Docker构建时如何从容器内复制产物到宿主机?
docker build? Great question! Let's break this down clearly:
First, the short answer: There is no built-in command in Dockerfile that can directly copy files from the build container to the host filesystem during docker build. This is intentional—Docker's build process runs in an isolated container environment, which doesn't have direct access to the host's filesystem. This isolation ensures build reproducibility and security, preventing untrusted build steps from modifying your host system.
But don't worry, there are several straightforward workarounds to achieve your goal of exporting build artifacts with just a single build-related command:
1. Use the docker build --output flag (Docker 17.05+)
This is the most direct and recommended method for modern Docker versions. You can use multi-stage builds to isolate your build process, then export the final artifacts directly to your host.
Here's an example Dockerfile for a Go application:
# Build stage: compile the application FROM golang:1.21 AS builder WORKDIR /app COPY go.mod go.sum ./ RUN go mod download COPY . . RUN go build -o my-go-app . # Export stage: prepare artifacts for extraction FROM scratch AS export-stage COPY --from=builder /app/my-go-app /
Then run this build command to export the binary to your host's target path:
docker build --output type=local,dest=/home/your-user/build-outputs .
This will copy all files from the export-stage to /home/your-user/build-outputs on your host—no manual docker cp needed.
2. Temporary container + script (for older Docker versions)
If you're stuck with a Docker version before 17.05, you can wrap the build, temporary container creation, copy, and cleanup steps into a simple bash script. This lets you run everything in one command.
Create a script named build-and-export.sh:
#!/bin/bash # Build the image docker build -t my-app-builder . # Create a temporary container (without starting it) docker create --name temp-export-container my-app-builder # Copy the artifact to your host docker cp temp-export-container:/app/my-go-app /home/your-user/build-outputs/ # Clean up the temporary container docker rm temp-export-container
Make it executable and run it:
chmod +x build-and-export.sh ./build-and-export.sh
3. Docker Buildx for multi-platform builds
If you need to build artifacts for multiple architectures (e.g., AMD64, ARM64), Docker Buildx extends the --output functionality to support multi-platform exports:
docker buildx build --platform linux/amd64,linux/arm64 --output type=local,dest=/home/your-user/multi-platform-builds .
Buildx will handle cross-compilation and export all platform-specific artifacts to your host directory.
Why isn't there a Dockerfile command for this?
To recap: Docker's core design principles emphasize build reproducibility and isolation. A Dockerfile command that directly modifies the host filesystem would break these principles—builds would no longer be consistent across different environments, and could introduce security risks if untrusted Dockerfiles are executed. The workarounds above maintain these principles while still letting you export artifacts easily.
内容的提问来源于stack exchange,提问作者JamesFaix

