From 0fd8f0dc7a0357694d0dadc403efec3c71cf7268 Mon Sep 17 00:00:00 2001 From: Dimitri Yatsenko Date: Fri, 2 Oct 2026 22:09:25 -0500 Subject: [PATCH] fix(ci): pull MinIO from a registry that still serves it The Development workflow -- the docs site deploy -- has failed on every push to main since MinIO withdrew its public images: minio Error pull access denied for minio/minio, repository does not exist or may require 'docker login' `minio/minio` on Docker Hub is gone entirely, any tag, and `quay.io/minio/minio` now requires authentication. Chainguard publishes a maintained build that needs no credentials, ships `mc` so the healthcheck is unchanged, and is what datajoint-python's test fixture already uses. Overridable through MINIO_IMAGE so a deployment can point at its own mirror. Verified by running what CI runs -- `MODE=BUILD docker compose up --exit-code-from docs --build` -- end to end: minio healthy in about ten seconds, site built, every container exited 0. One local-only wrinkle, documented in the file: the image runs as `nonroot`, so a `minio_data` volume left behind by the old root-owned image is not writable and MinIO exits with "Unable to write to the backend". A fresh volume inherits the image's world-writable /data, so `docker compose down -v` clears it once. CI runners start clean. --- docker-compose.yaml | 13 ++++++++++++- 1 file changed, 12 insertions(+), 1 deletion(-) diff --git a/docker-compose.yaml b/docker-compose.yaml index 384e5f7f..db5e9a98 100644 --- a/docker-compose.yaml +++ b/docker-compose.yaml @@ -37,7 +37,18 @@ services: retries: 10 minio: - image: minio/minio:latest + # MinIO withdrew its public images: `minio/minio` on Docker Hub is gone + # entirely, any tag, and `quay.io/minio/minio` now requires authentication. + # Chainguard publishes a maintained build that needs no credentials and is + # drop-in here -- it ships `mc`, so the healthcheck below is unchanged. + # Matches what datajoint-python's test fixture uses. + # + # It runs as `nonroot`, and a `minio_data` volume left behind by the old + # root-owned image is not writable by it: MinIO exits with "Unable to write + # to the backend". A fresh volume inherits the image's world-writable /data + # and is fine, so `docker compose down -v` once clears it. CI runners start + # clean and never see this. + image: ${MINIO_IMAGE:-cgr.dev/chainguard/minio:latest} environment: MINIO_ROOT_USER: datajoint MINIO_ROOT_PASSWORD: datajoint