Conversation
Signed-off-by: Zoorpha <aaron@kubedo.com>
🔐 Codex Security Review
|
Signed-off-by: Zoorpha <aaron@kubedo.com>
|
Follow-up review fixes pushed in 3e903b8.
The Kubernetes Helm MinIO quickstart remains intentionally separate and unchanged; it has its own chart fixtures and should be migrated in a dedicated follow-up. |
Signed-off-by: Zoorpha <aaron@kubedo.com>
|
Second comprehensive review completed. Pushed 21e119d. Additional fixes:
Final review: upstream |
Signed-off-by: Zoorpha <aaron@kubedo.com>
|
Third comprehensive review completed. Pushed 863c528.
Upstream |
Signed-off-by: Zoorpha <aaron@kubedo.com>
|
Fourth comprehensive review completed. Pushed 2c5ca5e. Fixed a startup race: all shared test, desktop smoke, isolated harness, and CI relay paths now require Validation: shell syntax, YAML parsing, Compose validation, diff checks, and an isolated RustFS harness run passed ( |
Signed-off-by: Zoorpha <aaron@kubedo.com>
|
Fifth comprehensive review completed. Pushed 5a72e79. Found and fixed an isolated-harness wait bug: Shell, YAML, Compose, and diff checks pass. Upstream |
|
Sixth comprehensive review completed. Pushed 5a72e79. The isolated harness init wait was corrected to use Final pass found no further issues: upstream alignment is clean, stale operational MinIO references are limited to the intentionally separate Helm quickstart and migration guard, and the working tree is clean. |
Signed-off-by: Zoorpha <aaron@kubedo.com>
|
Follow-up comprehensive review completed at Fixed the remaining RustFS alignment drift:
Validation: Upstream alignment remains exact: merge-base |
Signed-off-by: Zoorpha <aaron@kubedo.com>
|
Fresh comprehensive review completed at Finding fixed:
Validation passed: shell syntax, PostgreSQL discovery, relay-image workflow contract, Rust clippy ( Upstream alignment remains exact: merge-base |
|
Additional fresh review completed at Upstream alignment is still exact ( |
|
Another comprehensive review pass completed. No new findings were identified after the CI diagnostics fix. Verified current upstream alignment, complete diff, RustFS/Compose image pins, startup/bootstrap waits, diagnostics, CI path filters, stale MinIO references, formatting, shell syntax, workflow YAML, and clean working tree. HEAD remains |
|
Update: #7869 and #7870 have now landed and solve the immediate MinIO image-availability problem with the Block-maintained That changes the context for #7875, so there is no need to authorize the current security review yet. Rather than work against the new upstream direction, I’d like to rebase and narrow this PR once the preferred shape is clear: either keep MinIO as the default and support RustFS as an optional S3-compatible Compose backend/profile, or continue evaluating RustFS as the default. @tlongwell-block, since you just implemented the MinIO publisher/adoption path, would you be open to the optional RustFS backend/profile direction? The existing branch already has live media, Git/CAS, conditional-write, versioned-object, bootstrap, restart, and migration-boundary validation against RustFS. If that direction makes sense, I’ll preserve #7869/#7870, rebase onto current |
|
🤖 We tested this PR's direction on a real install: we copied our production object store (2,258 objects, 2.3 GiB of media plus Git packs and manifests) from MinIO into RustFS 1.0.0 on arm64. Every object's bytes, size and content type matched, and Buzz's media, Git CAS/412 and versioned-deletion tests passed against it, as did media and Git round trips through a separate relay. A few things we hit:
On the MinIO side: the image from #7869 packages RELEASE.2025-09-07, which is affected by GHSA-jjjj-jwhf-8rgr (fixed only in the source-only 2025-10-15 release). The 2026 MinIO advisories, including two unauthenticated object writes, are fixed only in MinIO's commercial releases. That seems worth weighing in the optional-versus-default decision. The dev and self-host Compose files also still point at quay.io, so #7880 and #7962 are still open. Happy to share the migration and comparison scripts if they help. |
Upstream status update
Since this PR was opened, #7869 and #7870 landed and solved the immediate MinIO image-availability issue through the Block-maintained
buzz-minioimage.The RustFS integration remains useful as validated S3-compatible backend work, but the desired upstream shape now needs maintainer agreement. This PR is temporarily back in draft while we decide whether RustFS should be supported as an optional Compose backend/profile or considered further as the default.
No implementation changes are being made until that direction is clear.
Summary
This replaces the default Docker Compose MinIO dependency with RustFS for local development, the isolated test harness, CI integration services, and the production Compose bundle.
Buzz's application-level S3 contract is unchanged:
BUZZ_S3_*settings, path-style addressing, bucket name, credentials, and therust-s3storage implementation remain the same.Closes the runtime portion of #2618.
Why
The current upstream Compose path depended on MinIO images that are no longer reliably anonymously pullable. The failure occurs before Buzz starts or any conformance test runs. This is an infrastructure availability failure, not a Buzz authorization or media-contract failure.
Changes
minio/minio-initservices withrustfs/rustfs-init.rcbootstrap image by multi-architecture digest.rcto create the private media bucket idempotently.rcclient; the RustFS server image does not contain a MinIO client.No Buzz application authorization, identity, relay protocol, or storage abstraction was changed.
Validation
cargo fmt --all --check— PASSSQLX_OFFLINE=true cargo clippy -p buzz-media --all-targets --all-features -- -D warnings— PASSSQLX_OFFLINE=true cargo test -p buzz-media --lib— 127 passedbuzz-mediabootstrap — PASSstatic_creds_miniolive media round-trip against RustFS — 1 passedThe live checks used fresh Compose projects and fresh volumes; no pre-existing Buzz database or object-store state was used.
Review notes
RustFS is used through its S3-compatible API only. The PR does not introduce direct database access, a second authorization state, or a MinIO compatibility shim. The separate Helm MinIO quickstart remains available until it can be migrated and validated independently.