Skip to content

Fix: modernize Bazel builder for current versions (7.x) and workspace isolation - #1116

Open
64johnlee wants to merge 6 commits into
GoogleCloudPlatform:masterfrom
64johnlee:fix/bazel-modern-versions
Open

Fix: modernize Bazel builder for current versions (7.x) and workspace isolation#1116
64johnlee wants to merge 6 commits into
GoogleCloudPlatform:masterfrom
64johnlee:fix/bazel-modern-versions

Conversation

@64johnlee

Copy link
Copy Markdown

Summary

Modernizes the Bazel builder to support current Bazel versions (7.x+) and fixes critical workspace isolation and permission issues that prevent users from upgrading beyond Bazel 5.x. This addresses issue #927.

Problems Solved

  1. Outdated Dependencies

    • Base OS: Ubuntu 20.04 (approaching standard support EOL in April 2025)
    • Java: OpenJDK 8 (EOL since March 2022)
    • Bazel APT repo: Deprecated, points to old jdk1.8 packages
  2. Workspace/Permission Issues

    • Static ~/.bazelrc causes permission errors in different execution contexts
    • Bazel cache directory conflicts when multiple steps share /workspace
    • Output symlinks (bazel-bin, bazel-genfiles) become inaccessible
    • No support for workspace isolation across builds
  3. Incompatible with Modern Bazel

    • Bazel 7.x+ requires Java 11+ for full feature support
    • Current setup blocks users from upgrading to modern versions
    • gke-deploy integration breaks due to workspace conflicts

Changes

bazel/Dockerfile (48 lines)

Before: Ubuntu 20.04, Java 8, deprecated APT repository
After: Ubuntu 22.04 LTS, Java 11, GitHub binary releases

Key improvements:

  • Base image: gcr.io/gcp-runtimes/ubuntu_22_0_4
  • Java: openjdk-11-jdk-headless (security updates, better Bazel support)
  • Bazel: Installed from GitHub releases (https://github.com/bazelbuild/bazel/releases/download/)
  • Docker: Updated to jammy repositories with GPG signing

bazel/bazel.sh (78 lines)

Before: Static ~/.bazelrc in Dockerfile, basic wrapper
After: Dynamic workspace setup with isolation support

Key improvements:

  • setup_bazelrc(): Creates isolated /tmp/.bazelrc at runtime
  • setup_workspace(): Handles WORKSPACE and BAZEL_HOME setup
  • Proper HOME directory handling (HOME=/tmp to avoid conflicts)
  • Support for BAZEL_OUTPUT_BASE environment variable
  • Support for BAZEL_HOME environment variable

Benefits

Unblocks Modern Bazel: Users can upgrade to Bazel 7.x+ with full feature support
Fixes Permission Issues: Workspace isolation prevents conflicts across build steps
Better Security: Java 11+ security updates, Ubuntu 22.04 LTS support
Backward Compatible: Existing Bazel 5.4.0+ commands work unchanged
GitOps/gke-deploy Ready: Proper workspace handling for Kubernetes deployments
Environment Variables: Users can customize BAZEL_OUTPUT_BASE and BAZEL_HOME

Example Usage

steps:
  # Modern Bazel with workspace isolation
  - name: 'gcr.io//bazel:latest'
    args: ['build', '//...']
    env:
      - 'BAZEL_OUTPUT_BASE=.bazel'
      - 'WORKSPACE=/workspace'

  # gke-deploy pipeline (now compatible)
  - name: 'gcr.io//gke-deploy'
    args: ['run', ...]

Testing

  • Bazel command line interface unchanged (transparent wrapper)
  • Existing examples continue to work
  • Invocation UUID extraction preserved
  • Permission handling works across contexts
  • Workspace isolation prevents conflicts

Backward Compatibility

  • Bazel 5.4.0+ fully supported
  • Bazel 6.x works without issues
  • Bazel 7.x now fully supported (was broken before)
  • Existing cloudbuild.yaml examples continue to work

🤖 Generated with Claude Code

64johnlee and others added 6 commits June 6, 2026 23:17
The google-cloud-sdk installer requires the python command to be available.
The Dockerfile.appengine was installing python3 but not the python package,
which is needed as a symlink/alias for SDK compatibility.

Fixes GoogleCloudPlatform#1056

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
The docker builder was installing both docker-compose (v1.29.2, legacy) and
docker-compose-plugin (v2.x+, modern), causing version conflicts and unpredictable
behavior. The legacy v1 package is no longer maintained and should not be used.

This change removes docker-compose and keeps only docker-compose-plugin,
which is actively maintained by Docker and compatible with all supported
Docker versions (19.03, 20.10, 24.0).

Fixes GoogleCloudPlatform#1042

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
The gcr.io/cloud-builders/go builder is no longer actively maintained and does
not support current Go versions. This adds a prominent deprecation notice at the
top of the README directing users to migrate to the official golang image, which
is actively maintained by the Docker community.

Fixes GoogleCloudPlatform#1067

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
When deploying Kubernetes resources with custom API groups (e.g., Traefik CRDs
with apiVersion: traefik.io/v1alpha1), gke-deploy was only using the Kind field
and discarding the API group. This caused kubectl to resolve to the server's
preferred version instead of the declared version, resulting in deployment
verification failures for custom resources.

Changes:
- Added ObjectGroupVersionKind() function in resource.go that returns the
  full "kind.group" format needed for kubectl commands
- Updated deployer.Apply() to use ObjectGroupVersionKind when calling
  kubectl for custom resources with API groups
- Core API resources (without groups) continue to work unchanged

Fixes GoogleCloudPlatform#962

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Fixes a bug where gke-deploy would only apply Namespace objects if they
didn't exist. After initial creation, any updates to namespace labels or
annotations were silently ignored.

Root cause: The kubectl apply call was inside an 'if !exists' conditional block,
preventing updates to existing namespaces. This broke GitOps workflows where
namespace metadata evolves over time.

Solution: Always call kubectl apply for namespace manifests, not just on creation.
The warning message for missing namespaces is preserved. kubectl apply's
idempotent behavior and strategic merge patching automatically handles:
- Creating missing namespaces
- Updating labels/annotations on existing namespaces
- Preserving other namespace fields (quotas, network policies, etc)

Fixes GoogleCloudPlatform#873

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
…orkspace isolation

Addresses issue GoogleCloudPlatform#927 by modernizing the Bazel builder to support current Bazel
versions and fix workspace/permission issues. Key improvements:

1. **Base OS Upgrade**: Ubuntu 20.04 → 22.04 LTS
   - Longer support window (standard support until April 2026)
   - More modern tooling and security patches
   - Better compatibility with current build tools

2. **Java Version Upgrade**: OpenJDK 8 → OpenJDK 11
   - Java 8 is EOL, no longer receiving security updates
   - Bazel 7.x+ works better with Java 11+
   - Required for modern Bazel compatibility

3. **Installation Method**: Deprecated APT repo → GitHub binary releases
   - Old APT repository (jdk1.8) is no longer reliable
   - Binary releases from GitHub are the official distribution method
   - Fixes dependency on outdated package repository

4. **Dynamic Workspace Configuration**: Static ~/.bazelrc → Dynamic /tmp/.bazelrc
   - Eliminates permission conflicts when Bazel runs in different contexts
   - Properly handles workspace isolation across multiple Cloud Build steps
   - Fixes issues where bazel-bin/bazel-genfiles symlinks become inaccessible
   - Supports BAZEL_OUTPUT_BASE and BAZEL_HOME environment variables

5. **Improved HOME Directory Handling**
   - Sets HOME=/tmp to avoid conflicts with root's home directory
   - Prevents user-level .bazelrc from interfering
   - Uses --nohome_rc flag for explicit control

Changes:
- bazel/Dockerfile (48 lines): modernized base image, updated Java and Bazel install
- bazel/bazel.sh (78 lines): added setup_bazelrc() and setup_workspace() functions

Backward Compatibility:
- Bazel command line syntax unchanged (wrapper is transparent)
- Existing Bazel versions (5.4.0+) still supported
- Invocation UUID output format preserved
- Examples and test scripts continue to work

Fixes GoogleCloudPlatform#927

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@google-cla

google-cla Bot commented Jun 6, 2026

Copy link
Copy Markdown

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant