From 6f3f8441b3aed6b64564ee3827ad6ae460cbc217 Mon Sep 17 00:00:00 2001 From: Michael Bunsen Date: Mon, 28 Sep 2026 14:44:46 -0700 Subject: [PATCH 1/4] fix(minio): make the bucket setup script work with current mc and fail on errors Current mc releases no longer have `mc config host add`, so the setup script now uses `mc alias set`. The script also stops on the first error; before, a failed setup exited 0 and left the storage tests erroring later with no clue. Co-Authored-By: Claude Fable 5.1 Claude-Session: https://claude.ai/code/session_01C7Xf6VPbwWtTumhjjF15g8 --- compose/local/minio/init.sh | 9 ++++----- 1 file changed, 4 insertions(+), 5 deletions(-) diff --git a/compose/local/minio/init.sh b/compose/local/minio/init.sh index 746627f0d..1cc007eaa 100755 --- a/compose/local/minio/init.sh +++ b/compose/local/minio/init.sh @@ -1,13 +1,12 @@ #!/bin/sh +# Stop on the first error so a failed bucket setup fails this container instead of passing silently. +set -e -# Create a default bucket -# /usr/bin/mc set alias minio "${MINIO_ENDPOINT}" "${MINIO_ROOT_USER}" "${MINIO_ROOT_PASSWORD}" -/usr/bin/mc config host add local "${MINIO_ENDPOINT}" "${MINIO_ROOT_USER}" "${MINIO_ROOT_PASSWORD}" +# Create the default buckets. Current mc releases dropped `mc config host add`, so use `mc alias set`. +/usr/bin/mc alias set local "${MINIO_ENDPOINT}" "${MINIO_ROOT_USER}" "${MINIO_ROOT_PASSWORD}" /usr/bin/mc mb local/"${MINIO_DEFAULT_BUCKET}" --ignore-existing /usr/bin/mc mb local/"${MINIO_TEST_BUCKET}" --ignore-existing # Give it public read access /usr/bin/mc anonymous set public local/"${MINIO_DEFAULT_BUCKET}" /usr/bin/mc anonymous set public local/"${MINIO_TEST_BUCKET}" - -exit 0 From e8a4a43f16f7de4dcc411fed7feebd2334a5d527 Mon Sep 17 00:00:00 2001 From: Michael Bunsen Date: Mon, 28 Sep 2026 14:44:46 -0700 Subject: [PATCH 2/4] fix(ci): pull MinIO from a registry that still allows anonymous pulls Docker Hub and quay.io both now refuse anonymous pulls of the MinIO images, so Backend Tests stopped before running any test. Both compose files now use the Chainguard MinIO image, pinned by digest. It ships the server, mc and a shell, so the bucket setup container reuses it. The local dev server runs as root so volumes written by the previous image stay readable, and bucket setup waits for MinIO to be healthy. Co-Authored-By: Claude Fable 5.1 Claude-Session: https://claude.ai/code/session_01C7Xf6VPbwWtTumhjjF15g8 --- docker-compose.ci.yml | 11 +++++++---- docker-compose.yml | 19 +++++++++++++------ 2 files changed, 20 insertions(+), 10 deletions(-) diff --git a/docker-compose.ci.yml b/docker-compose.ci.yml index 0bde678d3..c299e7c24 100644 --- a/docker-compose.ci.yml +++ b/docker-compose.ci.yml @@ -63,8 +63,11 @@ services: - ./.envs/.ci/.django minio: - image: quay.io/minio/minio:RELEASE.2024-11-07T00-52-20Z - command: minio server --console-address ":9001" /data + # MinIO no longer publishes pullable images (Docker Hub and quay.io both require a login). + # This image bundles the server, mc and a shell, so minio-init reuses it. Pinned by digest; + # to bump: docker pull cgr.dev/chainguard/minio:latest, then copy RepoDigests from docker image inspect. + image: cgr.dev/chainguard/minio:latest@sha256:6a1d0b45c8669726bba580ced0bfa4cb9fdeed1ed636dfabd81d1577beb6937b + command: server --console-address ":9001" /data volumes: - "minio_ci_data:/data" env_file: @@ -76,7 +79,7 @@ services: retries: 5 minio-init: - image: quay.io/minio/mc:RELEASE.2025-03-12T17-29-24Z + image: cgr.dev/chainguard/minio:latest@sha256:6a1d0b45c8669726bba580ced0bfa4cb9fdeed1ed636dfabd81d1577beb6937b env_file: - ./.envs/.ci/.django depends_on: @@ -84,7 +87,7 @@ services: condition: service_healthy volumes: - ./compose/local/minio/init.sh:/etc/minio/init.sh - entrypoint: /etc/minio/init.sh + entrypoint: ["/bin/sh", "/etc/minio/init.sh"] ml_backend: build: diff --git a/docker-compose.yml b/docker-compose.yml index 152d9ae42..901ee9e46 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -139,8 +139,13 @@ services: - antenna_network minio: - image: quay.io/minio/minio:RELEASE.2024-11-07T00-52-20Z - command: minio server --console-address ":9001" /data + # MinIO no longer publishes pullable images (Docker Hub and quay.io both require a login). + # This image bundles the server, mc and a shell, so minio-init reuses it. Pinned by digest; + # to bump: docker pull cgr.dev/chainguard/minio:latest, then copy RepoDigests from docker image inspect. + image: cgr.dev/chainguard/minio:latest@sha256:6a1d0b45c8669726bba580ced0bfa4cb9fdeed1ed636dfabd81d1577beb6937b + command: server --console-address ":9001" /data + # Existing dev volumes were written by the old image as root; the new one defaults to a non-root user. + user: root volumes: - "minio_data:/data" env_file: @@ -165,15 +170,17 @@ services: - minio minio-init: - image: quay.io/minio/mc:RELEASE.2025-03-12T17-29-24Z + image: cgr.dev/chainguard/minio:latest@sha256:6a1d0b45c8669726bba580ced0bfa4cb9fdeed1ed636dfabd81d1577beb6937b env_file: - ./.envs/.local/.django depends_on: - - minio - - minio-proxy + minio: + condition: service_healthy + minio-proxy: + condition: service_started volumes: - ./compose/local/minio/init.sh:/etc/minio/init.sh - entrypoint: /etc/minio/init.sh + entrypoint: ["/bin/sh", "/etc/minio/init.sh"] ml_backend: build: From 5fad924677df514cff266efcb5dbe7126da53229 Mon Sep 17 00:00:00 2001 From: Michael Bunsen Date: Mon, 28 Sep 2026 15:09:30 -0700 Subject: [PATCH 3/4] fix(ci): stop the test job when MinIO bucket setup fails The test container waited only for the bucket setup container to start, so a failed setup still let the tests run and fail later with no clear cause. The test container now waits for bucket setup to finish successfully, and compose aborts the run with the setup container's exit status otherwise. Co-Authored-By: Claude Fable 5.1 Claude-Session: https://claude.ai/code/session_01C7Xf6VPbwWtTumhjjF15g8 --- docker-compose.ci.yml | 19 +++++++++++++------ 1 file changed, 13 insertions(+), 6 deletions(-) diff --git a/docker-compose.ci.yml b/docker-compose.ci.yml index c299e7c24..fa9d13be0 100644 --- a/docker-compose.ci.yml +++ b/docker-compose.ci.yml @@ -17,12 +17,19 @@ services: extra_hosts: - "host.docker.internal:host-gateway" depends_on: - - postgres - - redis - - minio-init - - ml_backend - - rabbitmq - - nats + postgres: + condition: service_started + redis: + condition: service_started + # Wait for bucket setup to succeed so a failure stops the job here, not in later tests. + minio-init: + condition: service_completed_successfully + ml_backend: + condition: service_started + rabbitmq: + condition: service_started + nats: + condition: service_started env_file: - ./.envs/.ci/.django - ./.envs/.ci/.postgres From ae976d75cd4513534ce71700a5067579c6625b38 Mon Sep 17 00:00:00 2001 From: Michael Bunsen Date: Mon, 28 Sep 2026 20:57:43 -0700 Subject: [PATCH 4/4] fix(compose): start local Django only after MinIO bucket setup succeeds Co-Authored-By: Claude Opus 5.5 (1M context) Claude-Session: https://claude.ai/code/session_01C7Xf6VPbwWtTumhjjF15g8 --- docker-compose.yml | 19 +++++++++++++------ 1 file changed, 13 insertions(+), 6 deletions(-) diff --git a/docker-compose.yml b/docker-compose.yml index 901ee9e46..be3e9b2a7 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -19,12 +19,19 @@ services: extra_hosts: - "host.docker.internal:host-gateway" depends_on: - - postgres - - redis - - nats - - minio-init - - ml_backend - - rabbitmq + postgres: + condition: service_started + redis: + condition: service_started + nats: + condition: service_started + # Wait for bucket setup to succeed, so Django never starts against missing buckets. + minio-init: + condition: service_completed_successfully + ml_backend: + condition: service_started + rabbitmq: + condition: service_started volumes: - .:/app:z env_file: