
Docker Build
CertifiedBuild and optionally push a Docker image
Docker Build
Build and optionally push a Docker image
Builds an image from inline Dockerfile content or a path using the Docker daemon available to the task runner. Pulls the base image by default, tags are required, and pushing is optional with registry credentials; caller inherits daemon permissions.
type: io.kestra.plugin.docker.BuildExamples
Build and push a Docker image to a registry
id: docker_build
namespace: company.team
tasks:
- id: build
type: io.kestra.plugin.docker.Build
push: true
dockerfile: |
FROM ubuntu
ARG APT_PACKAGES=""
RUN apt-get update && apt-get install -y --no-install-recommends ${APT_PACKAGES};
platforms:
- linux/amd64
tags:
- private-registry.io/unit-test:latest
buildArgs:
APT_PACKAGES: curl
labels:
unit-test: "true"
credentials:
registry: <registry.url.com>
username: "{{ secret('DOCKERHUB_USERNAME') }}"
password: "{{ secret('DOCKERHUB_PASSWORD') }}"
Build and push a docker image to DockerHub
id: build_dockerhub_image
namespace: company.team
tasks:
- id: build
type: io.kestra.plugin.docker.Build
dockerfile: |
FROM python:3.10
RUN pip install --upgrade pip
RUN pip install --no-cache-dir kestra requests "polars[all]"
tags:
- kestra/polars:latest
push: true
credentials:
registry: https://index.docker.io/v1/
username: "{{ secret('DOCKERHUB_USERNAME') }}"
password: "{{ secret('DOCKERHUB_PASSWORD') }}"
Build a Docker image and push it to GitHub Container Registry (ghcr.io)
id: build_github_container_image
namespace: company.team
tasks:
- id: build
type: io.kestra.plugin.docker.Build
dockerfile: |
FROM python:3.10
RUN pip install --upgrade pip
RUN pip install --no-cache-dir kestra requests "polars[all]"
tags:
- ghcr.io/kestra-io/polars:latest
push: true
credentials:
username: kestra-io
password: "{{ secret('GITHUB_ACCESS_TOKEN') }}"
Build a Docker image and use it with Python script using a Docker Task Runner
id: build_task_runner_image
namespace: company.team
tasks:
- id: build
type: io.kestra.plugin.docker.Build
tags:
- my-py-data-app
dockerfile: |
FROM python:3.12-slim
WORKDIR /app
RUN pip install --no-cache-dir pandas
COPY . /app
- id: python
type: io.kestra.plugin.scripts.python.Commands
containerImage: "{{ outputs.build.imageId }}"
taskRunner:
type: io.kestra.plugin.scripts.runner.docker.Docker
pullPolicy: NEVER
namespaceFiles:
enabled: true
commands:
- python main.py
Properties
buildArgs object
Build arguments
Optional key/value map rendered before invoking the build.
config stringobject
Docker configuration file
Docker configuration file that can set access credentials to private container registries. Usually located in ~/.docker/config.json.
credentials
Credentials for a private container registry
Credentials for a private container registry.
The registry authentication.
The auth field is a base64-encoded authentication string of username: password or a token.
The identity token.
The registry password.
The registry URL.
If not defined, the registry will be extracted from the image name.
The registry token.
The registry username.
dockerfile string
Dockerfile content or path
Inline Dockerfile text, a relative path in the working directory, or a Kestra URI; inline content is stored as a temp file before build.
host string
The URI of your Docker host e.g. localhost
inputFiles Non-dynamicobjectstring
The files to create on the working. It can be a map or a JSON object.
Each file can be defined:
- Inline with its content
- As a URI, supported schemes are
kestrafor internal storage files,filefor host local files, andnsfilefor namespace files.
labels object
Image labels
Key/value labels to apply to the built image.
namespaceFiles Non-dynamic
Inject namespace files.
Inject namespace files to this task. When enabled, it will, by default, load all namespace files into the working directory. However, you can use the include or exclude properties to limit which namespace files will be injected.
io.kestra.core.models.tasks.NamespaceFiles
trueWhether to enable namespace files to be loaded into the working directory. If explicitly set to true in a task, it will load all Namespace Files into the task's working directory. Note that this property is by default set to true so that you can specify only the include and exclude properties to filter the files to load without having to explicitly set enabled to true.
A list of filters to exclude matching glob patterns. This allows you to exclude a subset of the Namespace Files from being downloaded at runtime. You can combine this property together with include to only inject a subset of files that you need into the task's working directory.
falseWhether to mount file into the root of the working directory, or create a folder per namespace
OVERWRITEOVERWRITEFAILWARNIGNOREComportment of the task if a file already exist in the working directory.
A list of filters to include only matching glob patterns. This allows you to only load a subset of the Namespace Files into the working directory.
["{{flow.namespace}}"]A list of namespaces in which searching files. The files are loaded in the namespace order, and only the latest version of a file is kept. Meaning if a file is present in the first and second namespace, only the file present on the second namespace will be loaded.
platforms array
Target platforms for the image
Each entry is passed to buildx as --platform; leave empty to use the daemon default.
pluginDefaultsRef Non-dynamicstring
Reference (ref) of the pluginDefaults to apply to this task.
pull booleanstring
truePull the base image first
Defaults to true so the build uses the latest base image; set false to rely on cached layers.
push booleanstring
falsePush the image to a registry
Defaults to false; when true, tags are pushed using the provided credentials.
target string
Target build stage
Name of the build stage to stop at in a multi-stage Dockerfile; equivalent to --target.
Outputs
imageId string
Built image ID
Metrics
bytes counter
bytesTotal bytes pushed to the container registry