Skip to content

fix: drop docker/docker and bump buildkit to v0.31.2 via the kaniko fork - #535

Open
stirby wants to merge 2 commits into
mainfrom
stirby/kaniko-moby
Open

stirby wants to merge 2 commits into
mainfrom
stirby/kaniko-moby

Conversation

@stirby

@stirby stirby commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Pins the kaniko fork to coder/kaniko#38, which drops github.com/docker/docker and the chrismellard ACR helper and bumps buildkit to v0.31.2. This fixes the remaining reachable advisories in envbuilder.

Generated by Coder Agents on behalf of @stirby.

Depends on coder/kaniko#38. The replace points at 61a5b7da on that PR. Later commits there only change CI and integration fixtures, not Go code. Re-pin to the merge commit once #38 lands.

Test template on dogfood, which builds envbuilder from this branch: https://dogfood.cdr.dev/templates/coder/kirby-envbuilder-rollup

Advisories

govulncheck ./... (reachable):

main (a5b7329) this branch
GO-2026-4858, GO-2026-4859, GO-2026-6255 (moby/buildkit) affected fixed (v0.31.2)
GO-2026-4883, GO-2026-4887 (docker/docker) affected fixed (removed from kaniko)
GO-2026-6253 (moby/go-archive) affected fixed (v0.3.3)
GO-2026-6225 (chrismellard/docker-credential-acr-env) affected fixed (ported with anchored host check)
Total 7 0
  • Binary scan: govulncheck -mode=binary on cmd/envbuilder reports only GO-2026-6443 (grpc). grpc is intentionally left alone in this PR.
  • What's not in the binary: docker/docker, the moby/moby monolith and chrismellard.
  • What module-level scanners will still flag: docker/docker and moby/moby stay in go.mod as the Docker client for ./integration tests only. Also x/crypto openpgp and dhcp findings, which are unreachable.

Changes

  • kaniko fork re-pinned: buildkit v0.16.0 → v0.31.2, go-containerregistry v0.20.7 → v0.21.7, go-archive v0.1.0 → v0.3.3. The rest are tidy fallout.
  • devcontainer.UserFromDockerfile: passes a buildkit linter to ParseInstructionWithLinter. Without one, buildkit v0.31 panics on Dockerfiles with # check= directives. Test: TestUserFromDockerfile_BuildArgs/LintCheckComment.
  • features.Extract: now closes the feature layer reader. go-containerregistry v0.21 holds a pull slot until the reader is closed.

Behavior changes

  • Unsupported Dockerfile flags: kaniko now fails COPY/ADD --exclude, COPY --parents, ADD --unpack, RUN --security=insecure and RUN --device with "not supported by kaniko". 1.3.0 also failed on these, as unknown flags.
  • *.local registries: go-containerregistry v0.21 no longer falls back to plain HTTP for them. Only localhost, *.localhost and loopback IPs fall back. Plain-HTTP in-cluster registries (for example registry.ns.svc.cluster.local:5000) need ENVBUILDER_INSECURE=true.
  • Private IP literals: go-containerregistry v0.21 rejects token realms, blob redirects and upload locations pointing at a different private IP literal.
  • Registry retries: backoff is now 1s/3s/9s, and 429 responses are retried, so a failing registry takes longer to error out.

Validation

  • make test passes (all 36 integration tests, 0 skipped), as do make lint, make fmt and make gen (no diff).
  • Local e2e with an image built from this commit:
    • The coder/coder main devcontainer (64-layer base image) builds to INIT. An earlier pin of this branch deadlocked at layer 5 (go-containerregistry pull limiter, fixed in kaniko#38).
    • A multi-stage Dockerfile with FROM <stage> and COPY --from=golang:1.25-bookworm builds. The earlier pin deadlocked in "Storing source image".
    • A # check= Dockerfile builds. COPY --exclude fails with the new error, and a plain Dockerfile builds.
  • Dogfood: workspace envbuilder-rollup-main on the test template builds coder/coder main. The agent is ready, /.envbuilder/built exists, and code-server returns healthy. The binary reports vcs.revision=9e64f32, coder/kaniko 61a5b7da and go-containerregistry v0.21.7.
  • kaniko#38 CI: all green, including the k3s integration tests.
  • Terraform provider: chore: bump envbuilder and kaniko to drop docker/docker and update buildkit terraform-provider-envbuilder#138 mirrors this pin (it copies envbuilder's replace directives) and its acceptance tests pass.
Decision log
  • docker/docker: it has no fixed release. The moby fixes exist only in github.com/moby/moby/v2 betas, so kaniko ports the few helpers it used instead of upgrading.
  • chrismellard: the module has no fix and is unmaintained, so it was ported into kaniko with an anchored hostname regex.
  • go-containerregistry v0.21.7, not v0.21.6: v0.21.6 tarball.Write leaks pull slots and hangs multi-stage builds. A subagent review of the v0.19 → v0.21 diff found it, and it was reproduced locally.
  • .local HTTP fallback documented, not shimmed: it is an upstream security hardening. ENVBUILDER_INSECURE covers kaniko pulls, pushes and the cache repo. It does not cover envbuilder's own devcontainer image config and feature fetches, which never honored it.
  • Out of scope: grpc (GO-2026-6443) and moving ./integration off docker/docker.

stirby added 2 commits October 8, 2026 17:08
Pins coder/kaniko to 8e293b69, which removes github.com/docker/docker,
bumps buildkit to v0.31.2 and go-archive to v0.3.3, and vendors a fixed
ACR credential helper. Fixes GO-2026-4858, GO-2026-4859, GO-2026-6255,
GO-2026-6253, GO-2026-6225, and removes docker/docker (GO-2026-4883,
GO-2026-4887) from the envbuilder binary.

Parse Dockerfiles with an initialized linter: buildkit v0.31 applies
"# check=" comments to the linter and panicked with a nil one.
…v0.21.7

go-containerregistry v0.21 holds a pull limiter slot per open remote blob
reader. The previous kaniko pin deadlocked extracting base images with more
than four layers, and v0.21.6 tarball.Write hangs the same way.

Also close the devcontainer feature layer reader.
Comment thread go.mod
// There are a few options we need added to Kaniko!
// See: https://github.com/GoogleContainerTools/kaniko/compare/main...coder:kaniko:main
replace github.com/GoogleContainerTools/kaniko => github.com/coder/kaniko v0.0.0-20251107135632-b20ff58093d8
replace github.com/GoogleContainerTools/kaniko => github.com/coder/kaniko v0.0.0-20261008191411-61a5b7da7ea3

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The pin points at an unmerged commit(v0.0.0-20261008191411-61a5b7da7ea3) - needs re-pined after merged and make sure coder/kaniko#38 is merged first 

@Lisa-Fiander Lisa-Fiander left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

few small comments

Comment thread go.mod
@@ -6,7 +6,7 @@ toolchain go1.26.6

// There are a few options we need added to Kaniko!

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not caused by this PR, but advisories published yesterday now flag toolchain go1.26.6 (12 reachable stdlib advisories, fixed in 1.26.9) and golang.org/x/net v0.58.0 (fixed in v0.60.0). Worth bumping both here or in a quick follow-up.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants