Skip to content

support BuildKit local output delete mode - #3883

Merged
tonistiigi merged 3 commits into
docker:masterfrom
crazy-max:local-output-delete
Jun 10, 2026
Merged

support BuildKit local output delete mode#3883
tonistiigi merged 3 commits into
docker:masterfrom
crazy-max:local-output-delete

Conversation

@crazy-max

@crazy-max crazy-max commented Jun 3, 2026

Copy link
Copy Markdown
Member

needs moby/buildkit#6561

This PR adds Buildx client-side support for the BuildKit local exporter mode=delete behavior introduced by moby/buildkit#6561. Buildx now passes the local exporter mode through for both build --output and Bake outputs, and it gates deletion of stale local output files behind the Buildx-local --allow=buildx.local.delete entitlement where the destination is potentially dangerous.

The build command now accepts --output=type=local,dest=...,mode=delete and keeps the exporter attribute intact when creating BuildKit export entries. Buildx parses --allow=buildx.local.delete separately from BuildKit entitlements, so the Buildx-local allow is used for client-side validation and is not forwarded to BuildKit as an AllowedEntitlement.

The build command allows mode=delete without an extra allow when the local output destination resolves to a subdirectory of the current working directory. It requires --allow=buildx.local.delete when the destination resolves to the current working directory, outside the current working directory, or through a symlink that escapes the current working directory. This keeps ordinary out or dist usage ergonomic while still making destructive destinations explicit.

Bake now recognizes the same buildx.local.delete entitlement for local outputs that use mode=delete. The Bake entitlement prompt and raw JSON error path both report the Buildx-local allow name, and Bake output definitions and --set output overrides are covered by the same entitlement flow.

Testing on buildx repo with mode=delete for binaries target:

$ docker buildx --builder builder bake binaries-cross --set *.platform=linux/amd64,linux/arm64 --print
#1 [internal] load local bake definitions
#1 reading docker-bake.hcl 4.94kB / 4.94kB done
#1 DONE 0.0s
{
  "group": {
    "default": {
      "targets": [
        "binaries-cross"
      ]
    }
  },
  "target": {
    "binaries-cross": {
      "context": ".",
      "dockerfile": "Dockerfile",
      "args": {
        "BUILDKIT_CONTEXT_KEEP_GIT_DIR": "1"
      },
      "target": "binaries",
      "platforms": [
        "linux/amd64,linux/arm64"
      ],
      "output": [
        {
          "dest": "./bin/build",
          "mode": "delete",
          "type": "local"
        }
      ]
    }
  }
}
$ tree -anh ./bin/build
[4.0K]  ./bin/build
├── [   0]  baz.txt
├── [ 62M]  buildx
├── [4.0K]  linux_amd64
│   └── [ 61M]  buildx
└── [4.0K]  linux_arm64
    └── [ 57M]  buildx

3 directories, 4 files
$ docker buildx --builder builder bake binaries-cross --set *.platform=linux/amd64,linux/arm64
#0 building with "builder" instance using docker-container driver

#1 [internal] load local bake definitions
#1 reading docker-bake.hcl 4.94kB / 4.94kB done
#1 DONE 0.0s
Your build is requesting privileges for following possibly insecure capabilities:

 - Deleting stale files from local output destinations

In order to not see this message in the future pass "--allow=local-output-delete" to grant requested privileges.

Your full command with requested privileges:

docker buildx --builder builder bake --allow=local-output-delete binaries-cross --set *.platform=linux/amd64,linux/arm64

Do you want to grant requested privileges and continue? [y/N] y
#0 building with "builder" instance using docker-container driver

#1 [internal] load build definition from Dockerfile
#1 transferring dockerfile: 6.43kB 0.1s done
#1 DONE 0.1s

...
$ tree -anh ./bin/build
[4.0K]  ./bin/build
├── [4.0K]  linux_amd64
│   └── [ 62M]  buildx
└── [4.0K]  linux_arm64
    └── [ 58M]  buildx

3 directories, 2 file

crazy-max and others added 3 commits June 10, 2026 16:41
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
@crazy-max
crazy-max force-pushed the local-output-delete branch from 9c204bb to b6e1b73 Compare June 10, 2026 14:41
@crazy-max
crazy-max marked this pull request as ready for review June 10, 2026 14:50
Comment thread bake/entitlements.go

func volumeNameLen(s string) int {
return len(filepath.VolumeName(s))
return osutil.EvaluateToExistingPath(in)

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

evaluateToExistingPath is not needed anymore

@tonistiigi
tonistiigi merged commit dd388bf into docker:master Jun 10, 2026
198 of 200 checks passed
@crazy-max
crazy-max deleted the local-output-delete branch June 10, 2026 21:54
eleboucher pushed a commit to eleboucher/runner that referenced this pull request Jul 9, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [buildx](https://github.com/docker/buildx) |  | minor | `v0.34.1` → `v0.35.0` |
| [buildx](https://github.com/docker/buildx) | uses-with | minor | `v0.34.1` → `v0.35.0` |

---

### Release Notes

<details>
<summary>docker/buildx (buildx)</summary>

### [`v0.35.0`](https://github.com/docker/buildx/releases/tag/v0.35.0)

[Compare Source](docker/buildx@v0.34.1...v0.35.0-rc2)

buildx 0.35.0

Welcome to the v0.35.0 release of buildx!

Please try out the release binaries and report any issues at
<https://github.com/docker/buildx/issues>.

##### Contributors

- CrazyMax
- Tõnis Tiigi
- Sebastiaan van Stijn
- Areeb Ahmed
- Jiří Moravčík
- Sopho Merkviladze
- Akihiro Suda
- Jonathan A. Sternberg

##### Notable Changes

- Local output now supports a `mode=delete` attribute for build and bake commands. This mode replaces the destination directory with the build result instead of merging it. Similar to the `--delete` flag in rsync. For safety, this mode is only allowed if the destination directory is a subdirectory of the working directory. To export to other destinations, `--allow=buildx.local.delete` needs to be provided or the action confirmed by the user in the TUI. When exporting multi-platform results, this mode requires BuildKit v0.31.0+. [#&#8203;3883](docker/buildx#3883)
- Source policies now support the new exec proxy feature of BuildKit v0.31.0+ that captures the network traffic of your build steps. To opt in to network proxy, your Dockerfile.rego source policy needs to return `caps: { "exec.proxy": true }` in the evaluation decision. After opting in, you can control what network requests are allowed to be made by the run steps with policy rules for regular `input.http` sources, similar to how this was done for direct HTTP build sources before. You can also opt in your whole builder with `--buildkitd-flags '--proxy-network'` in `buildx create`. [#&#8203;3895](docker/buildx#3895)
- Resource limits can now be set for CPU and memory using the `--resource` flag in `build` and the `resource` key in `bake` commands. This feature requires BuildKit v0.31.0+ and Dockerfile v1.25.0+. [#&#8203;3876](docker/buildx#3876) [#&#8203;3900](docker/buildx#3900)
- Fix possible "closed channel" panic. [#&#8203;3886](docker/buildx#3886)

##### Dependency Changes

- **github.com/aws/aws-sdk-go-v2**                                                  v1.41.7 -> v1.42.0
- **github.com/aws/aws-sdk-go-v2/config**                                           v1.32.17 -> v1.32.24
- **github.com/aws/aws-sdk-go-v2/credentials**                                      v1.19.16 -> v1.19.23
- **github.com/aws/aws-sdk-go-v2/feature/ec2/imds**                                 v1.18.23 -> v1.18.29
- **github.com/aws/aws-sdk-go-v2/internal/configsources**                           v1.4.23 -> v1.4.29
- **github.com/aws/aws-sdk-go-v2/internal/endpoints/v2**                            v2.7.23 -> v2.7.29
- **github.com/aws/aws-sdk-go-v2/internal/v4a**                                     v1.4.24 -> v1.4.30
- **github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding**                 v1.13.9 -> v1.13.12
- **github.com/aws/aws-sdk-go-v2/service/internal/presigned-url**                   v1.13.23 -> v1.13.29
- **github.com/aws/aws-sdk-go-v2/service/signin**                                   v1.0.11 -> v1.1.5
- **github.com/aws/aws-sdk-go-v2/service/sso**                                      v1.30.17 -> v1.31.3
- **github.com/aws/aws-sdk-go-v2/service/ssooidc**                                  v1.35.21 -> v1.36.6
- **github.com/aws/aws-sdk-go-v2/service/sts**                                      v1.42.1 -> v1.43.3
- **github.com/aws/smithy-go**                                                      v1.25.1 -> v1.27.2
- **github.com/containerd/containerd/v2**                                           v2.2.3 -> v2.2.4
- **github.com/containerd/continuity**                                              v0.4.5 -> v0.5.0
- **github.com/containerd/platforms**                                               v1.0.0-rc.2 -> v1.0.0-rc.4
- **github.com/containerd/typeurl/v2**                                              v2.2.3 -> v2.3.0
- **github.com/docker/cli**                                                         v29.4.3 -> v29.5.3
- **github.com/docker/distribution**                                                v2.8.3 ***new***
- **github.com/docker/docker-credential-helpers**                                   v0.9.5 -> v0.9.8
- **github.com/go-openapi/analysis**                                                v0.24.3 -> v0.25.2
- **github.com/go-openapi/jsonpointer**                                             v0.22.5 -> v0.23.1
- **github.com/go-openapi/jsonreference**                                           v0.21.5 -> v0.21.6
- **github.com/go-openapi/runtime**                                                 v0.29.3 -> v0.32.3
- **github.com/go-openapi/runtime/server-middleware**                               v0.30.0 ***new***
- **github.com/go-openapi/spec**                                                    v0.22.4 -> v0.22.5
- **github.com/go-openapi/strfmt**                                                  v0.26.1 -> v0.26.3
- **github.com/go-openapi/swag**                                                    v0.25.5 -> v0.26.0
- **github.com/go-openapi/swag/cmdutils**                                           v0.25.5 -> v0.26.0
- **github.com/go-openapi/swag/conv**                                               v0.25.5 -> v0.26.0
- **github.com/go-openapi/swag/fileutils**                                          v0.25.5 -> v0.26.0
- **github.com/go-openapi/swag/jsonname**                                           v0.25.5 -> v0.26.0
- **github.com/go-openapi/swag/jsonutils**                                          v0.25.5 -> v0.26.0
- **github.com/go-openapi/swag/loading**                                            v0.25.5 -> v0.26.0
- **github.com/go-openapi/swag/mangling**                                           v0.25.5 -> v0.26.0
- **github.com/go-openapi/swag/netutils**                                           v0.25.5 -> v0.26.0
- **github.com/go-openapi/swag/stringutils**                                        v0.25.5 -> v0.26.0
- **github.com/go-openapi/swag/typeutils**                                          v0.25.5 -> v0.26.0
- **github.com/go-openapi/swag/yamlutils**                                          v0.25.5 -> v0.26.0
- **github.com/go-openapi/validate**                                                v0.25.2 -> v0.25.3
- **github.com/google/certificate-transparency-go**                                 v1.3.2 -> v1.3.3
- **github.com/google/go-containerregistry**                                        v0.20.7 -> v0.21.6
- **github.com/gorilla/mux**                                                        v1.8.1 ***new***
- **github.com/grpc-ecosystem/grpc-gateway/v2**                                     v2.28.0 -> v2.29.0
- **github.com/in-toto/attestation**                                                v1.1.2 -> v1.2.0
- **github.com/moby/buildkit**                                                      v0.30.0 -> v0.31.0
- **github.com/moby/policy-helpers**                                                [`a39d601`](docker/buildx@a39d60132186) -> [`d5411a9`](docker/buildx@d5411a945cfc)
- **github.com/moby/sys/sequential**                                                v0.6.0 -> v0.7.0
- **github.com/pelletier/go-toml/v2**                                               v2.2.4 -> v2.3.1
- **github.com/prometheus/common**                                                  v0.66.1 -> v0.67.5
- **github.com/prometheus/procfs**                                                  v0.17.0 -> v0.20.1
- **github.com/secure-systems-lab/go-securesystemslib**                             v0.10.0 -> v0.11.0
- **github.com/sigstore/protobuf-specs**                                            v0.5.0 -> v0.5.1
- **github.com/sigstore/rekor**                                                     v1.5.0 -> v1.5.2
- **github.com/sigstore/rekor-tiles/v2**                                            v2.0.1 -> [`5d098a2`](docker/buildx@5d098a2b6443)
- **github.com/sigstore/sigstore**                                                  v1.10.5 -> v1.10.8
- **github.com/sigstore/sigstore-go**                                               v1.1.4 -> v1.2.1
- **github.com/sigstore/timestamp-authority/v2**                                    v2.0.6 -> v2.1.2
- **github.com/theupdateframework/go-tuf/v2**                                       v2.4.1 -> v2.4.2
- **github.com/tonistiigi/fsutil**                                                  [`a2aa163`](docker/buildx@a2aa163d723f) -> [`0257b33`](docker/buildx@0257b3308df4)
- **github.com/transparency-dev/formats**                                           [`404c0d5`](docker/buildx@404c0d5b696c) -> v0.1.1
- **github.com/youmark/pkcs8**                                                      [`a2c0da2`](docker/buildx@a2c0da244d78) ***new***
- **go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc**   v0.68.0 -> v0.69.0
- **go.opentelemetry.io/contrib/instrumentation/net/http/httptrace/otelhttptrace**  v0.68.0 -> v0.69.0
- **go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp**                 v0.68.0 -> v0.69.0
- **go.opentelemetry.io/otel**                                                      v1.43.0 -> v1.44.0
- **go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc**             v1.43.0 -> v1.44.0
- **go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp**             v1.43.0 -> v1.44.0
- **go.opentelemetry.io/otel/exporters/otlp/otlptrace**                             v1.43.0 -> v1.44.0
- **go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc**               v1.43.0 -> v1.44.0
- **go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp**               v1.43.0 -> v1.44.0
- **go.opentelemetry.io/otel/exporters/stdout/stdouttrace**                         v1.42.0 -> v1.44.0
- **go.opentelemetry.io/otel/metric**                                               v1.43.0 -> v1.44.0
- **go.opentelemetry.io/otel/sdk**                                                  v1.43.0 -> v1.44.0
- **go.opentelemetry.io/otel/sdk/metric**                                           v1.43.0 -> v1.44.0
- **go.opentelemetry.io/otel/trace**                                                v1.43.0 -> v1.44.0
- **go.yaml.in/yaml/v2**                                                            v2.4.3 -> v2.4.4
- **google.golang.org/genproto/googleapis/api**                                     [`6f92a3b`](docker/buildx@6f92a3bedf2d) -> [`3dc84a4`](docker/buildx@3dc84a4a5aaa)
- **google.golang.org/genproto/googleapis/rpc**                                     [`6f92a3b`](docker/buildx@6f92a3bedf2d) -> [`3dc84a4`](docker/buildx@3dc84a4a5aaa)
- **google.golang.org/grpc**                                                        v1.80.0 -> v1.81.1
- **google.golang.org/grpc/cmd/protoc-gen-go-grpc**                                 v1.5.1 -> v1.6.1
- **k8s.io/klog/v2**                                                                v2.130.1 -> v2.140.0

Previous release can be found at [v0.34.1](https://github.com/docker/buildx/releases/tag/v0.34.1)

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)
- Automerge
  - Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about these updates again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNTIuMSIsInVwZGF0ZWRJblZlciI6IjQzLjI1Mi4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJLaW5kL0RlcGVuZGVuY3lVcGRhdGUiLCJydW4tZW5kLXRvLWVuZC10ZXN0cyJdfQ==-->

Reviewed-on: https://code.forgejo.org/forgejo/runner/pulls/1603
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants