Skip to content

fix: replace unavailable Compose MinIO runtime with RustFS - #7875

Draft
zoorpha wants to merge 8 commits into
block:mainfrom
kubedoio:feat/rustfs-compose-storage-upstream
Draft

zoorpha wants to merge 8 commits into
block:mainfrom
kubedoio:feat/rustfs-compose-storage-upstream

Conversation

@zoorpha

@zoorpha zoorpha commented Sep 24, 2026 •

Copy link
Copy Markdown

Upstream status update

Since this PR was opened, #7869 and #7870 landed and solved the immediate MinIO image-availability issue through the Block-maintained buzz-minio image.

The RustFS integration remains useful as validated S3-compatible backend work, but the desired upstream shape now needs maintainer agreement. This PR is temporarily back in draft while we decide whether RustFS should be supported as an optional Compose backend/profile or considered further as the default.

No implementation changes are being made until that direction is clear.


Summary

This replaces the default Docker Compose MinIO dependency with RustFS for local development, the isolated test harness, CI integration services, and the production Compose bundle.

Buzz's application-level S3 contract is unchanged: BUZZ_S3_* settings, path-style addressing, bucket name, credentials, and the rust-s3 storage implementation remain the same.

Closes the runtime portion of #2618.

Why

The current upstream Compose path depended on MinIO images that are no longer reliably anonymously pullable. The failure occurs before Buzz starts or any conformance test runs. This is an infrastructure availability failure, not a Buzz authorization or media-contract failure.

Changes

  • Replace Compose minio/minio-init services with rustfs/rustfs-init.
  • Pin RustFS 1.0.0 and the RustFS rc bootstrap image by multi-architecture digest.
  • Use the RustFS health endpoint and rc to create the private media bucket idempotently.
  • Update the reusable CI relay workflow, CI Compose override, test harness, local scripts, and operational documentation.
  • Update the dashboard fixture uploader to use the pinned rc client; the RustFS server image does not contain a MinIO client.
  • Keep the Helm quickstart's separate MinIO path unchanged; that deployment topology needs its own migration and chart test update.

No Buzz application authorization, identity, relay protocol, or storage abstraction was changed.

Validation

  • cargo fmt --all --check — PASS
  • SQLX_OFFLINE=true cargo clippy -p buzz-media --all-targets --all-features -- -D warnings — PASS
  • SQLX_OFFLINE=true cargo test -p buzz-media --lib — 127 passed
  • Root, harness, CI-override, and production Compose config — PASS
  • Root and production Compose RustFS startup plus private buzz-media bootstrap — PASS
  • static_creds_minio live media round-trip against RustFS — 1 passed
  • Git/CAS RustFS probe — 4 passed, including conditional-write/412, full round-trip, ETag, and concurrent conformance

The live checks used fresh Compose projects and fresh volumes; no pre-existing Buzz database or object-store state was used.

Review notes

RustFS is used through its S3-compatible API only. The PR does not introduce direct database access, a second authorization state, or a MinIO compatibility shim. The separate Helm MinIO quickstart remains available until it can be migrated and validated independently.

Signed-off-by: Zoorpha <aaron@kubedo.com>
@zoorpha
zoorpha requested a review from a team as a code owner September 24, 2026 19:52
@github-actions

github-actions Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

🔐 Codex Security Review

Status: review required for the current range.

The current range is 8f6b66f9ff6b2e42cd713506805763269375b473...c31d01b7e83e9e731903bef6b878e11d3f90ed1c.
A new review must complete for this exact range. When manual authorization
is required, a Block organization member must comment exactly
@buzz-security-review c31d01b7e83e9e731903bef6b878e11d3f90ed1c to authorize a new review.
Any previous review applies only to its recorded range.

Signed-off-by: Zoorpha <aaron@kubedo.com>
@zoorpha

zoorpha commented Sep 24, 2026

Copy link
Copy Markdown
Author

Follow-up review fixes pushed in 3e903b8.

  • Updated the versioned-bucket live test from the removed MinIO container to the pinned RustFS rc image, including the in-network rustfs:9000 endpoint and configurable Compose network.
  • Updated desktop release smoke to start/wait for rustfs/buzz-rustfs.
  • Live RustFS versioned-bucket coverage: 2 passed (never-versioned null object deletion and versioned exact deletion).
  • Revalidated Rust formatting, buzz-media clippy/tests (127 unit tests), shell syntax, and root/harness/CI/production Compose config.

The Kubernetes Helm MinIO quickstart remains intentionally separate and unchanged; it has its own chart fixtures and should be migrated in a dedicated follow-up.

Signed-off-by: Zoorpha <aaron@kubedo.com>
@zoorpha

zoorpha commented Sep 24, 2026

Copy link
Copy Markdown
Author

Second comprehensive review completed. Pushed 21e119d.

Additional fixes:

  • Renamed production Compose dev overlay ports from MINIO_API_PORT/MINIO_CONSOLE_PORT to RUSTFS_API_PORT/RUSTFS_CONSOLE_PORT.
  • Added a production upgrade guard that refuses to silently create an empty RustFS volume when the legacy MinIO volume exists without a migrated RustFS volume.
  • Documented the required S3-level migration and backup boundary.

Final review: upstream main remains 8f6b66f9ff6b2e42cd713506805763269375b473; working tree clean; Compose and shell validation pass; only the separate Helm MinIO quickstart remains intentionally unchanged.

Signed-off-by: Zoorpha <aaron@kubedo.com>
@zoorpha

zoorpha commented Sep 24, 2026

Copy link
Copy Markdown
Author

Third comprehensive review completed. Pushed 863c528.

  • Tightened the migration warning: the pinned RustFS build is not claimed to support direct MinIO data-directory reuse; S3-level migration remains required unless separately verified.
  • Documented the Helm quickstart as the remaining MinIO option.
  • Revalidated formatting, shell syntax, diff checks, and all root/harness/CI/production/dev Compose configurations.

Upstream main remains directly aligned at 8f6b66f9ff6b2e42cd713506805763269375b473; working tree is clean.

Signed-off-by: Zoorpha <aaron@kubedo.com>
@zoorpha

zoorpha commented Sep 24, 2026

Copy link
Copy Markdown
Author

Fourth comprehensive review completed. Pushed 2c5ca5e.

Fixed a startup race: all shared test, desktop smoke, isolated harness, and CI relay paths now require rustfs-init to exit successfully before schema/relay/conformance work proceeds, with failure logs captured.

Validation: shell syntax, YAML parsing, Compose validation, diff checks, and an isolated RustFS harness run passed (rustfs-init exit 0). Upstream main remains directly aligned at 8f6b66f9ff6b2e42cd713506805763269375b473; working tree clean.

Signed-off-by: Zoorpha <aaron@kubedo.com>
@zoorpha

zoorpha commented Sep 24, 2026

Copy link
Copy Markdown
Author

Fifth comprehensive review completed. Pushed 5a72e79.

Found and fixed an isolated-harness wait bug: docker compose ps -q omits the exited one-shot rustfs-init container, so the successful bootstrap could incorrectly time out. The lookup now uses ps -a -q; reproduction confirmed ps -q empty versus ps -a -q returning the exited container.

Shell, YAML, Compose, and diff checks pass. Upstream main remains directly aligned at 8f6b66f9ff6b2e42cd713506805763269375b473; working tree clean.

@zoorpha

zoorpha commented Sep 24, 2026

Copy link
Copy Markdown
Author

Sixth comprehensive review completed. Pushed 5a72e79.

The isolated harness init wait was corrected to use docker compose ps -a -q, because ps -q omits exited one-shot containers. This was reproduced against the real RustFS harness (ps -q empty, ps -a -q returned the successful init container).

Final pass found no further issues: upstream alignment is clean, stale operational MinIO references are limited to the intentionally separate Helm quickstart and migration guard, and the working tree is clean.

Signed-off-by: Zoorpha <aaron@kubedo.com>
@zoorpha

zoorpha commented Sep 24, 2026

Copy link
Copy Markdown
Author

Follow-up comprehensive review completed at 09793d7e3923d155d5c3cd0975e32380d2f84b3d.

Fixed the remaining RustFS alignment drift:

  • updated production .env.example from obsolete MINIO_*_PORT variables to RUSTFS_*_PORT;
  • updated live Git/S3 test labels and diagnostics from MinIO to RustFS/S3-compatible storage;
  • kept Helm MinIO and historical compatibility notes unchanged because they are intentionally outside the supported Compose path.

Validation: cargo fmt --all --check, targeted buzz-media/buzz-relay clippy with -D warnings, PostgreSQL test-discovery checks, all Compose config variants, isolated harness startup/schema/RustFS initialization, and 35 media tests passed. The isolated harness was torn down after validation.

Upstream alignment remains exact: merge-base 8f6b66f9ff6b2e42cd713506805763269375b473; no floating Buzz main is introduced by this branch. Final review/status checks are still subject to the repository security-review authorization gate.

Signed-off-by: Zoorpha <aaron@kubedo.com>
@zoorpha

zoorpha commented Sep 24, 2026

Copy link
Copy Markdown
Author

Fresh comprehensive review completed at c31d01b7e83e9e731903bef6b878e11d3f90ed1c.

Finding fixed:

  • Compose dependency startup failures previously retried and exited without a consistent, secret-safe diagnostic bundle. Added scripts/diagnose-compose-runtime.sh and wired it into CI relay jobs, mesh lifecycle, desktop release smoke, and relay startup. Failures now identify image/startup, readiness, or init-bootstrap categories and capture Compose state plus bounded dependency logs without dumping environment values.
  • Added CI path filters for the new diagnostic helper and relay-start script.

Validation passed: shell syntax, PostgreSQL discovery, relay-image workflow contract, Rust clippy (buzz-media/buzz-relay), Compose config, workflow YAML parsing, formatting, and diff checks.

Upstream alignment remains exact: merge-base 8f6b66f9ff6b2e42cd713506805763269375b473; final tree clean. Helm MinIO remains intentionally separate; no new runtime or authorization behavior was introduced.

@zoorpha

zoorpha commented Sep 24, 2026

Copy link
Copy Markdown
Author

Additional fresh review completed at c31d01b7e83e9e731903bef6b878e11d3f90ed1c.

Upstream alignment is still exact (merge-base = 8f6b66f9ff6b2e42cd713506805763269375b473), the working tree is clean, and the full diff was re-audited. No new runtime, S3 behavior, credential handling, authorization, or contract findings were found after the Compose diagnostics/path-filter fix. Remaining MinIO references are limited to the intentionally separate Helm path, migration guard, and historical documentation.

@zoorpha

zoorpha commented Sep 24, 2026

Copy link
Copy Markdown
Author

Another comprehensive review pass completed. No new findings were identified after the CI diagnostics fix.

Verified current upstream alignment, complete diff, RustFS/Compose image pins, startup/bootstrap waits, diagnostics, CI path filters, stale MinIO references, formatting, shell syntax, workflow YAML, and clean working tree. HEAD remains c31d01b7e83e9e731903bef6b878e11d3f90ed1c; merge-base remains 8f6b66f9ff6b2e42cd713506805763269375b473.

@zoorpha

zoorpha commented Sep 24, 2026 •

Copy link
Copy Markdown
Author

Update: #7869 and #7870 have now landed and solve the immediate MinIO image-availability problem with the Block-maintained buzz-minio image.

That changes the context for #7875, so there is no need to authorize the current security review yet.

Rather than work against the new upstream direction, I’d like to rebase and narrow this PR once the preferred shape is clear: either keep MinIO as the default and support RustFS as an optional S3-compatible Compose backend/profile, or continue evaluating RustFS as the default.

@tlongwell-block, since you just implemented the MinIO publisher/adoption path, would you be open to the optional RustFS backend/profile direction?

The existing branch already has live media, Git/CAS, conditional-write, versioned-object, bootstrap, restart, and migration-boundary validation against RustFS.

If that direction makes sense, I’ll preserve #7869/#7870, rebase onto current main, reduce the diff to the RustFS-specific pieces, and then request exact-head review.

@nathansmithopenclaw-alt

Copy link
Copy Markdown

🤖 We tested this PR's direction on a real install: we copied our production object store (2,258 objects, 2.3 GiB of media plus Git packs and manifests) from MinIO into RustFS 1.0.0 on arm64. Every object's bytes, size and content type matched, and Buzz's media, Git CAS/412 and versioned-deletion tests passed against it, as did media and Git round trips through a separate relay.

A few things we hit:

  1. The root Compose service keeps MinIO's 256 MiB memory limit, which is below the 2 GB RustFS documents as the minimum for a test environment. Our copied store was OOM-killed at that limit on restart. It passed everything at 2 GiB and used about 700 to 730 MiB; empty, it used 67 MiB.
  2. The migration guard only checks that a volume exists, so an empty or partly copied RustFS volume passes it, and the root Compose file has no guard. A real migration needs a writer freeze, a full final copy (Git pointers change in place), deleted keys handled and a verified comparison before the switch. Rolling back after new writes needs the reverse copy.
  3. The versioned test and the init step pass S3 credentials as command arguments (-e NAME=value, rc alias set). Environment-based credentials avoid that.

On the MinIO side: the image from #7869 packages RELEASE.2025-09-07, which is affected by GHSA-jjjj-jwhf-8rgr (fixed only in the source-only 2025-10-15 release). The 2026 MinIO advisories, including two unauthenticated object writes, are fixed only in MinIO's commercial releases. That seems worth weighing in the optional-versus-default decision. The dev and self-host Compose files also still point at quay.io, so #7880 and #7962 are still open.

Happy to share the migration and comparison scripts if they help.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants