
Tõnis Tiigi and GitHub
e540bb03a4
Merge pull request #2773 from crazy-max/dockerfile-bump-versions
...
dockerfile: update testing tools
2024-11-13 15:54:31 -08:00
Tõnis Tiigi and GitHub
6caa151e98
Merge pull request #2777 from LaurentGoderre/metadata-list-support
...
Add ability to output json lists in metadata build file
2024-11-11 13:52:09 -08:00
Tõnis Tiigi and GitHub
7855f8324b
Merge pull request #2781 from crazy-max/update-fsutil
...
vendor: github.com/tonistiigi/fsutil 8d32dbdd27d3
2024-11-10 20:21:13 -08:00
Tõnis Tiigi and GitHub
8cdeac54ab
Merge pull request #2780 from glours/bump-compose-go-v2.4.3
...
bump compose-go to version v2.4.3
2024-11-05 09:48:20 -08:00
Tõnis Tiigi and GitHub
83dd969dc1
Merge pull request #2774 from crazy-max/freebsd
...
build freebsd
2024-11-05 08:30:26 -08:00
Tõnis Tiigi and GitHub
bcac44f658
Merge pull request #2771 from docker/dependabot/github_actions/softprops/action-gh-release-2.0.9
...
build(deps): bump softprops/action-gh-release from 2.0.8 to 2.0.9
2024-10-31 16:59:55 -07:00
Tõnis Tiigi and GitHub
62407927fa
Merge pull request #2757 from dvdksn/pprof-dev-docs
...
docs: add dev instructions on generating/analyzing pprof samples
2024-10-30 15:09:19 -07:00
Tõnis Tiigi and GitHub
c7b0a84c6a
Merge pull request #2767 from tonistiigi/buildkit-v0.17.0
...
vendor: update buildkit to v0.17.0
2024-10-30 14:41:33 -07:00
Tonis Tiigi
1aac809c63
vendor: update buildkit to v0.17.0
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2024-10-30 12:04:42 -07:00
Tõnis Tiigi and GitHub
9b0575b589
Merge pull request #2766 from tonistiigi/prune-caps-detection
...
prune: detect if buildkit supports newer storage filters
2024-10-29 13:55:29 -07:00
Tonis Tiigi
9f3a578149
prune: detect if buildkit supports newer storage filters
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2024-10-29 13:18:04 -07:00
Tõnis Tiigi and GitHub
cd8d61a9d7
Merge pull request #2763 from neumantm/feat/listWithoutBuilder
...
Skip Builder Init For Bake List Flags
2024-10-29 10:20:58 -07:00
Tõnis Tiigi and GitHub
3a56161d03
Merge pull request #2761 from crazy-max/fix-workflow-perms
...
ci: fix workflow permissions
2024-10-29 10:19:04 -07:00
Tonis Tiigi
a585faf3d2
vendor: update compose to v2.4.1
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2024-10-28 17:26:28 -07:00
Tõnis Tiigi and GitHub
181348397c
Merge pull request #2742 from tonistiigi/otel-build
...
build: add OTEL span around build function
2024-10-28 16:16:08 -07:00
Tõnis Tiigi and GitHub
ad371e428e
Merge pull request #2759 from tonistiigi/vendor-buildkit-v0.17.0-rc2
...
vendor: update buildkit to v0.17.0-rc2
2024-10-28 16:15:19 -07:00
Tonis Tiigi
f35dae3726
build: add OTEL span around build function
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2024-10-28 15:53:22 -07:00
Tonis Tiigi
6fcc6853d9
vendor: update buildkit to v0.17.0-rc2
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2024-10-28 15:39:50 -07:00
Tõnis Tiigi and GitHub
202c390fca
Merge pull request #2722 from crazy-max/test-details-link-exp
...
build: fix build details link in experimental mode
2024-10-28 10:03:10 -07:00
Tõnis Tiigi and GitHub
2bdf451b68
Merge pull request #2754 from crazy-max/call-localstate
...
build: don't generate local state for subrequests
2024-10-25 11:06:22 -07:00
Tõnis Tiigi and GitHub
746eadd16e
Merge pull request #2745 from crazy-max/detect-sudo
...
config: fix file/folder ownership
2024-10-23 10:04:38 -07:00
Tõnis Tiigi and GitHub
08a973a148
Merge pull request #2741 from crazy-max/cli-fix-unknown-command
...
cli: error out on unknown command
2024-10-23 08:47:44 -07:00
Tõnis Tiigi and GitHub
8d32cabc22
Merge pull request #2740 from dvdksn/src-attr-secret-env
...
docs: clarify options for secret types (file, env)
2024-10-16 12:20:58 -07:00
Tõnis Tiigi and GitHub
1de332530f
Merge pull request #2729 from thaJeztah/touchup_security
...
touch-up security policy
2024-10-10 09:57:55 -07:00
Tõnis Tiigi and GitHub
d3ff70ace0
Merge pull request #2724 from jsternberg/vtproto
...
hack: generate vtproto files for buildx
2024-10-08 17:04:19 -07:00
Tonis Tiigi
14de641bec
vendor: update buildkit to v0.17.0-rc1
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2024-10-08 16:54:03 -07:00
Tõnis Tiigi and GitHub
d353f5f6ba
Merge pull request #2717 from crazy-max/fix-ls-notrunc
...
ls: ensure deterministic output for truncated platforms
2024-10-04 12:52:45 -07:00
Tõnis Tiigi and GitHub
4507a492da
Merge pull request #2719 from jsternberg/bake-remote-size
...
bake: raise maximum size limit and fix size check
2024-10-04 12:51:28 -07:00
Tõnis Tiigi and GitHub
48153169d8
Merge pull request #2716 from jsternberg/dockerfile-size-limit
...
build: raise maximum size limit for dockerfile and fix size check
2024-10-03 14:25:31 -07:00
Tõnis Tiigi and GitHub
7c91f3d0dd
Merge pull request #2138 from crazy-max/ls-notrunc
...
ls: no-trunc opt
2024-10-03 08:21:09 -07:00
Tõnis Tiigi and GitHub
1db8f6789f
Merge pull request #2713 from jsternberg/gogoproto-remove
...
protobuf: remove gogoproto
2024-10-02 15:39:47 -07:00
Tõnis Tiigi and GitHub
f102ad73a8
Merge pull request #2672 from daghack/dockerfile-path-on-warnings
...
build: display Dockerfile path on check warnings
2024-09-19 08:30:48 -07:00
Tonis Tiigi
f8657e8798
build: use better references for --call fallback images
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2024-09-18 18:43:40 -07:00
Tõnis Tiigi and GitHub
9eb0318ee6
Merge pull request #2696 from crazy-max/test-fix-cleanup
...
test: fix missing envs when cleaning up some workers
2024-09-17 20:27:29 -07:00
Tonis Tiigi
c60afbb25b
bake: fix linking to targets with entitlements
...
When linked target requires entitlement, same entitlement
is also needed by the caller. Otherwise, the request will
fail when the build is processed.
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2024-09-16 16:31:22 -07:00
Tonis Tiigi
9bfa8603f6
bake: fix validation for linking to itself
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2024-09-16 16:29:32 -07:00
Tõnis Tiigi and GitHub
604b723007
Merge pull request #2684 from crazy-max/inspect-buildkitd-conf
...
inspect: display buildkit daemon configuration file
2024-09-11 17:32:25 -07:00
Tõnis Tiigi and GitHub
cd5381900c
Merge pull request #2688 from crazy-max/bump-xx
...
dockerfile: update xx to 1.5.0
2024-09-11 10:50:58 -07:00
Tõnis Tiigi and GitHub
bba2bb4b89
Merge pull request #2686 from crazy-max/bump-buildkit
...
dockerfile, ci: update buildkit to latest stable
2024-09-11 10:50:40 -07:00
Tõnis Tiigi and GitHub
8fd27b8c23
Merge pull request #2685 from crazy-max/skip-networkhost-conf
...
builder: do not set network.host entitlement flag if already set in buildkitd conf
2024-09-11 10:39:29 -07:00
Tõnis Tiigi and GitHub
6dcc8d8b84
Merge pull request #2689 from crazy-max/bake-fix-network-field
...
bake: fix missing omitempty and optional tags for network field
2024-09-11 10:35:33 -07:00
Tonis Tiigi
7213b2a814
vendor: update buildkit to v0.16.0-rc2
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2024-09-09 16:29:01 -07:00
Tonis Tiigi
f0f8876902
docs: add docs for bake network mode config
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2024-09-04 09:02:06 -07:00
Tonis Tiigi
fa1d19bb1e
docs: add docs for bake entitlements config
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2024-09-04 09:01:59 -07:00
Tonis Tiigi
83d5c0c61b
bake: allow setting networkmode in HCL/JSON
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2024-09-03 18:18:59 -07:00
Tõnis Tiigi and GitHub
e58a1d35d1
Merge pull request #2670 from docker/dependabot/github_actions/peter-evans/create-pull-request-7.0.0
...
build(deps): bump peter-evans/create-pull-request from 6.1.0 to 7.0.0
2024-09-03 14:44:14 -07:00
Tõnis Tiigi and GitHub
f369377d74
Merge pull request #2666 from tonistiigi/bake-entitlements
...
bake: enable support for entitlements
2024-09-03 10:49:48 -07:00
Tõnis Tiigi and GitHub
b7486e5cd5
Merge pull request #2647 from daghack/print-warning-count
...
build: print out the number of warnings after completing a rule check
2024-09-03 10:22:46 -07:00
Tonis Tiigi
5ecff53e0c
bake: read original command name from the env for prompt
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2024-09-03 08:54:42 -07:00
Tonis Tiigi
203fd8aee5
bake: enable support for entitlements
...
Add support for security.insecure and network.host
entitlements via bake. User needs to confirm elevated
privileges through a prompt or CLI flags.
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2024-08-30 09:33:28 -07:00
Tõnis Tiigi and GitHub
96eb69aea4
Merge pull request #2663 from tonistiigi/git-attr-panic-fix
...
build: avoid possible panic when reading git info
2024-08-23 16:59:30 +03:00
Tonis Tiigi
d1d8d6e19c
build: avoid possible panic when reading git info
...
Not all the error cases from getGitAttributes returned
appendNoneFunc. When nil was returned it caused a panic.
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2024-08-23 16:42:04 +03:00
Tonis Tiigi
7a7a9c8e01
commands: add debug as persistent flag
...
Allows using `--debug` to enable debug logging under
any subcommand. Currently it needed to be set as
`docker --debug buildx` meaning only way to enable debug
in standalone mode was to set env variable instead and
updating existing commands to add `--debug` was cumbersome.
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2024-08-16 13:20:28 +03:00
Tõnis Tiigi and GitHub
8411a763d9
Merge pull request #2657 from jsternberg/metricwriter-race-condition
...
metrics: add mutex to the metric writer
2024-08-14 19:23:51 +03:00
Tõnis Tiigi and GitHub
0e64eb4f8b
Merge pull request #2651 from tonistiigi/bake-wrap-target-name
...
build: when building multiple targets include name in error
2024-08-14 13:19:26 +03:00
Tonis Tiigi
adbcc2225e
build: allow builds from stdin for multi-node builders
...
When building from same stream all nodes need to read
data from the same stream. In order to achive that there
is a new SyncMultiReader wrapper that sends the stream
concurrently to all readers. Readers must read at similar
speed or pauses will happen while they wait for each other.
Dockerfiles were already written to disk before sent. Now
the file written by first node is reused for others.
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2024-08-14 13:13:18 +03:00
Tõnis Tiigi and GitHub
4787b5c046
Merge pull request #2649 from tonistiigi/bake-path-stdlib-functions
...
bake: add basename, dirname and sanitize functions
2024-08-13 13:15:12 +03:00
Tõnis Tiigi and GitHub
1c66f293c7
Merge pull request #2650 from crazy-max/fix-subrequest-metadatafile
...
build: skip build ref and provenance metadata for subrequests
2024-08-13 13:13:35 +03:00
Tonis Tiigi
246a36d463
build: when building multiple targets include name in error
...
Some errors can appear without a stacktrace or progress record,
eg. wrong Dockerfile name passed. In that case when building many
targets with bake it might be hard to figure out which target
failed as in the progressbar there will only be steps that
were cancelled.
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2024-08-13 12:21:30 +03:00
Tonis Tiigi
a4adae3d6b
bake: add basename, dirname and sanitize functions
...
These functions help with dealing with path inputs and
using parts of them to configure targets.
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
2024-08-13 11:46:04 +03:00