Skip to content

fix(ci): pull MinIO from quay.io, not Docker Hub - #304

Merged
LKSNDRTMLKV merged 2 commits into
mainfrom
fix/minio-image-source
Sep 13, 2026
Merged

LKSNDRTMLKV merged 2 commits into
mainfrom
fix/minio-image-source

Conversation

@LKSNDRTMLKV

Copy link
Copy Markdown
Member

🚨 This blocks every pull request in the repository, and therefore the 0.13.0 release.

What happened

docker.io/minio/minio has been removed from Docker Hub.

docker: Error response from daemon: pull access denied for minio/minio,
        repository does not exist or may require 'docker login'

Every PR fails at the Start MinIO step of Integration tests (testcontainers) and can never reach a mergeable state. I found it on the docs PR (#303) for this release.

It is not a flake and not a rate limit

Established before changing anything:

Check Result
Re-ran the failed job failed at the same step
Pulled from my own machine, different network same denial
Pulled minio/minio:latest (not just the pinned tag) same denial
hub.docker.com/v2/repositories/minio/minio 404 — the repository is gone

A rate limit answers toomanyrequests; a 404 on the repository endpoint is the repository not existing. PR #292 passed this same job earlier today, so it disappeared within hours.

The fix

Both pin sites move to quay.io, MinIO's own registry:

quay.io/minio/minio:RELEASE.2025-09-07T16-13-09Z

The exact pinned tag exists there — I checked the tag list before assuming, and it is present alongside …-cpuv1 and …hotfix.… variants. So this is a host change only: same publisher, same release tag, same build. What the tests exercise does not change, which is the whole reason for preferring it over bumping to a newer release while CI is red.

Two sites, because the workflow step and s3_archive.rs are pinned as a pair and the file already said they "must move together". Both now also record why the registry is not Docker Hub, so the next person does not repoint it back.

Verified, not assumed

docker pull quay.io/minio/minio:RELEASE.2025-09-07T16-13-09Z   → Downloaded
cargo nextest run -p dpp-node --features integration-tests,s3 --test s3_archive
     Summary [4.714s] 4 tests run: 4 passed, 0 skipped

That also confirms testcontainers' GenericImage::new accepts a registry-qualified image name — the one thing about this change that could have failed quietly.

Note on the supply chain

This repoints a build input to a different registry, which is a supply-chain change and worth stating plainly rather than burying: it is the same publisher's own registry, carrying the same tag that was previously pulled from Docker Hub, and the pin stays exact. No version was bumped to get CI green.

Merge this first — #303 and the release cut are both blocked behind it.

@LKSNDRTMLKV
LKSNDRTMLKV merged commit bfbec14 into main Sep 13, 2026
14 checks passed
@LKSNDRTMLKV
LKSNDRTMLKV deleted the fix/minio-image-source branch September 13, 2026 07:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant