Conversation
…they exist The entrypoint starts the server, waits until it is ready, then creates each listed bucket and applies its anonymous-access policy. The health check only passes once that setup has finished, so compose can wait on service_healthy instead of running a separate init container. Without the variable the server is exec'd directly, as before. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FA1nFdyB4WmWTw4syt89Yz
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FA1nFdyB4WmWTw4syt89Yz
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FA1nFdyB4WmWTw4syt89Yz
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FA1nFdyB4WmWTw4syt89Yz
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Stacks that use this image currently need a second, short-lived "init" container whose only job is to create buckets and make some of them publicly readable before the application starts. This change moves that job into the image itself. Setting
MINIO_DEFAULT_BUCKETS=media:public,backupson the server container creates those buckets at startup, and the image's health check only turns healthy once they exist. A compose file can then drop the init container and simply wait for the MinIO service to be healthy. Stacks that do not set the variable see no change: the server starts exactly as it did before.The variable name and format match the old Bitnami MinIO image, which many compose files were written against before that image was withdrawn.
List of Changes
MINIO_DEFAULT_BUCKETSto a comma-separated list ofname[:policy]entries creates each bucket and applies its anonymous-access policy (none,download,uploadorpublic). One log line is printed per bucket.depends_on: condition: service_healthyreplaces the init container.--versionand other non-servercommands go straight tominio, and--entrypoint mcstill runs the client.test/smoke.shagainst it before the multi-arch build.Detailed Description
Entrypoint.
docker-entrypoint.shis the newENTRYPOINT; the defaultCMDis unchanged (server /data --console-address ":9001"). If the first argument is notserver, orMINIO_DEFAULT_BUCKETSis empty, itexecs/usr/bin/miniowith the original arguments, so the server is PID 1 as before. Otherwise it starts the server in the background, forwards SIGTERM and SIGINT to it, pollsmc readyuntil the server answers (bounded per attempt, becausemc readyretries forever on its own, and bounded overall byMINIO_DEFAULT_BUCKETS_TIMEOUT, default 120 seconds), then runsmc mb --ignore-existingandmc anonymous setfor each entry. It then waits on the server so the container's exit code is the server's. Themcalias with the root credentials lives in a temporary config directory that is removed after setup, and credentials are never logged.Health check marker. After the last bucket is set up, the entrypoint writes
/tmp/minio-default-buckets.ready.minio-healthcheckpasses only ifmc readysucceeds against the local server and, whenMINIO_DEFAULT_BUCKETSis set, that marker exists. The entrypoint deletes the marker at every start, because/tmpsurvives adocker restart, so a restarted container is not reported healthy before its buckets are checked again.Port. The scripts reach the server at
http://127.0.0.1:<port>. The port is read from the server's--addressargument (default 9000) and written to/tmp/minio-api-portfor the health check.Limits.
MINIO_ROOT_USERandMINIO_ROOT_PASSWORD.MINIO_DEFAULT_BUCKETSis compatible with Bitnami; its other variables are not implemented.The final build stage still only copies files (
COPY --chmod=0755), so the arm64 variant continues to build on an amd64 runner without emulation.How to Test
The smoke test checks, in order:
minio --versionreports the pinned release through the entrypoint and--entrypoint mcworks; a container withMINIO_DEFAULT_BUCKETS=smoke-public:public, smoke-privatebecomes healthy, logs one line per bucket and never logs the password; both buckets exist with the right policies; an anonymous GET succeeds on the public bucket and is denied on the private one; the container is healthy again afterdocker restart;docker stopreturns well within the timeout with exit code 0; an unknown policy stops the container with a non-zero code and a clear message; and a container without the variable becomes healthy withminioas PID 1.For arm64:
🤖 Generated with Claude Code
https://claude.ai/code/session_01FA1nFdyB4WmWTw4syt89Yz