minio: pin the server image to the maintained fork #56

Closed
jschoubben wants to merge 1 commits from feat/object-store-on-the-maintained-fork into main
Owner

modules/minio/module.json line 83 pinned quay.io/minio/minio@sha256:14cea493…. Upstream deleted that repository from every public registry on 2026-09-11, so the digest resolves to nothing and the module cannot be installed on any node (hq issue 113). No credential fixes it — there is nothing left to authenticate against.

- quay.io/minio/minio@sha256:14cea493d9a34af32f524e538b8346cf79f3321eff8e708c1e2960462bd8936e
+ docker.io/pgsty/minio@sha256:b6bfe7239bfc83fb90d31612d9704d86039dd714f7904b3f1ad68f211e602372

pgsty/minio is a maintained fork of the community edition — keeps the on-disk format, the S3 API and the MINIO_* variables compatible with upstream, restores the console stripped in May 2025, and tracks CVEs.

Verified rather than assumed: pulled it and it reports minio version RELEASE.2026-08-04T00-00-00Z, Go 1.26.5, AGPLv3, labels maintainer=pgsty. The digest is the multi-arch OCI index (application/vnd.oci.image.index.v1+json), so arm64 nodes resolve too. 752,949 pulls.

JSON validates. No quay.io/minio references remain anywhere in the catalogue.

Deliberately not in this change

The runtime sidecar still reads mesh-runtime-minio@sha256:0000…0000. That placeholder is resolved by building and publishing the sidecar, which is not a catalogue concern.

Caveat

The fork is maintenance-mode and largely one project's effort. This makes the module installable again and restores patching; it does not end the dependence on an abandoned codebase. Replacement evaluation continues in hq research 015.

`modules/minio/module.json` line 83 pinned `quay.io/minio/minio@sha256:14cea493…`. Upstream **deleted that repository from every public registry on 2026-09-11**, so the digest resolves to nothing and the module cannot be installed on any node (hq issue 113). No credential fixes it — there is nothing left to authenticate against. ``` - quay.io/minio/minio@sha256:14cea493d9a34af32f524e538b8346cf79f3321eff8e708c1e2960462bd8936e + docker.io/pgsty/minio@sha256:b6bfe7239bfc83fb90d31612d9704d86039dd714f7904b3f1ad68f211e602372 ``` `pgsty/minio` is a maintained fork of the community edition — keeps the on-disk format, the S3 API and the `MINIO_*` variables compatible with upstream, restores the console stripped in May 2025, and tracks CVEs. Verified rather than assumed: pulled it and it reports `minio version RELEASE.2026-08-04T00-00-00Z`, Go 1.26.5, AGPLv3, labels `maintainer=pgsty`. The digest is the **multi-arch OCI index** (`application/vnd.oci.image.index.v1+json`), so arm64 nodes resolve too. 752,949 pulls. JSON validates. No `quay.io/minio` references remain anywhere in the catalogue. ## Deliberately not in this change The runtime sidecar still reads `mesh-runtime-minio@sha256:0000…0000`. That placeholder is resolved by **building and publishing** the sidecar, which is not a catalogue concern. ## Caveat The fork is maintenance-mode and largely one project's effort. This makes the module installable again and restores patching; it does not end the dependence on an abandoned codebase. Replacement evaluation continues in hq research 015.
jschoubben added 1 commit 2026-09-24 15:51:26 +00:00
Upstream deleted minio/minio from every public registry on 2026-09-11, so the digest this
module pinned resolves to nothing and no node can install it (hq issue 113).

docker.io/pgsty/minio is a maintained fork of the community edition: it keeps the on-disk
format, the S3 API and the MINIO_* variables compatible with upstream, restores the console
stripped in May 2025, and tracks CVEs. Verified by pulling it — RELEASE.2026-08-04T00-00-00Z,
AGPLv3, built by pgsty. The digest is the multi-arch OCI index, so arm64 nodes resolve too.

The runtime sidecar's placeholder digest is deliberately left alone: that is resolved by
building and publishing it, not by the catalogue.
Author
Owner

Superseded by #57, which carries this same image repin plus the fix for the data path (was pointing at HAL's live production drive) and the previously-missing Dockerfile/build section for the runtime sidecar. Closing in favor of that one.

Superseded by #57, which carries this same image repin plus the fix for the data path (was pointing at HAL's live production drive) and the previously-missing Dockerfile/build section for the runtime sidecar. Closing in favor of that one.
jschoubben closed this pull request 2026-09-24 16:14:41 +00:00

Pull request closed

This pull request cannot be reopened because the branch was deleted.
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-catalog#56