Repository navigation
ci(milvus): drop MinIO from the Milvus job with local storage - #471
Merged
Merged
Conversation
The job downloaded the upstream standalone compose file, whose MinIO image is no longer pullable without credentials -- neither `minio/minio` on Docker Hub nor the `quay.io/minio/minio` mirror this job switched to in #460 answers an anonymous pull any more, so every run since fails in 20 seconds on `unauthorized: access to the requested resource is not authorized`. Run Milvus as a single container with embedded etcd and local-disk segment storage instead -- `ETCD_USE_EMBED` plus `COMMON_STORAGETYPE`, the same knobs upstream's `scripts/standalone_embed.sh` uses. That leaves one image, `milvusdb/milvus`, which still pulls anonymously, and removes the compose download and the `sed` patching along with it. Local storage is a development topology: it drops the object-store hop, which no assertion in these suites reads -- they all speak to the Milvus SDK. A test that needs the S3 path would need a different setup. Verified by extracting the start and stop steps from this file and running them verbatim, then running all four test steps against the container: `test_milvus_remote.py` 5 passed, the `/get` truncation e2e 1 passed, `test_tiers -k milvus` 27 passed, `test_index_contract.py` 18 passed. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
dani1005
approved these changes
Sep 30, 2026
dani1005
left a comment
Member
There was a problem hiding this comment.
LGTM — approving. Verified the docker run flags and embedEtcd.yaml against upstream scripts/standalone_embed.sh at v2.6.22; the only omissions (data volume, user.yaml, port 2379) are irrelevant for CI. The Milvus job is green, and faster than the last green run on main (14m vs 17m).
Two non-blocking nits:
- The "updated docs" / "added or updated tests" boxes don't apply to a CI-only change. Untick them or mark them N/A.
docker rm -f -v milvuswould mirror the olddown -v. Harmless on an ephemeral runner, so optional.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The Milvus job downloads the upstream
milvus-standalone-docker-compose.yml, whose MinIO image can no longer be pulled anonymously. #460 moved the image toquay.io/minio/miniowhen Docker Hub started refusing; quay.io now refuses the same tag, so the job fails after 20 seconds onunauthorized: access to the requested resource is not authorized. Both registries, probed without credentials:This replaces the three-service compose stack with a single container: embedded etcd (
ETCD_USE_EMBED) and local-disk segment storage (COMMON_STORAGETYPE=local), the knobs upstream'sscripts/standalone_embed.shuses. Onlymilvusdb/milvusis pulled, the compose download and thesedpatching go away, and the etcd image drops out with MinIO.Local storage is a development topology — it removes the object-store hop. No assertion in the four suites this job runs reads that hop; they all speak to the Milvus SDK. A test that needs the S3 path would need a different setup, and this PR does not add one.
Area
Verification
The start and stop steps were extracted from the edited
ci.ymlwithyaml.safe_loadand run verbatim underbash -e(the shell Actions uses), so the heredoc and the health loop are tested as written, not as a hand-typed equivalent. The container came up healthy in 4s; all four of the job's test steps then ran against it.make integrationfailed once ontest_memorize_agent_mode.py::test_agent_mode_two_user_assistant_msgs-- asession_lock_timeout_secondstimeout while the machine was loaded -- and is green on a rerun; the numbers above are that rerun. The only file this branch changes is.github/workflows/ci.yml, which no pytest run reads.Run on macOS/arm64 with Docker Desktop 29.7.2,
milvusdb/milvus:v2.6.22.Checklist
main..envfiles, dependency folders, or generated output.Notes for Reviewers
bitnami/miniois the same dependency under a different vendor that has also restricted its catalog. Local storage removes the dependency rather than relocating it.--security-opt seccomp:unconfinedand theembedEtcd.yamlcontents are carried over from upstream's script unchanged.By submitting this pull request, I agree that my contribution is licensed under
the Apache License 2.0.
🤖 Generated with Claude Code