MinIO¶
Summary
MinIO is a high-performance, S3-compatible object store written in Go, built on erasure coding, bitrot checks, and a single-binary, no-metadata-server design. Its AGPLv3 community edition is finished: the admin console was removed in May 2025, binaries and images stopped in October 2025, the repository went into maintenance mode in December 2025 and was archived in February 2026, and the Docker Hub images were deleted on 2026-09-11. MinIO, Inc. now develops only AIStor, a commercial product with a free single-node tier. Existing clusters keep running, but new CVEs are fixed only in AIStor or in community forks such as PGSTY Silo.
Key Facts¶
| Attribute | Detail |
|---|---|
| Latest Version | Community: RELEASE.2025-10-15T17-29-55Z (2025-10-15), the last tagged release. AIStor: RELEASE.2026-08-07T18-34-35Z (2026-08-07), newest release notes found (2026-09) |
| Status | Community repo archived (no longer maintained since 2026-02-12). AIStor actively developed |
| Repository | github.com/minio/minio (archived, read-only) |
| Language | Go (community source needs Go 1.24+) |
| License | GNU AGPLv3 (community, since 2021-05). AIStor: proprietary free license (Free) or commercial subscription |
| Company | MinIO, Inc. (private, venture-funded) |
| Commercial tiers | AIStor Free (single node), Enterprise Lite (multi-node, under 400 TiB), Enterprise (unlimited, 24/7). Prices on request |
| Install paths | AIStor packages; community go install github.com/minio/minio@latest; fork images pgsty/silo; Operator v7.1.1 Helm charts (frozen) |
| Stars | ~50k+ (recorded by 2026-08) |
Unpatched community codebase
CVE-2026-39414 (S3 Select memory exhaustion, high severity, published 2026-04-09) affects every community release and is fixed only in AIStor. docker pull minio/minio now fails. See How-to Guides and Reference.
Architecture at a Glance¶
The compact view shows how a request reaches drives. The full component diagram is in Explanation.
flowchart LR
C["S3 client / mc"] --> LB["Load balancer"]
LB --> N["Any minio server node"]
N -->|"hash bucket/key"| P1
N -->|"hash bucket/key"| P2
subgraph P1["Server pool 1"]
ES1[("Erasure set<br/>K data + M parity shards")]
end
subgraph P2["Server pool 2"]
ES2[("Erasure set<br/>K data + M parity shards")]
end
N -.->|"SSE keys"| KES["KES / MinKMS"]
N -.->|"STS"| IDP["OIDC / LDAP"]
Evaluation¶
| Pros | Cons |
|---|---|
| Very broad S3 API compatibility, widely used as the default S3 target in tools and tests | Community edition archived: no updates, no security fixes |
| High throughput on NVMe with erasure coding and HighwayHash bitrot checks | No official community binaries or images; build from source or use a fork |
| Single binary, no separate metadata or monitor services | Community console reduced to an object browser; admin via mc only |
| IAM, STS with OIDC/LDAP, SSE-S3/KMS/C, object lock, versioning | AGPLv3 obligations for embedding or modified network services |
| Site replication (active-active) and ILM tiering | AIStor multi-node needs a quote-priced subscription |
| Same design continues in AIStor and the Silo fork | Object storage only: no block or file interface |
When It Fits¶
- Existing MinIO clusters that can move to AIStor, or to a fork that backports fixes, and keep their on-disk data.
- AI/analytics platforms willing to pay for AIStor features such as AIStor Tables (Iceberg V3 REST catalog, GA 2026-02-03).
- Single-node labs, CI, and backups with AIStor Free, or with the Silo fork where an open-source license matters.
Consider something else for new open-source deployments that need vendor-neutral maintenance: Ceph RGW, SeaweedFS, Garage, or RustFS (see alternatives).
Choosing a Path¶
The flowchart summarises the options for a team running or considering MinIO in 2026.
flowchart TD
A["Need S3-compatible object storage"] --> B{"Already running MinIO?"}
B -->|"yes"| C{"Budget for a vendor subscription?"}
B -->|"no"| G{"Open-source license required?"}
C -->|"yes"| D["Upgrade to AIStor Enterprise Lite or Enterprise"]
C -->|"no"| E{"Single node is enough?"}
E -->|"yes"| F["AIStor Free"]
E -->|"no"| H["PGSTY Silo fork, or migrate with mc mirror"]
G -->|"yes"| I{"Also need block or file storage?"}
G -->|"no"| D
I -->|"yes"| J["Ceph RGW"]
I -->|"no"| K["RustFS, SeaweedFS, Garage, or Silo"]
Licensing and Pricing¶
- Community edition: GNU AGPLv3 since
RELEASE.2021-05-11T23-27-41Z(Apache 2.0 before). The README warns that commercial or proprietary use must meet AGPLv3 obligations "at your own risk". - AIStor Free: no-cost license for single-node deployments with the full feature set.
- AIStor Enterprise Lite / Enterprise: subscription, priced per quote; Enterprise Lite is for capacity below 400 TiB.
- Details and dates: Reference.
Community Edition Status¶
Admin console removed (2025-05-24), docs taken offline (2025-10-10), source-only distribution (2025-10), maintenance mode (2025-12-03), repository archived (2026-02, re-archived 2026-04-25 as reported), Docker Hub images deleted (2026-09-11). The Operator, mc, and KES repositories are archived or deprecated too. Full dated table: Reference. Background: Explanation.
Ecosystem and Compatibility¶
- Clients: any AWS S3 SDK,
minio-go/minio-py/minio-jsSDKs,mc(archived; forkmcli), rclone, s3cmd. - Common consumers: Grafana LGTM (Loki, Tempo, Mimir), OpenObserve, Longhorn backups, Velero, Pulsar tiered storage, Spark/Trino/Iceberg.
- Events: bucket notifications to Kafka, NATS, AMQP, MQTT, webhooks, and databases.
- Requirements: Linux, XFS on local NVMe/SSD in JBOD, at least 4 homogeneous nodes for distributed HA; Operator v7.1.1 needs Kubernetes 1.30+.
- Lock-in: data is plain S3;
mc mirroror rclone moves it to any S3 store. IAM export works between MinIO-compatible servers.
Topic Map¶
- How-to Guides: install from source, Silo fork, distributed and Kubernetes deployment, parity, IAM, SSE, TLS, audit, site replication, ILM, monitoring, image replacement, migration, Commands & Recipes
- Reference: editions, artifact status, timeline, CVEs, S3 and erasure-code limits, variables, policies, STS APIs, metrics, hardening checklist, alternatives, performance figures
- Explanation: pools, erasure sets, quorum, healing, bitrot, read and write paths, IAM/STS, SSE and KES, site replication, threat model, the move from open source to AIStor
Related Topics¶
- Comparison: Storage Comparison: Ceph vs MinIO vs Longhorn
- Comparison: MinIO Alternatives: Silo vs RustFS vs SeaweedFS vs Garage vs Ceph RGW
- Storage topics: Ceph (RGW is the main open-source S3 alternative), Longhorn (uses S3 targets for backups)
- Other domains: Grafana LGTM, NATS, Pulsar
Sources¶
- minio/minio repository and README: no-longer-maintained notice, source-only distribution, AGPLv3
- minio/docs repository: community documentation source (hosting ended 2025-10-10)
- MinIO AIStor documentation
- AIStor mc CLI reference
- MinIO AIStor product page and pricing
- MinIO introduces AIStor Free and Enterprise Lite tiers (2025-12-23)
- MinIO is now fully licensed under GNU AGPLv3 (2021)
- Release RELEASE.2025-05-24T17-08-30Z (console removal)
- Blocks and Files: admin UI removed from Community Edition (2025-06)
- GIGAZINE: MinIO stops distributing free Docker images (2025-10)
- Maintenance Mode, issue #21714
- StableBuild: MinIO images disappeared from Docker Hub (2026-09)
- GHSA-h749-fxx7-pwpg / CVE-2026-39414
- Blocks and Files: AIStor Tables (2026-02)
- PGSTY Silo fork
- RustFS
Questions¶
Answered¶
- Can I still run existing MinIO? Yes. The binaries keep working and data stays readable, but there are no community fixes. Move to AIStor, a maintained fork, or another store. See Choosing a Path.
- Is MinIO still open source? The archived code remains AGPLv3 and can be forked. The actively developed product, AIStor, is not open source.
- Where do I get MinIO images now? Not from Docker Hub (deleted 2026-09-11). Quay gates anonymous pulls too (401 since about 2026-09-24). Build from source or use the Silo fork. See How-to Guides.
- What are erasure sets and how is parity chosen? Groups of 2 to 16 drives; default
EC:4for sets of 8 or more. See Explanation and Reference. - What are the read and write quorums? Read needs K drives; write needs K, or K+1 when parity is half the set. See Explanation.
- How does bitrot protection work? HighwayHash per shard, checked on every read, with automatic rebuild. See Explanation.
- How do SSE-S3, SSE-KMS, and SSE-C differ, and why KES? See Explanation. Open-source KES is deprecated.
- What does site replication copy? Objects, buckets, IAM, and most bucket settings, but not notifications or ILM. See Reference.
- Does MinIO need a load balancer? Not strictly, but production should use one that passes signed headers unchanged. See Explanation.
Open¶
- Which open-source replacement fits best for S3 workloads that used MinIO? Needs a structured comparison of Silo, RustFS, SeaweedFS, Garage, and Ceph RGW on S3 compatibility, performance, and operations. A domain comparison page would be the right home.
- How long will the Silo fork keep pace with security fixes? It has shipped regular releases since 2026-02 (latest 2026-09-03); long-term funding and maintainer depth are unknown.
- What do AIStor Enterprise Lite and Enterprise cost per TiB? Not published: both tiers are quote-only through sales (checked 2026-09-27).
- Do the AIStor performance features (multi-NIC, coalesced locks, Go eBPF loader) deliver measurable gains? MinIO documents the features (see Reference) but publishes no before/after numbers for them, and no independent benchmarks were found (2026-09-28).
- What is the practical latency cost of each extra server pool? Documented qualitatively only; no published benchmarks.