Repository navigation
CORE-1489: ci: replace MinIO with RustFS in the Spark, Trino and Dremio test stacks - #1067
Conversation
MinIO removed its images from Docker Hub (Sept 11) and then from quay.io (Sept 24), so the spark, trino and dremio CI jobs fail at image pull. Swap the S3-compatible storage in the three docker-compose stacks for RustFS (rustfs/rustfs:1.0.0) and the mc bucket-setup containers for the RustFS client (rustfs/rc:v0.1.36), pinned to exact versions. Rename the minio services, hosts, containers, volumes, credentials and seeder env vars to rustfs, and update the S3 endpoints in the Spark, Trino and Dremio configs and the CI wait step accordingly. Setup containers now wait on a storage healthcheck instead of a fixed sleep or TCP probe, and bucket creation is idempotent. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
👋 @EladBarkay |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (8)
Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 3 remain after this review. 📝 WalkthroughWalkthroughThe integration-test storage services and setup jobs now use RustFS instead of MinIO. Dremio, Spark, Trino, and the Spark S3 seeder use RustFS endpoints and credentials. ChangesRustFS integration-test storage
Priority: ⬆️ High Estimated code review effort: 2 (Simple) | ~12 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to The integration-test stacks appear ready to merge after normal checks; no storage configuration mismatch or blocking health-check issue was found. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The change is confined to integration-test storage. The clients and setup jobs appear to agree on their new endpoints, credentials, and buckets, and the review found no demonstrated expansion of access or production exposure. Runtime behavior and the security properties of the replacement images remain unverified. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings
🧪 Generate unit tests (beta)
🛠️ Fix failing CI checks 💡
Comment |
Picks up the MinIO to RustFS switch (#1067), which the Trino, Dremio and Spark CI stacks need. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Why
The
spark,trinoanddremioCI jobs fail at image pull:MinIO deleted
minio/minioandminio/mcfrom Docker Hub on Sept 11, and since about Sept 24 thequay.io/minio/*copies reject anonymous pulls with401 unauthorized(IBM notice, registry-stack#1402). That also breaks the quay.io switch in elementary-data/elementary#2360: a rerun of its dremio job today fails in seconds.What
Replace MinIO with RustFS, an Apache-2.0 S3-compatible server, in the three test stacks:
rustfs/rustfs:1.0.0, credentials viaRUSTFS_ACCESS_KEY/RUSTFS_SECRET_KEY, healthcheck on/health.mccontainers becomerustfs/rc:v0.1.36(the RustFS client) and userc alias set+rc bucket create --ignore-existing.minioservices, hostnames, containers, volumes, credentials and seeder env vars (MINIO_*→RUSTFS_*) are nowrustfs. The S3 endpoints inspark-defaults.conf, the Trino catalog and Hive metastore, and the Dremio S3 source, plus the Spark wait step intest-warehouse.yml, are updated to match.sleep 5(Trino) or a TCP probe (Dremio), and bucket creation can be rerun safely.Dremio's
MINIO_DOMAIN/ region settings are dropped. Dremio uses path-style access, so they aren't needed.Testing
Run locally on Docker (arm64 Mac, Dremio emulated as amd64), using a subset that exercises the storage paths: volume, column, freshness, dimension and schema-change anomalies, plus sampling.
Pre-commit hooks pass, and all three compose files validate. The full suites run in CI.
🤖 Generated with Claude Code
Summary by CodeRabbit