在GCP Cloud Build中启用DOCKER_BUILDKIT=1的问题求助
解决GCP Cloud Build构建依赖BuildKit的Dockerfile问题
问题背景
使用GCP Cloud Build构建仓库内的Dockerfile时失败,该Dockerfile需要启用Docker BuildKit才能正确构建(否则会出现can't create directory 'packages/': Permission denied这类权限错误),但Cloud Build默认未启用BuildKit,且对Docker技术不熟悉,尝试修改后仍未解决问题。
解决方案
有两种可行方案,根据需求选择:
方案1:在Cloud Build中启用Docker BuildKit
无需修改Dockerfile,只需调整Cloud Build的构建配置:
- 若使用
cloudbuild.yaml,添加环境变量及构建参数:
steps: - name: 'gcr.io/cloud-builders/docker' args: ['build', '-t', 'gcr.io/$PROJECT_ID/your-image-name', '.'] env: - 'DOCKER_BUILDKIT=1' options: machineType: 'E2_HIGHCPU_8' # 可选,复杂构建建议使用更高配置机器
- 若使用Cloud Build控制台配置构建触发器,在「构建配置」的「环境变量」中添加
DOCKER_BUILDKIT=1。
方案2:修改Dockerfile移除BuildKit依赖
若不想调整Cloud Build配置,可以修改Dockerfile,避免依赖BuildKit的WORKDIR自动创建权限特性:
核心修改Stage 3的目录创建逻辑,手动确保/app目录归属node用户。
修改后的完整Dockerfile:
# Stage 1 - Create yarn install skeleton layer FROM node:16-bullseye-slim AS packages WORKDIR /app COPY package.json yarn.lock ./ COPY packages packages # Comment this out if you don't have any internal plugins COPY plugins plugins RUN find packages \! -name "package.json" -mindepth 2 -maxdepth 2 -exec rm -rf {} \+ # Stage 2 - Install dependencies and build packages FROM node:16-bullseye-slim AS build # install sqlite3 dependencies RUN --mount=type=cache,target=/var/cache/apt,sharing=locked \ --mount=type=cache,target=/var/lib/apt,sharing=locked \ apt-get update && \ apt-get install -y --no-install-recommends libsqlite3-dev python3 build-essential && \ yarn config set python /usr/bin/python3 USER node WORKDIR /app COPY --from=packages --chown=node:node /app . # Stop cypress from downloading it's massive binary. ENV CYPRESS_INSTALL_BINARY=0 RUN --mount=type=cache,target=/home/node/.cache/yarn,sharing=locked,uid=1000,gid=1000 \ yarn install --frozen-lockfile --network-timeout 600000 COPY --chown=node:node . . RUN yarn tsc RUN yarn --cwd packages/backend build # If you have not yet migrated to package roles, use the following command instead: # RUN yarn --cwd packages/backend backstage-cli backend:bundle --build-dependencies RUN mkdir packages/backend/dist/skeleton packages/backend/dist/bundle \ && tar xzf packages/backend/dist/skeleton.tar.gz -C packages/backend/dist/skeleton \ && tar xzf packages/backend/dist/bundle.tar.gz -C packages/backend/dist/bundle # Stage 3 - Build the actual backend image and install production dependencies FROM node:16-bullseye-slim # Install sqlite3 dependencies. You can skip this if you don't use sqlite3 in the image, # in which case you should also move better-sqlite3 to "devDependencies" in package.json. RUN --mount=type=cache,target=/var/cache/apt,sharing=locked \ --mount=type=cache,target=/var/lib/apt,sharing=locked \ apt-get update && \ apt-get install -y --no-install-recommends libsqlite3-dev wget python3 build-essential && \ yarn config set python /usr/bin/python3 RUN apt-get update && apt-get install -y python3 python3-pip RUN pip3 install mkdocs-techdocs-core==1.0.1 # From here on we use the least-privileged `node` user to run the backend. USER node # 手动创建/app目录并确保归属node用户,避免依赖BuildKit的自动创建权限逻辑 RUN mkdir -p /app WORKDIR /app # Copy the install dependencies from the build stage and context COPY --from=build --chown=node:node /app/yarn.lock /app/package.json /app/packages/backend/dist/skeleton/ ./ RUN --mount=type=cache,target=/home/node/.cache/yarn,sharing=locked,uid=1000,gid=1000 \ yarn install --frozen-lockfile --production --network-timeout 600000 # Copy the built packages from the build stage COPY --from=build --chown=node:node /app/packages/backend/dist/bundle/ ./ # Copy any other files that we need at runtime COPY --chown=node:node app-config.yaml ./ RUN wget https://dl.google.com/cloudsql/cloud_sql_proxy.linux.amd64 -O cloud_sql_proxy RUN chmod +x cloud_sql_proxy # This switches many Node.js dependencies to production mode. ENV NODE_ENV production ADD start.sh credentials.json ./ COPY catalog ./ CMD ["./start.sh"]
关键修改点:在Stage 3切换到node用户后,添加RUN mkdir -p /app命令手动创建工作目录,确保目录归属node用户,避免BuildKit未启用时WORKDIR自动创建的目录属于root导致的权限问题。
内容的提问来源于stack exchange,提问作者AlvaroC
相关产品推荐
相关产品推荐

