feat(renovate): add Gitea update automation
Run Renovate in Kubernetes to create reviewed image update PRs. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This commit is contained in:
1 parent
6715f9e9af
commit
7288058df6
11 files changed
+331
No files matched your search
@@ -0,0 +1,59 @@
|
||||
# Renovate for Gitea
|
||||
|
||||
Renovate runs as a Kubernetes CronJob and creates container image update pull
|
||||
requests in Gitea. It does not deploy changes itself.
|
||||
|
||||
## Kubernetes
|
||||
|
||||
Create a dedicated Gitea user named `renovate-bot`, create a repository access
|
||||
token, and grant it repository read/write plus issue read/write permissions.
|
||||
Add `read:packages` if Renovate must inspect private Gitea registry images.
|
||||
|
||||
Create the ignored Secret locally; never commit the PAT:
|
||||
|
||||
```sh
|
||||
cp renovate/k8s/secrets.yaml.example renovate/k8s/secrets.yaml
|
||||
$EDITOR renovate/k8s/secrets.yaml
|
||||
kubectl apply -f renovate/k8s/namespace.yaml
|
||||
kubectl apply -f renovate/k8s/secrets.yaml
|
||||
kubectl apply -f renovate/k8s/configmap.yaml
|
||||
kubectl apply -f renovate/k8s/cronjob.yaml
|
||||
```
|
||||
|
||||
The `renovate/k8s/active` marker makes the normal deployment workflow include
|
||||
the namespace, ConfigMap, and CronJob. The Secret is intentionally excluded
|
||||
from Git and must be applied separately after every new cluster.
|
||||
|
||||
Run it immediately instead of waiting for the six-hour schedule:
|
||||
|
||||
```sh
|
||||
kubectl create job --from=cronjob/renovate renovate-manual-$(date +%s) -n renovate
|
||||
```
|
||||
|
||||
Inspect runs with:
|
||||
|
||||
```sh
|
||||
kubectl get cronjob,jobs,pods -n renovate
|
||||
kubectl logs -n renovate job/<job-name>
|
||||
```
|
||||
|
||||
`RENOVATE_GITHUB_COM_TOKEN` is optional but recommended for changelogs and
|
||||
GitHub API rate limits. Set it in the Kubernetes Secret if available.
|
||||
|
||||
## Compose
|
||||
|
||||
Copy `.env.example` to `.env`, set the PAT, and run:
|
||||
|
||||
```sh
|
||||
docker compose -f renovate-compose.yaml run --rm renovate
|
||||
```
|
||||
|
||||
The Compose file is intentionally named `renovate-compose.yaml`, so the
|
||||
repository's automatic deployment discovery does not start it accidentally.
|
||||
|
||||
## How updates flow
|
||||
|
||||
Renovate scans both `compose.yaml` files and Kubernetes manifests, opens a
|
||||
branch and PR with image tag changes, and waits for CI. After merge, the
|
||||
existing deployment workflow applies Kubernetes changes or redeploys Compose
|
||||
stacks. Renovate never updates running workloads directly.
|
||||
Reference in new issue
Block a user