From 52a0c1ee1589f4fd7f4cb217173d1f1f926a80c5 Mon Sep 17 00:00:00 2001 From: Karl Anderson Date: Thu, 24 Sep 2026 15:00:41 -0700 Subject: [PATCH 1/7] use minimus as a minio image replacement instead of quay.io --- docker-compose.ci.yml | 4 ++-- docker-compose.yml | 4 ++-- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/docker-compose.ci.yml b/docker-compose.ci.yml index 0bde678d3..6e6903621 100644 --- a/docker-compose.ci.yml +++ b/docker-compose.ci.yml @@ -63,7 +63,7 @@ services: - ./.envs/.ci/.django minio: - image: quay.io/minio/minio:RELEASE.2024-11-07T00-52-20Z + image: reg.mini.dev/minio:latest command: minio server --console-address ":9001" /data volumes: - "minio_ci_data:/data" @@ -76,7 +76,7 @@ services: retries: 5 minio-init: - image: quay.io/minio/mc:RELEASE.2025-03-12T17-29-24Z + image: reg.mini.dev/minio:latest env_file: - ./.envs/.ci/.django depends_on: diff --git a/docker-compose.yml b/docker-compose.yml index 152d9ae42..4239db777 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -139,7 +139,7 @@ services: - antenna_network minio: - image: quay.io/minio/minio:RELEASE.2024-11-07T00-52-20Z + image: reg.mini.dev/minio:latest command: minio server --console-address ":9001" /data volumes: - "minio_data:/data" @@ -165,7 +165,7 @@ services: - minio minio-init: - image: quay.io/minio/mc:RELEASE.2025-03-12T17-29-24Z + image: reg.mini.dev/minio:latest env_file: - ./.envs/.local/.django depends_on: From a16c2c4d086e501e9bd477506fe52e044eb49f38 Mon Sep 17 00:00:00 2001 From: Michael Bunsen Date: Mon, 28 Sep 2026 14:44:46 -0700 Subject: [PATCH 2/7] fix(minio): make the bucket setup script work with current mc and fail on errors Current mc releases no longer have `mc config host add`, so the setup script now uses `mc alias set`. The script also stops on the first error; before, a failed setup exited 0 and left the storage tests erroring later with no clue. Co-Authored-By: Claude Fable 5.1 Claude-Session: https://claude.ai/code/session_01C7Xf6VPbwWtTumhjjF15g8 --- compose/local/minio/init.sh | 9 ++++----- 1 file changed, 4 insertions(+), 5 deletions(-) diff --git a/compose/local/minio/init.sh b/compose/local/minio/init.sh index 746627f0d..1cc007eaa 100755 --- a/compose/local/minio/init.sh +++ b/compose/local/minio/init.sh @@ -1,13 +1,12 @@ #!/bin/sh +# Stop on the first error so a failed bucket setup fails this container instead of passing silently. +set -e -# Create a default bucket -# /usr/bin/mc set alias minio "${MINIO_ENDPOINT}" "${MINIO_ROOT_USER}" "${MINIO_ROOT_PASSWORD}" -/usr/bin/mc config host add local "${MINIO_ENDPOINT}" "${MINIO_ROOT_USER}" "${MINIO_ROOT_PASSWORD}" +# Create the default buckets. Current mc releases dropped `mc config host add`, so use `mc alias set`. +/usr/bin/mc alias set local "${MINIO_ENDPOINT}" "${MINIO_ROOT_USER}" "${MINIO_ROOT_PASSWORD}" /usr/bin/mc mb local/"${MINIO_DEFAULT_BUCKET}" --ignore-existing /usr/bin/mc mb local/"${MINIO_TEST_BUCKET}" --ignore-existing # Give it public read access /usr/bin/mc anonymous set public local/"${MINIO_DEFAULT_BUCKET}" /usr/bin/mc anonymous set public local/"${MINIO_TEST_BUCKET}" - -exit 0 From 1fb4d6aa53287e3e54b23544a247409f0cf4d357 Mon Sep 17 00:00:00 2001 From: Michael Bunsen Date: Mon, 28 Sep 2026 15:09:30 -0700 Subject: [PATCH 3/7] fix(ci): stop the test job when MinIO bucket setup fails The test container waited only for the bucket setup container to start, so a failed setup still let the tests run and fail later with no clear cause. The test container now waits for bucket setup to finish successfully, and compose aborts the run with the setup container's exit status otherwise. Co-Authored-By: Claude Fable 5.1 Claude-Session: https://claude.ai/code/session_01C7Xf6VPbwWtTumhjjF15g8 --- docker-compose.ci.yml | 19 +++++++++++++------ 1 file changed, 13 insertions(+), 6 deletions(-) diff --git a/docker-compose.ci.yml b/docker-compose.ci.yml index 6e6903621..b98ee4561 100644 --- a/docker-compose.ci.yml +++ b/docker-compose.ci.yml @@ -17,12 +17,19 @@ services: extra_hosts: - "host.docker.internal:host-gateway" depends_on: - - postgres - - redis - - minio-init - - ml_backend - - rabbitmq - - nats + postgres: + condition: service_started + redis: + condition: service_started + # Wait for bucket setup to succeed so a failure stops the job here, not in later tests. + minio-init: + condition: service_completed_successfully + ml_backend: + condition: service_started + rabbitmq: + condition: service_started + nats: + condition: service_started env_file: - ./.envs/.ci/.django - ./.envs/.ci/.postgres From 5adafb94d9549510bee7b86b66cf0f34e2d77747 Mon Sep 17 00:00:00 2001 From: Michael Bunsen Date: Mon, 28 Sep 2026 20:57:43 -0700 Subject: [PATCH 4/7] fix(compose): start local Django only after MinIO bucket setup succeeds In the local development stack, Django waited only for the bucket setup container to start, and the setup container did not wait for the MinIO server to be healthy. Django could therefore start against missing buckets, and setup could race the server on a cold start. The setup container now waits for the server's healthcheck, and Django (plus the services that inherit its settings) waits for setup to complete successfully, matching the CI stack. Co-Authored-By: Claude Fable 5.1 Claude-Session: https://claude.ai/code/session_01C7Xf6VPbwWtTumhjjF15g8 --- docker-compose.yml | 25 +++++++++++++++++-------- 1 file changed, 17 insertions(+), 8 deletions(-) diff --git a/docker-compose.yml b/docker-compose.yml index 4239db777..5980776ba 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -19,12 +19,19 @@ services: extra_hosts: - "host.docker.internal:host-gateway" depends_on: - - postgres - - redis - - nats - - minio-init - - ml_backend - - rabbitmq + postgres: + condition: service_started + redis: + condition: service_started + nats: + condition: service_started + # Wait for bucket setup to succeed, so Django never starts against missing buckets. + minio-init: + condition: service_completed_successfully + ml_backend: + condition: service_started + rabbitmq: + condition: service_started volumes: - .:/app:z env_file: @@ -169,8 +176,10 @@ services: env_file: - ./.envs/.local/.django depends_on: - - minio - - minio-proxy + minio: + condition: service_healthy + minio-proxy: + condition: service_started volumes: - ./compose/local/minio/init.sh:/etc/minio/init.sh entrypoint: /etc/minio/init.sh From d23f7c02377c21f77d79acbb2f86ab19cc7eb9b2 Mon Sep 17 00:00:00 2001 From: Michael Bunsen Date: Mon, 28 Sep 2026 22:01:46 -0700 Subject: [PATCH 5/7] fix(compose): pull MinIO from a registry that will still exist after October 2026 Minimus has announced that it will turn off its registry (reg.mini.dev) on 22 October 2026, so the image this branch switched to would stop being pullable in a few weeks. Both compose files now use Chainguard's MinIO image instead, which is publicly pullable and pinned by digest so it cannot change under us. The digest is a multi-arch index, so it works on amd64 and arm64. The Chainguard image bundles the server, mc and a shell, so the same image serves the server and the bucket setup container. Its entrypoint is the minio binary itself, so the server command drops the leading "minio", and the setup script is run through /bin/sh explicitly. The image runs as a non-root user by default, which cannot write to local development volumes created by the previous image, so the development server runs as root. Co-Authored-By: Claude Fable 5.1 Claude-Session: https://claude.ai/code/session_01C7Xf6VPbwWtTumhjjF15g8 --- docker-compose.ci.yml | 8 ++++---- docker-compose.yml | 10 ++++++---- 2 files changed, 10 insertions(+), 8 deletions(-) diff --git a/docker-compose.ci.yml b/docker-compose.ci.yml index b98ee4561..6712caad3 100644 --- a/docker-compose.ci.yml +++ b/docker-compose.ci.yml @@ -70,8 +70,8 @@ services: - ./.envs/.ci/.django minio: - image: reg.mini.dev/minio:latest - command: minio server --console-address ":9001" /data + image: cgr.dev/chainguard/minio:latest@sha256:6a1d0b45c8669726bba580ced0bfa4cb9fdeed1ed636dfabd81d1577beb6937b + command: server --console-address ":9001" /data volumes: - "minio_ci_data:/data" env_file: @@ -83,7 +83,7 @@ services: retries: 5 minio-init: - image: reg.mini.dev/minio:latest + image: cgr.dev/chainguard/minio:latest@sha256:6a1d0b45c8669726bba580ced0bfa4cb9fdeed1ed636dfabd81d1577beb6937b env_file: - ./.envs/.ci/.django depends_on: @@ -91,7 +91,7 @@ services: condition: service_healthy volumes: - ./compose/local/minio/init.sh:/etc/minio/init.sh - entrypoint: /etc/minio/init.sh + entrypoint: ["/bin/sh", "/etc/minio/init.sh"] ml_backend: build: diff --git a/docker-compose.yml b/docker-compose.yml index 5980776ba..ba6117894 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -146,8 +146,10 @@ services: - antenna_network minio: - image: reg.mini.dev/minio:latest - command: minio server --console-address ":9001" /data + image: cgr.dev/chainguard/minio:latest@sha256:6a1d0b45c8669726bba580ced0bfa4cb9fdeed1ed636dfabd81d1577beb6937b + command: server --console-address ":9001" /data + # Existing dev volumes were written by the old image as root; the new one defaults to a non-root user. + user: root volumes: - "minio_data:/data" env_file: @@ -172,7 +174,7 @@ services: - minio minio-init: - image: reg.mini.dev/minio:latest + image: cgr.dev/chainguard/minio:latest@sha256:6a1d0b45c8669726bba580ced0bfa4cb9fdeed1ed636dfabd81d1577beb6937b env_file: - ./.envs/.local/.django depends_on: @@ -182,7 +184,7 @@ services: condition: service_started volumes: - ./compose/local/minio/init.sh:/etc/minio/init.sh - entrypoint: /etc/minio/init.sh + entrypoint: ["/bin/sh", "/etc/minio/init.sh"] ml_backend: build: From 15f843d64a7c4fb242805885557026a55363dedc Mon Sep 17 00:00:00 2001 From: Michael Bunsen Date: Mon, 28 Sep 2026 22:01:46 -0700 Subject: [PATCH 6/7] docs(compose): explain the MinIO image choice and how to bump the digest pin Chainguard publishes only a "latest" tag publicly, so the digest is the only stable reference. The comment above each MinIO service records why the image was chosen and the two commands needed to move the pin forward. Co-Authored-By: Claude Fable 5.1 Claude-Session: https://claude.ai/code/session_01C7Xf6VPbwWtTumhjjF15g8 --- docker-compose.ci.yml | 3 +++ docker-compose.yml | 3 +++ 2 files changed, 6 insertions(+) diff --git a/docker-compose.ci.yml b/docker-compose.ci.yml index 6712caad3..fa9d13be0 100644 --- a/docker-compose.ci.yml +++ b/docker-compose.ci.yml @@ -70,6 +70,9 @@ services: - ./.envs/.ci/.django minio: + # MinIO no longer publishes pullable images (Docker Hub and quay.io both require a login). + # This image bundles the server, mc and a shell, so minio-init reuses it. Pinned by digest; + # to bump: docker pull cgr.dev/chainguard/minio:latest, then copy RepoDigests from docker image inspect. image: cgr.dev/chainguard/minio:latest@sha256:6a1d0b45c8669726bba580ced0bfa4cb9fdeed1ed636dfabd81d1577beb6937b command: server --console-address ":9001" /data volumes: diff --git a/docker-compose.yml b/docker-compose.yml index ba6117894..be3e9b2a7 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -146,6 +146,9 @@ services: - antenna_network minio: + # MinIO no longer publishes pullable images (Docker Hub and quay.io both require a login). + # This image bundles the server, mc and a shell, so minio-init reuses it. Pinned by digest; + # to bump: docker pull cgr.dev/chainguard/minio:latest, then copy RepoDigests from docker image inspect. image: cgr.dev/chainguard/minio:latest@sha256:6a1d0b45c8669726bba580ced0bfa4cb9fdeed1ed636dfabd81d1577beb6937b command: server --console-address ":9001" /data # Existing dev volumes were written by the old image as root; the new one defaults to a non-root user. From e442bb3c73c2b8783319fe0ff6b356980cf06eef Mon Sep 17 00:00:00 2001 From: Michael Bunsen Date: Tue, 29 Sep 2026 14:22:37 -0700 Subject: [PATCH 7/7] fix(compose): run MinIO from our own insectai/minio image instead of a third-party registry Both the local stack and the CI stack pull insectai/minio, built from pinned pgsty/silo and pgsty/mc sources by RolnickLab/minio-image and published to the sponsored insectai Docker Hub organisation, which is exempt from pull rate limits. The image runs as root like the historical official one, so the user: root override on the dev service is no longer needed. Closes #1445 Co-Authored-By: Claude Fable 5.1 Claude-Session: https://claude.ai/code/session_01FA1nFdyB4WmWTw4syt89Yz --- docker-compose.ci.yml | 8 +++----- docker-compose.yml | 10 +++------- 2 files changed, 6 insertions(+), 12 deletions(-) diff --git a/docker-compose.ci.yml b/docker-compose.ci.yml index fa9d13be0..4caa357f3 100644 --- a/docker-compose.ci.yml +++ b/docker-compose.ci.yml @@ -70,10 +70,8 @@ services: - ./.envs/.ci/.django minio: - # MinIO no longer publishes pullable images (Docker Hub and quay.io both require a login). - # This image bundles the server, mc and a shell, so minio-init reuses it. Pinned by digest; - # to bump: docker pull cgr.dev/chainguard/minio:latest, then copy RepoDigests from docker image inspect. - image: cgr.dev/chainguard/minio:latest@sha256:6a1d0b45c8669726bba580ced0bfa4cb9fdeed1ed636dfabd81d1577beb6937b + # Our own MinIO + mc build, from github.com/RolnickLab/minio-image (bump procedure there). See #1445. + image: insectai/minio:RELEASE.2026-09-16T00-00-00Z@sha256:1dca54196431cf11e745ebf743e1ceaa69f6d5a3070a6d8b068c7f5b0c981fa1 command: server --console-address ":9001" /data volumes: - "minio_ci_data:/data" @@ -86,7 +84,7 @@ services: retries: 5 minio-init: - image: cgr.dev/chainguard/minio:latest@sha256:6a1d0b45c8669726bba580ced0bfa4cb9fdeed1ed636dfabd81d1577beb6937b + image: insectai/minio:RELEASE.2026-09-16T00-00-00Z@sha256:1dca54196431cf11e745ebf743e1ceaa69f6d5a3070a6d8b068c7f5b0c981fa1 env_file: - ./.envs/.ci/.django depends_on: diff --git a/docker-compose.yml b/docker-compose.yml index be3e9b2a7..f8b6d6498 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -146,13 +146,9 @@ services: - antenna_network minio: - # MinIO no longer publishes pullable images (Docker Hub and quay.io both require a login). - # This image bundles the server, mc and a shell, so minio-init reuses it. Pinned by digest; - # to bump: docker pull cgr.dev/chainguard/minio:latest, then copy RepoDigests from docker image inspect. - image: cgr.dev/chainguard/minio:latest@sha256:6a1d0b45c8669726bba580ced0bfa4cb9fdeed1ed636dfabd81d1577beb6937b + # Our own MinIO + mc build, from github.com/RolnickLab/minio-image (bump procedure there). See #1445. + image: insectai/minio:RELEASE.2026-09-16T00-00-00Z@sha256:1dca54196431cf11e745ebf743e1ceaa69f6d5a3070a6d8b068c7f5b0c981fa1 command: server --console-address ":9001" /data - # Existing dev volumes were written by the old image as root; the new one defaults to a non-root user. - user: root volumes: - "minio_data:/data" env_file: @@ -177,7 +173,7 @@ services: - minio minio-init: - image: cgr.dev/chainguard/minio:latest@sha256:6a1d0b45c8669726bba580ced0bfa4cb9fdeed1ed636dfabd81d1577beb6937b + image: insectai/minio:RELEASE.2026-09-16T00-00-00Z@sha256:1dca54196431cf11e745ebf743e1ceaa69f6d5a3070a6d8b068c7f5b0c981fa1 env_file: - ./.envs/.local/.django depends_on: