[FIX] Pull MinIO from unstract/* Chainguard mirrors now that quay.io requires auth - #2300
Merged
Merged
Conversation
…requires auth quay.io/minio/minio and quay.io/minio/mc started returning 'unauthorized', breaking the integration (testcontainers) and e2e (compose) CI tiers. Mirror cgr.dev/chainguard/minio and minio-client:latest-dev to Docker Hub under unstract/* and pin by digest. Run minio as root so existing root-owned minio_data volumes stay writable under Chainguard's uid 65532.
|
ritwik-g
approved these changes
Sep 25, 2026
Contributor
|
Contributor
Unstract test resultsPer-group results
Critical paths
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



What
quay.io/minio/*to Unstract-owned Docker Hub mirrors of the Chainguard images, pinned by digest:unstract/minio:RELEASE.2026-09-22T19-25-18Z←cgr.dev/chainguard/minio:latestunstract/minio-client:2026-09-24-dev←cgr.dev/chainguard/minio-client:latest-devdocker/docker-compose-dev-essentials.yaml(minio,minio-bootstrap) andtests/rig/runtime.py(testcontainersMinioContainer).Why
quay.io/minio/minioandquay.io/minio/mcnow returnunauthorized: access to the requested resource is not authorized, which fails both the integration tier (testcontainersImageNotFound) and the e2e tier (compose pull ofminio/minio-bootstrap) — e.g. https://github.com/Zipstack/unstract/actions/runs/36096700836/job/107950388806unstract/*means we no longer depend on a third-party registry staying anonymously pullable.How
docker buildx imagetools create; digests are identical to the Chainguard originals.minio-bootstrapuses the-devclient variant because its entrypoint runs through/bin/sh, which the distroless variant lacks.minioservice getsuser: root: the Chainguard image runs as uid 65532, and against an existing root-ownedminio_datavolume it fails withfile access denied.Can this PR break any existing features. If yes, please list possible items. If no, please explain why. (PS: Admins do not merge the PR without this section filled)
RELEASE.2025-09-07toRELEASE.2026-09-22(same S3 API; the on-disk format is read by newer releases). Existing local volumes stay writable because ofuser: root. The bootstrap script is unchanged and verified.Database Migrations
Env Config
Relevant Docs
Related Issues or PRs
Dependencies Versions
RELEASE.2026-09-22T19-25-18Z(Chainguard build)Notes on Testing
docker compose -f docker-compose-dev-essentials.yaml up minio minio-bootstrap: minio healthy, bootstrap logsBucket created successfully minio/unstract.MinioContainerwith the new image: started; bucket create/list works.user: root, works with it.Screenshots
Checklist
I have read and understood the Contribution Guidelines.