Sign inSign up

readystack/minio

By readystack

•Updated about 18 hours ago

Image
0

2.4K

readystack/minio repository overview

⁠MinIO

Docker Scout: Grade A Fixable Critical/High CVEs: 0 Signed: cosign

readystack/minio:RELEASE.2025-10-15T17-29-55Z-CE-ubuntu24.04-r3

A hardened, cosign-signed, offline-rebuildable build of github.com/minio/minio RELEASE.2025-10-15T17-29-55Z (AGPL-3.0), built clean-room from official upstream source by ReadyStack⁠.

⁠What you get

  • Docker Scout Grade A — 0 fixable Critical/High, non-root, SBOM + provenance attestations; re-checked daily at https://readystack.dev/queue⁠.
  • Signed — cosign signature by the ReadyStack release key; verify with cosign verify --key https://readystack.dev/keys/cosign.pub --insecure-ignore-tlog=true readystack/minio:RELEASE.2025-10-15T17-29-55Z-CE-ubuntu24.04-r3.
  • Built from source, non-root.

⁠Which tag should I pull?

This image follows the ReadyStack release-tag convention:

  • The current release is RELEASE.2025-10-15T17-29-55Z-CE-ubuntu24.04-r3 — the release on sale at readystack.dev. Release tags use the pattern <upstream-version>-CE-<base-os>-r<N>; the current one is hermetically built, signed, attested, and supported under your ReadyStack agreement.

  • Earlier release tags (an older version or revision in the same pattern) are superseded. They stay pullable so existing deployments can pin them, but they are no longer patched or re-graded: move to the current release. A superseded release's build kit is available through support.

  • Any tag beginning with internal- is an engineering-pipeline artifact published for build observability. It is unsupported, may change or disappear without notice, and must not be used in production.

# ✓ current release
docker pull readystack/minio:RELEASE.2025-10-15T17-29-55Z-CE-ubuntu24.04-r3

# ✗ unsupported (do not pull)
docker pull readystack/minio:internal-...

Each release tag is signed; verify with cosign verify --key https://readystack.dev/keys/cosign.pub --insecure-ignore-tlog=true readystack/minio:RELEASE.2025-10-15T17-29-55Z-CE-ubuntu24.04-r3 (ReadyStack keeps signatures off the public transparency log, so the check is key-only). Support: [email protected]⁠.

⁠Deployment

Single container, single static Go binary (CGO-free), foreground process. S3-compatible OBJECT STORAGE: objects + metadata persisted on the local filesystem under /data (internal state under /data/.minio.sys). NO relational/SQL database. Embeds and serves a web Console (an object browser) on port 9001. The image IS the complete running instance (no docker-compose, no Kubernetes, no external DB). The entrypoint, /usr/local/bin/readystack-entrypoint.sh, works out the root password MinIO will use (from MINIO_ROOT_PASSWORD, a MINIO_ROOT_PASSWORD_FILE secret or MINIO_CONFIG_ENV_FILE), exits 1 unless it is set and is not minioadmin, and then runs minio with the default arguments server /data --address :9000 --console-address :9001, which arguments after the image name replace.

docker run -d --name minio -p 9000:9000 -p 9001:9001 -e 'MINIO_ROOT_USER=YOUR_ACCESS_KEY' -e 'MINIO_ROOT_PASSWORD=YOUR_STRONG_SECRET' -v minio-data:/data readystack/minio:RELEASE.2025-10-15T17-29-55Z-CE-ubuntu24.04-r3

minio is this command's own container name. MINIO_ROOT_USER and MINIO_ROOT_PASSWORD are required: without a root password, or with the password minioadmin, the container exits at once with a readystack: message. Boot is fast (about 2 seconds to a 200 on /minio/health/live, tested). Sign in to the Console at http://:9001 with the same access key and secret key, or drive the S3 API on :9000 with a sig-v4 client (curl --aws-sigv4 or an AWS SDK; mc is not in this image). Arguments after readystack/minio:RELEASE.2025-10-15T17-29-55Z-CE-ubuntu24.04-r3 replace the default server /data --address :9000 --console-address :9001. ReadyStack ships no Compose file for this image.

⁠The full ReadyStack Agent-ready Archive

The complete --network=none build kit to recreate this exact image yourself — plus admin/DB/API handbooks, seed data, a validated test suite, and signed provenance — is at readystack.dev/buy.html⁠.

— ReadyStack · readystack.dev

Tag summary

Content type

Image

Digest

sha256:de05d6e16…

Size

107.7 MB

Last updated

about 18 hours ago

docker pull readystack/minio:RELEASE.2025-10-15T17-29-55Z-CE-ubuntu24.04-r3