Repository navigation
fix(ci): pull MinIO from quay.io — docker.io/minio/minio is no longer public - #4208
Conversation
… public Every PR's Example Unit Testing job fails at Start MinIO with "pull access denied for minio/minio, repository does not exist or may require 'docker login'", on all three Go versions. It fails on PRs that touch no example and no workflow, so it is not the PRs: Docker Hub's minio/minio repository is no longer publicly pullable. Checked anonymously rather than inferred: alpine:3.20 resolves, while docker.io/minio/minio:latest AND the digest pinned here both return "denied: requested access to the resource is denied". The last green PR pipeline was 2026-09-11. quay.io/minio/minio:RELEASE.2025-09-07T16-13-09Z carries the identical manifest list — sha256:14cea493… , byte-for-byte the digest already pinned — so this changes the registry and nothing else. The image CI runs is provably the one it ran on 2026-09-11, and the digest pin protecting the integration guard for gofr-dev#3804 stays intact. Bumping to a newer release instead would have changed two things at once. examples/using-s3-filestore/README.md told readers to run the same now-broken docker.io image, so it moves too. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01YMKLwXTgzev7GTP3hSkzv1
aryanmehrotra
left a comment
There was a problem hiding this comment.
Approving. I re-verified the claim independently against the live registries rather than taking the description's word for it:
| check | result |
|---|---|
docker.io/minio/minio:RELEASE.2025-09-07T16-13-09Z (anon) |
HTTP 401 — denied |
docker.io/library/alpine:3.20 (control) |
HTTP 200 — Docker Hub itself is healthy |
quay.io/minio/minio:RELEASE.2025-09-07T16-13-09Z (anon) |
HTTP 200 |
quay.io docker-content-digest |
sha256:14cea493d9a34af32f524e538b8346cf79f3321eff8e708c1e2960462bd8936e |
digest already pinned in go.yml |
sha256:14cea493… — identical |
So this is provably a registry change and not an image change, and the digest pin protecting the #3804 integration guard is unaffected. Keeping the pin rather than bumping to a newer MinIO release was the right call — a version bump would have changed two things at once and made the pin meaningless.
Also confirmed:
grep -rE '(^|[^./a-zA-Z0-9-])minio/minio'over the tree returns exactly the two occurrences this PR changes — no bare reference is left behind.- CI on this PR is green on all three Go versions, i.e.
Example Unit Testingactually reachesgo test ./examples/...again.
For context on why this is worth merging ahead of anything else: the green ticks on the other open PRs are stale, not healthy. Last Example Unit Testing (v1.26) run per PR:
| PR | last run | result |
|---|---|---|
| #4205 | 2026-09-14 04:40 | FAILURE |
| #4203 | 2026-09-11 15:37 | success (pre-break) |
| #4201 | 2026-09-11 11:11 | success (pre-break) |
| #4170 | 2026-09-10 18:29 | success (pre-break) |
Every one of those turns red on its next push. This unblocks all 31 open PRs, not the three currently showing red.
Nit, non-blocking: please strip the 🤖 Generated with [Claude Code] footer and the claude.ai/code/session_… link from the PR description before merge.
Follow-up, deliberately not in this PR. #3868 already predicted this failure class — "it works today; the day it stops working, every example test that touches pub/sub fails at once and the cause will not be obvious from the logs" — and that is exactly what happened here, just with MinIO instead of Kafka. #3868 covers pinning. What no issue covers yet is detection: there is nothing that tells us a required external dependency has become unpullable, so this broke on 2026-09-11 and was found on 2026-09-14 only because a contributor pushed and read a red X as their own fault. I'll open a separate issue for the preflight-job + scheduled-canary side of it.
* Merge pull request #4147 from gofr-dev/chore/gcp-exporter-pin-v1.60.1 chore(metrics): pin gcp exporter to gofr.dev v1.60.1 * fix(middleware): require a path separator in the well-known auth exemption (#4099) * fix(middleware): require a path separator in the well-known auth exemption * test(middleware): cover the rate limiter well-known exemption * chore(middleware): satisfy goconst and noctx in the well-known check * docs(auth): describe the separator requirement in the well-known exemption --------- Co-authored-by: Aryan Mehrotra <aryanmehrotra2000@gmail.com> Co-authored-by: Umang Mundhra <mundhraumang.02@gmail.com> * perf(metrics): build the measurement option once per route, method and status (#3972) * perf(http): pool the response envelope and stop recanonicalising Content-Type (#3973) * perf(cors): build the fixed response headers once, not per request (#3971) * fix: prevent concurrent map panic during kafka client teardown (#3502) Co-authored-by: aryanmehrotra <aryanmehrotra2000@gmail.com> * fix(sql): correct query duration logging unit to microseconds (#3878) * chore(deps): consolidate minor/patch dependency updates (2026-08-21) (#4048) * fix(tools): require a path separator in the framework route check (#4102) Co-authored-by: Umang Mundhra <mundhraumang.02@gmail.com> Co-authored-by: Aryan Mehrotra <aryanmehrotra2000@gmail.com> * perf(container): run health checks concurrently, and collapse concurrent probes (#3496) * feat(mqtt): add span links for pub/sub tracing (#3595) * fix(pubsub/google): guard shared subscription maps against concurrent writes (#4054) (#4055) --------- Co-authored-by: Umang Mundhra <mundhraumang.02@gmail.com> Co-authored-by: Aryan Mehrotra <aryanmehrotra2000@gmail.com> * feat: implement EventHub Health check (#3649) * test(terminal): add unit tests for SetColor and ResetColor (#3648) * fix: add transaction support for dgraph migration (#3186) * fix(crud): keep digits intact in toSnakeCase for auto-generated SQL (#3676) * feat(metrics): add app_server_error/app_circuit_open_count counters + global metrics accessor (#3856) * test(service): fix flaky CB test intervals and add deterministic concurrent recovery test (#3755) * chore(deps): bump the go_modules group across 12 directories with 1 update (#4153) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Aryan Mehrotra <aryanmehrotra2000@gmail.com> * feat(metrics): configurable per-instrument cardinality limit (#4160) * fix(websocket): don't panic on a plain HTTP request to a WebSocket route (#3932) * ci: run the full pipeline and a website build on docs-only PRs (#4195) * Fix CONTRIBUTING.md wording (#3647) Co-authored-by: Aryan Mehrotra <aryanmehrotra2000@gmail.com> Co-authored-by: Umang Mundhra <mundhraumang.02@gmail.com> * fix: broken links in README and CONTRIBUTING (#3798) Co-authored-by: Aryan Mehrotra <aryanmehrotra2000@gmail.com> * chore(deps): bump crate-ci/typos from 1.50.0 to 1.50.1 in the actions group (#4197) Closes: #4171 Co-authored-by: Aryan Mehrotra <aryanmehrotra2000@gmail.com> * chore(deps): consolidate minor/patch dependency updates (2026-09-09) (#4196) Applied surgically per direct-dependency module (per-module go get + go mod tidy; no go work sync). All bumps are minor/patch/security — no majors, no go-redis mock regen needed (miniredis is a test double, not go-redis). Updates: - go.opentelemetry.io/otel/sdk 1.45.0 -> 1.46.0 (root, metrics/exporters/gcp, pubsub/nats, pubsub/sqs) - go.opentelemetry.io/otel/exporters/zipkin 1.44.0 -> 1.46.0 (root) - go.opentelemetry.io/contrib/detectors/gcp 1.44.0 -> 1.46.0 (metrics/exporters/gcp) - github.com/aws/aws-sdk-go-v2/config 1.32.37 -> 1.33.3 (file/s3, kv-store/dynamodb, pubsub/sqs, examples/using-s3-filestore) - github.com/aws/aws-sdk-go-v2/service/dynamodb 1.63.3 -> 1.67.0 (kv-store/dynamodb) - github.com/aws/aws-sdk-go-v2/service/sqs 1.46.6 -> 1.51.0 (pubsub/sqs) - github.com/nats-io/nats-server/v2 2.14.5 -> 2.14.6 (pubsub/nats) - golang.org/x/sync 0.22.0 -> 0.23.0 (root) - modernc.org/sqlite 1.56.0 -> 1.58.0 (root) - github.com/alicebob/miniredis/v2 2.38.0 -> 2.39.0 (root, test) - google.golang.org/grpc 1.83.1 -> 1.83.2 security (root + library modules + examples; pulls golang.org/x/net 0.57.0 -> 0.58.0). examples/using-gcp-metrics is excluded: it is baseline-untidy (excluded from the CI tidy gate) and tidying it to apply grpc would settle unrelated versions. Closes: #4172, #4173, #4174, #4175, #4176, #4177, #4178, #4179, #4180, #4181, #4182, #4183, #4184, #4185, #4186, #4187, #4188, #4189, #4190, #4191, #4192, #4194 Co-authored-by: Aryan Mehrotra <aryanmehrotra2000@gmail.com> * docs: fix American English spelling of canceled (#3651) Co-authored-by: Umang Mundhra <mundhraumang.02@gmail.com> Co-authored-by: Aryan Mehrotra <aryanmehrotra2000@gmail.com> * docs(cron): correct the minimum-interval claim and the "every 5 hours" example (#3876) (#3977) Co-authored-by: Aryan Mehrotra <aryanmehrotra2000@gmail.com> * docs(readme): link Custom Middleware and update the Go version prerequisite (#3461) The broken Auth Middleware link this PR also carried has since landed via #3798, so what remains is: - "Custom Middleware" was plain text next to the linked Auth Middleware; it now points at docs/advanced-guide/middlewares. - The prerequisite said Go 1.24. Every go.mod in the repo declares go 1.26.0, and CI's 1.24/1.25 matrix entries only pass because a setup-go-toolchain step auto-upgrades them, so 1.26 is the real floor. Co-authored-by: Aryan Mehrotra <aryanmehrotra2000@gmail.com> Co-authored-by: Umang Mundhra <mundhraumang.02@gmail.com> * fix(file): correct SFTP/S3 observability defects and stale comments (#3227) Co-authored-by: Umang Mundhra <mundhraumang.02@gmail.com> Co-authored-by: Aryan Mehrotra <aryanmehrotra2000@gmail.com> * fix(sql): validate unsigned int not-null fields without panicking (#3677) * ci(website-prod): move prod build and deploy to asia-south1 zopdev-tech (#4198) Point the prod website image build/push at the asia-south1 zopdev Artifact Registry and deploy to the zopdev-tech cluster (asia-south1), replacing the us-central1 kops-dev registry and raramuri-tech cluster. Namespace, app name, and image tagging are unchanged. * feat(health): optional readiness check for /.well-known/health (#3857) (#3858) * ci(website-stage): move stage build and deploy to asia-south1 zopdev-tech (#4199) Co-authored-by: Aryan Mehrotra <aryanmehrotra2000@gmail.com> * chore(deps): bump zopdev/static-server v0.0.9 -> v1.0.0 in (#4050) Major version bump (v0 -> v1) of the docs static-server base image. Consolidated from Dependabot #3990. Closes: #3990 Co-authored-by: Aryan Mehrotra <aryanmehrotra2000@gmail.com> * Add HTTP QUERY Method Support (RFC 10008) (#3760) * fix(rbac): make wildcard-method rules reachable and resolve overlapping patterns deterministically (#3808) (#3934) Co-authored-by: Aryan Mehrotra <aryanmehrotra2000@gmail.com> * fix(rbac): compile endpoint patterns once at load, not per rule per request (#3979) (#4047) * fix(ci): pull MinIO from quay.io — docker.io/minio/minio is no longer public (#4208) quay.io/minio/minio:RELEASE.2025-09-07T16-13-09Z carries the identical manifest list — sha256:14cea493… , byte-for-byte the digest already pinned — so this changes the registry and nothing else. The image CI runs is provably the one it ran on 2026-09-11, and the digest pin protecting the integration guard for #3804 stays intact. Bumping to a newer release instead would have changed two things at once. * fix(http,metrics,mcp): don't lose a shutdown that arrives before the server starts (#3801) (#4139) * fix(tracing): derive OTLP transport security from the TRACER_URL scheme (#4205) * ci: stop passing -short to submodule tests, which skipped 10 mongo tests entirely (#4201) Co-authored-by: Aryan Mehrotra <aryanmehrotra2000@gmail.com> * ci: measure every in-repo pkg/gofr package, not just the 29 top-level files (#4202) (#4203) * chore(deps): consolidate minor dependency updates (2026-09-16) (#4244) * update release version to v1.61.0 * fix(metrics): keep caller-controlled labels from crowding out real routes (#4163) * fix(tracing): redact tracer config in logs (#4247) Co-authored-by: Umang Mundhra <mundhraumang.02@gmail.com> * fix(tracing): stop tracer parameters shadowing the net/url import (#4249) --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: Ronan Donnelly <ronan.donnelly@ymail.com> Co-authored-by: Umang Mundhra <mundhraumang.02@gmail.com> Co-authored-by: Aditya Kumar Mishra <154746713+adityakrmishra@users.noreply.github.com> Co-authored-by: Pritesh jena <priteshjena16@gmail.com> Co-authored-by: Yash Israni <118755067+yashisrani@users.noreply.github.com> Co-authored-by: Sujan Vulasala <154114096+SujanVulasala@users.noreply.github.com> Co-authored-by: Suhas-zs <110016885+Suhas-zs@users.noreply.github.com> Co-authored-by: Lokesh Malik <lokeshmalik2910@gmail.com> Co-authored-by: Hari Antara <hariantara.iputu@gmail.com> Co-authored-by: Krishna Potdar <potdarkrishna352@gmail.com> Co-authored-by: umar ahad uddin ahmed usmani <150610336+umarahad2005@users.noreply.github.com> Co-authored-by: Om Kulkarni <127368012+om7057@users.noreply.github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Nivaas V <nivaas9293@gmail.com> Co-authored-by: Ryanisyyds <129717677+RyanisyydsTT@users.noreply.github.com> Co-authored-by: Salvatore Damon <rajarajanselvarajan02@gmail.com> Co-authored-by: Akshat Singhal <65562230+akshat-kumar-singhal@users.noreply.github.com> Co-authored-by: Napat Rungruangbangchan <Napat.joe@gmail.com> Co-authored-by: Rohit Nair P <rohitnairmuttathethu@gmail.com> Co-authored-by: Piyush Singh <piyush.singh@zop.dev> Co-authored-by: Gajendra Malviya <gajendra.malviya@zop.dev>
…r public either (#4378) #4208 moved the "Start MinIO" step from docker.io to quay.io after Docker Hub stopped serving minio/minio. quay.io/minio/minio now answers "unauthorized" to anonymous pulls for every tag and for the pinned digest, so every go.yml run fails at "Start MinIO" with exit 125. Checked anonymously on 2026-09-25: - docker.io/minio/minio -> requested access to the resource is denied - quay.io/minio/minio -> 401 unauthorized (repo, tag and digest) - docker.io/bitnami/minio -> manifest unknown - dl.min.io binaries -> 410 Gone - cgr.dev/chainguard/minio -> pullable, linux/amd64 + arm64 cgr.dev/chainguard/minio is MinIO built from upstream AGPL source (RELEASE.2026-09-22T19-25-18Z at the pinned digest) with /usr/bin/minio as its entrypoint, so the existing `server /data` args and the /minio/health/live readiness poll are unchanged. Still pinned by digest. Verified: ran the pinned image with `server /data` and the step's env, then `S3_REQUIRE_MINIO=true go test ./...` in examples/using-s3-filestore: TestS3FileStore_RoundTrip and TestS3FileStore_CopyAndReadAt both PASS. The example README pointed users at the same dead quay.io image; updated.
Description:
Example Unit Testingis currently failing on every open PR, on all three Go versions, at theStart MinIOstep:It fails on PRs that touch no example and no workflow, so it is not the PRs — Docker Hub's
minio/miniorepository is no longer publicly pullable.Checked anonymously rather than inferred:
alpine:3.20(control)docker.io/minio/minio:latestdenied: requested access to the resource is denieddocker.io/minio/minio@sha256:14cea493…(the pin ingo.yml)denied: …quay.io/minio/minio:RELEASE.2025-09-07T16-13-09ZThe last green PR pipeline on this repo was 2026-09-11, so it broke after that date.
The fix is a registry prefix and nothing else.
quay.io/minio/minio:RELEASE.2025-09-07T16-13-09Zcarries the identical manifest list —sha256:14cea493d9a34af32f524e538b8346cf79f3321eff8e708c1e2960462bd8936e, byte-for-byte the digestgo.ymlalready pins:So the image CI runs is provably the one it ran on 2026-09-11, and the digest pin that protects the integration guard for #3804 stays intact. Bumping to a newer MinIO release instead would have changed two things at once and weakened that pin's purpose.
examples/using-s3-filestore/README.mdtold readers todocker run … minio/minio server /data, which is broken for the same reason, so it moves in the same change.Breaking Changes (if applicable):
None. Same image, different registry; no MinIO version change, no test changes.
Additional Information:
docker runnow records why the registry is quay.io, so a future reader doesn't "helpfully" move it back to Docker Hub.Checklist:
goimportandgolangci-lint.