Skip base image inspection when a named build context provides it - #1313
Open
Gundy (nsgundy) wants to merge 1 commit into
Open
Gundy (nsgundy) wants to merge 1 commit into
Gundy (nsgundy) wants to merge 1 commit into
Conversation
A Compose service can satisfy its Dockerfile's FROM through build.additional_contexts, for example `service:<name>`. BuildKit substitutes the named context at build time, so the reference need not exist locally or in any registry. The CLI inspected (and pulled) the FROM reference before building, which failed with "pull access denied". Pass the service's additional context names through to the build info lookup and skip the inspection when the resolved base image matches one, using the familiar reference form BuildKit uses for the lookup.
Author
|
@microsoft-github-policy-service agree |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
A Compose service can satisfy its Dockerfile's
FROMthroughbuild.additional_contexts, e.g. to layer a dev image on another service's build:BuildKit substitutes the named context at build time, so
my-basenever needs to exist locally or in a registry, anddocker compose buildsucceeds.devcontainer upfails before it gets there:getImageBuildInfoFromDockerfileresolves the final stage'sFROMand inspects it (pulling on a miss), which ends in:The current workaround is to seed a dummy local image under the base's name before the CLI runs.
Change
getBuildInfoForServicenow returns the service'sadditional_contexts(mapping orname=valuelist form).getImageBuildInfoFromDockerfile.USER(or defaults toroot), and no base-image metadata is used, same as the existing fallback when no base image is resolved.docker.io/library/prefix and:latestsuffix stripped).Dockerfile-based configs passing
--build-contextviabuild.optionshave the same issue. I kept this PR to Compose and can follow up if wanted.Testing
getBuildInfoForService,isNamedBuildContext, andinternalGetImageBuildInfoFromDockerfilewith a context-provided base.devcontainer upfails with "pull access denied" onmainand succeeds with this change;whoamiin the container returns theUSERfrom the dev Dockerfile.