Skip to content

fix(ci): switch MinIO tests to Chainguard images - #4985

Merged
carderne merged 2 commits into
mainfrom
fix/chainguard-minio
Sep 28, 2026
Merged

carderne merged 2 commits into
mainfrom
fix/chainguard-minio

Conversation

@carderne

Copy link
Copy Markdown
Collaborator

Summary

Switches the MinIO test and local development containers to Chainguard's maintained Docker Hub images because the previous Quay images are no longer publicly pullable.

Fix

Pins the multi-platform server and client images by digest. The local stack now uses the Chainguard client entrypoint for bucket initialization, while test containers keep client state in a writable temporary directory.

@changeset-bot

changeset-bot Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 65585f0

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@coderabbitai

coderabbitai Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Advanced

Run ID: 40353fbc-bc90-40a7-a77e-1d4f1d5ca9f4

📥 Commits

Reviewing files that changed from the base of the PR and between c2b7a72 and 65585f0.

📒 Files selected for processing (4)
  • .github/workflows/e2e-webapp.yml
  • .github/workflows/unit-tests-webapp.yml
  • docker/docker-compose.yml
  • internal-packages/testcontainers/src/minio.ts

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review.

📜 Recent review details
⏰ Context from checks skipped due to timeout. (4)
  • GitHub Check: webapp / 🧪 Unit Tests: Webapp (11, 24)
  • GitHub Check: webapp / 🧪 Unit Tests: Webapp (21, 24)
  • GitHub Check: internal / 🧪 Unit Tests: Internal (2)
  • GitHub Check: internal / 🧪 Unit Tests: Internal (1)
🧰 Additional context used
🪛 Betterleaks (1.8.1)
docker/docker-compose.yml

[high] 153-153: Detected a password embedded in a service connection URI, which may expose direct access to the referenced service.

(generic-credential-uri)


[high] 152-152: Detected a potential hardcoded password literal, which may expose account credentials.

(generic-password)


[high] 176-176: Detected a password embedded in a service connection URI, which may expose direct access to the referenced service.

(generic-credential-uri)

🪛 Checkov (3.3.16)
docker/docker-compose.yml

[medium] 153-154: Basic Auth Credentials

(CKV_SECRET_4)


Walkthrough

The CI workflows now pre-pull pinned Chainguard MinIO images. Docker Compose uses Chainguard MinIO and client images, checks readiness with mc ready local, and creates the packets bucket after MinIO becomes healthy. The MinIO test container uses a Chainguard image and supplies an explicit mc config directory for alias setup, bucket creation, and bucket reset operations.

Priority: ➖ Normal

Merge Risk: ⚪ Minimal · up to 65585

The changed MinIO commands are compatible with the pinned images on the inspected platforms. No actionable merge-blocking issue remains after normal checks.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 65585

The changes affect local development and test infrastructure. No new security exposure was established, but the replacement images and startup behavior have not been fully verified in execution.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The evidenced privileged operations target the addressed MinIO container or the local Compose MinIO service. The changed exported methods and fixture do not establish a new caller or a broader Docker target.

Trust Boundaries and Controls

  • inferred — The explicit mc configuration path does not itself establish cross-container credential sharing: startup and reset address a specific container ID. Whether other processes inside that container can read the resulting configuration is not established.

Resilience and Maintainability Implications

  • inferred — A reset can report success without proving the bucket is empty if deletion fails, and overlapping users of one container can observe intermediate state. The changed configuration-directory arguments do not introduce those pre-existing transition semantics.

Hardening Proposals

  • proposed — If an empty bucket is required for test isolation, fail reset when deletion fails and ensure a container created during startup is cleaned up if later setup fails.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description clearly explains the MinIO image migration and the main implementation changes. However, it omits the required issue reference, checklist, testing section, changelog, and screenshots s… Add the required template sections. Include the issue reference, completed checklist items, testing steps and results, a short changelog entry, and screenshots or an explicit statement that screenshots are not applicable.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely describes the main change: switching MinIO tests to Chainguard images. It follows the conventional commit format shown in the title.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 1…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Description check

Explanation

The description clearly explains the MinIO image migration and the main implementation changes. However, it omits the required issue reference, checklist, testing section, changelog, and screenshots section.

  • Fix all pre-merge checks with AI
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

devin-ai-integration[bot]

This comment was marked as resolved.

@carderne
carderne added this pull request to the merge queue Sep 28, 2026
Merged via the queue into main with commit ad005a4 Sep 28, 2026
57 checks passed
@carderne
carderne deleted the fix/chainguard-minio branch September 28, 2026 09:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants