Files
stack/infra/images/mc.Dockerfile
kert bc3bab8a42
All checks were successful
CI / lint (push) Successful in 47s
CI / notebooks-smoke (push) Successful in 1m33s
Deploy / notebooks (push) Has been skipped
Deploy / zotero (push) Has been skipped
Deploy / docs (push) Has been skipped
Deploy / api (push) Has been skipped
Deploy / llm (push) Has been skipped
Deploy / mc (push) Successful in 18s
Infra CI / notebooks (push) Successful in 1m12s
Infra CI / zotero (push) Successful in 23s
Infra CI / docs (push) Successful in 1m37s
Infra CI / api (push) Successful in 1m6s
Infra CI / llm (push) Successful in 47s
Infra CI / mc (push) Successful in 14s
Deploy / report (push) Successful in 14s
CI / test (push) Successful in 17m50s
fix(infra,ci): mc base image moved to quay.io (docker.io/minio/mc is gone); failure-issue step bootstraps uv
Infra CI's mc job has failed on every push since docker.io/minio/mc
started returning 'pull access denied, repository does not exist' — and
nobody heard, because the generated File-failure-issue step ran
`uv run` in a job that never installs uv ("uv: command not found",
swallowed by the trailing || true). Pin quay.io/minio/mc to a release
tag; the filer installs uv when it is missing.
2026-09-11 17:53:42 -04:00

14 lines
553 B
Docker

# syntax=docker/dockerfile:1
# MinIO Client (mc) sidecar — least-privilege admin helper for RustFS.
# The image moved off Docker Hub (docker.io/minio/mc now 404s — pull access
# denied) to quay.io; pinned to a release tag so a base-image change is a
# reviewed diff, not a silent CI break.
# Runs as non-root, read-only filesystem, no capabilities.
FROM quay.io/minio/mc:RELEASE.2025-08-13T08-35-41Z AS mc
FROM alpine:3
RUN addgroup -g 10002 -S mc && adduser -u 10002 -S mc -G mc
COPY --from=mc /usr/bin/mc /usr/bin/mc
USER mc:mc
ENTRYPOINT ["mc"]