docs.rs failed to build oci-builder-0.1.6
Please check the build logs for more information.
See Builds for ideas on how to fix a failed build, or Metadata for how to configure docs.rs builds.
If you believe this is docs.rs' fault, open an issue.
Please check the build logs for more information.
See Builds for ideas on how to fix a failed build, or Metadata for how to configure docs.rs builds.
If you believe this is docs.rs' fault, open an issue.
oci-builder
Rust library (oci_builder) and CLI (oci-builder) that embeds Buildah directly in-process. There is no Buildah daemon and no buildah executable on $PATH.
- Linux: Runs the Buildah engine directly in-process via a statically linked Go C-archive (
-buildmode=c-archive) with priority 101 user namespace setup. - macOS: Runs the engine inside a lightweight Linux guest managed by Apple's Virtualization framework over virtio-vsock.
- Other OSes: Links a lightweight stub returning
ErrorCode::Unsupported.
Installation
Add as a Library Dependency
[]
= "0.1"
Install CLI Binary
Rust Library Usage
[!IMPORTANT] On Linux,
startup()must be called at the very beginning ofmain(), before spawning threads or parsing CLI arguments. Buildah re-executes/proc/self/exefor rootless user namespaces and helper child processes.
use ;
CLI Usage
Check System Prerequisites
Build an Image
Push an Image
policy.json for a local store without remote signature checks:
Build Requirements
- Linux: Go ≥ 1.26, C compiler (
gccorclang),pkg-config, and optionallylibseccomp-dev. - macOS: Built-in Apple Virtualization framework. Codesigning is automatically handled via
.cargo/config.tomlwith thecom.apple.security.virtualizationentitlement.
Limitations
- Process Re-execution Hook: On Linux,
startup()must be the very first instruction inmain(). If invoked after thread creation, async runtime initialization, or argument parsing, Buildah's rootless user namespace helpers and re-exec child dispatches will fail. - Rootless User Namespaces: Building images rootless requires user namespaces (
/proc/sys/kernel/unprivileged_userns_clone = 1or configured/etc/subuidand/etc/subgidranges). - Isolation Dependencies:
chrootisolation supports simple container builds (such asFROM scratchwithCOPY) without external helper binaries.ociandrootlessisolation require an OCI runtime binary (runcorcrun) present on$PATHto executeRUNinstructions.- Builds requiring network access during
RUNinstructions require network helper utilities (netavarkor CNI).
- macOS Guest Ephemeral Storage: On macOS, builds execute inside a managed Linux Virtualization guest. Output artifacts (like pushed
docker-archivetarballs) must target shared virtiofs mount directories to persist onto the macOS host. - Storage Driver in Nested Environments: When running inside an existing Docker or container environment that lacks nested overlayfs kernel support, the
vfsstorage driver must be selected (--storage-driver vfs). - Platform Support: Fully supported on Linux and macOS (Apple Silicon and x86_64). Other operating systems link a stub implementation that returns
ErrorCode::Unsupported.