[bitnami/minio] Release 2026.5.20-debian-12-r2 (#94003)

Signed-off-by: Bitnami Bot <bitnami.bot@broadcom.com>
This commit is contained in:
Bitnami Bot
2026-05-26 12:14:00 +02:00
committed by GitHub
parent dca2840934
commit 50ee49a3f6
8 changed files with 64 additions and 17 deletions
+2 -2
View File
@@ -7,7 +7,7 @@ ARG DOWNLOADS_URL="downloads.bitnami.com/files/stacksmith"
ARG TARGETARCH
LABEL org.opencontainers.image.base.name="docker.io/bitnami/minideb:bookworm" \
org.opencontainers.image.created="2026-05-23T09:31:11Z" \
org.opencontainers.image.created="2026-05-26T10:04:00Z" \
org.opencontainers.image.description="Application packaged by Broadcom, Inc." \
org.opencontainers.image.documentation="https://github.com/bitnami/containers/tree/main/bitnami/minio/README.md" \
org.opencontainers.image.source="https://github.com/bitnami/containers/tree/main/bitnami/minio" \
@@ -50,7 +50,7 @@ RUN /opt/bitnami/scripts/minio-client/postunpack.sh
RUN /opt/bitnami/scripts/minio/postunpack.sh
ENV APP_VERSION="2026.5.20" \
BITNAMI_APP_NAME="minio" \
IMAGE_REVISION="1" \
IMAGE_REVISION="2" \
PATH="/opt/bitnami/minio-client/bin:/opt/bitnami/minio/bin:$PATH"
VOLUME [ "/bitnami/minio/data", "/certs" ]
@@ -9,6 +9,9 @@ services:
- '9001:9001'
volumes:
- 'minio_data:/bitnami/minio/data'
environment:
- MINIO_ROOT_USER=minio
- MINIO_ROOT_PASSWORD=miniosecret
volumes:
minio_data:
@@ -139,3 +139,40 @@ wait_for_log_entry() {
return 1
fi
}
########################
# Creates a secure temporary file containing the provided secret
# Arguments:
# $1 - secret to write to the temporary file
# Returns:
# String
#########################
credential_to_temp_file() {
local secret="$1"
local tmp_file
# Use mktemp with a specific prefix for easier debugging if something lingers
if ! tmp_file=$(mktemp "${TMPDIR:-/tmp}/at.cred.XXXXXXXX"); then
echo "Error: Failed to create temp file" >&2
return 1
fi
# Restrict permissions before writing the secret
chmod 0600 "$tmp_file"
# Write secret and ensure it's flushed to disk
printf "%s" "$secret" > "$tmp_file"
# Output the filename so the caller can capture it
echo "$tmp_file"
}
########################
# Cleans up temporary files created by credential_to_temp_file
# Arguments:
# None
# Returns:
# None
#########################
cleanup_credentials() {
debug "Cleaning up temporary files containing credentials"
rm -rf "${TMPDIR:-/tmp}"/at.cred.*
}
@@ -269,10 +269,11 @@ minio_validate() {
fi
}
if [[ -z "${MINIO_ROOT_USER:-}" ]] || [[ -z "${MINIO_ROOT_PASSWORD:-}" ]]; then
print_validation_error "Both MINIO_ROOT_USER and MINIO_ROOT_PASSWORD environment must be set"
fi
if is_boolean_yes "$MINIO_DISTRIBUTED_MODE_ENABLED"; then
if [[ -z "${MINIO_ROOT_USER:-}" ]] || [[ -z "${MINIO_ROOT_PASSWORD:-}" ]]; then
print_validation_error "Distributed mode is enabled. Both MINIO_ROOT_USER and MINIO_ROOT_PASSWORD environment must be set"
fi
if [[ -z "${MINIO_DISTRIBUTED_NODES:-}" ]]; then
print_validation_error "Distributed mode is enabled. Nodes must be indicated setting the environment variable MINIO_DISTRIBUTED_NODES"
else
@@ -367,11 +368,10 @@ minio_regenerate_keys() {
error_code=1
fi
fi
echo "$MINIO_ROOT_USER" >"${MINIO_DATA_DIR}/.root_user"
echo "$MINIO_ROOT_PASSWORD" >"${MINIO_DATA_DIR}/.root_password"
if ! chmod 600 "${MINIO_DATA_DIR}/.root_user" "${MINIO_DATA_DIR}/.root_password"; then
warn "Unable to set secure permissions on key files ${MINIO_DATA_DIR}/.root_*"
fi
install -m 600 /dev/null "${MINIO_DATA_DIR}/.root_user" || error_code=1
install -m 600 /dev/null "${MINIO_DATA_DIR}/.root_password" || error_code=1
echo "$MINIO_ROOT_USER" >> "${MINIO_DATA_DIR}/.root_user"
echo "$MINIO_ROOT_PASSWORD" >> "${MINIO_DATA_DIR}/.root_password"
[[ "$error_code" -eq 0 ]] || exit "$error_code"
}
@@ -58,11 +58,15 @@ minio_client_execute() {
# None
minio_client_execute_timeout() {
local -r args=("--config-dir" "${MINIO_CLIENT_CONF_DIR}" "--quiet" "$@")
local exec
local exec script_file
exec=$(command -v mc)
if am_i_root; then
cat > /tmp/cmd.sh << EOF
if ! script_file=$(mktemp "${TMPDIR:-/tmp}/cmd.XXXXXXXX"); then
echo "Error: Failed to create script file" >&2
return 1
fi
cat > "$script_file" << EOF
#!/bin/bash
# timeout forks its own shell process, so we need to provide it with the expected environment
. /opt/bitnami/scripts/libos.sh
@@ -72,9 +76,9 @@ minio_client_execute_timeout() {
. /opt/bitnami/scripts/libminioclient.sh
run_as_user "$MINIO_DAEMON_USER" "${exec}" ${args[@]}
EOF
chmod +x /tmp/cmd.sh
timeout 5s bash -c "/tmp/cmd.sh"
rm -f /tmp/cmd.sh
chmod +x "$script_file"
timeout 5s bash -c "$script_file"
rm -f "$script_file"
else
timeout 5s "${exec}" "${args[@]}"
fi
@@ -94,7 +94,7 @@ export MINIO_APACHE_API_HTTPS_PORT_NUMBER="${MINIO_APACHE_API_HTTPS_PORT_NUMBER:
export MINIO_FORCE_NEW_KEYS="${MINIO_FORCE_NEW_KEYS:-no}"
export MINIO_ROOT_USER="${MINIO_ROOT_USER:-minio}"
export MINIO_SERVER_ROOT_USER="$MINIO_ROOT_USER"
export MINIO_ROOT_PASSWORD="${MINIO_ROOT_PASSWORD:-miniosecret}"
export MINIO_ROOT_PASSWORD="${MINIO_ROOT_PASSWORD:-}"
export MINIO_SERVER_ROOT_PASSWORD="$MINIO_ROOT_PASSWORD"
# Custom environment variables may be defined below
+1 -1
View File
@@ -94,7 +94,7 @@ The following tables list the main variables you can set.
| `MINIO_APACHE_API_HTTPS_PORT_NUMBER` | MinIO API HTTPS port, exposed via Apache with basic authentication. | `9443` |
| `MINIO_FORCE_NEW_KEYS` | Force recreating MinIO keys. | `no` |
| `MINIO_ROOT_USER` | MinIO root user name. | `minio` |
| `MINIO_ROOT_PASSWORD` | Password for MinIO root user. | `miniosecret` |
| `MINIO_ROOT_PASSWORD` | Password for MinIO root user. | `nil` |
#### Read-only environment variables
+3
View File
@@ -9,6 +9,9 @@ services:
- '9001:9001'
volumes:
- 'minio_data:/bitnami/minio/data'
environment:
- MINIO_ROOT_USER=minio
- MINIO_ROOT_PASSWORD=miniosecret
volumes:
minio_data: