Ubuntu Server构建Rust Docker镜像时遇-lssl/-lcrypto找不到错误
问题
在GCP的Ubuntu Server 24.04 LTS(配置10GB存储、2GB内存)上构建Rust Docker镜像时失败,尽管已安装musl-dev,但仍出现链接错误,提示找不到-lssl和-lcrypto。以下是Dockerfile及报错日志:
Dockerfile
FROM rust:alpine AS builder # Set the current working directory inside the Docker image WORKDIR /usr/src # Copy the Cargo.toml file and your source code into the Docker image COPY Cargo.toml Cargo.lock ./ COPY src ./src COPY secrets ./secrets # Copy the dev-config.toml file COPY dev-config.toml . # Install build dependencies RUN apk add --no-cache build-base libgcc libstdc++ openssl openssl-dev pkgconfig musl-dev pcc-libs-dev # Build the application in release mode RUN cargo build --release # Start a new build stage with Alpine FROM alpine:latest # Install necessary libraries. libgcc and libstdc++, etc are needed for the Rust binary RUN apk add --no-cache libgcc libstdc++ openssl pcc-libs-dev build-base openssl-dev pkgconfig musl-dev # Add a new user 'appuser' RUN addgroup -S appgroup && adduser -S appuser -G appgroup # Copy the binary from the builder stage to the current stage COPY --from=builder /usr/src/target/release/my-api /usr/local/bin # Change to non-root privilege USER appuser # Set the command to run your application CMD ["my-api"]
报错信息
error: linking with `cc` failed: exit status: 1 = note: LC_ALL="C" PATH="/usr/local/rustup/toolchains/1.80.0-x86_64-unknown-linux-musl/lib/rustlib/x86_64-unknown-linux-musl/bin:/usr/local/rustup/toolchains/1.80.0-x86_64-unknown-linux-musl/lib/rustlib/x86_64-unknown-linux-musl/bin/self-contained:/usr/local/rustup/toolchains/1.80.0-x86_64-unknown-linux-musl/lib/rustlib/x86_64-unknown-linux-musl/bin:/usr/local/rustup/toolchains/1.80.0-x86_64-unknown-linux-musl/lib/rustlib/x86_64-unknown-linux-musl..... .....the rest = note: /usr/lib/gcc/x86_64-alpine-linux-musl/13.2.1/../../../../x86_64-alpine-linux-musl/bin/ld: cannot find -lssl: No such file or directory 1099.5 /usr/lib/gcc/x86_64-alpine-linux-musl/13.2.1/../../../../x86_64-alpine-linux-musl/bin/ld: cannot find -lcrypto: No such file or directory 1099.5 collect2: error: ld returned 1 exit status
解决方案
问题根源是Alpine环境下,openssl包仅提供运行时库,链接阶段需要的静态库或开发包符号链接未被正确识别。可以通过以下方式修复:
调整builder阶段的依赖与环境变量
安装必要依赖后,添加环境变量指定OpenSSL静态链接路径,让Rust能找到对应的库文件。修改builder阶段的命令:# Install build dependencies RUN apk add --no-cache build-base pkgconfig musl-dev openssl-dev # 设置环境变量,指定OpenSSL静态链接参数 ENV OPENSSL_STATIC=1 ENV OPENSSL_DIR=/usr/lib/ssl ENV OPENSSL_LIB_DIR=/usr/lib ENV OPENSSL_INCLUDE_DIR=/usr/include/openssl # Build the application in release mode RUN cargo build --release精简runtime阶段的依赖
运行阶段不需要开发类包,只保留运行时必需的库即可,减少镜像体积:FROM alpine:latest # 仅安装运行时依赖 RUN apk add --no-cache libgcc libstdc++ openssl # 添加非root用户 RUN addgroup -S appgroup && adduser -S appuser -G appgroup # 复制编译好的二进制文件 COPY --from=builder /usr/src/target/release/my-api /usr/local/bin # 切换到非root用户运行 USER appuser # 设置启动命令 CMD ["my-api"]备选方案:使用openssl crate的vendored特性
如果项目依赖opensslcrate,直接在Cargo.toml中启用vendored特性,让crate编译内置的OpenSSL版本,彻底规避系统库兼容问题:[dependencies] openssl = { version = "0.10", features = ["vendored"] }
以上调整后,构建过程就能正确找到-lssl和-lcrypto库文件,完成链接操作。
内容的提问来源于stack exchange,提问作者notnuyy
相关产品推荐
相关产品推荐

