From 0c753756ffaaf7ec2964d7bda59c285eb9112416 Mon Sep 17 00:00:00 2001 From: Daniel Bernstein Date: Thu, 24 Sep 2026 13:42:49 -0700 Subject: [PATCH 1/2] Record PP-5245 as the MinIO mirror's retirement ticket The Dockerfile, the workflow header and the README all said the mirror was a bridge that should be retired, but none of them named the ticket, so a reader had no way to find it. Given the file also says "do not add features to it", the missing pointer was the thing most likely to let the mirror quietly become permanent. Also folds the 5,000-download deletion threshold into the README's retirement section alongside the delete command, so the cost of waiting is visible next to the instruction, and updates the workflow's "flip the package to public" note from a pending one-time step to a record of what was done. Comment-only: no instruction in the Dockerfile changes, so the image contents are unchanged. Merging does re-trigger the publish workflow, since both files are in its paths filter. Co-Authored-By: Claude Opus 5 --- .github/workflows/build-minio-mirror.yml | 10 +++++++--- README.md | 15 +++++++++++++-- images/minio/Dockerfile | 7 +++++-- 3 files changed, 25 insertions(+), 7 deletions(-) diff --git a/.github/workflows/build-minio-mirror.yml b/.github/workflows/build-minio-mirror.yml index d23d74f..6f9c3af 100644 --- a/.github/workflows/build-minio-mirror.yml +++ b/.github/workflows/build-minio-mirror.yml @@ -13,9 +13,13 @@ name: Build MinIO Mirror # verify the pinned checksums, then throw the result away — an unmerged branch must never be able # to overwrite the release tag that three other repos pin their CI to. # -# One-time manual step: GHCR packages are created private. After the first successful run, set the -# package visibility to public (Org -> Packages -> palace-ci-minio -> Package settings), matching -# the other Palace images. Without that, every developer and CI job would need a docker login. +# The package is public, matching the other Palace images, so no docker login is needed by +# developers or CI. That is not something this workflow can set: GHCR creates packages private, and +# the visibility was flipped by hand (Org -> Packages -> palace-ci-minio -> Package settings). If +# the package is ever recreated, it has to be flipped again. +# +# This mirror is meant to be short-lived. PP-5245 tracks replacing MinIO outright: +# https://ebce-lyrasis.atlassian.net/browse/PP-5245 on: push: diff --git a/README.md b/README.md index f0f0ed6..f1be708 100644 --- a/README.md +++ b/README.md @@ -24,9 +24,20 @@ Used by `circulation`, `library-registry` and `virtual-library-card`. Only pushe publish — pull requests and manual runs from a branch build and validate, then discard, so an unmerged branch cannot overwrite the tag those repos depend on. +### Retirement + This mirror is a bridge, not a destination: the intent is to drop MinIO for a maintained -S3-compatible image. Note that GitHub does not allow self-service deletion of a public package -once any version passes 5,000 downloads. +S3-compatible image, tracked by [PP-5245](https://ebce-lyrasis.atlassian.net/browse/PP-5245). + +It should be short-lived for two reasons. We do not want to become a de-facto public distributor of +a frozen MinIO build. And GitHub does not allow self-service deletion of a public package once any +version passes 5,000 downloads — above that it becomes a Support request. With `pull=True` on every +tox-docker build, ephemeral CI runners and three repos pulling, that threshold arrives faster than +it sounds, so check the count before assuming deletion is still a one-liner: + +``` +gh api -X DELETE /orgs/ThePalaceProject/packages/container/palace-ci-minio +``` ## sync.py diff --git a/images/minio/Dockerfile b/images/minio/Dockerfile index 7023e9d..6df65d7 100644 --- a/images/minio/Dockerfile +++ b/images/minio/Dockerfile @@ -31,8 +31,11 @@ # Dockerfiles — they change only their `FROM` line. Baking configuration in here would fork # the image between repos immediately. # -# This mirror is a bridge, not a destination; see the retirement ticket for replacing MinIO -# outright. Do not add features to it. +# This mirror is a bridge, not a destination. PP-5245 tracks replacing MinIO outright: +# https://ebce-lyrasis.atlassian.net/browse/PP-5245 +# Do not add features to it. Retiring it gets harder the longer it lives: GitHub does not allow +# self-service deletion of a public package once any version passes 5,000 downloads, after which +# it becomes a Support request. # # Updating # -------- From 87d4a6a40a978561ee74582224fd14d76224cfbb Mon Sep 17 00:00:00 2001 From: Daniel Bernstein Date: Thu, 24 Sep 2026 13:53:36 -0700 Subject: [PATCH 2/2] Document the mirror's entrypoint difference from upstream The upstream image set ENTRYPOINT to a docker-entrypoint.sh that supplied the `minio` binary, so `docker run server /data` worked. This mirror has no entrypoint, so that same invocation fails with `exec: "server": executable file not found in $PATH` and the container never leaves Created. The three CI Dockerfiles set their own command and never hit this, which is why it went unnoticed -- but virtual-library-card's README documented exactly that invocation for local development, and it silently broke. Recording the difference here so the next person invoking the image directly finds it before debugging a container that refuses to start. Co-Authored-By: Claude Opus 5 --- images/minio/Dockerfile | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/images/minio/Dockerfile b/images/minio/Dockerfile index 6df65d7..c879830 100644 --- a/images/minio/Dockerfile +++ b/images/minio/Dockerfile @@ -118,4 +118,12 @@ VOLUME ["/data"] EXPOSE 9000 9001 # A plain, unconfigured server. Consumers override this with their own CMD/ENTRYPOINT. +# +# Note one deliberate difference from the upstream image: it set ENTRYPOINT to a +# docker-entrypoint.sh that supplied the `minio` binary, so `docker run server /data` +# worked. There is no entrypoint here, so the binary has to be named: +# `docker run minio server /data`. The old form fails with +# `exec: "server": executable file not found in $PATH` and the container never starts. The three +# CI Dockerfiles set their own command and are unaffected, but anything invoking the image +# directly -- a README, a docker-compose service, a one-off container -- needs the full command. CMD ["minio", "server", "/data", "--address", ":9000", "--console-address", ":9001"]