feat(renovate): add manual run pipeline and sync configs
ci / lint-prettier (push) Successful in 8s
ci / lint-ruff (push) Successful in 5s
ci / lint-yaml (push) Successful in 7s
ci / lint-dockerfiles (push) Successful in 4s
ci / validate (push) Successful in 5s
renovate-ci / validate-renovate (push) Successful in 1m27s
ci / build (push) Successful in 3s
ci / deploy-userbot-panel (push) Has been skipped
ci / lint-prettier (push) Successful in 8s
ci / lint-ruff (push) Successful in 5s
ci / lint-yaml (push) Successful in 7s
ci / lint-dockerfiles (push) Successful in 4s
ci / validate (push) Successful in 5s
renovate-ci / validate-renovate (push) Successful in 1m27s
ci / build (push) Successful in 3s
ci / deploy-userbot-panel (push) Has been skipped
renovate-run workflow_dispatch runs pinned renovate via docker on self-hosted runner. Sync helm-values manager into config.js/configmap, bump compose and validator pins to 44.97.2.
This commit is contained in:
1 parent
043923fc64
commit
7f0bd5f609
6 files changed
+80
-6
No files matched your search
@@ -48,5 +48,5 @@ jobs:
|
|||||||
docker run --rm \
|
docker run --rm \
|
||||||
-v "$PWD:/work" \
|
-v "$PWD:/work" \
|
||||||
-w /work \
|
-w /work \
|
||||||
renovate/renovate:44.83.2 \
|
renovate/renovate:44.97.2 \
|
||||||
renovate-config-validator renovate.json
|
renovate-config-validator renovate.json
|
||||||
@@ -0,0 +1,52 @@
|
|||||||
|
name: renovate-run
|
||||||
|
|
||||||
|
on:
|
||||||
|
workflow_dispatch:
|
||||||
|
inputs:
|
||||||
|
repositories:
|
||||||
|
description: "Repositories to scan (comma-separated)"
|
||||||
|
required: false
|
||||||
|
default: "forust/homelab"
|
||||||
|
log_level:
|
||||||
|
description: "Renovate log level"
|
||||||
|
required: false
|
||||||
|
default: "info"
|
||||||
|
type: choice
|
||||||
|
options:
|
||||||
|
- info
|
||||||
|
- debug
|
||||||
|
|
||||||
|
concurrency:
|
||||||
|
group: renovate-run
|
||||||
|
cancel-in-progress: false
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
run-renovate:
|
||||||
|
runs-on: [self-hosted, linux, arch, homelab]
|
||||||
|
steps:
|
||||||
|
- name: Checkout repository
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- name: Run Renovate
|
||||||
|
shell: bash
|
||||||
|
env:
|
||||||
|
RENOVATE_TOKEN: ${{ secrets.RENOVATE_TOKEN }}
|
||||||
|
RENOVATE_GITHUB_COM_TOKEN: ${{ secrets.RENOVATE_GITHUB_COM_TOKEN }}
|
||||||
|
RENOVATE_REPOSITORIES: ${{ inputs.repositories }}
|
||||||
|
LOG_LEVEL: ${{ inputs.log_level }}
|
||||||
|
run: |
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
: "${RENOVATE_TOKEN:?missing RENOVATE_TOKEN secret — add a renovate-bot PAT in repo/org Actions secrets}"
|
||||||
|
|
||||||
|
docker run --rm \
|
||||||
|
-v "$PWD/renovate/config.js:/opt/renovate/config.js:ro" \
|
||||||
|
-e RENOVATE_PLATFORM=gitea \
|
||||||
|
-e RENOVATE_ENDPOINT=https://gitea.forust.xyz/api/v1 \
|
||||||
|
-e RENOVATE_TOKEN="$RENOVATE_TOKEN" \
|
||||||
|
-e RENOVATE_GITHUB_COM_TOKEN="${RENOVATE_GITHUB_COM_TOKEN:-}" \
|
||||||
|
-e RENOVATE_REPOSITORIES="${RENOVATE_REPOSITORIES:-forust/homelab}" \
|
||||||
|
-e RENOVATE_CONFIG_FILE=/opt/renovate/config.js \
|
||||||
|
-e RENOVATE_BASE_DIR=/tmp/renovate \
|
||||||
|
-e LOG_LEVEL="${LOG_LEVEL:-info}" \
|
||||||
|
renovate/renovate:44.97.2
|
||||||
+14
-1
@@ -24,12 +24,25 @@ The `renovate/k8s/active` marker makes the normal deployment workflow include
|
|||||||
the namespace, ConfigMap, and CronJob. The Secret is intentionally excluded
|
the namespace, ConfigMap, and CronJob. The Secret is intentionally excluded
|
||||||
from Git and must be applied separately after every new cluster.
|
from Git and must be applied separately after every new cluster.
|
||||||
|
|
||||||
Run it immediately instead of waiting for the six-hour schedule:
|
Run it immediately instead of waiting for the six-hour schedule.
|
||||||
|
|
||||||
|
Two options, both use the same `renovate/config.js`:
|
||||||
|
|
||||||
```sh
|
```sh
|
||||||
kubectl create job --from=cronjob/renovate renovate-manual-$(date +%s) -n renovate
|
kubectl create job --from=cronjob/renovate renovate-manual-$(date +%s) -n renovate
|
||||||
```
|
```
|
||||||
|
|
||||||
|
or the `renovate-run` Actions workflow (Actions tab → `renovate-run` →
|
||||||
|
Run workflow). It runs `renovate/renovate:44.97.2` on the self-hosted
|
||||||
|
runner via Docker. Required Actions secrets (repo or org settings):
|
||||||
|
|
||||||
|
- `RENOVATE_TOKEN` — renovate-bot PAT (repository + issue read/write).
|
||||||
|
- `RENOVATE_GITHUB_COM_TOKEN` — optional, for changelogs and GitHub rate limits.
|
||||||
|
|
||||||
|
Inputs: `repositories` (default `forust/homelab`), `log_level`
|
||||||
|
(`info`/`debug`). Only one run at a time (concurrency group
|
||||||
|
`renovate-run`), same as the CronJob `Forbid` policy.
|
||||||
|
|
||||||
Inspect runs with:
|
Inspect runs with:
|
||||||
|
|
||||||
```sh
|
```sh
|
||||||
|
|||||||
+4
-1
@@ -1,7 +1,10 @@
|
|||||||
module.exports = {
|
module.exports = {
|
||||||
platform: 'gitea',
|
platform: 'gitea',
|
||||||
endpoint: process.env.RENOVATE_ENDPOINT,
|
endpoint: process.env.RENOVATE_ENDPOINT,
|
||||||
enabledManagers: ['docker-compose', 'kubernetes'],
|
enabledManagers: ['docker-compose', 'kubernetes', 'helm-values'],
|
||||||
|
'helm-values': {
|
||||||
|
managerFilePatterns: ['/k8s/.+values\\.ya?ml$/'],
|
||||||
|
},
|
||||||
kubernetes: {
|
kubernetes: {
|
||||||
managerFilePatterns: ['/k8s/.+\\.ya?ml$/'],
|
managerFilePatterns: ['/k8s/.+\\.ya?ml$/'],
|
||||||
},
|
},
|
||||||
|
|||||||
@@ -8,7 +8,10 @@ data:
|
|||||||
module.exports = {
|
module.exports = {
|
||||||
platform: 'gitea',
|
platform: 'gitea',
|
||||||
endpoint: process.env.RENOVATE_ENDPOINT,
|
endpoint: process.env.RENOVATE_ENDPOINT,
|
||||||
enabledManagers: ['docker-compose', 'kubernetes'],
|
enabledManagers: ['docker-compose', 'kubernetes', 'helm-values'],
|
||||||
|
'helm-values': {
|
||||||
|
managerFilePatterns: ['/k8s/.+values\\.ya?ml$/'],
|
||||||
|
},
|
||||||
kubernetes: {
|
kubernetes: {
|
||||||
managerFilePatterns: ['/k8s/.+\\.ya?ml$/'],
|
managerFilePatterns: ['/k8s/.+\\.ya?ml$/'],
|
||||||
},
|
},
|
||||||
@@ -22,7 +25,10 @@ data:
|
|||||||
dependencyDashboard: true,
|
dependencyDashboard: true,
|
||||||
prCreation: 'immediate',
|
prCreation: 'immediate',
|
||||||
labels: ['dependencies', 'automated'],
|
labels: ['dependencies', 'automated'],
|
||||||
extends: ['config:recommended', ':dependencyDashboard'],
|
extends: [
|
||||||
|
'config:recommended',
|
||||||
|
':dependencyDashboard',
|
||||||
|
],
|
||||||
packageRules: [
|
packageRules: [
|
||||||
{
|
{
|
||||||
description: 'Do not update private homelab images',
|
description: 'Do not update private homelab images',
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
services:
|
services:
|
||||||
renovate:
|
renovate:
|
||||||
image: renovate/renovate:44.83.2
|
image: renovate/renovate:44.97.2
|
||||||
container_name: renovate
|
container_name: renovate
|
||||||
restart: "no"
|
restart: "no"
|
||||||
env_file:
|
env_file:
|
||||||
|
|||||||
Reference in new issue
Block a user