A MinIO-compatible S3 server and mc client in one small container image, built from source at pinned git tags and published as insectai/minio on Docker Hub. It exists so the Antenna test suite and local development stacks stop depending on registries and images that other organisations can withdraw.
MinIO archived its open-source server and client repositories in 2026, stopped serving binaries from dl.min.io, and removed or restricted the minio/minio and minio/mc images on Docker Hub and quay.io. Each of those changes broke the Antenna CI job for every open pull request at once. This repository builds the image we depend on, from sources we can point to, into a Docker Hub organisation we own.
The insectai organisation is a Docker-Sponsored Open Source namespace, so anonymous pulls of this image are not subject to Docker Hub's pull rate limits. That matters on shared CI runners.
| Component | Source | Notes |
|---|---|---|
/usr/bin/minio |
pgsty/silo, the community-maintained fork of minio/minio |
Built with the fork's own gen-ldflags.go, so minio --version reports the pinned release. |
/usr/bin/mc |
pgsty/mc, the matching fork of minio/mc |
Same command set as upstream mc (alias set, mb, anonymous set, ready). |
/bin/sh and BusyBox |
Alpine base | Lets an init container run a shell script with mc. |
/licenses/ |
Copied from the source checkouts | AGPL-3.0 licence, NOTICE and CREDITS files. |
The binaries keep their original names (minio, mc) so existing compose files and scripts work unchanged. The image runs as root by default, like the historical official image, and /data is world-writable so a non-root user: also works on a fresh volume.
Platforms: linux/amd64 and linux/arm64.
Exact source revisions are recorded in versions.env and in the image labels (org.insectai.minio.*, org.insectai.mc.*), and a pinned commit SHA is verified after cloning, so a moved tag fails the build.
Pin by tag and digest in compose files. The digest for each published tag is printed in the workflow run's summary. To look it up later, read the first Digest: line (the manifest list, which covers both platforms) from:
docker buildx imagetools inspect insectai/minio:RELEASE.2026-09-16T00-00-00Zservices:
minio:
image: insectai/minio:RELEASE.2026-09-16T00-00-00Z@sha256:<digest>
command: server /data --console-address ":9001"
healthcheck:
test: ["CMD", "mc", "ready", "local"]
minio-init:
image: insectai/minio:RELEASE.2026-09-16T00-00-00Z@sha256:<digest>
entrypoint: ["/bin/sh", "/etc/minio/init.sh"]The image tag is the server release tag. The client version is recorded in the org.insectai.mc.tag label.
-
Find the new release tags on pgsty/silo/releases and pgsty/mc/releases, and read their release notes for behaviour changes.
-
Resolve each tag to its commit (annotated tags need the second command):
gh api repos/pgsty/silo/git/ref/tags/<tag> -q '.object | "\(.type) \(.sha)"' gh api repos/pgsty/silo/git/tags/<tag-object-sha> -q .object.sha
-
Edit
versions.env:MINIO_TAG,MINIO_COMMIT,MC_TAG,MC_COMMIT. Check thegodirective in bothgo.modfiles and raiseGO_IMAGEif needed. BumpRUNTIME_IMAGEto the current Alpine patch release. -
Build locally and smoke-test:
./build.sh docker run --rm insectai/minio:dev --version docker run --rm --entrypoint mc insectai/minio:dev --version
-
Open a pull request. The workflow builds both platforms without pushing.
-
Merge to
main. The workflow pushesinsectai/minio:<MINIO_TAG>andinsectai/minio:latest, and prints the digest pin line in the run summary. -
Update the digest pins in the consuming repositories (for Antenna:
docker-compose.ymlanddocker-compose.ci.yml).
To republish an existing version without moving latest (for example after a base-image security update), run the workflow manually with "Also move the latest tag" unchecked.
The workflow needs two repository secrets:
DOCKERHUB_USERNAME: the Docker Hub account or organisation the token belongs to.DOCKERHUB_TOKEN: an access token with read and write access toinsectai/minio. Create it under the Docker Hub organisation settings (organisation access token) or as a personal access token of an organisation member.
The build files in this repository are licensed under the GNU Affero General Public License v3.0 or later, the same licence as the software they package. The published image contains unmodified builds of AGPL-3.0 software from the repositories named in versions.env; the corresponding source for any published image is the tagged commit recorded in that file and in the image labels. MinIO is a trademark of MinIO, Inc.; the name is used here only to identify the upstream project and compatibility lineage.