Skip to content

RustFS replaces MinIO; snapshot.sh finds the database the services actually use - #9

Merged
bridgerahul merged 4 commits into
mainfrom
s3-rustfs
Sep 26, 2026
Merged

bridgerahul merged 4 commits into
mainfrom
s3-rustfs

Conversation

@bridgerahul

@bridgerahul bridgerahul commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Why

  • MinIO stopped publishing images. Quay now answers an anonymous pull of quay.io/minio/minio with unauthorized (after Docker Hub on 2026-09-16), and the binary archive answers 410. The Integration skeleton job has been red on main since.
  • snapshot.sh could leave a bundled Postgres out of a snapshot (introduced with the Neon work, 2a00b12). Two defects, both fixed here.

What

RustFS 1.0.0 instead of MinIO — CI, the object-storage test (renamed object-storage-s3.test.ts), the self-host object-storage profile, env templates, SELF-HOSTING.md, CHANGELOG. Candidates were run against the real suite (19 tests):

Result
RustFS 1.0.0 18/19 → 19/19 after the provider-gap test became positive (RustFS keeps an abort-incomplete rule, as Hetzner does)
Chainguard MinIO 19/19, but latest only — no version pin
SeaweedFS, Garage 17/19 — signed browser upload fails
LocalStack 17/19 — serves a private object unsigned

RustFS does not open CORS to every origin, so the self-host setup gains a bucket CORS rule (commands run against the real compose file: healthy → bucket → CORS → preflight answers the origin).

snapshot.sh

  1. compose config --services | grep -qx postgres under pipefail misread a bundled Postgres as external 26 times in 300; capturing the list first: 0 in 300.
  2. It now asks where DATABASE_URL points, not only whether a postgres service exists. Proven on oa-ci: bundled → volume (0/50 wrong over repeats); URL elsewhere with the service still defined → external + a note naming the host; restoring a volume snapshot there → refused; DATABASE_URL_FILE → falls back to the service; Neon overlay → external.

Proof

CI on this branch: 6/6 green (run).

Upgrade note

Only installs with the object-storage profile enabled have anything to do (in CHANGELOG [Unreleased]).

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features
    • Self-hosted deployments can now use RustFS for optional S3-compatible object storage, with updated setup and migration guidance.
    • Snapshots now account for whether PostgreSQL is hosted within the stack or configured externally. Restores reject bundled PostgreSQL data when the current stack uses an external database.
  • Bug Fixes
    • Object-storage lifecycle rules can now combine incomplete-upload cleanup with expiration rules.

Quay now answers an anonymous pull of quay.io/minio/minio with unauthorized,
after Docker Hub stopped resolving minio/minio on 2026-09-16, and the binary
archive answers 410. The Integration skeleton job has failed since.

RustFS 1.0.0 passes the whole object-storage suite. SeaweedFS and Garage fail
the signed browser upload; LocalStack serves a private object unsigned. The
provider-gap test becomes a positive one: RustFS keeps an abort-incomplete rule
beside an expiration rule, as Hetzner does in production.

Self-host: the object-storage profile runs RustFS; setup gains a bucket CORS
rule, because unlike MinIO it does not open CORS to every origin.
The previous commit carried only the two renames; this is the content it
describes.
…xternal

postgres_in_stack piped compose config into grep -q under pipefail. grep exits
at its first match, compose can take SIGPIPE while still writing, and the
pipeline then reads as no postgres: the bundled database was left out of the
snapshot. Measured 26 wrong answers in 300; capturing the list first gives 0.
A configuration compose cannot resolve is now an error, not an answer.
…hether postgres is defined

A postgres service that is still defined while env/api.env names another host
(NEON.md's step 5 skipped, or any managed Postgres) holds nothing the services
write; archiving it was a snapshot of the wrong database, and a rollback would
have restored it and started the stack against the untouched real one. Now
that case is external, with a note naming the host (never the credentials).
DATABASE_URL_FILE, which the host cannot read, falls back to the service.

Proven on oa-ci: bundled -> volume (and 0/50 wrong over repeats), URL elsewhere
-> external + note, restore of a volume snapshot there -> refused,
DATABASE_URL_FILE -> volume, neon overlay -> external.
@github-actions

Copy link
Copy Markdown
Contributor

Thanks for the pull request. Before it can be merged we need you to sign the Contributor License Agreement — once, ever, for every future contribution too.

Read it, then post exactly this as a comment on this pull request:


I have read the CLA Document and I hereby sign the CLA


You can retrigger this bot by commenting recheck in this Pull Request. Posted by the CLA Assistant Lite bot.

@coderabbitai

coderabbitai Bot commented Sep 26, 2026

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: e5cc0074-8965-457b-b804-755f05588c5e

📥 Commits

Reviewing files that changed from the base of the PR and between 2a00b12 and 8167c8a.

📒 Files selected for processing (12)
  • .github/workflows/ci.yml
  • CHANGELOG.md
  • SELF-HOSTING.md
  • infra/selfhost/docker-compose.yml
  • infra/selfhost/env/api.env.example
  • infra/selfhost/env/minio.env.example
  • infra/selfhost/env/rustfs.env.example
  • infra/selfhost/env/worker.env.example
  • infra/selfhost/generate-secrets.sh
  • infra/selfhost/snapshot.sh
  • tests/integration/object-storage-s3.test.ts
  • tests/unit/object-storage-adapter.test.ts
 __________________________________________________
< My OKRs are all about finding bugs in your code. >
 --------------------------------------------------
  \
   \   (\__/)
       (•ㅅ•)
       /   づ
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@bridgerahul
bridgerahul merged commit 8167c8a into main Sep 26, 2026
12 of 15 checks passed
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 26, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant