Skip to content

fix(ci): pull MinIO from Block's public GHCR image (upstream #7869, #7870) - #33

Merged
QuicksilverSlick merged 2 commits into
mainfrom
fix/ci-minio-ghcr
Sep 28, 2026
Merged

QuicksilverSlick merged 2 commits into
mainfrom
fix/ci-minio-ghcr

Conversation

@QuicksilverSlick

Copy link
Copy Markdown
Owner

What this is

MinIO's own image registry now refuses anonymous pulls. quay.io/minio/minio answers "unauthorized: access to the requested resource is not authorized". So every CI job that starts MinIO fails at "Start relay" or "Start integration services" before any test runs. On main 438cec8 (run 36434385770) that was Relay E2E, Backend Integration and both Desktop E2E Integration shards. The same jobs passed on 16 Sep.

Block hit the same wall (block#7867) and fixed it in two PRs. This cherry-picks both:

  • fix(ci): bootstrap the reusable MinIO image in GHCR block/buzz#7869 (99c2acf90): a publisher workflow for ghcr.io/block/buzz-minio:latest, built from MinIO's checksummed release binaries, plus the opt-in docker-compose.ci.yml override. Its publish steps only run on block/buzz main, so on this fork it only builds and smoke-tests when its own files change.
  • fix(ci): consume the published MinIO image block/buzz#7870 (797012ff0): points every MinIO-backed CI job (relay E2E, backend integration, desktop integration shards, mesh lifecycle, Helm quickstart values) at that image through COMPOSE_FILE=docker-compose.yml:docker-compose.ci.yml.

The one conflict was scripts/ci-selection.test.mjs, a test the fork doesn't have. I dropped it; the path-filter change it covered is still in ci.yml.

Verified

  • ghcr.io/block/buzz-minio:latest is public: an anonymous token request and manifest fetch both return 200.
  • Every changed YAML file parses.
  • This PR's own CI runs the affected jobs, because ci.yml selects them when docker-compose.ci.yml changes. That run is the real test.

🤖 Generated with Claude Code

Upstream MinIO image pulls are blocking CI (block#7867). Add a separate
publisher for `ghcr.io/block/buzz-minio:latest`, so the reusable image
can be bootstrapped before CI adopts it in block#7870.

- Build the checksummed official MinIO/mc release binaries from block#7868 on
a digest-pinned Alpine base.
- Build only when image/workflow/Compose inputs change or on manual
dispatch. PRs build and smoke-test; only `block/buzz` main can publish.
- Run the real Compose healthcheck and initializer, object
upload/read/delete, and anonymous-access denial before publishing
`latest` plus a unique `sha-<commit>-run-<id>-<attempt>` tag.
- Manual dispatch disables Docker's layer cache to refresh Alpine
packages. Normal image builds retain caching; each maintenance rebuild
keeps its own tag.

### Rollout

This PR contains only the publisher and opt-in Compose override. **It
does not switch ordinary CI consumers**, so its checks do not require
the unpublished image. This is a separate PR from adoption, as required
by Buzz's squash-only merge rules.

1. Merge this PR; its main-branch workflow builds, tests, and publishes
the image.
2. Make the `buzz-minio` GHCR package public and verify an anonymous
pull of `ghcr.io/block/buzz-minio:latest`. New GHCR packages default to
private.
3. Rebase draft block#7870 onto current main, retarget it to main, run its
integration checks, and merge it to switch all MinIO-backed CI jobs to
the published image.

### Validation

- Updated hosted [MinIO image build and smoke
test](https://github.com/block/buzz/actions/runs/36018177877) passed at
`700ab6d5346b37a64c9defde0016dc65c98aa790`; publication correctly
skipped on the PR.
- Hosted [ordinary
CI](https://github.com/block/buzz/actions/runs/36018178123) passed at
the same head. Its actual Git comparison detected only the five
publisher files, all application path filters were false, and the
MinIO-dependent integration checks were correctly skipped. Synced
current main before this run to eliminate an earlier stale-base
comparison that included unrelated ACP changes.
- Actual five changed paths were passed through the repo's pinned
`dorny/paths-filter`: all application domains were false. All 12
existing path-selection cases and the required-context isolation
contract also passed.
- Publisher actionlint, smoke-script shellcheck, and commit/push hooks
passed.
- Fresh local rebuild of `700ab6d5346b37a64c9defde0016dc65c98aa790`
passed with `docker buildx build --no-cache --platform linux/amd64
--load`. Logs confirm new Alpine index fetches and package installation
rather than a cached install layer. The committed smoke script passed
under local AMD64 emulation using the current merged Compose services
with isolated resource names and no published ports: healthcheck,
initializer/private bucket, object upload/read/delete, and anonymous
HTTP 403. Temporary containers, network, and volume were removed. Both
pinned binary checksums match the official release SHA-256 files.
- Full `just ci` was previously attempted: workspace formatting/Clippy,
desktop checks, and Tauri formatting passed; the run was stopped during
Tauri Clippy. No full local application-suite pass is claimed; hosted
application suites correctly skip this publisher-only change.

---------

Signed-off-by: Tyler Longwell <tlongwell@squareup.com>
(cherry picked from commit 99c2acf)
Switch every CI job that starts MinIO to the public
`ghcr.io/block/buzz-minio:latest` image published by block#7869. Integration
jobs pull the image; image builds stay in the separate, path-filtered
publisher workflow.

- Apply the CI Compose override to both desktop integration shards,
backend integration, relay E2E, and mesh lifecycle, including
script-mediated Compose calls. Both the server and bucket initializer
use the Buzz image.
- Override both MinIO images in Helm's quickstart CI values, covering
the server, bucket initializer, and relay's wait-for-bucket init
container in the gated kind installation.
- Select integration and mesh checks when either Compose file changes,
with regression coverage using the real pinned `dorny/paths-filter`
action.

publication](https://github.com/block/buzz/actions/runs/36021389137/job/107706874954)
succeeded. An anonymous pull using an empty Docker configuration
returned the publisher's digest:
`sha256:b8470bbeafbf57b20c86cf63804682b714bdcfdbb517f3770247e321e623f48f`.
This PR is rebased onto main and ready for consumer integration checks.

- Ran the repository's MinIO smoke script against the actual published
AMD64 image: healthy startup, bucket initialization, object
upload/read/delete, and rejection of anonymous reads all passed. Used
the rendered CI Compose services with isolated local ports and resource
names.
- Verified `mc` runs and writes its configuration as Helm's non-root
UID/GID 65532 with dropped capabilities and no privilege escalation.
- Helm 3.16.4 lint and quickstart rendering passed; all three rendered
MinIO container references use the Buzz image.
- All 14 CI selection cases and the required-context isolation check
passed. Mesh workflow passes actionlint; shared workflows pass with
shellcheck disabled for pre-existing findings.
- Fresh repository-wide review traced workflow and script consumers and
found no remaining CI image omissions. Full application integration
checks and a real kind installation have not been run locally.

---------

Signed-off-by: Tyler Longwell <tlongwell@squareup.com>
(cherry picked from commit 797012f)
@QuicksilverSlick
QuicksilverSlick merged commit 0fe9d0f into main Sep 28, 2026
147 of 149 checks passed
@QuicksilverSlick
QuicksilverSlick deleted the fix/ci-minio-ghcr branch September 28, 2026 15:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants