From 33766ea6c300bde8f4e45a184c8219240e792f26 Mon Sep 17 00:00:00 2001 From: zhanghui Date: Wed, 30 Sep 2026 22:22:57 +0800 Subject: [PATCH] ci(milvus): drop MinIO from the Milvus job with local storage The job downloaded the upstream standalone compose file, whose MinIO image is no longer pullable without credentials -- neither `minio/minio` on Docker Hub nor the `quay.io/minio/minio` mirror this job switched to in #460 answers an anonymous pull any more, so every run since fails in 20 seconds on `unauthorized: access to the requested resource is not authorized`. Run Milvus as a single container with embedded etcd and local-disk segment storage instead -- `ETCD_USE_EMBED` plus `COMMON_STORAGETYPE`, the same knobs upstream's `scripts/standalone_embed.sh` uses. That leaves one image, `milvusdb/milvus`, which still pulls anonymously, and removes the compose download and the `sed` patching along with it. Local storage is a development topology: it drops the object-store hop, which no assertion in these suites reads -- they all speak to the Milvus SDK. A test that needs the S3 path would need a different setup. Verified by extracting the start and stop steps from this file and running them verbatim, then running all four test steps against the container: `test_milvus_remote.py` 5 passed, the `/get` truncation e2e 1 passed, `test_tiers -k milvus` 27 passed, `test_index_contract.py` 18 passed. Co-Authored-By: Claude Opus 5 (1M context) --- .github/workflows/ci.yml | 34 ++++++++++++++++++++++++---------- 1 file changed, 24 insertions(+), 10 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index ed521bf0b..9320b7d94 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -168,23 +168,37 @@ jobs: - name: Install dependencies (frozen) run: make install-deps + # One container instead of the three-service compose file: embedded etcd + # plus local-disk segment storage, the same knobs upstream's + # scripts/standalone_embed.sh uses. The compose file wants MinIO, and + # MinIO now refuses anonymous pulls on both Docker Hub and quay.io + # ("unauthorized"), which broke this job. Local storage is a dev/CI mode + # -- it drops the object-store hop, not any behaviour these tests read. - name: Start Milvus 2.6.22 run: | - curl --fail --location --retry 3 \ - --output /tmp/milvus-compose.yml \ - https://github.com/milvus-io/milvus/releases/download/v2.6.22/milvus-standalone-docker-compose.yml - # MinIO stopped publishing to Docker Hub (`minio/minio` now returns - # "pull access denied"); the same tags live on quay.io, which is - # where the etcd image in this compose file already comes from. - sed -i 's#image: minio/minio:#image: quay.io/minio/minio:#' /tmp/milvus-compose.yml - docker compose -f /tmp/milvus-compose.yml up -d + cat > /tmp/embedEtcd.yaml <<'EOF' + listen-client-urls: http://0.0.0.0:2379 + advertise-client-urls: http://0.0.0.0:2379 + quota-backend-bytes: 4294967296 + auto-compaction-mode: revision + auto-compaction-retention: '1000' + EOF + docker run -d --name milvus --security-opt seccomp:unconfined \ + -e ETCD_USE_EMBED=true \ + -e ETCD_DATA_DIR=/var/lib/milvus/etcd \ + -e ETCD_CONFIG_PATH=/milvus/configs/embedEtcd.yaml \ + -e COMMON_STORAGETYPE=local \ + -e DEPLOY_MODE=STANDALONE \ + -v /tmp/embedEtcd.yaml:/milvus/configs/embedEtcd.yaml \ + -p 19530:19530 -p 9091:9091 \ + milvusdb/milvus:v2.6.22 milvus run standalone for attempt in {1..60}; do if curl --fail --silent http://127.0.0.1:9091/healthz >/dev/null; then exit 0 fi sleep 2 done - docker compose -f /tmp/milvus-compose.yml logs + docker logs milvus exit 1 - name: Milvus repository contract @@ -221,7 +235,7 @@ jobs: - name: Stop Milvus if: always() - run: docker compose -f /tmp/milvus-compose.yml down -v + run: docker rm -f milvus package: name: package build