mirror of
https://github.com/pgsty/minio.git
synced 2026-08-09 15:53:28 +03:00
b6d47b739c
Findings from an adversarial review (Codex, gpt-5.6-sol at max effort) of2ff594f4band4c34d2309, each independently verified before fixing: - SBOM generation: buildx attaches a provenance attestation, so every per-arch digest names an OCI index; Syft's platform default on an amd64 runner cannot resolve an arm64-only index and the step dies. Pass --platform explicitly on all four Syft calls (the two classic lanes had the same latent defect - the renamed workflow has not run yet, which is why it never fired). - Release ordering: the HEALTHCHECK survival check now runs against the pushed architecture image before the versioned and rolling multi-arch manifests are created, so a broken health config blocks their promotion; the comment now states honestly that the arch-suffixed tags are already public at that point. - Gate assertions: tar's member-argument mode exits non-zero on any missing name, which under pipefail masked a found forbidden file when exactly one of them existed; -tv prints symlinks as 'name -> target', defeating $-anchored greps; and the licenses check proved only one-of-three. Export the rootfs once and assert every required and forbidden entry individually (busybox/sh and usr/bin/mc[li] now covered), and match the image healthcheck as an exact array instead of a substring. - Probe target vs CLI-configured servers: a probe process cannot see PID 1's argv, so --url gains EnvVar MINIO_HEALTHCHECK_URL as the documented way to point the baked-in HEALTHCHECK at a server whose address/TLS comes from command-line arguments (verified end to end: server on --address :9010, env var alone turns the container healthy). Baseline regenerated for the new env token. - IPv6 zone identifiers: serialize probe URLs via url.URL.String() so [fe80::1%eth0]:9000 becomes a valid %25-escaped URL (tests added). - Boolean flags: read --json/--quiet via Bool() so --json=false is false, instead of IsSet() which treats any occurrence as true. - Docker's HEALTHCHECK timeout raised to 10s: an outer deadline equal to the probe's own 5s always SIGKILLed the probe before it could print its diagnostic line. - test-release path filter now also triggers on cmd/healthcheck-main.go and cmd/main.go, so subcommand regressions run the image gate. Not adopted: require_text's comment-insensitivity in verify-rebrand.sh (snapshot-tripwire by design, consistent with its other assertions - the semantic check lives in the CI gate now), and full staging-then-promote tag publishing (a workflow-wide redesign shared with the classic lanes, tracked as follow-up). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
51 lines
2.2 KiB
Docker
51 lines
2.2 KiB
Docker
# The distroless variant ships exactly one program: the silo binary.
|
|
# No shell, no mc, no curl, no entrypoint script; health checking is
|
|
# provided by the binary itself (`silo healthcheck`).
|
|
# Design note: https://silo.pgsty.com/compatibility/feature/healthcheck/
|
|
|
|
# A distroless final stage cannot RUN anything, so /data is prepared in a
|
|
# throwaway stage. It ships world-writable (see pgsty/silo#55): Docker
|
|
# seeds fresh volumes from the image-layer mountpoint, no entrypoint
|
|
# exists to repair ownership at runtime, and 0777 is what keeps every
|
|
# privilege mode working, --user included.
|
|
FROM busybox:1.37.0 AS prep
|
|
RUN mkdir -p /prep/data && chmod 0777 /prep/data
|
|
|
|
FROM gcr.io/distroless/static-debian12:latest
|
|
|
|
LABEL org.opencontainers.image.title="Silo" \
|
|
org.opencontainers.image.description="S3-Interface Libre Object Storage (distroless)" \
|
|
org.opencontainers.image.url="https://silo.pgsty.com" \
|
|
org.opencontainers.image.source="https://github.com/pgsty/silo" \
|
|
org.opencontainers.image.licenses="AGPL-3.0-or-later" \
|
|
maintainer="PGSTY <https://silo.pgsty.com>"
|
|
|
|
ENV MINIO_ACCESS_KEY_FILE=access_key \
|
|
MINIO_SECRET_KEY_FILE=secret_key \
|
|
MINIO_ROOT_USER_FILE=access_key \
|
|
MINIO_ROOT_PASSWORD_FILE=secret_key \
|
|
MINIO_KMS_SECRET_KEY_FILE=kms_master_key \
|
|
MINIO_CONFIG_ENV_FILE=config.env \
|
|
HOME=/tmp
|
|
|
|
COPY --chmod=0755 silo /usr/bin/silo
|
|
# COPY of a directory copies its contents, not the directory entry, so an
|
|
# empty /prep/data would arrive as a default root:0755 /data and non-root
|
|
# runs would fail storage init. Copying the parent makes data/ itself a
|
|
# copied entry, which --chmod then actually applies to.
|
|
COPY --from=prep --chmod=0777 /prep/ /
|
|
COPY LICENSE NOTICE CREDITS /licenses/
|
|
|
|
EXPOSE 9000
|
|
VOLUME ["/data"]
|
|
|
|
# Exec form is mandatory: there is no /bin/sh in this image. `ready`
|
|
# rather than `live` because Docker health feeds start-order gating
|
|
# (readiness semantics); the two are identical unless KMS/etcd are used.
|
|
# The outer timeout stays above the probe's own 5s deadline so the
|
|
# probe can report its diagnostic line instead of being SIGKILLed.
|
|
HEALTHCHECK --interval=30s --timeout=10s --start-period=2m --start-interval=2s --retries=3 \
|
|
CMD ["/usr/bin/silo", "healthcheck", "ready"]
|
|
|
|
ENTRYPOINT ["/usr/bin/silo"]
|