Build with setup-buildx-action@v4 + bake-action@v7 uses remote git context -> Git LFS pointer files in build context
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 48/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Ít trao đổi
- Công nghệ
- docker, github-actions
- Lĩnh vực
- build-system, ci-cd, devops
Hướng nghiên cứu
Bắt đầu với .github/workflows/smoke-test.yml và so sánh các cấu hình setup-buildx-action@v3/bake-action@v5 và @v4/@v7, đặc biệt là context của thư mục con. Xem lại các dòng Dockerfile sao chép và xác thực docker/akeeba-backup.zip, sau đó tái hiện bằng actions/checkout@v6 với Git LFS được bật. Hoàn tất nghĩa là hành vi của local context được sửa hoặc được ghi rõ trong tài liệu, và build không còn nhận một LFS pointer.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Environment
- Repository using workflow: https://github.com/zeckson/mykapitel.ru (workflow path: .github/workflows/smoke-test.yml)
- GitHub Actions run: https://github.com/zeckson/mykapitel.ru/actions/runs/30447565481
- Workflow uses: actions/checkout@v6 (with lfs: true), docker/setup-buildx-action@v4, docker/bake-action@v7
- Works with older actions: setup-buildx-action@v3 + bake-action@v5
What happens
- When building with setup-buildx-action@v4 + bake-action@v7 and a build context that points to a subdirectory (./docker) containing a Git LFS-tracked file (docker/akeeba-backup.zip), BuildKit resolves that context as a remote git checkout and does not apply Git LFS smudge filters.
- The file seen inside the build context is a Git LFS pointer (contains the text "version https://git-lfs.github.com/spec/v1"), and the Dockerfile in this project intentionally rejects pointer files, causing the build to fail.
Failure log excerpt
- Error: akeeba-backup.zip is a Git LFS pointer, not the actual file.
- Dockerfile lines involved:
COPY docker/akeeba-backup.zip /tmp/backup.zip
RUN if grep -q "version https://git-lfs.github.com/spec/v1" /tmp/backup.zip; then echo "Error: akeeba-backup.zip is a Git LFS pointer, not the actual file." && exit 1; fi && unzip -t /tmp/backup.zip && unzip /tmp/backup.zip -d /app && rm /tmp/backup.zip
Reproduction steps
- actions/checkout@v6 with lfs: true is used in the workflow so the runner workspace contains the smudged LFS file after checkout and (optionally) git lfs pull.
- The workflow then sets up buildx using docker/setup-buildx-action@v4 and invokes docker/bake-action@v7 with a context set to the docker/ subdirectory (or similar subdir context).
- BuildKit/bake resolves the subdirectory context via a remote git fetch which returns raw pointer file(s) and the build fails when the Dockerfile detects the pointer.
Expected
- When the runner workspace already has LFS objects checked out (actions/checkout + git lfs pull), bake/buildx should be able to use the smudged local files when the workflow requests a local workspace context, or at minimum there should be a clear way to force local context usage so builds don’t inadvertently use remote git checkouts that skip smudge filters.
- Behavior observed with setup-buildx@v3 + bake-action@v5: build used local workspace context (or LFS smudged files) and succeeded.
Notes and suggestions
- This appears to be related to how bake/buildx resolves subdirectory contexts — resolving them as remote git contexts causes LFS smudge filters to be bypassed, exposing pointer files to the build.
- Possible mitigation in workflows: explicitly force bake to use the local workspace context (e.g. *.context=./) and ensure git lfs pull runs on the runner before bake. But the action should either document this nuance or provide an option to prefer the runner workspace/local context when available.
Attachments / additional info
- Full failing run: https://github.com/zeckson/mykapitel.ru/actions/runs/30447565481 (logs are attached to that run)
Please let me know if you want me to open a minimal repro PR; I can also provide the exact workflow file and Dockerfile used in the failing run.
- Ngôn ngữ chính
- TypeScript
- Star
- 303
- Fork
- 43
- Merge trung bình
- 1 ngày 15 giờ
- Pull request đã merge (30 ngày)
- 19
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Không có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của docker/bake-action
-
Add support for dockerignoreĐang mởkind/enhancement status/triage
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 52/100
docker/bake-action#458 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
[subaction/matrix] Generate multiple matrices when targets reference other targets as build contextsĐang mởkind/enhancement
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 48/100
docker/bake-action#435 · 2 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
status/triage
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 25/100
docker/bake-action#329 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
status/triage
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 35/100
docker/bake-action#322 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
status/needs-more-info
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 25/100
docker/bake-action#312 · 2 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của docker/bake-action
Issue tương tự
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 78/100
lichess-org/api#678 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
PostHog/posthog.com#20628 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug status:Needs Triage
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 92/100
jupyterlab/jupyterlab#19964 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
agentscope-ai/QwenPaw#8064 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
area: notebooks-jupyter bug theme: new notebook frontend
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
posit-dev/positron#16347 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày