From 316f6557db305c92d21713c16a89e01812ec5f07 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E5=8B=92=E5=B8=83=E6=9C=97-=E8=A9=B9=E5=A7=86=E6=96=AF?= <2986253039@qq.com> Date: Tue, 15 Sep 2026 14:06:22 +0800 Subject: [PATCH] fix(ci): resolve MinIO images from quay.io after the Docker Hub withdrawal MinIO stopped publishing container images in October 2025 and removed the `minio/minio` and `minio/mc` repositories from Docker Hub. Every reference this repository holds therefore fails to resolve, and the failure is on the critical path: `Validate Agent memory` -> `HTTP, CLI and MCP lifecycle` needs the `e2e` Compose profile, so an anonymous `docker compose up -d --wait postgres minio` dies during container startup: minio Error pull access denied for minio/minio, repository does not exist or may require 'docker login': denied: requested access to the resource is denied `HTTP, CLI and MCP lifecycle` is a required status context on `main`, so that withdrawal blocked every pull request in the repository from merging, not just the ones touching this stack. `postgres` reports `Interrupted` in the same log line only as a consequence. `quay.io` still serves the exact images. Both digests pinned in `docker-compose.test.yml` were resolved there before this change: quay.io/minio/minio @ sha256:14cea493... -> 200 (manifest list) quay.io/minio/mc @ sha256:a7fe349e... -> 200 (manifest list) So no image bytes change. The digest-pinned test stack keeps its digests, the release-tagged deployment stack keeps its tags, and only the registry host differs. `docker-compose.yml` and `deploy/compose/compose.yaml` are included because the documented local and self-hosted paths reference the same missing repositories; `deploy/compose/compose.yaml` would have failed on a cold host, and no workflow exercises it, so it would have gone unnoticed. Deliberately not changed: the `pgvector/pgvector` references. That repository is still present on Docker Hub, and the `PostgreSQL integration` job that pulls it was green in the same runs that failed on MinIO (#207), which is the evidence that this is specific to the MinIO repositories rather than general registry egress. Refs #207. --- CHANGELOG.md | 14 ++++++++++++++ deploy/compose/compose.yaml | 8 +++++--- docker-compose.test.yml | 6 ++++-- docker-compose.yml | 6 ++++-- 4 files changed, 27 insertions(+), 7 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 7bdac57..51f7a23 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -75,6 +75,20 @@ The project publishes 0.x prerelease versions; a stable release line is not yet ### Fixed +- Every MinIO image reference in the test stack, the local development stack and + the self-hosted single-node Compose profile now resolves from `quay.io` instead + of Docker Hub. MinIO stopped publishing container images in October 2025 and + removed the `minio/minio` and `minio/mc` repositories from Docker Hub, so an + anonymous `docker compose up` fails with `pull access denied for minio/minio, + repository does not exist or may require 'docker login'`. Because `Validate + Agent memory` → `HTTP, CLI and MCP lifecycle` is a required status context, + that registry withdrawal blocked every pull request from merging (`#207`). + `quay.io` still serves the exact digests pinned in `docker-compose.test.yml`, + so no image bytes change: the digest-pinned test stack keeps its digests and + the release-tagged deployment stack keeps its tags — only the registry host + differs. `deploy/compose/compose.yaml` previously carried the same broken + reference, so the documented self-hosted path would have failed on a cold + host even though no workflow exercises it. - A configured URL that carries credentials in a shape `url.Parse` does not report as userinfo no longer reaches output. `admin:pw@host` parses as `Scheme="admin"` with the credential in `Opaque` and `User` unset, so an diff --git a/deploy/compose/compose.yaml b/deploy/compose/compose.yaml index 29d3e17..e123d59 100644 --- a/deploy/compose/compose.yaml +++ b/deploy/compose/compose.yaml @@ -90,7 +90,9 @@ services: start_period: 5s minio: - image: minio/minio:RELEASE.2025-04-22T22-12-26Z + # MinIO withdrew its Docker Hub repositories in October 2025; quay.io serves + # the same release tags. + image: quay.io/minio/minio:RELEASE.2025-04-22T22-12-26Z restart: unless-stopped command: server /data --console-address :9001 environment: @@ -108,7 +110,7 @@ services: start_period: 10s minio-init: - image: minio/mc:RELEASE.2025-04-16T18-13-26Z + image: quay.io/minio/mc:RELEASE.2025-04-16T18-13-26Z restart: "no" depends_on: minio: @@ -217,7 +219,7 @@ services: start_period: 10s minio-client: - image: minio/mc:RELEASE.2025-04-16T18-13-26Z + image: quay.io/minio/mc:RELEASE.2025-04-16T18-13-26Z profiles: ["tools"] environment: MEM_S3_BUCKET: ${MEM_S3_BUCKET:-mem} diff --git a/docker-compose.test.yml b/docker-compose.test.yml index a411755..eea98e1 100644 --- a/docker-compose.test.yml +++ b/docker-compose.test.yml @@ -22,7 +22,9 @@ services: minio: profiles: ["e2e"] - image: minio/minio:latest@sha256:14cea493d9a34af32f524e538b8346cf79f3321eff8e708c1e2960462bd8936e + # MinIO withdrew its Docker Hub repositories in October 2025; quay.io serves + # the same digest-pinned image. + image: quay.io/minio/minio:latest@sha256:14cea493d9a34af32f524e538b8346cf79f3321eff8e708c1e2960462bd8936e command: server /data --console-address ":9001" environment: MINIO_ROOT_USER: mem @@ -40,7 +42,7 @@ services: minio-init: profiles: ["e2e"] - image: minio/mc:latest@sha256:a7fe349ef4bd8521fb8497f55c6042871b2ae640607cf99d9bede5e9bdf11727 + image: quay.io/minio/mc:latest@sha256:a7fe349ef4bd8521fb8497f55c6042871b2ae640607cf99d9bede5e9bdf11727 depends_on: minio: condition: service_healthy diff --git a/docker-compose.yml b/docker-compose.yml index 3642946..8c13718 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -40,7 +40,9 @@ services: retries: 10 minio: - image: minio/minio:latest + # MinIO withdrew its Docker Hub repositories in October 2025; quay.io serves + # the same image. + image: quay.io/minio/minio:latest container_name: mem-minio restart: unless-stopped command: server /data --console-address ":9001" @@ -60,7 +62,7 @@ services: # Bootstrap: create default bucket minio-init: - image: minio/mc:latest + image: quay.io/minio/mc:latest depends_on: minio: condition: service_healthy