-
Notifications
You must be signed in to change notification settings - Fork 23
Expand file tree
/
Copy pathbuildkitd.toml
More file actions
74 lines (63 loc) · 2.13 KB
/
Copy pathbuildkitd.toml
File metadata and controls
74 lines (63 loc) · 2.13 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
# BuildKit configuration for kali-builder
# Enables automatic cache invalidation when Dockerfile or base images change
debug = false
[worker.oci]
enabled = true
# Enable garbage collection
gc = true
# Cache storage limits - increased for stable single-run builds
reservedSpace = "25GB"
maxUsedSpace = "90GB"
minFreeSpace = "30GB"
# Reduce parallelism for stability and SBOM generation
max-parallelism = 1
# Registry configuration for insecure HTTP registry
[registry."kali-cache-registry:5000"]
http = true
insecure = true
# SBOM scanner configuration for stability
[worker.oci.attestations]
# Conservative timeout for SBOM generation
timeout = "60m"
memory = "3GB"
# Specific SBOM scanner settings with aggressive memory limits
[scanner."docker.io/docker/buildkit-syft-scanner:stable-1"]
timeout = "60m"
memory = "3GB"
# Strict resource limits for container
limits = { memory = "3GB", cpus = "3.0" }
# Environment variables for syft stability and aggressive memory control
env = [
"SYFT_LOG_LEVEL=warn",
"SYFT_FAIL_ON_ERROR=false",
"SYFT_PYTHON_CATALOGER_GUESS_UNPINNED_REQUIREMENTS=false",
"SYFT_CATALOGER_ENABLED=true",
"SYFT_PACKAGE_SEARCH_LAYER_LIMIT=200",
# Aggressive memory optimization
"GOMEMLIMIT=2GiB",
"GOGC=50",
"SYFT_MAX_PARALLEL_WORKERS=1",
# Additional memory-saving options
"SYFT_DISABLE_RECURSIVE_PACKAGE_SEARCH=true",
"SYFT_PYTHON_CATALOGER_MAX_WORKER_COUNT=1"
]
# GC Policy 1: Minimal interference during builds
# Remove only old temporary contexts with high limits
[[worker.oci.gcpolicy]]
filters = ["type==source.local", "type==exec.cachemount", "type==source.git.checkout"]
keepDuration = "72h"
maxUsedSpace = "85GB"
# GC Policy 2: Main cache preservation with extended retention
[[worker.oci.gcpolicy]]
keepDuration = "336h"
reservedSpace = "25GB"
maxUsedSpace = "90GB"
# GC Policy 3: Unshared cache - careful cleanup
[[worker.oci.gcpolicy]]
reservedSpace = "20GB"
maxUsedSpace = "95GB"
# GC Policy 4: Emergency cleanup only at critical disk usage
[[worker.oci.gcpolicy]]
all = true
reservedSpace = "15GB"
maxUsedSpace = "100GB"