Repository navigation
ci: pull MinIO from Chainguard (quay.io/Docker Hub now 401) - #66
Merged
Merged
Conversation
…nymous pulls main's CI failed at 'start minio' with 'unauthorized' although the tree is identical to the one that passed two days earlier: MinIO stopped serving its images anonymously. Chainguard's build of the same server is free to pull. It runs as uid 65532 with no /data, so CI mounts a tmpfs owned by that uid, and the compose demo service runs as root against its named volume. The image carries no mc, so the compose healthcheck goes. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
After Wave 1 merged,
main's CI failed at start minio withunauthorized: access to the requested resource is not authorized. The tree is byte-identical to the one that passed full CI two days earlier. MinIO no longer serves its images anonymously:quay.io/minio/minioanddocker.io/minio/minioboth return 401 for every tag, including the pinned digest.Change
MINIO_IMAGE(ci.yml) and the composeminioservice now usecgr.dev/chainguard/minio, Chainguard's free build of the same MinIO server, pinned by digest (multi-arch: amd64 + arm64)./data:--tmpfs /dataowned by that uid.user: '0:0'so it can write its root-owned named volume. It's a local demo service only.mcand nocurl, and nothingdepends_onMinIO being healthy.scripts/fresh-clone-demo.shalready polls/minio/health/liveitself.Risk
Chainguard's free tier only publishes
latest, so older digests may eventually stop being pullable. Dependabot's docker-compose ecosystem will propose digest bumps for compose;MINIO_IMAGEin ci.yml must be kept in step by hand (as before).🤖 Generated with Claude Code