美文网首页
小心 Dockerfile RUN 指令陷进

小心 Dockerfile RUN 指令陷进

作者: kong62 | 来源:发表于2021-01-12 19:25 被阅读0次

    alpine 基础镜像

    首先我们看下 alpine 镜像本身大小,其解压到本地文件系统后是 5.58MB:

    # docker pull alpine:3.10
    # docker history alpine:3.10
    IMAGE               CREATED             CREATED BY                                      SIZE                COMMENT
    be4e4bea2c2e        8 months ago        /bin/sh -c #(nop)  CMD ["/bin/sh"]              0B                  
    <missing>           8 months ago        /bin/sh -c #(nop) ADD file:66a440394c2442570…   5.58MB              
    

    查看下 alpine 镜像的层,发现只有 1 层,而这一层是 ADD 指令导致的,CMD 不会导致镜像层的增加:

    # docker image inspect alpine:3.10
            "GraphDriver": {
                "Data": {
                    "MergedDir": "/var/lib/docker/overlay2/3b0e120c79d2194fc167b05ec04ec63573b19461f0eda04e2090f87dfa62c4c3/merged",
                    "UpperDir": "/var/lib/docker/overlay2/3b0e120c79d2194fc167b05ec04ec63573b19461f0eda04e2090f87dfa62c4c3/diff",
                    "WorkDir": "/var/lib/docker/overlay2/3b0e120c79d2194fc167b05ec04ec63573b19461f0eda04e2090f87dfa62c4c3/work"
                },
                "Name": "overlay2"
            },
            "RootFS": {
                "Type": "layers",
                "Layers": [
                    "sha256:1b3ee35aacca9866b01dd96e870136266bde18006ac2f0d6eb706c798d1fa3c3"
                ]
            },
    
    # ll /var/lib/docker/overlay2/
    total 40
    drwx------ 3 root root  4096 Jan 12 18:37 3b0e120c79d2194fc167b05ec04ec63573b19461f0eda04e2090f87dfa62c4c3       # alpine 基础层
    drwx------ 2 root root 32768 Jan 12 20:29 l
    
    # du -sh /var/lib/docker/overlay2/3b0e120c79d2194fc167b05ec04ec63573b19461f0eda04e2090f87dfa62c4c3
    5.9M   /var/lib/docker/overlay2/3b0e120c79d2194fc167b05ec04ec63573b19461f0eda04e2090f87dfa62c4c3
    

    测试用例说明

    这里涉及 2 个文件,一个是 Dockerfile 本身,另外一个就是我们需要构建的二进制可执行文件:

    # ll
    total 68416
    -rw-r--r-- 1 root root      114 Jan 12 18:26 Dockerfile
    -rwxr-xr-x 1 root root 70045960 Jan  8 18:35 server
    

    示例 1

    正确的构建方式,在构建镜像的机器上确保二进制可执行文件已经被赋予 +x 权限

    # vi Dockerfile
    FROM alpine:3.10
    
    WORKDIR /app
    
    COPY server /app/server
    
    RUN apk add ca-certificates --no-cache
    
    CMD ["./server"]
    
    # chmod +x server
    
    # docker build -t test:v1.1 .
    

    查看镜像多了 2 层,分别是 COPY 和 RUN 指令导致的 70MB 和 548kB:

    # docker history test:v1.1
    IMAGE               CREATED             CREATED BY                                      SIZE                COMMENT
    c07147a61fe1        4 minutes ago       /bin/sh -c #(nop)  CMD ["./server"]             0B                  
    f25b9fbccab9        4 minutes ago       /bin/sh -c apk add ca-certificates --no-cache   548kB               
    94f9882d94a6        5 minutes ago       /bin/sh -c #(nop) COPY file:12538126de007281…   70MB                
    ab6e817176dd        5 minutes ago       /bin/sh -c #(nop) WORKDIR /app                  0B                  
    be4e4bea2c2e        8 months ago        /bin/sh -c #(nop)  CMD ["/bin/sh"]              0B                  
    <missing>           8 months ago        /bin/sh -c #(nop) ADD file:66a440394c2442570…   5.58MB              
    

    查看镜像信息,发现总计 4 层,比之前多了 3 层:

    # docker image inspect test:v1.1
            "GraphDriver": {
                "Data": {
                    "LowerDir": "/var/lib/docker/overlay2/4e220bffb2bf1c0c98dd6e66d69a2f8a5437e00381da2215726a9975f5f25136/diff:/var/lib/docker/overlay2/1dfb6f9dd4043d614d9045e39ffde626a88744a1f1c21b8c5f362f870cfce2e3/diff:/var/lib/docker/overlay2/3b0e120c79d2194fc167b05ec04ec63573b19461f0eda04e2090f87dfa62c4c3/diff",
                    "MergedDir": "/var/lib/docker/overlay2/39bf6fd694c9491ea68bc2aaa4ab3676deaa2297c9926cf89f5aed27bd3138bd/merged",
                    "UpperDir": "/var/lib/docker/overlay2/39bf6fd694c9491ea68bc2aaa4ab3676deaa2297c9926cf89f5aed27bd3138bd/diff",
                    "WorkDir": "/var/lib/docker/overlay2/39bf6fd694c9491ea68bc2aaa4ab3676deaa2297c9926cf89f5aed27bd3138bd/work"
                },
                "Name": "overlay2"
            },
            "RootFS": {
                "Type": "layers",
                "Layers": [
                    "sha256:1b3ee35aacca9866b01dd96e870136266bde18006ac2f0d6eb706c798d1fa3c3",
                    "sha256:f664359f2a96e588b77c41928cf846b2622a1eed588fc990a64a415db017def0",
                    "sha256:1ae82946dc8868321b54e184e2dbdc2d6039afe8451695043e09143a3c2644ef",
                    "sha256:c539a2477f1cfd06c08816d7738d3ee27cd94777c3ad259cddad552cd5b2d82d"
                ]
            },
    

    为什么会多出一层呢?

    # ll /var/lib/docker/overlay2
    total 52
    drwx------ 4 root root  4096 Jan 12 20:33 1dfb6f9dd4043d614d9045e39ffde626a88744a1f1c21b8c5f362f870cfce2e3    # WORKDIR 创建的 /app 文件夹层
    drwx------ 4 root root  4096 Jan 12 20:34 39bf6fd694c9491ea68bc2aaa4ab3676deaa2297c9926cf89f5aed27bd3138bd    # 安装 ca-certificates 层
    drwx------ 3 root root  4096 Jan 12 18:37 3b0e120c79d2194fc167b05ec04ec63573b19461f0eda04e2090f87dfa62c4c3    # alpine 基础层
    drwx------ 4 root root  4096 Jan 12 20:33 4e220bffb2bf1c0c98dd6e66d69a2f8a5437e00381da2215726a9975f5f25136    # server 二进制可执行文件层
    drwx------ 2 root root 32768 Jan 12 20:34 l
    

    通过 du 查看下大小情况:

    # du -sh /var/lib/docker/overlay2/* |column -t
    24K   /var/lib/docker/overlay2/1dfb6f9dd4043d614d9045e39ffde626a88744a1f1c21b8c5f362f870cfce2e3
    1.6M  /var/lib/docker/overlay2/39bf6fd694c9491ea68bc2aaa4ab3676deaa2297c9926cf89f5aed27bd3138bd
    5.9M  /var/lib/docker/overlay2/3b0e120c79d2194fc167b05ec04ec63573b19461f0eda04e2090f87dfa62c4c3
    67M   /var/lib/docker/overlay2/4e220bffb2bf1c0c98dd6e66d69a2f8a5437e00381da2215726a9975f5f25136
    52K   /var/lib/docker/overlay2/l
    

    通过上面信息,我们可以猜测到:

    1. 第一行的 24K 就是莫名多出来的那个层,查看信息发现是 WORKDIR 创建了一个目录导致增了的层
    # tree /var/lib/docker/overlay2/1dfb6f9dd4043d614d9045e39ffde626a88744a1f1c21b8c5f362f870cfce2e3/diff/
    /var/lib/docker/overlay2/1dfb6f9dd4043d614d9045e39ffde626a88744a1f1c21b8c5f362f870cfce2e3/diff/
    `-- app
    
    1 directory, 0 files
    
    1. 第二行就是安装 ca-certificates 包导致的
    2. 第三行就是 alpine 镜像本身的那个 ADD
    3. 第四行就是我们的 server 二进制可执行文件
    # ls -lh /var/lib/docker/overlay2/4e220bffb2bf1c0c98dd6e66d69a2f8a5437e00381da2215726a9975f5f25136/diff/app/ 
    total 67M
    -rwxr-xr-x 1 root root 67M Jan  8 18:35 server
    

    示例 2

    增加一条 ls 指令

    # vi Dockerfile 
    FROM alpine:3.10
    
    WORKDIR /app
    
    COPY server /app/server
    
    RUN apk add ca-certificates --no-cache
    
    RUN ls /app/server
    
    CMD ["./server"]
    
    # docker build -t test:v1.2 .
    
    # docker history test:v1.2
    IMAGE               CREATED              CREATED BY                                      SIZE                COMMENT
    8fcdc8d7dd5e        About a minute ago   /bin/sh -c #(nop)  CMD ["./server"]             0B                  
    76bd2b605692        About a minute ago   /bin/sh -c ls /app/server                       0B                  
    f25b9fbccab9        29 minutes ago       /bin/sh -c apk add ca-certificates --no-cache   548kB               
    94f9882d94a6        30 minutes ago       /bin/sh -c #(nop) COPY file:12538126de007281…   70MB                
    ab6e817176dd        30 minutes ago       /bin/sh -c #(nop) WORKDIR /app                  0B                  
    be4e4bea2c2e        8 months ago         /bin/sh -c #(nop)  CMD ["/bin/sh"]              0B                  
    <missing>           8 months ago         /bin/sh -c #(nop) ADD file:66a440394c2442570…   5.58MB              
    

    从层信息看跟示例 1 一致:

    # docker image inspect test:v1.2 
            "GraphDriver": {
                "Data": {
                    "LowerDir": "/var/lib/docker/overlay2/4e220bffb2bf1c0c98dd6e66d69a2f8a5437e00381da2215726a9975f5f25136/diff:/var/lib/docker/overlay2/1dfb6f9dd4043d614d9045e39ffde626a88744a1f1c21b8c5f362f870cfce2e3/diff:/var/lib/docker/overlay2/3b0e120c79d2194fc167b05ec04ec63573b19461f0eda04e2090f87dfa62c4c3/diff",
                    "MergedDir": "/var/lib/docker/overlay2/39bf6fd694c9491ea68bc2aaa4ab3676deaa2297c9926cf89f5aed27bd3138bd/merged",
                    "UpperDir": "/var/lib/docker/overlay2/39bf6fd694c9491ea68bc2aaa4ab3676deaa2297c9926cf89f5aed27bd3138bd/diff",
                    "WorkDir": "/var/lib/docker/overlay2/39bf6fd694c9491ea68bc2aaa4ab3676deaa2297c9926cf89f5aed27bd3138bd/work"
                },
                "Name": "overlay2"
            },
            "RootFS": {
                "Type": "layers",
                "Layers": [
                    "sha256:1b3ee35aacca9866b01dd96e870136266bde18006ac2f0d6eb706c798d1fa3c3",
                    "sha256:f664359f2a96e588b77c41928cf846b2622a1eed588fc990a64a415db017def0",
                    "sha256:1ae82946dc8868321b54e184e2dbdc2d6039afe8451695043e09143a3c2644ef",
                    "sha256:c539a2477f1cfd06c08816d7738d3ee27cd94777c3ad259cddad552cd5b2d82d"
                ]
            },
    

    增加的 ls 指令并没有产生新的文件目录:

    # du -sh /var/lib/docker/overlay2/* |column -t
    24K   /var/lib/docker/overlay2/1dfb6f9dd4043d614d9045e39ffde626a88744a1f1c21b8c5f362f870cfce2e3        # WORKDIR 创建的 /app 文件夹层
    1.6M  /var/lib/docker/overlay2/39bf6fd694c9491ea68bc2aaa4ab3676deaa2297c9926cf89f5aed27bd3138bd        # 安装 ca-certificates 层
    5.9M  /var/lib/docker/overlay2/3b0e120c79d2194fc167b05ec04ec63573b19461f0eda04e2090f87dfa62c4c3        # alpine 基础层
    67M   /var/lib/docker/overlay2/4e220bffb2bf1c0c98dd6e66d69a2f8a5437e00381da2215726a9975f5f25136        # server 二进制可执行文件层
    60K   /var/lib/docker/overlay2/l
    

    示例 3

    在这里多了一条修改权限的 chmod 指令:

    # vi Dockerfile
    FROM alpine:3.10
    
    WORKDIR /app
    
    COPY server /app/server
    
    RUN apk add ca-certificates --no-cache 
    RUN chmod +x /app/server
    
    CMD ["./server"]
    
    # docker build -t test:v1.3 .
    

    这次构建的镜像因为写时拷贝而变大了,糟糕,额外多了 70MB,这正好是跟 COPY 的二进制可执行文件大小一致:

    # docker history test:v1.3
    IMAGE               CREATED             CREATED BY                                      SIZE                COMMENT
    8b232f3a584d        13 seconds ago      /bin/sh -c #(nop)  CMD ["./server"]             0B                  
    4c39eecac053        13 seconds ago      /bin/sh -c chmod +x /app/server                 70MB                
    f25b9fbccab9        3 minutes ago       /bin/sh -c apk add ca-certificates --no-cache   548kB               
    94f9882d94a6        4 minutes ago       /bin/sh -c #(nop) COPY file:12538126de007281…   70MB                
    ab6e817176dd        4 minutes ago       /bin/sh -c #(nop) WORKDIR /app                  0B                  
    be4e4bea2c2e        8 months ago        /bin/sh -c #(nop)  CMD ["/bin/sh"]              0B                  
    <missing>           8 months ago        /bin/sh -c #(nop) ADD file:66a440394c2442570…   5.58MB              
    

    这会导致我的镜像变大吗?
    查看镜像的层信息,发现总计 5 层,比示例 1 多了 1 层,貌似确实是变大了
    但是仔细看发现其中有 2 层:1ae82946dc8868321b54e184e2dbdc2d6039afe8451695043e09143a3c2644ef 是重复的,他们可以底层复用?会不会额外占用一份数据?虚惊一场?
    注意:这里镜像的 sha256 是基于文件内容来计算的,所以 COPY server 和 RUN chmod 指令结束后,对应的内容并没有改变,完全一致,所以 sha256 值也是一样的

    # docker image inspect test:v1.3
            "GraphDriver": {
                "Data": {
                    "LowerDir": "/var/lib/docker/overlay2/39bf6fd694c9491ea68bc2aaa4ab3676deaa2297c9926cf89f5aed27bd3138bd/diff:/var/lib/docker/overlay2/4e220bffb2bf1c0c98dd6e66d69a2f8a5437e00381da2215726a9975f5f25136/diff:/var/lib/docker/overlay2/1dfb6f9dd4043d614d9045e39ffde626a88744a1f1c21b8c5f362f870cfce2e3/diff:/var/lib/docker/overlay2/3b0e120c79d2194fc167b05ec04ec63573b19461f0eda04e2090f87dfa62c4c3/diff",
                    "MergedDir": "/var/lib/docker/overlay2/473d7fbaa49a570089e7050846448830613565ad74f24c165a2c0ab1fb2da13f/merged",
                    "UpperDir": "/var/lib/docker/overlay2/473d7fbaa49a570089e7050846448830613565ad74f24c165a2c0ab1fb2da13f/diff",
                    "WorkDir": "/var/lib/docker/overlay2/473d7fbaa49a570089e7050846448830613565ad74f24c165a2c0ab1fb2da13f/work"
                },
                "Name": "overlay2"
            },
            "RootFS": {
                "Type": "layers",
                "Layers": [
                    "sha256:1b3ee35aacca9866b01dd96e870136266bde18006ac2f0d6eb706c798d1fa3c3",
                    "sha256:f664359f2a96e588b77c41928cf846b2622a1eed588fc990a64a415db017def0",
                    "sha256:1ae82946dc8868321b54e184e2dbdc2d6039afe8451695043e09143a3c2644ef",
                    "sha256:c539a2477f1cfd06c08816d7738d3ee27cd94777c3ad259cddad552cd5b2d82d",
                    "sha256:1ae82946dc8868321b54e184e2dbdc2d6039afe8451695043e09143a3c2644ef"
                ]
            },
    

    查看文件系统,发现多了一个 473d7fbaa49a570089e7050846448830613565ad74f24c165a2c0ab1fb2da13f 目录,该目录大小 67M,显然数据已经多出了一份,镜像大小还是被增加了:

    # du -sh /var/lib/docker/overlay2/* |column -t
    24K   /var/lib/docker/overlay2/1dfb6f9dd4043d614d9045e39ffde626a88744a1f1c21b8c5f362f870cfce2e3    # WORKDIR 创建的 /app 文件夹层
    1.6M  /var/lib/docker/overlay2/39bf6fd694c9491ea68bc2aaa4ab3676deaa2297c9926cf89f5aed27bd3138bd    # 安装 ca-certificates 层
    5.9M  /var/lib/docker/overlay2/3b0e120c79d2194fc167b05ec04ec63573b19461f0eda04e2090f87dfa62c4c3    # alpine 基础层
    67M   /var/lib/docker/overlay2/473d7fbaa49a570089e7050846448830613565ad74f24c165a2c0ab1fb2da13f    # 示例 2 出现的层
    67M   /var/lib/docker/overlay2/4e220bffb2bf1c0c98dd6e66d69a2f8a5437e00381da2215726a9975f5f25136    # server 二进制可执行文件层
    56K   /var/lib/docker/overlay2/l
    

    示例 4

    我们稍微修改下 chmod 指令的位置,放到另外一个 RUN 指令中去:

    # vi Dockerfile
    FROM alpine:3.10
    
    WORKDIR /app
    
    COPY server /app/server
    
    RUN apk add ca-certificates --no-cache \
        && chmod +x /app/server
    
    CMD ["./server"]
    
    # docker build -t test:v1.4 .
    

    查看镜像信息,这次是 70.6MB:

    # docker history test:v1.4
    IMAGE               CREATED             CREATED BY                                      SIZE                COMMENT
    873246df9fb4        10 seconds ago      /bin/sh -c #(nop)  CMD ["./server"]             0B                  
    40ee884bc4b3        10 seconds ago      /bin/sh -c apk add ca-certificates --no-cach…   70.6MB              
    94f9882d94a6        13 minutes ago      /bin/sh -c #(nop) COPY file:12538126de007281…   70MB                
    ab6e817176dd        13 minutes ago      /bin/sh -c #(nop) WORKDIR /app                  0B                  
    be4e4bea2c2e        8 months ago        /bin/sh -c #(nop)  CMD ["/bin/sh"]              0B                  
    <missing>           8 months ago        /bin/sh -c #(nop) ADD file:66a440394c2442570…   5.58MB              
    

    继续查看层信息,总计 4 层,和示例 1 一致:

    # docker image inspect test:v1.4
            "GraphDriver": {
                "Data": {
                    "LowerDir": "/var/lib/docker/overlay2/4e220bffb2bf1c0c98dd6e66d69a2f8a5437e00381da2215726a9975f5f25136/diff:/var/lib/docker/overlay2/1dfb6f9dd4043d614d9045e39ffde626a88744a1f1c21b8c5f362f870cfce2e3/diff:/var/lib/docker/overlay2/3b0e120c79d2194fc167b05ec04ec63573b19461f0eda04e2090f87dfa62c4c3/diff",
                    "MergedDir": "/var/lib/docker/overlay2/89019296250e362e9de41e672181be98c853e85bb15c9018aa5272c596c3b6a8/merged",
                    "UpperDir": "/var/lib/docker/overlay2/89019296250e362e9de41e672181be98c853e85bb15c9018aa5272c596c3b6a8/diff",
                    "WorkDir": "/var/lib/docker/overlay2/89019296250e362e9de41e672181be98c853e85bb15c9018aa5272c596c3b6a8/work"
                },
                "Name": "overlay2"
            },
            "RootFS": {
                "Type": "layers",
                "Layers": [
                    "sha256:1b3ee35aacca9866b01dd96e870136266bde18006ac2f0d6eb706c798d1fa3c3",
                    "sha256:f664359f2a96e588b77c41928cf846b2622a1eed588fc990a64a415db017def0",
                    "sha256:1ae82946dc8868321b54e184e2dbdc2d6039afe8451695043e09143a3c2644ef",
                    "sha256:4fd98e3a9f49d0ef2bfb2ce5f910c3e1f9a4e9a95e44116a1b97ff8fb4081eef"
                ]
            },
    

    查看文件系统这里确实多了一个 69M 的文件夹,这仍然导致镜像实际真的翻倍了:

    # du -sh /var/lib/docker/overlay2/* |column -t
    24K   /var/lib/docker/overlay2/1dfb6f9dd4043d614d9045e39ffde626a88744a1f1c21b8c5f362f870cfce2e3    # WORKDIR 创建的 /app 文件夹层
    1.6M  /var/lib/docker/overlay2/39bf6fd694c9491ea68bc2aaa4ab3676deaa2297c9926cf89f5aed27bd3138bd    # 安装 ca-certificates 层
    5.9M  /var/lib/docker/overlay2/3b0e120c79d2194fc167b05ec04ec63573b19461f0eda04e2090f87dfa62c4c3    # alpine 基础层
    67M   /var/lib/docker/overlay2/473d7fbaa49a570089e7050846448830613565ad74f24c165a2c0ab1fb2da13f    # 示例 2 出现的层
    67M   /var/lib/docker/overlay2/4e220bffb2bf1c0c98dd6e66d69a2f8a5437e00381da2215726a9975f5f25136    # server 二进制可执行文件层
    69M   /var/lib/docker/overlay2/89019296250e362e9de41e672181be98c853e85bb15c9018aa5272c596c3b6a8    # 示例 3 出现的层
    60K   /var/lib/docker/overlay2/l
    
    # ll /var/lib/docker/overlay2/89019296250e362e9de41e672181be98c853e85bb15c9018aa5272c596c3b6a8/diff/
    total 20
    drwxr-xr-x 2 root root 4096 Jan 12 20:33 app
    drwxr-xr-x 5 root root 4096 Jan 12 20:46 etc
    drwxr-xr-x 3 root root 4096 Apr 23  2020 lib
    drwxr-xr-x 6 root root 4096 Apr 23  2020 usr
    drwxr-xr-x 3 root root 4096 Apr 23  2020 var
    

    总结

    在构建镜像的时候,我们需要慎重处理 chmod 指令,当然或许可以延伸到一些遍历读取、修改的指令上,这有可能会导致镜像体积的变化。

    相关文章

      网友评论

          本文标题:小心 Dockerfile RUN 指令陷进

          本文链接:https://www.haomeiwen.com/subject/plveaktx.html