Skip to content

ci(milvus): drop MinIO from the Milvus job with local storage - #471

Merged
gloryfromca merged 1 commit into
mainfrom
ci/milvus-local-storage
Oct 1, 2026
Merged

gloryfromca merged 1 commit into
mainfrom
ci/milvus-local-storage

Conversation

@gloryfromca

@gloryfromca gloryfromca commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

Summary

The Milvus job downloads the upstream milvus-standalone-docker-compose.yml, whose MinIO image can no longer be pulled anonymously. #460 moved the image to quay.io/minio/minio when Docker Hub started refusing; quay.io now refuses the same tag, so the job fails after 20 seconds on unauthorized: access to the requested resource is not authorized. Both registries, probed without credentials:

quay.io   minio/minio:RELEASE.2024-12-18T13-15-44Z -> 401
dockerhub minio/minio:RELEASE.2024-12-18T13-15-44Z -> 401
dockerhub milvusdb/milvus:v2.6.22                  -> 200

This replaces the three-service compose stack with a single container: embedded etcd (ETCD_USE_EMBED) and local-disk segment storage (COMMON_STORAGETYPE=local), the knobs upstream's scripts/standalone_embed.sh uses. Only milvusdb/milvus is pulled, the compose download and the sed patching go away, and the etcd image drops out with MinIO.

Local storage is a development topology — it removes the object-store hop. No assertion in the four suites this job runs reads that hop; they all speak to the Milvus SDK. A test that needs the S3 path would need a different setup, and this PR does not add one.

Area

  • Architecture method
  • Benchmark
  • Use case
  • Documentation
  • Developer experience
  • CI, build, or release

Verification

The start and stop steps were extracted from the edited ci.yml with yaml.safe_load and run verbatim under bash -e (the shell Actions uses), so the heredoc and the health loop are tested as written, not as a hand-typed equivalent. The container came up healthy in 4s; all four of the job's test steps then ran against it.

# start step, extracted from .github/workflows/ci.yml, run verbatim -> exit 0
EVEROS_TEST_MILVUS_URI=http://127.0.0.1:19530 EVEROS_TEST_MILVUS_FULL_STARTUP=1 \
  pytest tests/integration/test_milvus_remote.py
    5 passed in 129.77s

EVEROS_TEST_MILVUS_URI=... pytest \
  tests/e2e/test_get_endpoint_e2e.py::test_get_truncates_above_max_fetch -k milvus
    1 passed

EVEROS_TEST_MILVUS_URI=... pytest tests/integration/test_tiers -k milvus
    27 passed, 28 deselected in 703.95s

EVEROS_TEST_MILVUS_URI=... pytest tests/unit/test_infra/test_index_contract.py
    18 passed

# stop step, extracted and run verbatim -> exit 0, container gone

make lint                     # ruff, import-linter, repo gates, openapi drift -- exit 0
make test                     # 2618 passed, 4 skipped
make integration              # 186 passed, 5 skipped, 7 deselected
make check-commits            # Conventional Commits -- exit 0

make integration failed once on test_memorize_agent_mode.py::test_agent_mode_two_user_assistant_msgs -- a session_lock_timeout_seconds timeout while the machine was loaded -- and is green on a rerun; the numbers above are that rerun. The only file this branch changes is .github/workflows/ci.yml, which no pytest run reads.

Run on macOS/arm64 with Docker Desktop 29.7.2, milvusdb/milvus:v2.6.22.

Checklist

  • I kept the change scoped to the relevant area.
  • I am opening this from a separate branch, not pushing directly to main.
  • I updated docs, examples, or setup notes when behavior changed.
  • I added or updated tests when the change affects behavior.
  • I did not commit secrets, .env files, dependency folders, or generated output.
  • Active relative links in Markdown files resolve.

Notes for Reviewers

  • The alternatives are worse: a Docker Hub login needs a secret that fork PRs cannot read, and bitnami/minio is the same dependency under a different vendor that has also restricted its catalog. Local storage removes the dependency rather than relocating it.
  • --security-opt seccomp:unconfined and the embedEtcd.yaml contents are carried over from upstream's script unchanged.
  • The job kept its four test steps, its env vars and its 120s health budget; only how Milvus is started and stopped changed.

By submitting this pull request, I agree that my contribution is licensed under
the Apache License 2.0.

🤖 Generated with Claude Code

The job downloaded the upstream standalone compose file, whose MinIO
image is no longer pullable without credentials -- neither `minio/minio`
on Docker Hub nor the `quay.io/minio/minio` mirror this job switched to
in #460 answers an anonymous pull any more, so every run since fails in
20 seconds on `unauthorized: access to the requested resource is not
authorized`.

Run Milvus as a single container with embedded etcd and local-disk
segment storage instead -- `ETCD_USE_EMBED` plus `COMMON_STORAGETYPE`,
the same knobs upstream's `scripts/standalone_embed.sh` uses. That
leaves one image, `milvusdb/milvus`, which still pulls anonymously, and
removes the compose download and the `sed` patching along with it.

Local storage is a development topology: it drops the object-store hop,
which no assertion in these suites reads -- they all speak to the Milvus
SDK. A test that needs the S3 path would need a different setup.

Verified by extracting the start and stop steps from this file and
running them verbatim, then running all four test steps against the
container: `test_milvus_remote.py` 5 passed, the `/get` truncation e2e
1 passed, `test_tiers -k milvus` 27 passed, `test_index_contract.py`
18 passed.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

@dani1005 dani1005 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM — approving. Verified the docker run flags and embedEtcd.yaml against upstream scripts/standalone_embed.sh at v2.6.22; the only omissions (data volume, user.yaml, port 2379) are irrelevant for CI. The Milvus job is green, and faster than the last green run on main (14m vs 17m).

Two non-blocking nits:

  • The "updated docs" / "added or updated tests" boxes don't apply to a CI-only change. Untick them or mark them N/A.
  • docker rm -f -v milvus would mirror the old down -v. Harmless on an ephemeral runner, so optional.

@gloryfromca
gloryfromca merged commit d2aa949 into main Oct 1, 2026
11 checks passed
@gloryfromca
gloryfromca deleted the ci/milvus-local-storage branch October 1, 2026 13:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants