Skip to content

[FIX] Pull MinIO from unstract/* Chainguard mirrors now that quay.io requires auth - #2300

Merged
jaseemjaskp merged 1 commit into
mainfrom
UN-minio-chainguard-image
Sep 25, 2026
Merged

jaseemjaskp merged 1 commit into
mainfrom
UN-minio-chainguard-image

Conversation

@jaseemjaskp

Copy link
Copy Markdown
Contributor

What

  • Switch every OSS MinIO image reference from quay.io/minio/* to Unstract-owned Docker Hub mirrors of the Chainguard images, pinned by digest:
    • unstract/minio:RELEASE.2026-09-22T19-25-18Z ← cgr.dev/chainguard/minio:latest
    • unstract/minio-client:2026-09-24-dev ← cgr.dev/chainguard/minio-client:latest-dev
  • Files: docker/docker-compose-dev-essentials.yaml (minio, minio-bootstrap) and tests/rig/runtime.py (testcontainers MinioContainer).

Why

  • quay.io/minio/minio and quay.io/minio/mc now return unauthorized: access to the requested resource is not authorized, which fails both the integration tier (testcontainers ImageNotFound) and the e2e tier (compose pull of minio/minio-bootstrap) — e.g. https://github.com/Zipstack/unstract/actions/runs/36096700836/job/107950388806
  • Mirroring under unstract/* means we no longer depend on a third-party registry staying anonymously pullable.

How

  • Copied the multi-arch (amd64 + arm64) indexes with docker buildx imagetools create; digests are identical to the Chainguard originals.
  • minio-bootstrap uses the -dev client variant because its entrypoint runs through /bin/sh, which the distroless variant lacks.
  • The minio service gets user: root: the Chainguard image runs as uid 65532, and against an existing root-owned minio_data volume it fails with file access denied.

Can this PR break any existing features. If yes, please list possible items. If no, please explain why. (PS: Admins do not merge the PR without this section filled)

  • Low risk. MinIO moves from RELEASE.2025-09-07 to RELEASE.2026-09-22 (same S3 API; the on-disk format is read by newer releases). Existing local volumes stay writable because of user: root. The bootstrap script is unchanged and verified.

Database Migrations

  • None

Env Config

  • None

Relevant Docs

Related Issues or PRs

Dependencies Versions

  • MinIO server RELEASE.2026-09-22T19-25-18Z (Chainguard build)

Notes on Testing

  • docker compose -f docker-compose-dev-essentials.yaml up minio minio-bootstrap: minio healthy, bootstrap logs Bucket created successfully minio/unstract.
  • testcontainers 4.14.2 MinioContainer with the new image: started; bucket create/list works.
  • Simulated a root-owned pre-existing volume: fails without user: root, works with it.

Screenshots

Checklist

I have read and understood the Contribution Guidelines.

…requires auth

quay.io/minio/minio and quay.io/minio/mc started returning 'unauthorized',
breaking the integration (testcontainers) and e2e (compose) CI tiers.
Mirror cgr.dev/chainguard/minio and minio-client:latest-dev to Docker Hub
under unstract/* and pin by digest. Run minio as root so existing
root-owned minio_data volumes stay writable under Chainguard's uid 65532.
@sonarqubecloud

Copy link
Copy Markdown

@greptile-apps

greptile-apps Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

via Greptile

RetriggerConfidence Score: 5/5

[Medium risk] Switches container image sources for MinIO services.

The PR appears safe to merge; no actionable regression was established.

Summary

The PR replaces inaccessible quay.io MinIO images with digest-pinned Unstract mirrors in the development Compose stack and testcontainers rig. It also runs the Compose MinIO server as root to retain write access to existing data volumes.

Reviews (1) · Last reviewed commit: "[FIX] Pull MinIO from unstract/* Chaingu..."

@github-actions

Copy link
Copy Markdown
Contributor

Unstract test results

Per-group results

Status Group Tier Passed Failed Errors Skipped Duration (s)
✅ e2e-api-deployment e2e 3 0 0 0 14.6
✅ e2e-coowners e2e 1 0 0 0 1.7
✅ e2e-etl e2e 1 0 0 0 8.5
✅ e2e-login e2e 2 0 0 0 1.2
✅ e2e-prompt-studio e2e 1 0 0 0 9.9
✅ e2e-smoke e2e 2 0 0 0 1.4
✅ e2e-workflow e2e 1 0 0 0 16.3
❌ frontend unit 0 1 0 0 0.0
✅ integration-backend integration 603 0 0 26 45.1
✅ integration-connectors integration 1 0 0 7 7.5
❌ integration-workers integration 159 5 0 1 36.2
❌ ui e2e 0 1 0 0 0.0
✅ unit-backend unit 1320 0 0 1 44.2
✅ unit-connectors unit 72 0 0 0 10.0
✅ unit-core unit 237 0 0 0 2.9
✅ unit-platform-service unit 15 0 0 0 2.7
✅ unit-rig unit 120 0 0 0 4.6
✅ unit-runner unit 10 0 0 0 2.9
✅ unit-sdk1 unit 587 0 0 0 31.6
✅ unit-workers unit 1373 0 0 1 119.7
TOTAL 4508 7 0 36 361.1

Critical paths

⚠️ Critical paths not yet covered

  • workflow-execution-fan-out — Multi-file workflow execution fans out to file-processing workers and rejoins. (declared coverage: no groups declared)
✅ Covered critical paths
  • auth-login — covered by e2e-login
  • adapter-register-llm — covered by integration-backend
  • workflow-author — covered by integration-backend
  • co-owner-manage — covered by integration-backend, e2e-coowners
  • workflow-create-execute — covered by e2e-workflow
  • api-deployment-provision — covered by integration-backend
  • api-deployment-auth — covered by integration-backend
  • api-deployment-run — covered by e2e-api-deployment
  • mcp-server-auth — covered by integration-backend
  • mcp-platform-auth — covered by integration-backend
  • platform-key-whoami — covered by integration-backend
  • prompt-studio-author — covered by integration-backend
  • prompt-studio-fetch-response — covered by e2e-prompt-studio
  • connector-register-test — covered by integration-backend
  • pipeline-etl-execute — covered by e2e-etl
  • usage-aggregate-read — covered by integration-backend
  • usage-token-tracking — covered by e2e-api-deployment
  • callback-result-delivery — covered by e2e-api-deployment

@jaseemjaskp
jaseemjaskp merged commit c19081c into main Sep 25, 2026
10 checks passed
@jaseemjaskp
jaseemjaskp deleted the UN-minio-chainguard-image branch September 25, 2026 05:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants