Docker 이미지 빌드

Docker 이미지 빌드 (Build Docker Images)

Pinot 관련 Docker 이미지를 빌드하는 방법을 다루는 문서예요.

출처: 문서

본문

Pinot 관련 docker 이미지를 빌드하는 스크립트는 여기에 있어요.

다음 명령으로 Pinot 저장소를 체크아웃해 그 스크립트에 접근할 수 있어요:

git clone [email protected]:apache/pinot.git pinot
cd pinot/docker/images

이 디렉토리에서 현재 지원되는 2개의 이미지를 찾을 수 있어요:

  • Pinot: Pinot 올인원 배포 이미지
  • Pinot-Superset: Pinot 커넥터가 내장된 Superset 이미지

Pinot

이것은 Apache Pinot의 docker 이미지예요.

공식 Pinot 서비스 이미지는 이제 JDK 25를 대상으로 해요. 게시된 latest 태그는 25-ms-openjdk 런타임을 승격하며, *-21-* 서비스 태그는 더 이상 게시되지 않아요. 아래 헬퍼 스크립트로 Pinot 서비스 이미지를 로컬에서 빌드할 때는 현재 릴리스와 일치하도록 Java/JDK 버전 인자에 25를 전달하세요.

Docker 기본 이미지 업데이트 (Docker Base Image Updates)

PR #18178부터 Pinot Docker 이미지는 보안을 개선하고 CVE 취약점을 제거하기 위해 개편됐어요:

기본 이미지 변경 (Base Image Changes)
  • amazoncorretto 런타임: amazoncorretto:*-al2023-jdk에서 apt로 Corretto JDK를 설치하는 debian:bookworm-slim으로 마이그레이션. 이렇게 하면 Amazon Linux 기본 이미지에 있던 모든 Python 관련 CVE가 제거돼요.
  • ms-openjdk 런타임: 장기 지원·안정성을 위해 ubuntu:24.10(비 LTS, EOL)에서 ubuntu:24.04 LTS로 마이그레이션.
보안 개선 (Security Improvements)
  • 모든 기본 이미지는 이제 빌드 시 apt-get upgrade -y를 실행해 OS 보안 패치 적용
  • Thrift 컴파일러가 SHA-512 체크섬 검증과 함께 0.12.0에서 0.22.0으로 업그레이드
  • 공격 표면을 줄이기 위해 런타임 이미지에서 git 제거
  • 헤드리스 서버 배포에 불필요한 Corretto 이미지에서 fontconfig 제거
  • CVE 표면을 줄이기 위해 다운로드 도구를 curl에서 wget으로 변경
  • CVE 강화: amazoncorretto 이미지가 29개의 HIGH CVE에서 총 9개(수정 가능 0개)로 감소
마이그레이션 노트 (Migration Notes)

배포가 Pinot Docker 이미지에서 git을 사용할 수 있다는 것에 의존한다면, 이를 별도로 추가하거나 그것을 포함한 커스텀 이미지를 사용해야 해요.

docker 이미지 빌드 방법 (How to build a docker image)

주어진 Git 저장소/브랜치를 빌드하고 이미지에 태그를 붙이는 docker 빌드 스크립트가 있어요.

사용법:

./docker-build.sh [Docker Tag] [Git Branch] [Pinot Git URL] [Kafka Version] [Java Version] [JDK Version] [OpenJDK Image ]

이 스크립트는 [Git Branch] 브랜치의 Pinot 저장소 [Pinot Git URL]을 체크아웃하고 그에 대한 docker 이미지를 빌드해요.

docker 이미지는 [Docker Tag]로 태그돼요.

Docker Tag: docker 이미지 이름과 태그. 기본값은 pinot:latest.

Git Branch: 빌드할 Pinot 브랜치. 기본값은 master.

Pinot Git URL: 빌드할 Pinot Git 저장소, 사용자가 자신의 fork로 설정할 수 있음. URL은 git://가 아닌 https:// 기반이에요. 기본값은 Apache 저장소: https://github.com/apache/pinot.git.

Kafka Version: pinot를 빌드할 Kafka 버전. 기본값은 3.0. 지원 값은 3.0과 4.0.

Java Version: Java 빌드·런타임 이미지 버전. 현재 Pinot 서비스 릴리스에는 25를 사용. 헬퍼 스크립트는 생략되면 21을 기본값으로 함.

JDK Version: Pinot 빌드용 JDK 파라미터로, Maven 빌드 옵션 -Djdk.version=${JDK_VERSION}의 일부로 설정. 현재 Pinot 서비스 릴리스에는 25를 사용. 헬퍼 스크립트는 생략되면 21을 기본값으로 함.

OpenJDK Image: Pinot 빌드·런타임에 사용할 기본 이미지. 기본값은 openjdk.

  • 자신의 fork에서 스냅샷을 빌드·태그하는 예시:
./docker-build.sh pinot_fork:snapshot-5.2 snapshot-5.2 https://github.com/your_own_fork/pinot.git
  • 릴리스 버전을 빌드하는 예시:
./docker-build.sh pinot:latest latest https://github.com/apache/pinot.git

arm64 기본 이미지로 이미지 빌드 (Build image with arm64 base image)

Mac M1 칩 사용자는 arm64v8/openjdk 같은 arm64 기본 이미지로 빌드해야 해요.

  • arm64 이미지를 빌드하는 예시:
./docker-build.sh pinot:latest master https://github.com/apache/pinot.git 2.0 25 25 arm64v8/openjdk

또는 docker 빌드 스크립트를 직접 실행:

docker build -t pinot:latest --no-cache --network=host --build-arg PINOT_GIT_URL=https://github.com/apache/pinot.git --build-arg PINOT_BRANCH=master --build-arg JDK_VERSION=25 --build-arg OPENJDK_IMAGE=arm64v8/openjdk -f Dockerfile .

arm64 머신이 아니어도 docker의 실험 기능을 켜고 docker build ... 스크립트에 --platform linux/arm64를 추가하면 여전히 이미지를 빌드할 수 있어요:

docker build -t pinot:latest --platform linux/arm64 --no-cache --network=host --build-arg PINOT_GIT_URL=https://github.com/apache/pinot.git --build-arg PINOT_BRANCH=master --build-arg JDK_VERSION=25 --build-arg OPENJDK_IMAGE=arm64v8/openjdk -f Dockerfile .

docker 이미지 게시 방법 (How to publish a docker image)

docker-push.sh 스크립트는 주어진 docker 이미지를 docker 레지스트리에 게시해요.

자신의 저장소로 푸시하려면 이미지를 저장소 이름으로 명시적으로 태그해야 해요.

./docker-push.sh apachepinot/pinot:latest
  • 빌드된 이미지에 태그를 붙인 후 푸시:
docker tag pinot:latest apachepinot/pinot:latest
docker push apachepinot/pinot:latest

docker-build-and-push.sh 스크립트는 빌드 후 이 docker 이미지를 docker 레지스트리에 빌드·게시해요.

./docker-build-and-push.sh apachepinot/pinot:latest master https://github.com/apache/pinot.git

Kubernetes 예시 (Kubernetes Examples)

배포 예시는 Kubernetes 설치 가이드를 참조하세요.

Pinot Superset

Pinot 통합이 포함된 Superset용 Docker 이미지예요.

이 docker 빌드 프로젝트는 프로젝트 docker-superset를 기반으로 하며 Pinot에 특화됐어요.

빌드 방법 (How to build)

Makefile 파일을 수정해 image와 superset_version을 그에 맞게 변경해요.

아래 명령은 docker 이미지를 빌드하고 superset_version과 latest로 태그해요.

make latest

인자를 설정해 docker build 명령으로 직접 빌드할 수도 있어요:

docker build \
    --build-arg NODE_VERSION=latest \
    --build-arg PYTHON_VERSION=3.6 \
    --build-arg SUPERSET_VERSION=0.34.1 \
    --tag apachepinot/pinot-superset:0.34.1 \
    --target build .

푸시 방법 (How to push)

make push

구성 (Configuration)

Apache Superset이 제공하는 지침을 따라 자체 superset_config.py를 작성해요.

이 파일을 로컬 디렉토리에 두고 이 디렉토리를 컨테이너 안의 /etc/superset에 마운트해요. 이 위치는 이미지의 PYTHONPATH에 포함돼요. 이 파일을 다른 위치에 마운트하는 것도 가능하지만 PYTHONPATH에 있어야 해요.

볼륨 (Volumes)

이미지는 두 개의 데이터 볼륨을 정의해요: 하나는 구성을 컨테이너로 마운트하기 위한 것이고, 다른 하나는 데이터(로그, SQLite DB 등)용이에요.

구성 볼륨은 /etc/superset 또는 /home/superset에 위치하며, 둘 다 허용돼요. 두 디렉토리 모두 이미지의 PYTHONPATH에 포함돼요. 모든 구성(특히 superset_config.py 파일)을 여기에 마운트해 시작 시 앱이 읽게 해요.

데이터 볼륨은 /var/lib/superset에 있으며, SQLite 파일(백엔드로 사용한다면)을 마운트하거나 거기로 라우팅되는 로그를 모으는 볼륨을 두는 곳이에요. 이 위치는 SUPERSET_HOME 환경 변수의 값으로 사용돼요.

Kubernetes 예시 (Kubernetes Examples)

k8s 배포 예시는 superset.yaml을 참조하세요.

더 알아보기 (Learn more)