ci: replace MinIO with RustFS as the local/CI S3 backend - #148
Merged
Merged
Conversation
MinIO no longer publishes public images: Docker Hub and quay.io (minio/minio, minio/mc) now refuse anonymous pulls and dl.min.io returns 410, so the Integration Tests job failed at "Start MinIO" on every branch. RustFS (rustfs/rustfs:1.0.0, Apache-2.0) passes the S3 features the proxy relies on, including conditional PUT, and accepts the same minioadmin credentials, so wrangler configs are unchanged. Buckets are seeded with the aws CLI instead of mc. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Claude finished @alukach's task in 1m 33s —— View job Review complete
✅ No blocking issues — safe to merge. Verified the key claims in the PR description against the code:
Nothing else stood out — env var names, credentials, and health-check endpoints are consistent across Simplify (ponytail) Nothing to cut — the 💰 Estimated review cost: $0.33 · 1m33s · 12 turns |
|
📖 Docs preview deployed to https://multistore-docs-pr-148.development-seed.workers.dev
|
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What I'm changing
The Integration Tests job fails on every branch. It stops at the "Start MinIO" step, before any code under test runs:
MinIO has stopped publishing public images. Docker Hub refuses
minio/minioandminio/mc. The quay.io mirrors also refuse anonymous pulls:quay.io/minio/minioreturns 401 since about 2026-09-24.dl.min.io, where CI downloads themcbinary, returns 410. The only image still public,quay.io/minio/aistor/minio, starts but denies every S3 operation without a license. The last green CI run was on 2026-07-15.This PR replaces MinIO with RustFS, which is Apache-2.0 and at release 1.0.0. I compared RustFS, VersityGW, SeaweedFS and Garage with a probe of every S3 feature the proxy uses. RustFS passes all of them, including conditional PUT (
If-Match/If-None-Match); the proxy forwards those headers to the backend since #122. RustFS also accepts the existingminioadminstatic credentials, so no wrangler config changes. Garage does not enforce conditional PUTs, which rules it out.How I did it
.github/workflows/ci.yml: "Start MinIO" becomes "Start RustFS". It runsrustfs/rustfs:1.0.0with the tag pinned, so a registry change can't break every branch at once. The step polls/health. "Seed buckets" uses theawsCLI that is preinstalled on runners instead ofmc.docker-compose.yaml: the services are nowrustfsandrustfs-init. The healthcheck curls/health. The seeder runs onamazon/aws-cli:2.37.2and is idempotent: it skipsmbfor buckets that already exist, sodocker compose upworks on a volume that already has data.mc anonymous set download: the proxy already enforces anonymous access (anonymous_access = true) and always signs backend requests with the configured keys. A public bucket policy on the backend was never needed.scripts/integration-test.sh,Makefile,CONTRIBUTING.md,docs/getting-started/*: rename MinIO to RustFS in messages and docs. The readiness probe now uses/health. Mentions of MinIO as a user-configurable backend (for exampledocs/configuration/buckets.md) are unchanged because they describe production setups, not the local fixture.Test plan
scripts/integration-test.shlocally against RustFS: 37 passed, 7 skipped. The skipped tests are OIDC tests that only run in GitHub Actions.docker compose up: RustFS is healthy and the seeder creates both buckets and exits 0.TestRangeRequestshas failed on every branch since at least 2026-08-31.🤖 Generated with Claude Code