Build MinIO from source instead of depending on a registry mirror - #4
Merged
Merged
Conversation
sgamelin
had a problem deploying
to
integration
September 25, 2026 13:10 — with
GitHub Actions
Failure
sgamelin
had a problem deploying
to
integration
September 25, 2026 13:10 — with
GitHub Actions
Failure
sgamelin
had a problem deploying
to
integration
September 25, 2026 13:10 — with
GitHub Actions
Failure
sgamelin
had a problem deploying
to
integration
September 25, 2026 13:10 — with
GitHub Actions
Failure
sgamelin
had a problem deploying
to
integration
September 25, 2026 13:10 — with
GitHub Actions
Failure
sgamelin
had a problem deploying
to
integration
September 25, 2026 13:10 — with
GitHub Actions
Failure
sgamelin
had a problem deploying
to
integration
September 25, 2026 13:10 — with
GitHub Actions
Failure
sgamelin
had a problem deploying
to
integration
September 25, 2026 13:10 — with
GitHub Actions
Failure
sgamelin
had a problem deploying
to
integration
September 25, 2026 13:10 — with
GitHub Actions
Failure
sgamelin
had a problem deploying
to
integration
September 25, 2026 13:10 — with
GitHub Actions
Failure
sgamelin
had a problem deploying
to
integration
September 25, 2026 13:10 — with
GitHub Actions
Failure
sgamelin
had a problem deploying
to
integration
September 25, 2026 13:10 — with
GitHub Actions
Failure
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This project's CI (via
nisshi-io/nisshi'ssmokejob, which checks thisrepo out and runs its
docker composestack) has been failing atdocker compose up:minio Error unauthorized: access to the requested resource is not authorized.MinIO no longer distributes prebuilt binaries or container images for
anonymous/public use —
dl.min.ionow returns410 Gone, and theminio/minioDocker Hub repository is gone entirely (confirmeddirectly).
quay.io/minio/minio, pinned here, has also stopped servinganonymous pulls.
Both MinIO's server and its
mcclient stay public because they'reAGPLv3-licensed, so this builds both ourselves from that source instead
of depending on any registry's redistribution of them:
etc/minio/Dockerfile: clones the last tagged release of each (ontheir now archived, read-only upstream repos) and runs a plain
go build, matching each project's own local build command ratherthan their release pipelines, which themselves depend on the now-dead
dl.min.iodownloads.mcis needed alongside the server becauseCI execs it inside the same container (
docker compose exec minio /usr/bin/mc ...), matching the previous image's layout.compose.yaml: theminioservice now builds that image instead ofpulling a fixed reference.
Same fix as nisshi-io/nisshi#754,
applied here since this repo has its own separate
compose.yamlandminiopin.Also included: stop routing local minio test credentials through secrets
.github/workflows/ci.ymlsourced themc/AWS_*credentials for theephemeral, local-only MinIO instance from
${{ secrets.AWS_ACCESS_KEY_ID }}/${{ secrets.AWS_SECRET_ACCESS_KEY }}, gated behind anintegrationenvironment. These aren't real credentials — they're MinIO's default
root user/password for a container that only ever exists for the
duration of one CI job — so there's no reason to route them through
secrets, and
nisshi-io/nisshi's ownci.ymlalready treats theidentical value as a plain literal (
minioadmin).Beyond being unnecessary, this was actively causing a problem while
testing this very fix: GitHub withholds secrets from
pull_requestrunstriggered by a fork (as this PR is, since I don't have push access here),
so every run on this PR failed at
mc mbwithAccess Denied— themc/miniobuild itself worked fine (mc ready localsucceeded), itwas purely the empty secrets breaking the next step. Switched both
occurrences to the literal
minioadmin, and droppedenvironment: integrationfrom the job since it had no protection rules configured(confirmed via the API) and existed only to scope secret access.
Verification
Verified in the sibling fix for
nisshi-io/nisshi(identical Dockerfile,same MinIO/mc versions):
docker compose build miniosucceeds (~45s once the Go build cache iswarm).
docker compose up miniostarts successfully and reports(healthy).compose.yaml(
timeout 5s bash -c ...) passes inside the built image —bashadded to the minimal base image for this, since the previous
(registry-pulled) image happened to include it.
minio --version/mc --versionboth report their pinned releasetags correctly.
/minio/health/liveendpoint returns200.mc ready local,mc alias set, andmc mb(the exact commands CIruns) all succeed against the running container.
example (ubuntu-latest, ...)) exercises the samedocker compose up+mcsequence directly; confirmed the minio builditself succeeds there (
mc ready localpassed before the pre-existingsecrets issue was found and fixed above).
Expected failure on this PR: every
postgres://...matrix leg (pre-existing, unrelated to this change)Every
s3://nisshi/leg passes; everypostgres://postgres:postgres@dbleg fails, consistently, on every OS/Kafka-version combination. Root
cause is schema drift, not this change and not a timing flake:
etc/initdb.d/010-schema.sqlin this repo predates several schemachanges already live in
ghcr.io/nisshi-io/nisshi:main(a repartitionedheadertable keyed on(topition, offset_id, ordinal)instead of(id, record, k), and avirtual_topictable this repo's schema doesn'thave at all). Against the mismatched schema, produce fails silently
(
tests/test-topic.bats'sproducetest doesn't check$status), whichcascades into the stale-offset/timeout/
node assignmentfailures furtherinto the suite. Confirmed by reproduction: the identical test suite fails
3/3 runs against this repo's schema and passes 3/3 runs against nisshi's
current schema, with no other change.
This repo's own CI (
ci.yml) has apparently never exercised the postgresleg cleanly against a schema this far out of date —
nisshi-io/nisshi'ssmokejob doesn't hit it because that job copies nisshi's currentschema over this repo's before bringing the stack up.
Not fixed in this PR (scope is the minio/CI-credentials issue above) —
flagging clearly here so a reviewer doesn't mistake the postgres legs for
a regression from this change.
Risks / follow-ups
RELEASE.2025-10-15T17-29-55Z(minio) andRELEASE.2025-08-13T08-35-41Z(mc), the last officially taggedreleases before each upstream repo was archived.
fast enough that this wasn't judged necessary.
🤖 Generated with Claude Code