You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在GCP Cloud Build中启用DOCKER_BUILDKIT=1的问题求助

解决GCP Cloud Build构建依赖BuildKit的Dockerfile问题

问题背景

使用GCP Cloud Build构建仓库内的Dockerfile时失败,该Dockerfile需要启用Docker BuildKit才能正确构建(否则会出现can't create directory 'packages/': Permission denied这类权限错误),但Cloud Build默认未启用BuildKit,且对Docker技术不熟悉,尝试修改后仍未解决问题。

解决方案

有两种可行方案,根据需求选择:

方案1:在Cloud Build中启用Docker BuildKit

无需修改Dockerfile,只需调整Cloud Build的构建配置:

  • 若使用cloudbuild.yaml,添加环境变量及构建参数:
steps:
- name: 'gcr.io/cloud-builders/docker'
  args: ['build', '-t', 'gcr.io/$PROJECT_ID/your-image-name', '.']
  env:
  - 'DOCKER_BUILDKIT=1'
options:
  machineType: 'E2_HIGHCPU_8' # 可选,复杂构建建议使用更高配置机器
  • 若使用Cloud Build控制台配置构建触发器,在「构建配置」的「环境变量」中添加DOCKER_BUILDKIT=1。

方案2:修改Dockerfile移除BuildKit依赖

若不想调整Cloud Build配置,可以修改Dockerfile,避免依赖BuildKit的WORKDIR自动创建权限特性:
核心修改Stage 3的目录创建逻辑,手动确保/app目录归属node用户。

修改后的完整Dockerfile:

# Stage 1 - Create yarn install skeleton layer
FROM node:16-bullseye-slim AS packages

WORKDIR /app
COPY package.json yarn.lock ./

COPY packages packages

# Comment this out if you don't have any internal plugins
COPY plugins plugins

RUN find packages \! -name "package.json" -mindepth 2 -maxdepth 2 -exec rm -rf {} \+

# Stage 2 - Install dependencies and build packages
FROM node:16-bullseye-slim AS build

# install sqlite3 dependencies
RUN --mount=type=cache,target=/var/cache/apt,sharing=locked \
    --mount=type=cache,target=/var/lib/apt,sharing=locked \
    apt-get update && \
    apt-get install -y --no-install-recommends libsqlite3-dev python3 build-essential && \
    yarn config set python /usr/bin/python3

USER node
WORKDIR /app

COPY --from=packages --chown=node:node /app .

# Stop cypress from downloading it's massive binary.
ENV CYPRESS_INSTALL_BINARY=0
RUN --mount=type=cache,target=/home/node/.cache/yarn,sharing=locked,uid=1000,gid=1000 \
    yarn install --frozen-lockfile --network-timeout 600000

COPY --chown=node:node . .

RUN yarn tsc
RUN yarn --cwd packages/backend build
# If you have not yet migrated to package roles, use the following command instead:
# RUN yarn --cwd packages/backend backstage-cli backend:bundle --build-dependencies

RUN mkdir packages/backend/dist/skeleton packages/backend/dist/bundle \
    && tar xzf packages/backend/dist/skeleton.tar.gz -C packages/backend/dist/skeleton \
    && tar xzf packages/backend/dist/bundle.tar.gz -C packages/backend/dist/bundle

# Stage 3 - Build the actual backend image and install production dependencies
FROM node:16-bullseye-slim

# Install sqlite3 dependencies. You can skip this if you don't use sqlite3 in the image,
# in which case you should also move better-sqlite3 to "devDependencies" in package.json.
RUN --mount=type=cache,target=/var/cache/apt,sharing=locked \
    --mount=type=cache,target=/var/lib/apt,sharing=locked \
    apt-get update && \
    apt-get install -y --no-install-recommends libsqlite3-dev wget python3 build-essential && \
    yarn config set python /usr/bin/python3
RUN apt-get update && apt-get install -y python3 python3-pip
RUN pip3 install mkdocs-techdocs-core==1.0.1

# From here on we use the least-privileged `node` user to run the backend.
USER node

# 手动创建/app目录并确保归属node用户,避免依赖BuildKit的自动创建权限逻辑
RUN mkdir -p /app
WORKDIR /app

# Copy the install dependencies from the build stage and context
COPY --from=build --chown=node:node /app/yarn.lock /app/package.json /app/packages/backend/dist/skeleton/ ./

RUN --mount=type=cache,target=/home/node/.cache/yarn,sharing=locked,uid=1000,gid=1000 \
    yarn install --frozen-lockfile --production --network-timeout 600000

# Copy the built packages from the build stage
COPY --from=build --chown=node:node /app/packages/backend/dist/bundle/ ./

# Copy any other files that we need at runtime
COPY --chown=node:node app-config.yaml ./

RUN wget https://dl.google.com/cloudsql/cloud_sql_proxy.linux.amd64 -O cloud_sql_proxy
RUN chmod +x cloud_sql_proxy

# This switches many Node.js dependencies to production mode.
ENV NODE_ENV production
ADD start.sh credentials.json ./
COPY catalog ./
CMD ["./start.sh"]

关键修改点:在Stage 3切换到node用户后,添加RUN mkdir -p /app命令手动创建工作目录,确保目录归属node用户,避免BuildKit未启用时WORKDIR自动创建的目录属于root导致的权限问题。


内容的提问来源于stack exchange,提问作者AlvaroC

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.01 00:50:23