From 374f27ce487c80493680feff33908f4696449808 Mon Sep 17 00:00:00 2001 From: Daniel Bernstein Date: Thu, 24 Sep 2026 12:16:00 -0700 Subject: [PATCH] Build the CI MinIO container from the GHCR mirror MinIO has withdrawn anonymous public access to its server image from both Docker Hub and quay.io, so `FROM quay.io/minio/minio:latest` now fails with a 401 before the test suite starts. Pinning an older tag does not help (the whole repository is gated), and neither does a local cache (tox_docker passes pull=True on every build). Points the CI MinIO container at the Palace mirror instead, published from the ci-scripts repo. The mirror is an unmodified MinIO build, so the credentials, ports and command below the FROM line are untouched. Co-Authored-By: Claude Opus 5 --- docker/Dockerfile.minio.ci | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/docker/Dockerfile.minio.ci b/docker/Dockerfile.minio.ci index 622b3bbbf2..32ff1c0a08 100644 --- a/docker/Dockerfile.minio.ci +++ b/docker/Dockerfile.minio.ci @@ -1,4 +1,9 @@ -FROM quay.io/minio/minio:latest AS minio +# MinIO withdrew anonymous public access to its own image from both Docker Hub and quay.io, so +# this pulls from the Palace mirror of the upstream release instead. The mirror is an unmodified +# MinIO build, published from the ci-scripts repo: +# https://github.com/ThePalaceProject/ci-scripts/blob/main/images/minio/Dockerfile +# The tag is pinned deliberately; the mirror publishes no `latest`. +FROM ghcr.io/thepalaceproject/palace-ci-minio:RELEASE.2025-09-07T16-13-09Z AS minio ENV MINIO_ROOT_USER=palace ENV MINIO_ROOT_PASSWORD=palace123