使用Cloud Build时Dockerfile无法复制文件的问题排查
问题背景
计划通过Google Cloud Build和Cloud Run部署带有PHP表单的简单HTML网站,使用richarvey/nginx-php-fpm官方镜像测试。本地环境中Dockerfile运行正常,但在Cloud Build执行COPY命令时提示无法找到Git仓库内的文件。Cloud Build已成功拉取Git仓库并识别Dockerfile,但无法访问仓库中的website、configurations等目录,修改WORKDIR后问题仍未解决。
目标:拉取Git仓库代码,将配置文件放入php-fpm,同时将配置及网站文件部署到nginx。
Git仓库结构
root@3f1639b5e961:~# ls -l .git .gitignore .key Dockerfile website configurations additionals
本地运行正常的Dockerfile
FROM richarvey/nginx-php-fpm USER root WORKDIR /root/ mkdir /etc/nginx/website mkdir /etc/nginx/ssl COPY ./website/* /etc/nginx/website/ COPY ./configurations/nginx/nginx.conf /etc/nginx/nginx.conf COPY ./configurations/nginx/sites.conf /etc/nginx/conf.d/sites.conf COPY ./configurations/nginx/ssl/domain.crt /etc/nginx/ssl/ COPY ./configurations/nginx/ssl/domain.key /etc/nginx/ssl/ EXPOSE 80
Cloud Build测试用Dockerfile
FROM richarvey/nginx-php-fpm RUN ls / RUN ls /root RUN ls /tmp WORKDIR /workspace RUN pwd RUN ls -lah RUN mkdir /test COPY .git/* /test/ RUN ls -lah /test/ EXPOSE 80
Cloud Build关键日志片段
... FETCHSOURCE ... Initialized empty Git repository in /workspace/.git/ From https://github.com/test-project/websites * branch da12067dc2db6ce22fa2f6dccefafe42f1546b2f -> FETCH_HEAD Updating files: 47% (3988/8473) ... Updating files: 100% (8473/8473), done. HEAD is now at da12067 changes.. BUILD Already have image (with digest): gcr.io/cloud-builders/docker Sending build context to Docker daemon 1.657GB ... Step 8/12 : RUN ls -lah ---> Running in 3f3044d6ac2b total 16K drwx------ 1 root root 4.0K Apr 14 20:49 . drwxr-xr-x 1 root root 4.0K May 1 08:18 .. drwxr-xr-x 3 root root 4.0K Apr 14 20:44 .cache drwxr-xr-x 2 root root 4.0K Apr 14 20:49 .composer ... Step 10/12 : COPY .git/* /test/ ---> d4e3162b8107 Step 11/12 : RUN ls -lah /test/ ---> Running in de00358a4c5a total 1020K drwxr-xr-x 1 root root 4.0K May 1 08:18 . drwxr-xr-x 1 root root 4.0K May 1 08:18 .. -rw-r--r-- 1 root root 122 May 1 08:18 FETCH_HEAD ... # .git目录下的文件列表 ... Successfully built e05aacc1a054 Successfully tagged test-project:latest PUSH Pushing test-project:latest The push refers to repository [docker.io/library/test-project] denied: requested access to the resource is denied
问题原因及解决方案
核心问题1:对Docker构建上下文的误解
你在测试Dockerfile中执行RUN ls -lah时,查看的是容器内部的/root目录,而非Cloud Build拉取代码所在的构建上下文目录。此时还未执行任何COPY操作,容器内自然不存在仓库中的website、configurations等目录,这属于测试逻辑错误,并非COPY命令找不到文件。
从日志可以看到COPY .git/* /test/成功执行,说明构建上下文(Cloud Build的/workspace目录)中确实存在.git目录,其他仓库文件也应该在构建上下文中。
核心问题2:可能的.gitignore过滤
检查你的.gitignore文件,如果其中包含website、configurations等目录,Cloud Build拉取代码时会自动忽略这些文件,导致构建上下文中缺失对应内容。
解决方案
修正测试逻辑:要验证构建上下文是否包含目标文件,应在COPY操作后查看容器内的文件,或者在Cloud Build流程中添加前置步骤查看/workspace目录内容:
# cloudbuild.yaml 示例 steps: - name: 'gcr.io/cloud-builders/gcloud' args: ['ls', '-lah', '/workspace'] - name: 'gcr.io/cloud-builders/docker' args: ['build', '-t', 'gcr.io/你的项目ID/test-project', '.']修正测试Dockerfile:直接复制整个仓库内容到容器内查看:
FROM richarvey/nginx-php-fpm USER root COPY . /test/ RUN ls -lah /test/ EXPOSE 80检查.gitignore:确保
website、configurations等目录未被.gitignore排除。修正镜像推送目标:日志中PUSH失败是因为尝试推送到Docker Hub的官方库,应改为推送到Google Container Registry:
# cloudbuild.yaml 中添加推送步骤 images: - 'gcr.io/你的项目ID/test-project'
内容的提问来源于stack exchange,提问作者spala

