diff --git a/modules/minio/Dockerfile b/modules/minio/Dockerfile index e5588e6..fc0e121 100644 --- a/modules/minio/Dockerfile +++ b/modules/minio/Dockerfile @@ -9,6 +9,11 @@ # image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`. ARG BUILD_BASE ARG RUNTIME_BASE +ARG MC_CLI + +# Named so the final stage's COPY --from can reference a stage, not an ARG — the legacy builder +# this host still runs doesn't expand ARGs inside COPY --from, only inside FROM. +FROM ${MC_CLI} AS mccli FROM ${BUILD_BASE} AS build # Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own @@ -22,6 +27,13 @@ RUN node /app/node_modules/typescript/bin/tsc client.ts tools/index.ts provision FROM ${RUNTIME_BASE} COPY --from=build /app/modules/minio/dist /app/modules/minio/dist +# The provisioner shells out to mc to actually create buckets and service accounts on the running +# minio server — mc itself was never in this runtime image, only in minio's own. Silently retried +# "spawn mc ENOENT" forever: a requirement was granted at the control-plane level without ever +# materializing the credential on minio. /usr/bin/mc there is a symlink to the real binary, mcli — +# both copied so the symlink resolves. +COPY --from=mccli /usr/bin/mcli /usr/bin/mcli +COPY --from=mccli /usr/bin/mc /usr/bin/mc # Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a # provider's provisioner runs its reconcile loop in the same process, with the broker connected — # the convention novox/hq issues 060/061 settled. diff --git a/modules/minio/module.json b/modules/minio/module.json index bbca5d2..ef31847 100644 --- a/modules/minio/module.json +++ b/modules/minio/module.json @@ -133,6 +133,10 @@ "arg": "RUNTIME_BASE", "module": "mesh-tools", "artifact": "runtime" + }, + { + "arg": "MC_CLI", + "image": "docker.io/pgsty/minio@sha256:b6bfe7239bfc83fb90d31612d9704d86039dd714f7904b3f1ad68f211e602372" } ], "artifacts": [