diff --git a/.github/workflows/build-minio-mirror.yml b/.github/workflows/build-minio-mirror.yml index d23d74f..6f9c3af 100644 --- a/.github/workflows/build-minio-mirror.yml +++ b/.github/workflows/build-minio-mirror.yml @@ -13,9 +13,13 @@ name: Build MinIO Mirror # verify the pinned checksums, then throw the result away — an unmerged branch must never be able # to overwrite the release tag that three other repos pin their CI to. # -# One-time manual step: GHCR packages are created private. After the first successful run, set the -# package visibility to public (Org -> Packages -> palace-ci-minio -> Package settings), matching -# the other Palace images. Without that, every developer and CI job would need a docker login. +# The package is public, matching the other Palace images, so no docker login is needed by +# developers or CI. That is not something this workflow can set: GHCR creates packages private, and +# the visibility was flipped by hand (Org -> Packages -> palace-ci-minio -> Package settings). If +# the package is ever recreated, it has to be flipped again. +# +# This mirror is meant to be short-lived. PP-5245 tracks replacing MinIO outright: +# https://ebce-lyrasis.atlassian.net/browse/PP-5245 on: push: diff --git a/README.md b/README.md index f0f0ed6..f1be708 100644 --- a/README.md +++ b/README.md @@ -24,9 +24,20 @@ Used by `circulation`, `library-registry` and `virtual-library-card`. Only pushe publish — pull requests and manual runs from a branch build and validate, then discard, so an unmerged branch cannot overwrite the tag those repos depend on. +### Retirement + This mirror is a bridge, not a destination: the intent is to drop MinIO for a maintained -S3-compatible image. Note that GitHub does not allow self-service deletion of a public package -once any version passes 5,000 downloads. +S3-compatible image, tracked by [PP-5245](https://ebce-lyrasis.atlassian.net/browse/PP-5245). + +It should be short-lived for two reasons. We do not want to become a de-facto public distributor of +a frozen MinIO build. And GitHub does not allow self-service deletion of a public package once any +version passes 5,000 downloads — above that it becomes a Support request. With `pull=True` on every +tox-docker build, ephemeral CI runners and three repos pulling, that threshold arrives faster than +it sounds, so check the count before assuming deletion is still a one-liner: + +``` +gh api -X DELETE /orgs/ThePalaceProject/packages/container/palace-ci-minio +``` ## sync.py diff --git a/images/minio/Dockerfile b/images/minio/Dockerfile index 7023e9d..c879830 100644 --- a/images/minio/Dockerfile +++ b/images/minio/Dockerfile @@ -31,8 +31,11 @@ # Dockerfiles — they change only their `FROM` line. Baking configuration in here would fork # the image between repos immediately. # -# This mirror is a bridge, not a destination; see the retirement ticket for replacing MinIO -# outright. Do not add features to it. +# This mirror is a bridge, not a destination. PP-5245 tracks replacing MinIO outright: +# https://ebce-lyrasis.atlassian.net/browse/PP-5245 +# Do not add features to it. Retiring it gets harder the longer it lives: GitHub does not allow +# self-service deletion of a public package once any version passes 5,000 downloads, after which +# it becomes a Support request. # # Updating # -------- @@ -115,4 +118,12 @@ VOLUME ["/data"] EXPOSE 9000 9001 # A plain, unconfigured server. Consumers override this with their own CMD/ENTRYPOINT. +# +# Note one deliberate difference from the upstream image: it set ENTRYPOINT to a +# docker-entrypoint.sh that supplied the `minio` binary, so `docker run server /data` +# worked. There is no entrypoint here, so the binary has to be named: +# `docker run minio server /data`. The old form fails with +# `exec: "server": executable file not found in $PATH` and the container never starts. The three +# CI Dockerfiles set their own command and are unaffected, but anything invoking the image +# directly -- a README, a docker-compose service, a one-off container -- needs the full command. CMD ["minio", "server", "/data", "--address", ":9000", "--console-address", ":9001"]