Review the intent of FROM platform selection

Align each build stage’s platform with the intended target.

Description

FROM --platform selects the operating system and architecture for that stage. Hardcoding a value such as linux/arm64 can select an unintended platform when building for another target or require emulation.

Selecting a platform is not inherently wrong. It can be necessary for intentional cross-compilation or for running build tools on $BUILDPLATFORM.

Potential impact

  • A build can produce binaries for the wrong target or fail when they run.
  • Unnecessary emulation can slow down the build.

Remediation

  • Check whether a fixed platform is required. Remove an unnecessary FROM --platform selection from stages that should follow the build’s target platform.
  • Select build targets with an option such as buildx --platform and test the result on each required platform. Removing the option alone does not make an application portable.

Examples

The examples compare stage platform selection only. The base image and application dependencies must also support the intended platform.

Before

dockerfile
FROM --platform=linux/arm64 node:22-alpine

WORKDIR /app
COPY . .

After

dockerfile
FROM node:22-alpine

WORKDIR /app
COPY . .

Explanation:

  • Before: The stage is fixed to linux/arm64. This is valid for an intentional ARM64-only configuration.
  • After: The stage follows the build’s target platform. Verify actual runtime compatibility separately.

References