|
| 1 | +# TAGLINE |
| 2 | + |
| 3 | +Build an image with Docker Buildx and BuildKit |
| 4 | + |
| 5 | +# TLDR |
| 6 | + |
| 7 | +**Build** from the Dockerfile in the current directory |
| 8 | + |
| 9 | +```docker buildx build .``` |
| 10 | + |
| 11 | +**Tag** the image |
| 12 | + |
| 13 | +```docker buildx build -t [image:tag] .``` |
| 14 | + |
| 15 | +Use a **specific Dockerfile** |
| 16 | + |
| 17 | +```docker buildx build -f [path/to/Dockerfile] -t [image:tag] .``` |
| 18 | + |
| 19 | +Pass **build-time variables** |
| 20 | + |
| 21 | +```docker buildx build --build-arg [HTTP_PROXY=http://proxy.example.com] --build-arg [VERSION=1.0] .``` |
| 22 | + |
| 23 | +**Load** a single-platform result into **docker images** |
| 24 | + |
| 25 | +```docker buildx build --load -t [image:tag] .``` |
| 26 | + |
| 27 | +Build for **multiple platforms** and **push** to a registry |
| 28 | + |
| 29 | +```docker buildx build --platform [linux/amd64,linux/arm64] --push -t [registry.example.com/image:tag] .``` |
| 30 | + |
| 31 | +Build a **named stage** from a multi-stage Dockerfile |
| 32 | + |
| 33 | +```docker buildx build --target [stage_name] -t [image:tag] .``` |
| 34 | + |
| 35 | +Build with a **secret** and **SSH** forwarding for private fetches |
| 36 | + |
| 37 | +```docker buildx build --secret [id=aws,src=$HOME/.aws/credentials] --ssh default .``` |
| 38 | + |
| 39 | +# SYNOPSIS |
| 40 | + |
| 41 | +**docker buildx build** [_options_] _PATH_ | _URL_ | **-** |
| 42 | + |
| 43 | +# PARAMETERS |
| 44 | + |
| 45 | +**-t**, **--tag** _name_[:_tag_] |
| 46 | +> Image name and optional tag. Repeatable. |
| 47 | +
|
| 48 | +**-f**, **--file** _path_|_url_|**-** |
| 49 | +> Dockerfile location. Default: **PATH/Dockerfile**. **-** reads the Dockerfile from stdin. |
| 50 | +
|
| 51 | +**--build-arg** _key_[=_value_] |
| 52 | +> Build-time variable for **ARG**. If _value_ is omitted, the value is taken from the client environment. |
| 53 | +
|
| 54 | +**--platform** _platforms_ |
| 55 | +> Target platform(s), comma-separated (**linux/amd64**, **linux/arm64**, **linux/arm/v7**). Multiple values produce a manifest list (requires a driver other than **docker**). |
| 56 | +
|
| 57 | +**--load** |
| 58 | +> Shorthand for **--output=type=docker**. Loads a single-platform image into the local image store. |
| 59 | +
|
| 60 | +**--push** |
| 61 | +> Shorthand for **--output=type=registry**. Pushes the result to a registry. |
| 62 | +
|
| 63 | +**-o**, **--output** _dest_ |
| 64 | +> Export destination, for example **type=local,dest=**_path_, **type=tar,dest=-**, **type=oci**, **type=docker**, **type=image**, **type=registry**. |
| 65 | +
|
| 66 | +**--target** _stage_ |
| 67 | +> Build only up to the named stage in a multi-stage Dockerfile. |
| 68 | +
|
| 69 | +**--no-cache** |
| 70 | +> Do not use cache when building. |
| 71 | +
|
| 72 | +**--no-cache-filter** _stages_ |
| 73 | +> Ignore cache for the named stages only (comma-separated). |
| 74 | +
|
| 75 | +**--pull** |
| 76 | +> Always attempt to pull referenced images. |
| 77 | +
|
| 78 | +**--cache-from** _source_ |
| 79 | +> External cache source (**type=registry,ref=...**, **type=local,src=...**, **gha**, **s3**, **azblob**). Default type is registry. |
| 80 | +
|
| 81 | +**--cache-to** _dest_ |
| 82 | +> External cache destination (**registry**, **local**, **inline**, **gha**, **s3**, **azblob**). |
| 83 | +
|
| 84 | +**--secret** _id=..._ |
| 85 | +> Expose a secret to **RUN --mount=type=secret**. **type=file** (default if no matching env var) or **type=env**. |
| 86 | +
|
| 87 | +**--ssh** _default_|_id_[=_socket_|_key_] |
| 88 | +> Expose an SSH agent socket or keys to **RUN --mount=type=ssh**. |
| 89 | +
|
| 90 | +**--build-context** _name_=_value_ |
| 91 | +> Additional named context (local path, Git/HTTP URL, **docker-image://**, or **oci-layout:///**). |
| 92 | +
|
| 93 | +**--attest** _type=sbom_|_type=provenance_ |
| 94 | +> Attach SBOM or SLSA provenance attestations. **--sbom** and **--provenance** are shorthands. |
| 95 | +
|
| 96 | +**--progress** _mode_ |
| 97 | +> Progress output: **auto** (default), **tty**, **plain**, **quiet**, **rawjson**, **none**. Also settable via **BUILDKIT_PROGRESS**. |
| 98 | +
|
| 99 | +**-q**, **--quiet** |
| 100 | +> Suppress build output and print the image ID on success. |
| 101 | +
|
| 102 | +**--network** _mode_ |
| 103 | +> Network for **RUN**: **default**, **none**, or **host**. |
| 104 | +
|
| 105 | +**--allow** _entitlement_ |
| 106 | +> Extra privilege: **network.host**, **security.insecure**, **device**, **buildx.local.delete**. The BuildKit daemon must also allow insecure entitlements. |
| 107 | +
|
| 108 | +**--call** _method_ |
| 109 | +> Frontend method instead of a full build: **build** (default), **check**, **outline**, **targets**. **--check** is shorthand for **--call=check**. |
| 110 | +
|
| 111 | +**--metadata-file** _file_ |
| 112 | +> Write build metadata JSON (digests, provenance) to _file_. |
| 113 | +
|
| 114 | +**--iidfile** _file_ |
| 115 | +> Write the image ID to _file_. |
| 116 | +
|
| 117 | +**--label** _key=value_ |
| 118 | +> Image metadata label. Repeatable. |
| 119 | +
|
| 120 | +**--annotation** _key=value_ |
| 121 | +> OCI annotation on the index, manifest, or descriptor. |
| 122 | +
|
| 123 | +**--builder** _name_ |
| 124 | +> Builder instance to use (overrides the currently selected builder). |
| 125 | +
|
| 126 | +# DESCRIPTION |
| 127 | + |
| 128 | +**docker buildx build** starts a build using BuildKit. It is the Buildx form of **docker build** (also aliased as **docker builder build** and **docker image build**). |
| 129 | + |
| 130 | +The positional argument is the build context: a local directory, a Git or HTTP URL, or **-** for stdin. BuildKit executes the Dockerfile, caches layers, and exports the result according to **--output** / **--load** / **--push**. |
| 131 | + |
| 132 | +The default **docker** driver builds on the engine's built-in builder and implies a local image load, but it cannot produce multi-platform images or export cache. Drivers such as **docker-container** (created with **docker buildx create**) support **--platform** lists, cache export, attestations, and registry pushes. **--load** is single-platform only; multi-platform results should be **--push**ed to a registry unless the engine uses the containerd image store. |
| 133 | + |
| 134 | +# CAVEATS |
| 135 | + |
| 136 | +The **docker** driver does not support multi-platform builds or **--cache-to**. **--load** fails for multi-platform output on the default image store. Attestations persist when pushing to a registry; they are dropped if you only load into the classic image store. **--allow security.insecure** and **network.host** also need **--allow-insecure-entitlement** on the BuildKit daemon. Large contexts slow the upload; use **.dockerignore**. Secrets must be mounted in the Dockerfile with **RUN --mount=type=secret**; passing **--secret** alone does not inject files. |
| 137 | + |
| 138 | +# HISTORY |
| 139 | + |
| 140 | +Docker's image builder dates to the **2013** Docker release. **BuildKit** landed in **2017** and became the default builder in Docker **23.0** (**2023**). **buildx** is the CLI plugin that drives BuildKit for multi-platform builds, cache backends, and attestations; **docker buildx build** is its primary command. |
| 141 | + |
| 142 | +# INSTALL |
| 143 | + |
| 144 | +```apt: sudo apt install docker-cli``` |
| 145 | + |
| 146 | +```dnf: sudo dnf install docker-cli``` |
| 147 | + |
| 148 | +```pacman: sudo pacman -S docker``` |
| 149 | + |
| 150 | +```apk: sudo apk add docker-cli``` |
| 151 | + |
| 152 | +```zypper: sudo zypper install docker``` |
| 153 | + |
| 154 | +```brew: brew install docker``` |
| 155 | + |
| 156 | +```nix: nix profile install nixpkgs#docker``` |
| 157 | + |
| 158 | +<!-- packages: 2026-09-15 --> |
| 159 | + |
| 160 | +# SEE ALSO |
| 161 | + |
| 162 | +[docker-build](/man/docker-build)(1), [docker-buildx-create](/man/docker-buildx-create)(1), [docker-buildx-ls](/man/docker-buildx-ls)(1), [docker-buildx-inspect](/man/docker-buildx-inspect)(1), [docker](/man/docker)(1) |
| 163 | + |
| 164 | +# RESOURCES |
| 165 | + |
| 166 | +```[Source code](https://github.com/docker/buildx)``` |
| 167 | + |
| 168 | +```[Documentation](https://docs.docker.com/reference/cli/docker/buildx/build/)``` |
| 169 | + |
| 170 | +<!-- verified: 2026-09-15 --> |
0 commit comments