Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 7 additions & 3 deletions .github/workflows/build-minio-mirror.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,9 +13,13 @@ name: Build MinIO Mirror
# verify the pinned checksums, then throw the result away — an unmerged branch must never be able
# to overwrite the release tag that three other repos pin their CI to.
#
# One-time manual step: GHCR packages are created private. After the first successful run, set the
# package visibility to public (Org -> Packages -> palace-ci-minio -> Package settings), matching
# the other Palace images. Without that, every developer and CI job would need a docker login.
# The package is public, matching the other Palace images, so no docker login is needed by
# developers or CI. That is not something this workflow can set: GHCR creates packages private, and
# the visibility was flipped by hand (Org -> Packages -> palace-ci-minio -> Package settings). If
# the package is ever recreated, it has to be flipped again.
#
# This mirror is meant to be short-lived. PP-5245 tracks replacing MinIO outright:
# https://ebce-lyrasis.atlassian.net/browse/PP-5245

on:
push:
Expand Down
15 changes: 13 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -24,9 +24,20 @@ Used by `circulation`, `library-registry` and `virtual-library-card`. Only pushe
publish — pull requests and manual runs from a branch build and validate, then discard, so an
unmerged branch cannot overwrite the tag those repos depend on.

### Retirement

This mirror is a bridge, not a destination: the intent is to drop MinIO for a maintained
S3-compatible image. Note that GitHub does not allow self-service deletion of a public package
once any version passes 5,000 downloads.
S3-compatible image, tracked by [PP-5245](https://ebce-lyrasis.atlassian.net/browse/PP-5245).

It should be short-lived for two reasons. We do not want to become a de-facto public distributor of
a frozen MinIO build. And GitHub does not allow self-service deletion of a public package once any
version passes 5,000 downloads — above that it becomes a Support request. With `pull=True` on every
tox-docker build, ephemeral CI runners and three repos pulling, that threshold arrives faster than
it sounds, so check the count before assuming deletion is still a one-liner:

```
gh api -X DELETE /orgs/ThePalaceProject/packages/container/palace-ci-minio
```

## sync.py

Expand Down
15 changes: 13 additions & 2 deletions images/minio/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -31,8 +31,11 @@
# Dockerfiles — they change only their `FROM` line. Baking configuration in here would fork
# the image between repos immediately.
#
# This mirror is a bridge, not a destination; see the retirement ticket for replacing MinIO
# outright. Do not add features to it.
# This mirror is a bridge, not a destination. PP-5245 tracks replacing MinIO outright:
# https://ebce-lyrasis.atlassian.net/browse/PP-5245
# Do not add features to it. Retiring it gets harder the longer it lives: GitHub does not allow
# self-service deletion of a public package once any version passes 5,000 downloads, after which
# it becomes a Support request.
#
# Updating
# --------
Expand Down Expand Up @@ -115,4 +118,12 @@ VOLUME ["/data"]
EXPOSE 9000 9001

# A plain, unconfigured server. Consumers override this with their own CMD/ENTRYPOINT.
#
# Note one deliberate difference from the upstream image: it set ENTRYPOINT to a
# docker-entrypoint.sh that supplied the `minio` binary, so `docker run <image> server /data`
# worked. There is no entrypoint here, so the binary has to be named:
# `docker run <image> minio server /data`. The old form fails with
# `exec: "server": executable file not found in $PATH` and the container never starts. The three
# CI Dockerfiles set their own command and are unaffected, but anything invoking the image
# directly -- a README, a docker-compose service, a one-off container -- needs the full command.
CMD ["minio", "server", "/data", "--address", ":9000", "--console-address", ":9001"]