Conversation
Adds DockerAssetBuilder.BUILDKIT to AwsAssetManagerOptions. When selected, addDockerImageAsset emits one buildkit_image resource plus a provider "buildkit" pinned to cruxstack/buildkit 0.0.1, instead of kreuzwerker's docker_image + docker_registry_image. Motivation: kreuzwerker/docker needs a Docker Engine to build (exportLoad) and push (client.ImagePush), which a daemonless TACOS host (Atlantis, no root-equivalent socket) cannot provide. buildkit_image solves and pushes directly against a reachable rootless buildkitd. buildkit_autodiscover and embedded_buildkitd are hardcoded false (not configurable) as a security control: embedded_buildkitd would let config spawn a private daemon. The cdktn binding in src/aws/private/buildkit-provider.ts is hand-written since no @cdktn/provider-buildkit package is published. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Dgqc87KhZ9EijLMoJ61ZXe
vincenthsh
reviewed
Sep 11, 2026
Merged
7 of 8 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Docker image assets in TerraConstructs are built and pushed via
kreuzwerker/docker'sdocker_image+docker_registry_imageresources. Both need a real Docker Engine:docker_imagebuild hardcodesexportLoad, anddocker_registry_imagepush goes throughclient.ImagePush. That's a non-starter on a TACOS (Terraform-as-CI/CD-on-a-server) host suchas Atlantis that intentionally has no Docker daemon and no root-equivalent socket — a
daemon or
docker.sockaccess is effectively root on the host, which a public-facingautomation server shouldn't carry, and
local-exec/provisioners are equally unwelcome there.Design
Adds an opt-in
DockerAssetBuilder.BUILDKITtoAwsAssetManagerOptions. When selected,addDockerImageAssetemits a singlebuildkit_imageresource (providercruxstack/buildkit,pinned to exactly
0.0.1) instead ofdocker_image+docker_registry_image. It solves andpushes the image by talking directly to a reachable buildkitd over gRPC — no Docker Engine
API involved.
The
provider "buildkit"block is minimal and non-configurable beyond the daemon address:buildkit_address— where to dial (buildkitAddressprop, defaultunix:///run/buildkit/buildkitd.sock).buildkit_autodiscover = falseandembedded_buildkitd = false— hardcoded, not exposedas options.
autodiscoverwould let the provider probe for and use an arbitrary daemon onthe host;
embedded_buildkitd = truelets the provider download and spawn its own privatebuildkitd process. Either defeats the point of pointing Terraform at one operator-managed,
already-hardened daemon, so both are forced off rather than left as knobs a stack author
could flip.
~/.docker/config.jsoncredHelpers(e.g.ecr-login) on the host running buildkitd — no credentials pass through Terraform state.The default builder (
docker/kreuzwerker) is unchanged; this is additive and opt-in.src/aws/private/buildkit-provider.tsis a small hand-writtencdktnbinding forbuildkit_image/provider "buildkit", since no@cdktn/provider-buildkitpackage ispublished (see Caveats).
Validation
Ran as part of a separate infrastructure spike into daemonless Docker asset builders for a
TACOS host. Full environment: Ubuntu 24.04 arm64, rootless
buildkitdv0.33.0 (unix-socket +group-ACL exposure,
insecure-entitlements=[]), pnpm 11.24.0,cdktn0.24.0, Terraform1.15.9. (An earlier cut of the same design was also exercised against TF 1.10-era provider
pins; not claiming that combination was re-verified against this exact code.)
Against a real ECR repository:
buildkit_image.<id>_Buildkit+provider "buildkit"are emitted — zerodocker_image/docker_registry_imageresources.Plan: 1 to add→Apply complete! Resources: 1 added; pushed an arm64image to ECR (verified image architecture + a marker file baked into the image).
No changes), and a re-apply reports0 added, 0 changed.1 to add, 1 to destroy— the asset'scontext hash changes, which is also this resource's
triggers), producing a new digest,then a clean re-plan.
Tests
test/aws/storage/assets/image-asset-buildkit.test.ts: synth asserts the pinnedprovider block, the
buildkit_imageattributes (context, dockerfile, platforms, args,secrets, target, publish, cache_from, triggers) and the
ImageUrioutput expression, plusresourceCountIs= 0 for both kreuzwerker resource types; a missing-platformguard; and aguard rejecting
networkMode/dockerBuildSsh/dockerOutputs, whichbuildkit_imagecan'texpress.
image-asset.test.ts/build-image-cache.test.ts(kreuzwerker path) unchangedand still passing, confirming the default builder is untouched.
jsiicompile clean,eslint --fixclean (no changes),jsii-pacmakpackaging clean, full Jest suite across all 5 CI shards — 255/255 suites, 4548 passed / 54
skipped, 0 failed, no snapshot diffs.
Caveats
cruxstack/buildkitis a young provider (v0.0.1, single vendor). Worth vetting/pinningcarefully before relying on it in production, and revisiting the pin as it matures.
src/aws/private/buildkit-provider.tsis a hand-written binding, not generated bycdktn get, because no published@cdktn/provider-buildkitpackage exists yet. If one appearsupstream, this should be regenerated against it rather than hand-maintained indefinitely.
🤖 Generated with Claude Code
https://claude.ai/code/session_01Dgqc87KhZ9EijLMoJ61ZXe