Pull MinIO from a registry that still serves it - #294
Open
dimitri-yatsenko wants to merge 1 commit into
Open
dimitri-yatsenko wants to merge 1 commit into
dimitri-yatsenko wants to merge 1 commit into
Conversation
The Development workflow -- the docs site deploy -- has failed on every push to main since MinIO withdrew its public images: minio Error pull access denied for minio/minio, repository does not exist or may require 'docker login' `minio/minio` on Docker Hub is gone entirely, any tag, and `quay.io/minio/minio` now requires authentication. Chainguard publishes a maintained build that needs no credentials, ships `mc` so the healthcheck is unchanged, and is what datajoint-python's test fixture already uses. Overridable through MINIO_IMAGE so a deployment can point at its own mirror. Verified by running what CI runs -- `MODE=BUILD docker compose up --exit-code-from docs --build` -- end to end: minio healthy in about ten seconds, site built, every container exited 0. One local-only wrinkle, documented in the file: the image runs as `nonroot`, so a `minio_data` volume left behind by the old root-owned image is not writable and MinIO exits with "Unable to write to the backend". A fresh volume inherits the image's world-writable /data, so `docker compose down -v` clears it once. CI runners start clean.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The Development workflow — the docs site deploy — has failed on every push to
mainsince MinIO withdrew its public images. Today's three merges all show it red:minio/minioon Docker Hub is gone entirely — any tag, not justlatest— andquay.io/minio/minionow requires authentication. Chainguard publishes a maintained build that needs no credentials and is drop-in here. It shipsmc, so themc ready localhealthcheck is unchanged, and it is already what datajoint-python's test fixture uses (datajoint/datajoint-python#1559).Overridable through
MINIO_IMAGEso a deployment can point at its own mirror without editing the file.Verification
Ran what CI runs, end to end:
MinIO healthy in about ten seconds,
Documentation built in 9.82 seconds, every container exited 0.One local-only wrinkle, documented in the file
The image runs as
nonroot(uid 65532). Aminio_datavolume left behind by the old root-owned image is not writable by it, and MinIO exits with "Unable to write to the backend". A fresh volume inherits the image's world-writable/dataand is fine, sodocker compose down -vclears it once. CI runners start clean and never see this — I hit it locally and it cost a confusing build, which is why the comment is in the file rather than only here.Worth a follow-up, not done here
In
MODE=BUILDthedocsservice only runspip install,gen_llms_full.pyandmkdocs build— it never touches MySQL, PostgreSQL or MinIO. Butdepends_onmakes all three start and go healthy first, which is why a registry outage took down the docs deploy at all. Putting the three behind a compose profile would make BUILD and LIVE independent of them. Out of scope for a red-CI fix.