mirror of
https://github.com/GoogleContainerTools/kaniko
synced 2026-10-01 09:31:18 +02:00
To add layer caching to kaniko, I added two flags: --cache and --use-cache. If --use-cache is set, then the cache will be used, and if --cache is specified then that repo will be used to store cached layers. If --cache isn't set, a cache will be inferred from the destination provided. Currently, caching only works for RUN commands. Before executing the command, kaniko checks if the cached layer exists. If it does, it pulls it and extracts it. It then adds those files to the snapshotter and append a layer to the config history. If the cached layer does not exist, kaniko executes the command and pushes the newly created layer to the cache. All cached layers are tagged with a stable key, which is built based off of: 1. The base image digest 2. The current state of the filesystem 3. The current command being run 4. The current config file (to account for metadata changes) I also added two integration tests to make sure caching works 1. Dockerfile_test_cache runs 'date', which should be exactly the same the second time the image is built 2. Dockerfile_test_cache_install makes sure apt-get install can be reproduced
133 lines
4.0 KiB
Go
133 lines
4.0 KiB
Go
/*
|
|
Copyright 2018 Google LLC
|
|
|
|
Licensed under the Apache License, Version 2.0 (the "License");
|
|
you may not use this file except in compliance with the License.
|
|
You may obtain a copy of the License at
|
|
|
|
http://www.apache.org/licenses/LICENSE-2.0
|
|
|
|
Unless required by applicable law or agreed to in writing, software
|
|
distributed under the License is distributed on an "AS IS" BASIS,
|
|
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
See the License for the specific language governing permissions and
|
|
limitations under the License.
|
|
*/
|
|
|
|
package executor
|
|
|
|
import (
|
|
"crypto/tls"
|
|
"fmt"
|
|
"net/http"
|
|
|
|
"github.com/GoogleContainerTools/kaniko/pkg/cache"
|
|
"github.com/GoogleContainerTools/kaniko/pkg/config"
|
|
"github.com/GoogleContainerTools/kaniko/pkg/constants"
|
|
"github.com/GoogleContainerTools/kaniko/pkg/version"
|
|
"github.com/google/go-containerregistry/pkg/authn"
|
|
"github.com/google/go-containerregistry/pkg/authn/k8schain"
|
|
"github.com/google/go-containerregistry/pkg/name"
|
|
"github.com/google/go-containerregistry/pkg/v1"
|
|
"github.com/google/go-containerregistry/pkg/v1/empty"
|
|
"github.com/google/go-containerregistry/pkg/v1/mutate"
|
|
"github.com/google/go-containerregistry/pkg/v1/remote"
|
|
"github.com/google/go-containerregistry/pkg/v1/tarball"
|
|
"github.com/pkg/errors"
|
|
"github.com/sirupsen/logrus"
|
|
)
|
|
|
|
type withUserAgent struct {
|
|
t http.RoundTripper
|
|
}
|
|
|
|
func (w *withUserAgent) RoundTrip(r *http.Request) (*http.Response, error) {
|
|
r.Header.Set("User-Agent", fmt.Sprintf("kaniko/%s", version.Version()))
|
|
return w.t.RoundTrip(r)
|
|
}
|
|
|
|
// DoPush is responsible for pushing image to the destinations specified in opts
|
|
func DoPush(image v1.Image, opts *config.KanikoOptions) error {
|
|
if opts.NoPush {
|
|
logrus.Info("Skipping push to container registry due to --no-push flag")
|
|
return nil
|
|
}
|
|
destRefs := []name.Tag{}
|
|
for _, destination := range opts.Destinations {
|
|
destRef, err := name.NewTag(destination, name.WeakValidation)
|
|
if err != nil {
|
|
return errors.Wrap(err, "getting tag for destination")
|
|
}
|
|
destRefs = append(destRefs, destRef)
|
|
}
|
|
|
|
if opts.TarPath != "" {
|
|
tagToImage := map[name.Tag]v1.Image{}
|
|
for _, destRef := range destRefs {
|
|
tagToImage[destRef] = image
|
|
}
|
|
return tarball.MultiWriteToFile(opts.TarPath, tagToImage, nil)
|
|
}
|
|
|
|
// continue pushing unless an error occurs
|
|
for _, destRef := range destRefs {
|
|
if opts.InsecurePush {
|
|
newReg, err := name.NewInsecureRegistry(destRef.Repository.Registry.Name(), name.WeakValidation)
|
|
if err != nil {
|
|
return errors.Wrap(err, "getting new insecure registry")
|
|
}
|
|
destRef.Repository.Registry = newReg
|
|
}
|
|
|
|
k8sc, err := k8schain.NewNoClient()
|
|
if err != nil {
|
|
return errors.Wrap(err, "getting k8schain client")
|
|
}
|
|
kc := authn.NewMultiKeychain(authn.DefaultKeychain, k8sc)
|
|
pushAuth, err := kc.Resolve(destRef.Context().Registry)
|
|
if err != nil {
|
|
return errors.Wrap(err, "resolving pushAuth")
|
|
}
|
|
|
|
// Create a transport to set our user-agent.
|
|
tr := http.DefaultTransport
|
|
if opts.SkipTLSVerify {
|
|
tr.(*http.Transport).TLSClientConfig = &tls.Config{
|
|
InsecureSkipVerify: true,
|
|
}
|
|
}
|
|
rt := &withUserAgent{t: tr}
|
|
|
|
if err := remote.Write(destRef, image, pushAuth, rt, remote.WriteOptions{}); err != nil {
|
|
return errors.Wrap(err, fmt.Sprintf("failed to push to destination %s", destRef))
|
|
}
|
|
}
|
|
return nil
|
|
}
|
|
|
|
// pushLayerToCache pushes layer (tagged with cacheKey) to opts.Cache
|
|
// if opts.Cache doesn't exist, infer the cache from the given destination
|
|
func pushLayerToCache(opts *config.KanikoOptions, cacheKey string, layer v1.Layer, createdBy string) error {
|
|
cache, err := cache.Destination(opts, cacheKey)
|
|
if err != nil {
|
|
return errors.Wrap(err, "getting cache destination")
|
|
}
|
|
logrus.Infof("Pushing layer %s to cache now", cache)
|
|
empty := empty.Image
|
|
empty, err = mutate.Append(empty,
|
|
mutate.Addendum{
|
|
Layer: layer,
|
|
History: v1.History{
|
|
Author: constants.Author,
|
|
CreatedBy: createdBy,
|
|
},
|
|
},
|
|
)
|
|
if err != nil {
|
|
return errors.Wrap(err, "appending layer onto empty image")
|
|
}
|
|
return DoPush(empty, &config.KanikoOptions{
|
|
Destinations: []string{cache},
|
|
})
|
|
}
|