Skip to content

chore: bump the bundled RustFS to 1.0.1 [ENG-1745] - #30

Merged
twk3 merged 2 commits into
mainfrom
chore/eng-1745-rustfs-1.0.1
Oct 9, 2026
Merged

twk3 merged 2 commits into
mainfrom
chore/eng-1745-rustfs-1.0.1

Conversation

@twk3

@twk3 twk3 commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the bundled RustFS from 1.0.0-alpha.79 to 1.0.1 and keeps the CORS headers the dashboard and trace.playwright.dev depend on (ENG-1745).

1.0.0-alpha.79 accepts a bucket lifecycle configuration and returns it from GetBucketLifecycleConfiguration, but never expires the objects it matches. ENG-1738 and ENG-1739 both add lifecycle rules, so they would ship as no-ops on the bundled storage. 1.0.1 enforces them and includes the fix for CVE-2026-73288 (lifecycle and scanner sweeps could expire objects under COMPLIANCE retention).

Changes

  • DC_RUSTFS_IMAGE defaults to rustfs/rustfs:1.0.1 in templates/compose.rustfs.yml, .env.example and docs/configuration.md. docker-compose.full.yml is regenerated with generate-compose.sh full; the only diff is the image line and the CORS setting below.
  • The rustfs service sets RUSTFS_CORS_ALLOWED_ORIGINS: "*". alpha.79 sent access-control-allow-origin: * on every response without configuration; 1.0.1 sends no CORS headers unless this or a bucket CORS rule is set. Without it the dashboard's stdout and attachment previews and trace.playwright.dev fail their cross-origin fetches. * is what alpha.79 sent, and what packages/on-premise in the currents repo already sets.
  • CHANGELOG entry under [Unreleased], including a note for anyone running 1.0.1 from their own compose file.

Testing

On the generated docker-compose.full.yml with the 2026-07-26-006 images, ports moved off the defaults:

  • rustfs is healthy (the image still ships curl for the healthcheck) and rustfs-init creates the bucket.
  • A past-dated expiry rule on expire/ makes objects under the prefix 404 within 5 seconds, including objects written after the rule; an object outside the prefix stays. The same test on alpha.79 left the object in place.
  • Recorded a Playwright run (one passing test, one failing test with screenshot, video and trace). All artifacts and the stdout land in the bucket, the step uploads through FILE_STORAGE_INTERNAL_ENDPOINT log upload successful, and no service logs a warning or error.
  • In the dashboard the screenshot, steps and stdout render, and the trace opens on trace.playwright.dev.
  • With RUSTFS_CORS_ALLOWED_ORIGINS removed from the rustfs service, Chrome blocks the dashboard's stdout fetch (Access to fetch ... has been blocked by CORS policy) and the Console tab stays empty. Restoring it fixes both.

Related

Checklist

  • PR title is Changelog-friendly: (fix|feat|chore): title [CSR-xxx]
  • User-friendly and meaningful description of the changes
  • Documentation was updated

🤖 Generated with Claude Code

twk3 and others added 2 commits October 9, 2026 10:54
1.0.0-alpha.79 accepts a bucket lifecycle configuration and returns it
from GetBucketLifecycleConfiguration, but never expires the objects it
matches. 1.0.1 enforces it, and includes the fix for CVE-2026-73288.

Verified on the generated docker-compose.full.yml: with a past-dated
expiry rule on expire/, objects under the prefix 404 within 5 seconds,
including ones written after the rule, and an object outside it stays.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1.0.0-alpha.79 answered every request with access-control-allow-origin: *
without any configuration. 1.0.1 sends no CORS headers unless
RUSTFS_CORS_ALLOWED_ORIGINS or a bucket CORS rule is set, so
trace.playwright.dev and the dashboard's stdout and attachment previews
fail their cross-origin fetches. "*" restores what alpha.79 sent and
matches packages/on-premise in the currents repo.

Verified on the generated docker-compose.full.yml: a preflight and a
GET on a presigned URL both return access-control-allow-origin: *.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@twk3

twk3 commented Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

Baz full review

@baz-reviewer

baz-reviewer Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Review this PR on Baz

Baz Summary

Upgrade the bundled RustFS to 1.0.1 so on-prem lifecycle rules are enforced and CVE-2026-73288 is fixed. Configure RUSTFS_CORS_ALLOWED_ORIGINS to preserve dashboard, attachment-preview, and trace.playwright.dev browser access, and update compose defaults, generated configuration, documentation, and changelog guidance.

Latest Contributors(1)
UserCommitDate
dj@currents.devfix: keep CORS headers...October 09, 2026

Merger  Activate to get a short verdict whether this PR is good to go or not

Skills  Activate Skill Maintainer to keep your skills up to date

Planner  This PR would have been improved with Baz Planner - Try it now

@twk3
twk3 merged commit 5fd4a85 into main Oct 9, 2026
5 checks passed
@twk3
twk3 deleted the chore/eng-1745-rustfs-1.0.1 branch October 9, 2026 20:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant