Skip to content

fix(ci): pull MinIO from quay.io — docker.io/minio/minio is no longer public - #4208

Merged
aryanmehrotra merged 1 commit into
gofr-dev:developmentfrom
akshat-kumar-singhal:fix/ci-minio-image-registry
Sep 14, 2026
Merged

aryanmehrotra merged 1 commit into
gofr-dev:developmentfrom
akshat-kumar-singhal:fix/ci-minio-image-registry

Conversation

@akshat-kumar-singhal

@akshat-kumar-singhal akshat-kumar-singhal commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

Description:

Example Unit Testing is currently failing on every open PR, on all three Go versions, at the Start MinIO step:

docker: Error response from daemon: pull access denied for minio/minio,
repository does not exist or may require 'docker login': denied: requested
access to the resource is denied

It fails on PRs that touch no example and no workflow, so it is not the PRs — Docker Hub's minio/minio repository is no longer publicly pullable.

Checked anonymously rather than inferred:

image result
alpine:3.20 (control) resolves
docker.io/minio/minio:latest denied: requested access to the resource is denied
docker.io/minio/minio@sha256:14cea493… (the pin in go.yml) denied: …
quay.io/minio/minio:RELEASE.2025-09-07T16-13-09Z resolves

The last green PR pipeline on this repo was 2026-09-11, so it broke after that date.

The fix is a registry prefix and nothing else. quay.io/minio/minio:RELEASE.2025-09-07T16-13-09Z carries the identical manifest list — sha256:14cea493d9a34af32f524e538b8346cf79f3321eff8e708c1e2960462bd8936e, byte-for-byte the digest go.yml already pins:

$ docker buildx imagetools inspect quay.io/minio/minio:RELEASE.2025-09-07T16-13-09Z
Name:      quay.io/minio/minio:RELEASE.2025-09-07T16-13-09Z
MediaType: application/vnd.docker.distribution.manifest.list.v2+json
Digest:    sha256:14cea493d9a34af32f524e538b8346cf79f3321eff8e708c1e2960462bd8936e

So the image CI runs is provably the one it ran on 2026-09-11, and the digest pin that protects the integration guard for #3804 stays intact. Bumping to a newer MinIO release instead would have changed two things at once and weakened that pin's purpose.

examples/using-s3-filestore/README.md told readers to docker run … minio/minio server /data, which is broken for the same reason, so it moves in the same change.

Breaking Changes (if applicable):

None. Same image, different registry; no MinIO version change, no test changes.

Additional Information:

  • This is deliberately a standalone CI fix rather than part of any feature branch — it unblocks every open PR in the repo and should be reviewable and mergeable on its own.
  • The comment above the docker run now records why the registry is quay.io, so a future reader doesn't "helpfully" move it back to Docker Hub.

Checklist:

  • I have formatted my code using goimport and golangci-lint.
  • All new code is covered by unit tests.
  • This PR does not decrease the overall code coverage.
  • I have reviewed the code comments and documentation for clarity.

… public

Every PR's Example Unit Testing job fails at Start MinIO with "pull access
denied for minio/minio, repository does not exist or may require 'docker
login'", on all three Go versions. It fails on PRs that touch no example and no
workflow, so it is not the PRs: Docker Hub's minio/minio repository is no longer
publicly pullable.

Checked anonymously rather than inferred: alpine:3.20 resolves, while
docker.io/minio/minio:latest AND the digest pinned here both return "denied:
requested access to the resource is denied". The last green PR pipeline was
2026-09-11.

quay.io/minio/minio:RELEASE.2025-09-07T16-13-09Z carries the identical manifest
list — sha256:14cea493… , byte-for-byte the digest already pinned — so this
changes the registry and nothing else. The image CI runs is provably the one it
ran on 2026-09-11, and the digest pin protecting the integration guard for gofr-dev#3804
stays intact. Bumping to a newer release instead would have changed two things
at once.

examples/using-s3-filestore/README.md told readers to run the same now-broken
docker.io image, so it moves too.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YMKLwXTgzev7GTP3hSkzv1

@aryanmehrotra aryanmehrotra left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approving. I re-verified the claim independently against the live registries rather than taking the description's word for it:

check result
docker.io/minio/minio:RELEASE.2025-09-07T16-13-09Z (anon) HTTP 401 — denied
docker.io/library/alpine:3.20 (control) HTTP 200 — Docker Hub itself is healthy
quay.io/minio/minio:RELEASE.2025-09-07T16-13-09Z (anon) HTTP 200
quay.io docker-content-digest sha256:14cea493d9a34af32f524e538b8346cf79f3321eff8e708c1e2960462bd8936e
digest already pinned in go.yml sha256:14cea493… — identical

So this is provably a registry change and not an image change, and the digest pin protecting the #3804 integration guard is unaffected. Keeping the pin rather than bumping to a newer MinIO release was the right call — a version bump would have changed two things at once and made the pin meaningless.

Also confirmed:

  • grep -rE '(^|[^./a-zA-Z0-9-])minio/minio' over the tree returns exactly the two occurrences this PR changes — no bare reference is left behind.
  • CI on this PR is green on all three Go versions, i.e. Example Unit Testing actually reaches go test ./examples/... again.

For context on why this is worth merging ahead of anything else: the green ticks on the other open PRs are stale, not healthy. Last Example Unit Testing (v1.26) run per PR:

PR last run result
#4205 2026-09-14 04:40 FAILURE
#4203 2026-09-11 15:37 success (pre-break)
#4201 2026-09-11 11:11 success (pre-break)
#4170 2026-09-10 18:29 success (pre-break)

Every one of those turns red on its next push. This unblocks all 31 open PRs, not the three currently showing red.

Nit, non-blocking: please strip the 🤖 Generated with [Claude Code] footer and the claude.ai/code/session_… link from the PR description before merge.


Follow-up, deliberately not in this PR. #3868 already predicted this failure class — "it works today; the day it stops working, every example test that touches pub/sub fails at once and the cause will not be obvious from the logs" — and that is exactly what happened here, just with MinIO instead of Kafka. #3868 covers pinning. What no issue covers yet is detection: there is nothing that tells us a required external dependency has become unpullable, so this broke on 2026-09-11 and was found on 2026-09-14 only because a contributor pushed and read a red X as their own fault. I'll open a separate issue for the preflight-job + scheduled-canary side of it.

@aryanmehrotra
aryanmehrotra merged commit 9bbdbbe into gofr-dev:development Sep 14, 2026
16 checks passed
@akshat-kumar-singhal
akshat-kumar-singhal deleted the fix/ci-minio-image-registry branch September 14, 2026 13:06
aryanmehrotra added a commit that referenced this pull request Sep 17, 2026
* Merge pull request #4147 from gofr-dev/chore/gcp-exporter-pin-v1.60.1

chore(metrics): pin gcp exporter to gofr.dev v1.60.1

* fix(middleware): require a path separator in the well-known auth exemption (#4099)

* fix(middleware): require a path separator in the well-known auth exemption

* test(middleware): cover the rate limiter well-known exemption

* chore(middleware): satisfy goconst and noctx in the well-known check

* docs(auth): describe the separator requirement in the well-known exemption

---------

Co-authored-by: Aryan Mehrotra <aryanmehrotra2000@gmail.com>
Co-authored-by: Umang Mundhra <mundhraumang.02@gmail.com>

* perf(metrics): build the measurement option once per route, method and status (#3972)

* perf(http): pool the response envelope and stop recanonicalising Content-Type (#3973)

* perf(cors): build the fixed response headers once, not per request (#3971)

* fix: prevent concurrent map panic during kafka client teardown (#3502)

Co-authored-by: aryanmehrotra <aryanmehrotra2000@gmail.com>

* fix(sql): correct query duration logging unit to microseconds (#3878)

* chore(deps): consolidate minor/patch dependency updates (2026-08-21) (#4048)

* fix(tools): require a path separator in the framework route check (#4102)

Co-authored-by: Umang Mundhra <mundhraumang.02@gmail.com>
Co-authored-by: Aryan Mehrotra <aryanmehrotra2000@gmail.com>

* perf(container): run health checks concurrently, and collapse concurrent probes (#3496)

* feat(mqtt): add span links for pub/sub tracing (#3595)

* fix(pubsub/google): guard shared subscription maps against concurrent writes (#4054) (#4055)


---------

Co-authored-by: Umang Mundhra <mundhraumang.02@gmail.com>
Co-authored-by: Aryan Mehrotra <aryanmehrotra2000@gmail.com>

* feat: implement EventHub Health check (#3649)

* test(terminal): add unit tests for SetColor and ResetColor (#3648)

* fix: add transaction support for dgraph migration (#3186)

* fix(crud): keep digits intact in toSnakeCase for auto-generated SQL (#3676)

* feat(metrics): add app_server_error/app_circuit_open_count counters + global metrics accessor (#3856)

* test(service): fix flaky CB test intervals and add deterministic concurrent recovery test (#3755)

* chore(deps): bump the go_modules group across 12 directories with 1 update (#4153)



Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Aryan Mehrotra <aryanmehrotra2000@gmail.com>

* feat(metrics): configurable per-instrument cardinality limit (#4160)

* fix(websocket): don't panic on a plain HTTP request to a WebSocket route (#3932)

* ci: run the full pipeline and a website build on docs-only PRs (#4195)

* Fix CONTRIBUTING.md wording (#3647)

Co-authored-by: Aryan Mehrotra <aryanmehrotra2000@gmail.com>
Co-authored-by: Umang Mundhra <mundhraumang.02@gmail.com>

* fix: broken links in README and CONTRIBUTING (#3798)

Co-authored-by: Aryan Mehrotra <aryanmehrotra2000@gmail.com>

* chore(deps): bump crate-ci/typos from 1.50.0 to 1.50.1 in the actions group (#4197)

Closes: #4171

Co-authored-by: Aryan Mehrotra <aryanmehrotra2000@gmail.com>

* chore(deps): consolidate minor/patch dependency updates (2026-09-09) (#4196)

Applied surgically per direct-dependency module (per-module go get + go mod
tidy; no go work sync). All bumps are minor/patch/security — no majors, no
go-redis mock regen needed (miniredis is a test double, not go-redis).

Updates:
- go.opentelemetry.io/otel/sdk 1.45.0 -> 1.46.0 (root, metrics/exporters/gcp, pubsub/nats, pubsub/sqs)
- go.opentelemetry.io/otel/exporters/zipkin 1.44.0 -> 1.46.0 (root)
- go.opentelemetry.io/contrib/detectors/gcp 1.44.0 -> 1.46.0 (metrics/exporters/gcp)
- github.com/aws/aws-sdk-go-v2/config 1.32.37 -> 1.33.3 (file/s3, kv-store/dynamodb, pubsub/sqs, examples/using-s3-filestore)
- github.com/aws/aws-sdk-go-v2/service/dynamodb 1.63.3 -> 1.67.0 (kv-store/dynamodb)
- github.com/aws/aws-sdk-go-v2/service/sqs 1.46.6 -> 1.51.0 (pubsub/sqs)
- github.com/nats-io/nats-server/v2 2.14.5 -> 2.14.6 (pubsub/nats)
- golang.org/x/sync 0.22.0 -> 0.23.0 (root)
- modernc.org/sqlite 1.56.0 -> 1.58.0 (root)
- github.com/alicebob/miniredis/v2 2.38.0 -> 2.39.0 (root, test)
- google.golang.org/grpc 1.83.1 -> 1.83.2 security (root + library modules + examples; pulls golang.org/x/net 0.57.0 -> 0.58.0). examples/using-gcp-metrics is excluded: it is baseline-untidy (excluded from the CI tidy gate) and tidying it to apply grpc would settle unrelated versions.

Closes: #4172, #4173, #4174, #4175, #4176, #4177, #4178, #4179, #4180, #4181, #4182, #4183, #4184, #4185, #4186, #4187, #4188, #4189, #4190, #4191, #4192, #4194

Co-authored-by: Aryan Mehrotra <aryanmehrotra2000@gmail.com>

* docs: fix American English spelling of canceled (#3651)

Co-authored-by: Umang Mundhra <mundhraumang.02@gmail.com>
Co-authored-by: Aryan Mehrotra <aryanmehrotra2000@gmail.com>

* docs(cron): correct the minimum-interval claim and the "every 5 hours" example (#3876) (#3977)

Co-authored-by: Aryan Mehrotra <aryanmehrotra2000@gmail.com>

* docs(readme): link Custom Middleware and update the Go version prerequisite (#3461)

The broken Auth Middleware link this PR also carried has since landed via
#3798, so what remains is:

- "Custom Middleware" was plain text next to the linked Auth Middleware; it now
  points at docs/advanced-guide/middlewares.
- The prerequisite said Go 1.24. Every go.mod in the repo declares go 1.26.0,
  and CI's 1.24/1.25 matrix entries only pass because a setup-go-toolchain step
  auto-upgrades them, so 1.26 is the real floor.

Co-authored-by: Aryan Mehrotra <aryanmehrotra2000@gmail.com>
Co-authored-by: Umang Mundhra <mundhraumang.02@gmail.com>

* fix(file): correct SFTP/S3 observability defects and stale comments (#3227)



Co-authored-by: Umang Mundhra <mundhraumang.02@gmail.com>
Co-authored-by: Aryan Mehrotra <aryanmehrotra2000@gmail.com>

* fix(sql): validate unsigned int not-null fields without panicking (#3677)

* ci(website-prod): move prod build and deploy to asia-south1 zopdev-tech (#4198)

Point the prod website image build/push at the asia-south1 zopdev
Artifact Registry and deploy to the zopdev-tech cluster (asia-south1),
replacing the us-central1 kops-dev registry and raramuri-tech cluster.
Namespace, app name, and image tagging are unchanged.

* feat(health): optional readiness check for /.well-known/health (#3857) (#3858)

* ci(website-stage): move stage build and deploy to asia-south1 zopdev-tech (#4199)



Co-authored-by: Aryan Mehrotra <aryanmehrotra2000@gmail.com>

* chore(deps): bump zopdev/static-server v0.0.9 -> v1.0.0 in (#4050)

Major version bump (v0 -> v1) of the docs static-server base image.
Consolidated from Dependabot #3990.

Closes: #3990

Co-authored-by: Aryan Mehrotra <aryanmehrotra2000@gmail.com>

* Add HTTP QUERY Method Support (RFC 10008) (#3760)

* fix(rbac): make wildcard-method rules reachable and resolve overlapping patterns deterministically (#3808) (#3934)



Co-authored-by: Aryan Mehrotra <aryanmehrotra2000@gmail.com>

* fix(rbac): compile endpoint patterns once at load, not per rule per request (#3979) (#4047)

* fix(ci): pull MinIO from quay.io — docker.io/minio/minio is no longer public (#4208)

quay.io/minio/minio:RELEASE.2025-09-07T16-13-09Z carries the identical manifest
list — sha256:14cea493… , byte-for-byte the digest already pinned — so this
changes the registry and nothing else. The image CI runs is provably the one it
ran on 2026-09-11, and the digest pin protecting the integration guard for #3804
stays intact. Bumping to a newer release instead would have changed two things
at once.

* fix(http,metrics,mcp): don't lose a shutdown that arrives before the server starts (#3801) (#4139)

* fix(tracing): derive OTLP transport security from the TRACER_URL scheme (#4205)

* ci: stop passing -short to submodule tests, which skipped 10 mongo tests entirely (#4201)

Co-authored-by: Aryan Mehrotra <aryanmehrotra2000@gmail.com>

* ci: measure every in-repo pkg/gofr package, not just the 29 top-level files (#4202) (#4203)

* chore(deps): consolidate minor dependency updates (2026-09-16) (#4244)

* update release version to v1.61.0

* fix(metrics): keep caller-controlled labels from crowding out real routes (#4163)

* fix(tracing): redact tracer config in logs (#4247)


Co-authored-by: Umang Mundhra <mundhraumang.02@gmail.com>

* fix(tracing): stop tracer parameters shadowing the net/url import (#4249)

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: Ronan Donnelly <ronan.donnelly@ymail.com>
Co-authored-by: Umang Mundhra <mundhraumang.02@gmail.com>
Co-authored-by: Aditya Kumar Mishra <154746713+adityakrmishra@users.noreply.github.com>
Co-authored-by: Pritesh jena <priteshjena16@gmail.com>
Co-authored-by: Yash Israni <118755067+yashisrani@users.noreply.github.com>
Co-authored-by: Sujan Vulasala <154114096+SujanVulasala@users.noreply.github.com>
Co-authored-by: Suhas-zs <110016885+Suhas-zs@users.noreply.github.com>
Co-authored-by: Lokesh Malik <lokeshmalik2910@gmail.com>
Co-authored-by: Hari Antara <hariantara.iputu@gmail.com>
Co-authored-by: Krishna Potdar <potdarkrishna352@gmail.com>
Co-authored-by: umar ahad uddin ahmed usmani <150610336+umarahad2005@users.noreply.github.com>
Co-authored-by: Om Kulkarni <127368012+om7057@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Nivaas V <nivaas9293@gmail.com>
Co-authored-by: Ryanisyyds <129717677+RyanisyydsTT@users.noreply.github.com>
Co-authored-by: Salvatore Damon <rajarajanselvarajan02@gmail.com>
Co-authored-by: Akshat Singhal <65562230+akshat-kumar-singhal@users.noreply.github.com>
Co-authored-by: Napat Rungruangbangchan <Napat.joe@gmail.com>
Co-authored-by: Rohit Nair P <rohitnairmuttathethu@gmail.com>
Co-authored-by: Piyush Singh <piyush.singh@zop.dev>
Co-authored-by: Gajendra Malviya <gajendra.malviya@zop.dev>
aryanmehrotra added a commit that referenced this pull request Sep 25, 2026
…r public either (#4378)

#4208 moved the "Start MinIO" step from docker.io to quay.io after Docker
Hub stopped serving minio/minio. quay.io/minio/minio now answers
"unauthorized" to anonymous pulls for every tag and for the pinned digest,
so every go.yml run fails at "Start MinIO" with exit 125.

Checked anonymously on 2026-09-25:
- docker.io/minio/minio   -> requested access to the resource is denied
- quay.io/minio/minio     -> 401 unauthorized (repo, tag and digest)
- docker.io/bitnami/minio -> manifest unknown
- dl.min.io binaries      -> 410 Gone
- cgr.dev/chainguard/minio -> pullable, linux/amd64 + arm64

cgr.dev/chainguard/minio is MinIO built from upstream AGPL source
(RELEASE.2026-09-22T19-25-18Z at the pinned digest) with /usr/bin/minio
as its entrypoint, so the existing `server /data` args and the
/minio/health/live readiness poll are unchanged. Still pinned by digest.

Verified: ran the pinned image with `server /data` and the step's env,
then `S3_REQUIRE_MINIO=true go test ./...` in examples/using-s3-filestore:
TestS3FileStore_RoundTrip and TestS3FileStore_CopyAndReadAt both PASS.

The example README pointed users at the same dead quay.io image; updated.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants