使用docker:24.0.0-dind时,安装Git后执行docker build会捕获哪些信息?
问题解答
当使用docker:24.0.0-dind搭配docker:24.0.0-cli时,未安装Git执行docker build出现的警告,是因为Docker Buildx需要Git来捕获构建上下文所在仓库的版本控制信息。安装Git后,Buildx会自动捕获以下Git相关信息:
- 当前代码的提交哈希(commit SHA)
- 检出的Git分支名称
- 关联当前提交的Git标签
- Git仓库的远程地址(如
origin的URL)
关于你的测试结果说明
你测试中无论是未装Git、装了Git,还是显式启用溯源attestation,docker buildx imagetools inspect都输出null,原因如下:
- 默认构建不生成SLSA溯源:
docker build默认不会生成SLSA格式的溯源声明,必须显式通过--attest type=provenance参数启用,且需要确保Buildx使用的构建器支持该功能(比如容器化构建器,可通过docker buildx create --use创建)。 - 仓库支持问题:镜像仓库需要支持OCI Attestations标准(如Docker Hub、GHCR等),否则推送后attestations不会被存储,自然无法通过
imagetools inspect查询到。 - 命令格式问题:Docker 24.0.0中,
imagetools inspect的Provenance字段结构可能与你使用的.Provenance.SLSA路径不符,可尝试改用{{ json .Provenance }}来查看完整的溯源数据。
翻译后的测试代码
# 此时未安装Git # 会输出警告:"WARNING: buildx: git was not found in the system. Current commit information was not captured by the build" docker build -t "$REGISTRY/without-git" . # 安装Git apk add git # Git已安装,不再出现buildx警告 docker build -t "$REGISTRY/with-git" . # 推送镜像到仓库 docker push "$REGISTRY/without-git" docker push "$REGISTRY/with-git" # 输出:null docker buildx imagetools inspect "$REGISTRY/without-git" --format "{{ json .Provenance.SLSA }}" # 输出:null docker buildx imagetools inspect "$REGISTRY/with-git" --format "{{ json .Provenance.SLSA }}" # 显式启用溯源,输出仍为null docker buildx build -t "$CI_REGISTRY_IMAGE/with-git-attested" --attest type=provenance,mode=max . docker push "$REGISTRY/with-git-attested" docker buildx imagetools inspect "$REGISTRY/with-git-attested" --format "{{ json .Provenance.SLSA }}"
内容的提问来源于stack exchange,提问作者gtpzkldqc
相关产品推荐
相关产品推荐

