小心 Dockerfile RUN 指令陷进

2021-01-12  本文已影响0人  kong62

alpine 基础镜像

首先我们看下 alpine 镜像本身大小,其解压到本地文件系统后是 5.58MB:

# docker pull alpine:3.10
# docker history alpine:3.10
IMAGE               CREATED             CREATED BY                                      SIZE                COMMENT
be4e4bea2c2e        8 months ago        /bin/sh -c #(nop)  CMD ["/bin/sh"]              0B                  
<missing>           8 months ago        /bin/sh -c #(nop) ADD file:66a440394c2442570…   5.58MB              

查看下 alpine 镜像的层,发现只有 1 层,而这一层是 ADD 指令导致的,CMD 不会导致镜像层的增加:

# docker image inspect alpine:3.10
        "GraphDriver": {
            "Data": {
                "MergedDir": "/var/lib/docker/overlay2/3b0e120c79d2194fc167b05ec04ec63573b19461f0eda04e2090f87dfa62c4c3/merged",
                "UpperDir": "/var/lib/docker/overlay2/3b0e120c79d2194fc167b05ec04ec63573b19461f0eda04e2090f87dfa62c4c3/diff",
                "WorkDir": "/var/lib/docker/overlay2/3b0e120c79d2194fc167b05ec04ec63573b19461f0eda04e2090f87dfa62c4c3/work"
            },
            "Name": "overlay2"
        },
        "RootFS": {
            "Type": "layers",
            "Layers": [
                "sha256:1b3ee35aacca9866b01dd96e870136266bde18006ac2f0d6eb706c798d1fa3c3"
            ]
        },
# ll /var/lib/docker/overlay2/
total 40
drwx------ 3 root root  4096 Jan 12 18:37 3b0e120c79d2194fc167b05ec04ec63573b19461f0eda04e2090f87dfa62c4c3       # alpine 基础层
drwx------ 2 root root 32768 Jan 12 20:29 l
# du -sh /var/lib/docker/overlay2/3b0e120c79d2194fc167b05ec04ec63573b19461f0eda04e2090f87dfa62c4c3
5.9M   /var/lib/docker/overlay2/3b0e120c79d2194fc167b05ec04ec63573b19461f0eda04e2090f87dfa62c4c3

测试用例说明

这里涉及 2 个文件,一个是 Dockerfile 本身,另外一个就是我们需要构建的二进制可执行文件:

# ll
total 68416
-rw-r--r-- 1 root root      114 Jan 12 18:26 Dockerfile
-rwxr-xr-x 1 root root 70045960 Jan  8 18:35 server

示例 1

正确的构建方式,在构建镜像的机器上确保二进制可执行文件已经被赋予 +x 权限

# vi Dockerfile
FROM alpine:3.10

WORKDIR /app

COPY server /app/server

RUN apk add ca-certificates --no-cache

CMD ["./server"]
# chmod +x server
# docker build -t test:v1.1 .

查看镜像多了 2 层,分别是 COPY 和 RUN 指令导致的 70MB 和 548kB:

# docker history test:v1.1
IMAGE               CREATED             CREATED BY                                      SIZE                COMMENT
c07147a61fe1        4 minutes ago       /bin/sh -c #(nop)  CMD ["./server"]             0B                  
f25b9fbccab9        4 minutes ago       /bin/sh -c apk add ca-certificates --no-cache   548kB               
94f9882d94a6        5 minutes ago       /bin/sh -c #(nop) COPY file:12538126de007281…   70MB                
ab6e817176dd        5 minutes ago       /bin/sh -c #(nop) WORKDIR /app                  0B                  
be4e4bea2c2e        8 months ago        /bin/sh -c #(nop)  CMD ["/bin/sh"]              0B                  
<missing>           8 months ago        /bin/sh -c #(nop) ADD file:66a440394c2442570…   5.58MB              

查看镜像信息,发现总计 4 层,比之前多了 3 层:

# docker image inspect test:v1.1
        "GraphDriver": {
            "Data": {
                "LowerDir": "/var/lib/docker/overlay2/4e220bffb2bf1c0c98dd6e66d69a2f8a5437e00381da2215726a9975f5f25136/diff:/var/lib/docker/overlay2/1dfb6f9dd4043d614d9045e39ffde626a88744a1f1c21b8c5f362f870cfce2e3/diff:/var/lib/docker/overlay2/3b0e120c79d2194fc167b05ec04ec63573b19461f0eda04e2090f87dfa62c4c3/diff",
                "MergedDir": "/var/lib/docker/overlay2/39bf6fd694c9491ea68bc2aaa4ab3676deaa2297c9926cf89f5aed27bd3138bd/merged",
                "UpperDir": "/var/lib/docker/overlay2/39bf6fd694c9491ea68bc2aaa4ab3676deaa2297c9926cf89f5aed27bd3138bd/diff",
                "WorkDir": "/var/lib/docker/overlay2/39bf6fd694c9491ea68bc2aaa4ab3676deaa2297c9926cf89f5aed27bd3138bd/work"
            },
            "Name": "overlay2"
        },
        "RootFS": {
            "Type": "layers",
            "Layers": [
                "sha256:1b3ee35aacca9866b01dd96e870136266bde18006ac2f0d6eb706c798d1fa3c3",
                "sha256:f664359f2a96e588b77c41928cf846b2622a1eed588fc990a64a415db017def0",
                "sha256:1ae82946dc8868321b54e184e2dbdc2d6039afe8451695043e09143a3c2644ef",
                "sha256:c539a2477f1cfd06c08816d7738d3ee27cd94777c3ad259cddad552cd5b2d82d"
            ]
        },

为什么会多出一层呢?

# ll /var/lib/docker/overlay2
total 52
drwx------ 4 root root  4096 Jan 12 20:33 1dfb6f9dd4043d614d9045e39ffde626a88744a1f1c21b8c5f362f870cfce2e3    # WORKDIR 创建的 /app 文件夹层
drwx------ 4 root root  4096 Jan 12 20:34 39bf6fd694c9491ea68bc2aaa4ab3676deaa2297c9926cf89f5aed27bd3138bd    # 安装 ca-certificates 层
drwx------ 3 root root  4096 Jan 12 18:37 3b0e120c79d2194fc167b05ec04ec63573b19461f0eda04e2090f87dfa62c4c3    # alpine 基础层
drwx------ 4 root root  4096 Jan 12 20:33 4e220bffb2bf1c0c98dd6e66d69a2f8a5437e00381da2215726a9975f5f25136    # server 二进制可执行文件层
drwx------ 2 root root 32768 Jan 12 20:34 l

通过 du 查看下大小情况:

# du -sh /var/lib/docker/overlay2/* |column -t
24K   /var/lib/docker/overlay2/1dfb6f9dd4043d614d9045e39ffde626a88744a1f1c21b8c5f362f870cfce2e3
1.6M  /var/lib/docker/overlay2/39bf6fd694c9491ea68bc2aaa4ab3676deaa2297c9926cf89f5aed27bd3138bd
5.9M  /var/lib/docker/overlay2/3b0e120c79d2194fc167b05ec04ec63573b19461f0eda04e2090f87dfa62c4c3
67M   /var/lib/docker/overlay2/4e220bffb2bf1c0c98dd6e66d69a2f8a5437e00381da2215726a9975f5f25136
52K   /var/lib/docker/overlay2/l

通过上面信息,我们可以猜测到:

  1. 第一行的 24K 就是莫名多出来的那个层,查看信息发现是 WORKDIR 创建了一个目录导致增了的层
# tree /var/lib/docker/overlay2/1dfb6f9dd4043d614d9045e39ffde626a88744a1f1c21b8c5f362f870cfce2e3/diff/
/var/lib/docker/overlay2/1dfb6f9dd4043d614d9045e39ffde626a88744a1f1c21b8c5f362f870cfce2e3/diff/
`-- app

1 directory, 0 files
  1. 第二行就是安装 ca-certificates 包导致的
  2. 第三行就是 alpine 镜像本身的那个 ADD
  3. 第四行就是我们的 server 二进制可执行文件
# ls -lh /var/lib/docker/overlay2/4e220bffb2bf1c0c98dd6e66d69a2f8a5437e00381da2215726a9975f5f25136/diff/app/ 
total 67M
-rwxr-xr-x 1 root root 67M Jan  8 18:35 server

示例 2

增加一条 ls 指令

# vi Dockerfile 
FROM alpine:3.10

WORKDIR /app

COPY server /app/server

RUN apk add ca-certificates --no-cache

RUN ls /app/server

CMD ["./server"]
# docker build -t test:v1.2 .
# docker history test:v1.2
IMAGE               CREATED              CREATED BY                                      SIZE                COMMENT
8fcdc8d7dd5e        About a minute ago   /bin/sh -c #(nop)  CMD ["./server"]             0B                  
76bd2b605692        About a minute ago   /bin/sh -c ls /app/server                       0B                  
f25b9fbccab9        29 minutes ago       /bin/sh -c apk add ca-certificates --no-cache   548kB               
94f9882d94a6        30 minutes ago       /bin/sh -c #(nop) COPY file:12538126de007281…   70MB                
ab6e817176dd        30 minutes ago       /bin/sh -c #(nop) WORKDIR /app                  0B                  
be4e4bea2c2e        8 months ago         /bin/sh -c #(nop)  CMD ["/bin/sh"]              0B                  
<missing>           8 months ago         /bin/sh -c #(nop) ADD file:66a440394c2442570…   5.58MB              

从层信息看跟示例 1 一致:

# docker image inspect test:v1.2 
        "GraphDriver": {
            "Data": {
                "LowerDir": "/var/lib/docker/overlay2/4e220bffb2bf1c0c98dd6e66d69a2f8a5437e00381da2215726a9975f5f25136/diff:/var/lib/docker/overlay2/1dfb6f9dd4043d614d9045e39ffde626a88744a1f1c21b8c5f362f870cfce2e3/diff:/var/lib/docker/overlay2/3b0e120c79d2194fc167b05ec04ec63573b19461f0eda04e2090f87dfa62c4c3/diff",
                "MergedDir": "/var/lib/docker/overlay2/39bf6fd694c9491ea68bc2aaa4ab3676deaa2297c9926cf89f5aed27bd3138bd/merged",
                "UpperDir": "/var/lib/docker/overlay2/39bf6fd694c9491ea68bc2aaa4ab3676deaa2297c9926cf89f5aed27bd3138bd/diff",
                "WorkDir": "/var/lib/docker/overlay2/39bf6fd694c9491ea68bc2aaa4ab3676deaa2297c9926cf89f5aed27bd3138bd/work"
            },
            "Name": "overlay2"
        },
        "RootFS": {
            "Type": "layers",
            "Layers": [
                "sha256:1b3ee35aacca9866b01dd96e870136266bde18006ac2f0d6eb706c798d1fa3c3",
                "sha256:f664359f2a96e588b77c41928cf846b2622a1eed588fc990a64a415db017def0",
                "sha256:1ae82946dc8868321b54e184e2dbdc2d6039afe8451695043e09143a3c2644ef",
                "sha256:c539a2477f1cfd06c08816d7738d3ee27cd94777c3ad259cddad552cd5b2d82d"
            ]
        },

增加的 ls 指令并没有产生新的文件目录:

# du -sh /var/lib/docker/overlay2/* |column -t
24K   /var/lib/docker/overlay2/1dfb6f9dd4043d614d9045e39ffde626a88744a1f1c21b8c5f362f870cfce2e3        # WORKDIR 创建的 /app 文件夹层
1.6M  /var/lib/docker/overlay2/39bf6fd694c9491ea68bc2aaa4ab3676deaa2297c9926cf89f5aed27bd3138bd        # 安装 ca-certificates 层
5.9M  /var/lib/docker/overlay2/3b0e120c79d2194fc167b05ec04ec63573b19461f0eda04e2090f87dfa62c4c3        # alpine 基础层
67M   /var/lib/docker/overlay2/4e220bffb2bf1c0c98dd6e66d69a2f8a5437e00381da2215726a9975f5f25136        # server 二进制可执行文件层
60K   /var/lib/docker/overlay2/l

示例 3

在这里多了一条修改权限的 chmod 指令:

# vi Dockerfile
FROM alpine:3.10

WORKDIR /app

COPY server /app/server

RUN apk add ca-certificates --no-cache 
RUN chmod +x /app/server

CMD ["./server"]
# docker build -t test:v1.3 .

这次构建的镜像因为写时拷贝而变大了,糟糕,额外多了 70MB,这正好是跟 COPY 的二进制可执行文件大小一致:

# docker history test:v1.3
IMAGE               CREATED             CREATED BY                                      SIZE                COMMENT
8b232f3a584d        13 seconds ago      /bin/sh -c #(nop)  CMD ["./server"]             0B                  
4c39eecac053        13 seconds ago      /bin/sh -c chmod +x /app/server                 70MB                
f25b9fbccab9        3 minutes ago       /bin/sh -c apk add ca-certificates --no-cache   548kB               
94f9882d94a6        4 minutes ago       /bin/sh -c #(nop) COPY file:12538126de007281…   70MB                
ab6e817176dd        4 minutes ago       /bin/sh -c #(nop) WORKDIR /app                  0B                  
be4e4bea2c2e        8 months ago        /bin/sh -c #(nop)  CMD ["/bin/sh"]              0B                  
<missing>           8 months ago        /bin/sh -c #(nop) ADD file:66a440394c2442570…   5.58MB              

这会导致我的镜像变大吗?
查看镜像的层信息,发现总计 5 层,比示例 1 多了 1 层,貌似确实是变大了
但是仔细看发现其中有 2 层:1ae82946dc8868321b54e184e2dbdc2d6039afe8451695043e09143a3c2644ef 是重复的,他们可以底层复用?会不会额外占用一份数据?虚惊一场?
注意:这里镜像的 sha256 是基于文件内容来计算的,所以 COPY server 和 RUN chmod 指令结束后,对应的内容并没有改变,完全一致,所以 sha256 值也是一样的

# docker image inspect test:v1.3
        "GraphDriver": {
            "Data": {
                "LowerDir": "/var/lib/docker/overlay2/39bf6fd694c9491ea68bc2aaa4ab3676deaa2297c9926cf89f5aed27bd3138bd/diff:/var/lib/docker/overlay2/4e220bffb2bf1c0c98dd6e66d69a2f8a5437e00381da2215726a9975f5f25136/diff:/var/lib/docker/overlay2/1dfb6f9dd4043d614d9045e39ffde626a88744a1f1c21b8c5f362f870cfce2e3/diff:/var/lib/docker/overlay2/3b0e120c79d2194fc167b05ec04ec63573b19461f0eda04e2090f87dfa62c4c3/diff",
                "MergedDir": "/var/lib/docker/overlay2/473d7fbaa49a570089e7050846448830613565ad74f24c165a2c0ab1fb2da13f/merged",
                "UpperDir": "/var/lib/docker/overlay2/473d7fbaa49a570089e7050846448830613565ad74f24c165a2c0ab1fb2da13f/diff",
                "WorkDir": "/var/lib/docker/overlay2/473d7fbaa49a570089e7050846448830613565ad74f24c165a2c0ab1fb2da13f/work"
            },
            "Name": "overlay2"
        },
        "RootFS": {
            "Type": "layers",
            "Layers": [
                "sha256:1b3ee35aacca9866b01dd96e870136266bde18006ac2f0d6eb706c798d1fa3c3",
                "sha256:f664359f2a96e588b77c41928cf846b2622a1eed588fc990a64a415db017def0",
                "sha256:1ae82946dc8868321b54e184e2dbdc2d6039afe8451695043e09143a3c2644ef",
                "sha256:c539a2477f1cfd06c08816d7738d3ee27cd94777c3ad259cddad552cd5b2d82d",
                "sha256:1ae82946dc8868321b54e184e2dbdc2d6039afe8451695043e09143a3c2644ef"
            ]
        },

查看文件系统,发现多了一个 473d7fbaa49a570089e7050846448830613565ad74f24c165a2c0ab1fb2da13f 目录,该目录大小 67M,显然数据已经多出了一份,镜像大小还是被增加了:

# du -sh /var/lib/docker/overlay2/* |column -t
24K   /var/lib/docker/overlay2/1dfb6f9dd4043d614d9045e39ffde626a88744a1f1c21b8c5f362f870cfce2e3    # WORKDIR 创建的 /app 文件夹层
1.6M  /var/lib/docker/overlay2/39bf6fd694c9491ea68bc2aaa4ab3676deaa2297c9926cf89f5aed27bd3138bd    # 安装 ca-certificates 层
5.9M  /var/lib/docker/overlay2/3b0e120c79d2194fc167b05ec04ec63573b19461f0eda04e2090f87dfa62c4c3    # alpine 基础层
67M   /var/lib/docker/overlay2/473d7fbaa49a570089e7050846448830613565ad74f24c165a2c0ab1fb2da13f    # 示例 2 出现的层
67M   /var/lib/docker/overlay2/4e220bffb2bf1c0c98dd6e66d69a2f8a5437e00381da2215726a9975f5f25136    # server 二进制可执行文件层
56K   /var/lib/docker/overlay2/l

示例 4

我们稍微修改下 chmod 指令的位置,放到另外一个 RUN 指令中去:

# vi Dockerfile
FROM alpine:3.10

WORKDIR /app

COPY server /app/server

RUN apk add ca-certificates --no-cache \
    && chmod +x /app/server

CMD ["./server"]
# docker build -t test:v1.4 .

查看镜像信息,这次是 70.6MB:

# docker history test:v1.4
IMAGE               CREATED             CREATED BY                                      SIZE                COMMENT
873246df9fb4        10 seconds ago      /bin/sh -c #(nop)  CMD ["./server"]             0B                  
40ee884bc4b3        10 seconds ago      /bin/sh -c apk add ca-certificates --no-cach…   70.6MB              
94f9882d94a6        13 minutes ago      /bin/sh -c #(nop) COPY file:12538126de007281…   70MB                
ab6e817176dd        13 minutes ago      /bin/sh -c #(nop) WORKDIR /app                  0B                  
be4e4bea2c2e        8 months ago        /bin/sh -c #(nop)  CMD ["/bin/sh"]              0B                  
<missing>           8 months ago        /bin/sh -c #(nop) ADD file:66a440394c2442570…   5.58MB              

继续查看层信息,总计 4 层,和示例 1 一致:

# docker image inspect test:v1.4
        "GraphDriver": {
            "Data": {
                "LowerDir": "/var/lib/docker/overlay2/4e220bffb2bf1c0c98dd6e66d69a2f8a5437e00381da2215726a9975f5f25136/diff:/var/lib/docker/overlay2/1dfb6f9dd4043d614d9045e39ffde626a88744a1f1c21b8c5f362f870cfce2e3/diff:/var/lib/docker/overlay2/3b0e120c79d2194fc167b05ec04ec63573b19461f0eda04e2090f87dfa62c4c3/diff",
                "MergedDir": "/var/lib/docker/overlay2/89019296250e362e9de41e672181be98c853e85bb15c9018aa5272c596c3b6a8/merged",
                "UpperDir": "/var/lib/docker/overlay2/89019296250e362e9de41e672181be98c853e85bb15c9018aa5272c596c3b6a8/diff",
                "WorkDir": "/var/lib/docker/overlay2/89019296250e362e9de41e672181be98c853e85bb15c9018aa5272c596c3b6a8/work"
            },
            "Name": "overlay2"
        },
        "RootFS": {
            "Type": "layers",
            "Layers": [
                "sha256:1b3ee35aacca9866b01dd96e870136266bde18006ac2f0d6eb706c798d1fa3c3",
                "sha256:f664359f2a96e588b77c41928cf846b2622a1eed588fc990a64a415db017def0",
                "sha256:1ae82946dc8868321b54e184e2dbdc2d6039afe8451695043e09143a3c2644ef",
                "sha256:4fd98e3a9f49d0ef2bfb2ce5f910c3e1f9a4e9a95e44116a1b97ff8fb4081eef"
            ]
        },

查看文件系统这里确实多了一个 69M 的文件夹,这仍然导致镜像实际真的翻倍了:

# du -sh /var/lib/docker/overlay2/* |column -t
24K   /var/lib/docker/overlay2/1dfb6f9dd4043d614d9045e39ffde626a88744a1f1c21b8c5f362f870cfce2e3    # WORKDIR 创建的 /app 文件夹层
1.6M  /var/lib/docker/overlay2/39bf6fd694c9491ea68bc2aaa4ab3676deaa2297c9926cf89f5aed27bd3138bd    # 安装 ca-certificates 层
5.9M  /var/lib/docker/overlay2/3b0e120c79d2194fc167b05ec04ec63573b19461f0eda04e2090f87dfa62c4c3    # alpine 基础层
67M   /var/lib/docker/overlay2/473d7fbaa49a570089e7050846448830613565ad74f24c165a2c0ab1fb2da13f    # 示例 2 出现的层
67M   /var/lib/docker/overlay2/4e220bffb2bf1c0c98dd6e66d69a2f8a5437e00381da2215726a9975f5f25136    # server 二进制可执行文件层
69M   /var/lib/docker/overlay2/89019296250e362e9de41e672181be98c853e85bb15c9018aa5272c596c3b6a8    # 示例 3 出现的层
60K   /var/lib/docker/overlay2/l
# ll /var/lib/docker/overlay2/89019296250e362e9de41e672181be98c853e85bb15c9018aa5272c596c3b6a8/diff/
total 20
drwxr-xr-x 2 root root 4096 Jan 12 20:33 app
drwxr-xr-x 5 root root 4096 Jan 12 20:46 etc
drwxr-xr-x 3 root root 4096 Apr 23  2020 lib
drwxr-xr-x 6 root root 4096 Apr 23  2020 usr
drwxr-xr-x 3 root root 4096 Apr 23  2020 var

总结

在构建镜像的时候,我们需要慎重处理 chmod 指令,当然或许可以延伸到一些遍历读取、修改的指令上,这有可能会导致镜像体积的变化。

上一篇下一篇

猜你喜欢

热点阅读