October 2, 2026

MinIO pulls from Quay now return unauthorized

MinIO pulls from Quay now return unauthorized

On September 17, we wrote about MinIO images disappearing from Docker Hub.

At the time, the historical MinIO images we needed were still available on Quay. Switching from Docker Hub to Quay got the affected pulls working again.

On October 2, we tried the same image again.

docker pull quay.io/minio/minio:RELEASE.2025-09-07T16-13-09Z

Quay returned:

Error response from daemon: unauthorized: access to the requested resource is not authorized

The anonymous pull failed with unauthorized. That doesn't tell us whether the image was deleted, only that we could no longer retrieve it anonymously.

We had recommended Quay as an alternative after the Docker Hub images disappeared. Now the same release was failing to pull anonymously there too.
‍

The same release was still available through StableBuild

When we added Quay support to StableBuild's Docker mirror, we pulled this exact MinIO release through it during testing. MinIO isn't only something we test against though. StableBuild relies on it internally as well.

Because that release had already been cached, we could pull the same copy again on October 2.

The digest matched the one we had recorded when the image was originally cached:

sha256:14cea493d9a34af32f524e538b8346cf79f3321eff8e708c1e2960462bd8936e

It was the same MinIO release we'd used in September. We didn't have to switch to an older version just to get a successful pull.
‍

Why the cached copy still worked

StableBuild's Docker mirror works as a pull-through cache.

The first time an image is pulled through the mirror, StableBuild retrieves it from the upstream registry and stores a copy. Later pulls of that cached tag are served from the stored copy.

Once the MinIO image had been cached, pulling it again no longer depended on Quay continuing to serve it anonymously.

The image has to be cached before upstream access is lost. StableBuild can't recover an image it never stored.

When the MinIO images disappeared from Docker Hub, Quay gave us another place to retrieve them. But we were still relying on another registry to keep serving the same image.

This time, we already had our own copy.
‍

If your MinIO build is failing now

If a build that depends on one of these MinIO images has started failing, first look for the exact image somewhere you already control.

That could be:

  • your own container registry
  • a pull-through cache
  • a CI runner
  • a development machine where the image was pulled previously

If you find a copy, verify that it is the release and architecture your build expects. Compare the digest if you have one recorded.

Replacing a missing image with a different MinIO release may get a build running, but it is still a software change and should be tested as one.

A cached copy can buy you time, but it is still only a temporary solution. If you continue to depend on MinIO, it is worth starting to evaluate actively maintained alternatives rather than treating that cached image as a permanent fix.

Quay gave us a workable alternative when the Docker Hub pulls failed. Having a copy already stored through StableBuild is what let us pull the same image again after the anonymous Quay pull started failing.

For dependencies that are still available upstream, you can create a free StableBuild account and try preserving an image through the Docker mirror.

‍