fix(cicd): isolate pull request runner jobs
ci / Compose (push) Skipped
ci / Workflows (push) Skipped
ci / Shell (push) Skipped
ci / Formatting (push) Skipped
ci / Python and tests (push) Skipped
ci / Compose (pull_request) Successful in 37s
ci / Shell (pull_request) Successful in 18s
ci / YAML (push) Skipped
ci / Dockerfiles (push) Skipped
ci / Kubernetes (push) Skipped
ci / Workflows (pull_request) Successful in 8s
ci / Python and tests (pull_request) Successful in 11s
ci / Kubernetes (pull_request) Successful in 8s
ci / Formatting (pull_request) Successful in 18s
ci / YAML (pull_request) Successful in 11s
ci / Dockerfiles (pull_request) Successful in 7s
ci / image-plan (pull_request) Skipped
ci / Image (${{ matrix.name }}) (pull_request) Skipped
ci / build (pull_request) Skipped
ci / Compose (push) Skipped
ci / Workflows (push) Skipped
ci / Shell (push) Skipped
ci / Formatting (push) Skipped
ci / Python and tests (push) Skipped
ci / Compose (pull_request) Successful in 37s
ci / Shell (pull_request) Successful in 18s
ci / YAML (push) Skipped
ci / Dockerfiles (push) Skipped
ci / Kubernetes (push) Skipped
ci / Workflows (pull_request) Successful in 8s
ci / Python and tests (pull_request) Successful in 11s
ci / Kubernetes (pull_request) Successful in 8s
ci / Formatting (pull_request) Successful in 18s
ci / YAML (pull_request) Successful in 11s
ci / Dockerfiles (pull_request) Successful in 7s
ci / image-plan (pull_request) Skipped
ci / Image (${{ matrix.name }}) (pull_request) Skipped
ci / build (pull_request) Skipped
This commit is contained in:
1 parent
2be089e048
commit
d7441bbbc2
8 files changed
+170
-36
No files matched your search
@@ -7,4 +7,5 @@ self-hosted-runner:
|
|||||||
labels:
|
labels:
|
||||||
- arch
|
- arch
|
||||||
- homelab
|
- homelab
|
||||||
|
- homelab-pr
|
||||||
- prod
|
- prod
|
||||||
+33
-6
@@ -1,17 +1,18 @@
|
|||||||
# Homelab CI/CD
|
# Homelab CI/CD
|
||||||
|
|
||||||
The native Gitea runner runs on **vps**; production runs on **workstation**.
|
The native Gitea runners run on **vps**; production runs on **workstation**.
|
||||||
Compose, workflow, shell, Python, formatting, YAML, Dockerfile and Kubernetes
|
Main-branch checks and image builds use `homelab:host`. Pull request and
|
||||||
checks appear as separate jobs. Jobs run on `homelab:host`, one at a time; the
|
non-main checks use `homelab-pr:host` under a separate account without Docker
|
||||||
build waits for every check to pass. CI and deploy runs also show a summary with
|
access. Each runner accepts one job at a time; the build waits for every check
|
||||||
|
to pass. CI and deploy runs also show a summary with
|
||||||
the release SHA, image build or reuse results, deploy mode, selected services,
|
the release SHA, image build or reuse results, deploy mode, selected services,
|
||||||
and image digests. Failed runs keep a summary of completed image builds, stage
|
and image digests. Failed runs keep a summary of completed image builds, stage
|
||||||
results, apply results, and recorded Kubernetes recovery. The final deploy
|
results, apply results, and recorded Kubernetes recovery. The final deploy
|
||||||
summary is in the smoke job; earlier jobs show the state observed at that time.
|
summary is in the smoke job; earlier jobs show the state observed at that time.
|
||||||
Apply success is separate from health and recovery. Update the installed
|
Apply success is separate from health and recovery. Update the installed
|
||||||
workstation controller with `setup-workstation.sh` when no deploy is running.
|
workstation controller with `setup-workstation.sh` when no deploy is running.
|
||||||
No job images or Kubernetes credentials
|
No job images or Kubernetes credentials are needed on the VPS. Builds use one
|
||||||
are needed on the VPS. Builds use one pinned BuildKit helper container. CI and deploy are separate workflows.
|
pinned BuildKit helper container. CI and deploy are separate workflows.
|
||||||
|
|
||||||
## Runner installation
|
## Runner installation
|
||||||
|
|
||||||
@@ -37,6 +38,32 @@ pushes directly to the registry, and caps retained local cache at 1 GiB with a
|
|||||||
2 GiB free-space target. This is not a hard limit on peak build disk usage.
|
2 GiB free-space target. This is not a hard limit on peak build disk usage.
|
||||||
Nothing runs `docker system prune`, removes unrelated images, or deletes volumes.
|
Nothing runs `docker system prune`, removes unrelated images, or deletes volumes.
|
||||||
|
|
||||||
|
### Pull request runner
|
||||||
|
|
||||||
|
Install the unprivileged host runner on the VPS:
|
||||||
|
|
||||||
|
```sh
|
||||||
|
sudo bash .gitea/runner/setup-pr-runner.sh
|
||||||
|
```
|
||||||
|
|
||||||
|
Get a registration token from the repository Actions runner settings. Run the
|
||||||
|
installer in a terminal. It asks for the token without echoing it, registers the
|
||||||
|
runner as `homelab-pr` with label `homelab-pr:host`, then enables the service.
|
||||||
|
The work directory is `/var/lib/gitea-pr-runner`. Confirm that Gitea lists
|
||||||
|
`homelab-pr:host` before merging the workflow change. An unmatched label can
|
||||||
|
fall back to the default job image.
|
||||||
|
|
||||||
|
Renovate PR validation uses `pull_request_target`, which reads the workflow from
|
||||||
|
the base branch. It checks out the PR head only after runner selection and runs
|
||||||
|
that code on `homelab-pr`. Keep this workflow read-only and do not add secrets.
|
||||||
|
|
||||||
|
The PR runner has a separate home and tool cache. Do not add it to the `docker`
|
||||||
|
group or give it access to `/var/run/docker.sock`. It runs repository code from
|
||||||
|
pull requests, so keep its registration and permissions separate from the
|
||||||
|
trusted `homelab` runner. This separates users and host permissions, but both
|
||||||
|
runners still share the VPS kernel and network. Use a disposable VM if PRs from
|
||||||
|
untrusted external authors must be fully isolated.
|
||||||
|
|
||||||
## Workstation setup
|
## Workstation setup
|
||||||
|
|
||||||
As the existing SSH deploy user on workstation:
|
As the existing SSH deploy user on workstation:
|
||||||
|
|||||||
@@ -0,0 +1,8 @@
|
|||||||
|
runner:
|
||||||
|
file: /var/lib/gitea-pr-runner/.runner
|
||||||
|
capacity: 1
|
||||||
|
timeout: 5h
|
||||||
|
labels:
|
||||||
|
- homelab-pr:host
|
||||||
|
cache:
|
||||||
|
enabled: false
|
||||||
@@ -0,0 +1,27 @@
|
|||||||
|
[Unit]
|
||||||
|
Description=Gitea Actions untrusted pull request runner
|
||||||
|
After=network-online.target
|
||||||
|
Wants=network-online.target
|
||||||
|
|
||||||
|
[Service]
|
||||||
|
User=gitea-pr-runner
|
||||||
|
Group=gitea-pr-runner
|
||||||
|
WorkingDirectory=/var/lib/gitea-pr-runner
|
||||||
|
Environment=HOME=/var/lib/gitea-pr-runner
|
||||||
|
Environment=PATH=/var/lib/gitea-pr-runner/.cache/homelab-ci/bin:/usr/local/bin:/usr/bin:/bin
|
||||||
|
ExecStart=/usr/local/bin/gitea-runner daemon --config /etc/gitea-pr-runner/config.yaml
|
||||||
|
Restart=on-failure
|
||||||
|
RestartSec=5
|
||||||
|
NoNewPrivileges=yes
|
||||||
|
PrivateTmp=yes
|
||||||
|
ProtectSystem=full
|
||||||
|
ProtectHome=yes
|
||||||
|
ProtectKernelTunables=yes
|
||||||
|
ProtectKernelModules=yes
|
||||||
|
ProtectControlGroups=yes
|
||||||
|
RestrictSUIDSGID=yes
|
||||||
|
LockPersonality=yes
|
||||||
|
UMask=0077
|
||||||
|
|
||||||
|
[Install]
|
||||||
|
WantedBy=multi-user.target
|
||||||
Executable
+55
@@ -0,0 +1,55 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
# Install a native runner for untrusted PR jobs without Docker access.
|
||||||
|
set -euo pipefail
|
||||||
|
here="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
||||||
|
[ "$(id -u)" -eq 0 ] || { echo 'Run with sudo on the runner host' >&2; exit 1; }
|
||||||
|
for tool in cp cut date getent id install runuser systemctl useradd; do
|
||||||
|
command -v "$tool" >/dev/null || { echo "Install missing prerequisite: $tool" >&2; exit 1; }
|
||||||
|
done
|
||||||
|
command -v /usr/local/bin/gitea-runner >/dev/null || {
|
||||||
|
echo 'Install gitea-runner 3.0.2 at /usr/local/bin/gitea-runner first' >&2
|
||||||
|
exit 1
|
||||||
|
}
|
||||||
|
|
||||||
|
id gitea-pr-runner >/dev/null 2>&1 || \
|
||||||
|
useradd --system --create-home --home-dir /var/lib/gitea-pr-runner --shell /usr/bin/bash gitea-pr-runner
|
||||||
|
runner_home="$(getent passwd gitea-pr-runner | cut -d: -f6)"
|
||||||
|
[ "$runner_home" = /var/lib/gitea-pr-runner ] || {
|
||||||
|
echo 'Unexpected PR runner home; inspect the existing service first' >&2
|
||||||
|
exit 1
|
||||||
|
}
|
||||||
|
case " $(id -nG gitea-pr-runner) " in
|
||||||
|
*' docker '*)
|
||||||
|
echo 'The PR runner account must not belong to the docker group' >&2
|
||||||
|
exit 1
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
|
||||||
|
install -d -m 0755 /etc/gitea-pr-runner
|
||||||
|
stamp="$(date -u +%Y%m%dT%H%M%SZ)"
|
||||||
|
for existing in /etc/gitea-pr-runner/config.yaml /etc/systemd/system/gitea-pr-runner.service; do
|
||||||
|
[ ! -f "$existing" ] || cp -p "$existing" "$existing.before-$stamp"
|
||||||
|
done
|
||||||
|
install -m 0644 "$here/pr-config.yaml" /etc/gitea-pr-runner/config.yaml
|
||||||
|
install -m 0644 "$here/pr-runner.service" /etc/systemd/system/gitea-pr-runner.service
|
||||||
|
|
||||||
|
if [ ! -f /var/lib/gitea-pr-runner/.runner ]; then
|
||||||
|
read -r -s -p 'Enter the Gitea repository runner registration token: ' runner_token
|
||||||
|
printf '\n'
|
||||||
|
[ -n "$runner_token" ] || { echo 'Runner token is required' >&2; exit 1; }
|
||||||
|
export GITEA_RUNNER_REGISTRATION_TOKEN="$runner_token"
|
||||||
|
unset runner_token
|
||||||
|
runuser --preserve-environment -u gitea-pr-runner -- \
|
||||||
|
/usr/local/bin/gitea-runner register \
|
||||||
|
--config /etc/gitea-pr-runner/config.yaml \
|
||||||
|
--instance https://gitea.forust.xyz \
|
||||||
|
--name homelab-pr \
|
||||||
|
--labels homelab-pr:host \
|
||||||
|
--no-interactive
|
||||||
|
unset GITEA_RUNNER_REGISTRATION_TOKEN
|
||||||
|
fi
|
||||||
|
|
||||||
|
systemctl daemon-reload
|
||||||
|
systemctl enable --now gitea-pr-runner.service
|
||||||
|
systemctl restart gitea-pr-runner.service
|
||||||
|
echo "PR runner ready. Configuration backups: *.before-$stamp"
|
||||||
@@ -14,7 +14,7 @@ concurrency:
|
|||||||
jobs:
|
jobs:
|
||||||
compose:
|
compose:
|
||||||
name: Compose
|
name: Compose
|
||||||
runs-on: homelab
|
runs-on: ${{ github.ref == 'refs/heads/main' && 'homelab' || 'homelab-pr' }}
|
||||||
timeout-minutes: 15
|
timeout-minutes: 15
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout repository
|
- name: Checkout repository
|
||||||
@@ -66,7 +66,7 @@ jobs:
|
|||||||
fi
|
fi
|
||||||
workflows:
|
workflows:
|
||||||
name: Workflows
|
name: Workflows
|
||||||
runs-on: homelab
|
runs-on: ${{ github.ref == 'refs/heads/main' && 'homelab' || 'homelab-pr' }}
|
||||||
timeout-minutes: 15
|
timeout-minutes: 15
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout repository
|
- name: Checkout repository
|
||||||
@@ -102,7 +102,7 @@ jobs:
|
|||||||
fi
|
fi
|
||||||
shell:
|
shell:
|
||||||
name: Shell
|
name: Shell
|
||||||
runs-on: homelab
|
runs-on: ${{ github.ref == 'refs/heads/main' && 'homelab' || 'homelab-pr' }}
|
||||||
timeout-minutes: 15
|
timeout-minutes: 15
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout repository
|
- name: Checkout repository
|
||||||
@@ -146,7 +146,7 @@ jobs:
|
|||||||
fi
|
fi
|
||||||
formatting:
|
formatting:
|
||||||
name: Formatting
|
name: Formatting
|
||||||
runs-on: homelab
|
runs-on: ${{ github.ref == 'refs/heads/main' && 'homelab' || 'homelab-pr' }}
|
||||||
timeout-minutes: 15
|
timeout-minutes: 15
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout repository
|
- name: Checkout repository
|
||||||
@@ -194,7 +194,7 @@ jobs:
|
|||||||
fi
|
fi
|
||||||
python:
|
python:
|
||||||
name: Python and tests
|
name: Python and tests
|
||||||
runs-on: homelab
|
runs-on: ${{ github.ref == 'refs/heads/main' && 'homelab' || 'homelab-pr' }}
|
||||||
timeout-minutes: 15
|
timeout-minutes: 15
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout repository
|
- name: Checkout repository
|
||||||
@@ -232,7 +232,7 @@ jobs:
|
|||||||
fi
|
fi
|
||||||
yaml:
|
yaml:
|
||||||
name: YAML
|
name: YAML
|
||||||
runs-on: homelab
|
runs-on: ${{ github.ref == 'refs/heads/main' && 'homelab' || 'homelab-pr' }}
|
||||||
timeout-minutes: 15
|
timeout-minutes: 15
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout repository
|
- name: Checkout repository
|
||||||
@@ -280,7 +280,7 @@ jobs:
|
|||||||
fi
|
fi
|
||||||
dockerfiles:
|
dockerfiles:
|
||||||
name: Dockerfiles
|
name: Dockerfiles
|
||||||
runs-on: homelab
|
runs-on: ${{ github.ref == 'refs/heads/main' && 'homelab' || 'homelab-pr' }}
|
||||||
timeout-minutes: 15
|
timeout-minutes: 15
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout repository
|
- name: Checkout repository
|
||||||
@@ -326,7 +326,7 @@ jobs:
|
|||||||
fi
|
fi
|
||||||
kubernetes:
|
kubernetes:
|
||||||
name: Kubernetes
|
name: Kubernetes
|
||||||
runs-on: homelab
|
runs-on: ${{ github.ref == 'refs/heads/main' && 'homelab' || 'homelab-pr' }}
|
||||||
timeout-minutes: 15
|
timeout-minutes: 15
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout repository
|
- name: Checkout repository
|
||||||
|
|||||||
@@ -1,7 +1,9 @@
|
|||||||
name: renovate-ci
|
name: renovate-ci
|
||||||
|
|
||||||
on:
|
on:
|
||||||
pull_request:
|
# Read the workflow from the trusted base branch. PR code runs only on the
|
||||||
|
# unprivileged runner selected below.
|
||||||
|
pull_request_target:
|
||||||
paths:
|
paths:
|
||||||
- "renovate/**"
|
- "renovate/**"
|
||||||
- ".gitea/workflows/renovate-ci.yaml"
|
- ".gitea/workflows/renovate-ci.yaml"
|
||||||
@@ -26,37 +28,47 @@ permissions:
|
|||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
validate-renovate:
|
validate-renovate:
|
||||||
runs-on: homelab
|
runs-on: ${{ github.event_name == 'push' && github.ref == 'refs/heads/main' && 'homelab' || 'homelab-pr' }}
|
||||||
timeout-minutes: 20
|
timeout-minutes: 20
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout repository
|
- name: Checkout repository
|
||||||
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
|
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
|
||||||
|
with:
|
||||||
|
ref: ${{ github.event_name == 'pull_request_target' && github.event.pull_request.head.sha || github.sha }}
|
||||||
|
|
||||||
# renovate/k8s/cronjob.yaml is the single source of truth for the image tag,
|
# renovate/k8s/cronjob.yaml is the single source of truth for the version.
|
||||||
# so the same version that runs in the cluster is the one validated here.
|
- name: Resolve the deployed Renovate version
|
||||||
- name: Resolve the deployed Renovate image
|
|
||||||
id: image
|
id: image
|
||||||
shell: bash
|
shell: bash
|
||||||
run: |
|
run: |
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
image="$(sed -n 's|.*image:[[:space:]]*\(renovate/renovate:[^[:space:]]*\).*|\1|p' \
|
image="$(sed -n 's|.*image:[[:space:]]*\(renovate/renovate:[^[:space:]]*\).*|\1|p' \
|
||||||
renovate/k8s/cronjob.yaml | head -1)"
|
renovate/k8s/cronjob.yaml | head -1)"
|
||||||
if [ -z "$image" ]; then
|
if [[ ! "$image" =~ ^renovate/renovate:([0-9]+\.[0-9]+\.[0-9]+)$ ]]; then
|
||||||
echo "::error::no renovate/renovate image found in renovate/k8s/cronjob.yaml"
|
echo "::error::expected a pinned renovate/renovate semantic version in renovate/k8s/cronjob.yaml"
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
echo "using $image"
|
version="${BASH_REMATCH[1]}"
|
||||||
echo "image=$image" >> "$GITHUB_OUTPUT"
|
echo "using Renovate $version"
|
||||||
|
printf 'version=%s\n' "$version" >> "$GITHUB_OUTPUT"
|
||||||
|
|
||||||
- name: Validate Renovate repository config
|
- name: Prepare pinned validation tools
|
||||||
shell: bash
|
shell: bash
|
||||||
run: |
|
run: |
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
docker run --rm \
|
tools_dir="$(bash .gitea/workflows/install-ci-tools.sh kubeconform node)"
|
||||||
-v "$PWD/renovate:/opt/renovate:ro" \
|
echo "$tools_dir" >> "$GITHUB_PATH"
|
||||||
-e RENOVATE_CONFIG_FILE=/opt/renovate/renovate.json \
|
|
||||||
"${{ steps.image.outputs.image }}" \
|
- name: Validate Renovate repository config
|
||||||
renovate-config-validator /opt/renovate/renovate.json
|
shell: bash
|
||||||
|
env:
|
||||||
|
RENOVATE_VERSION: ${{ steps.image.outputs.version }}
|
||||||
|
run: |
|
||||||
|
set -euo pipefail
|
||||||
|
npm_cache="$(mktemp -d "${RUNNER_TEMP:-/tmp}/renovate-npm-cache.XXXXXXXX")"
|
||||||
|
trap 'rm -rf "$npm_cache"' EXIT
|
||||||
|
NPM_CONFIG_CACHE="$npm_cache" RENOVATE_CONFIG_FILE="$PWD/renovate/renovate.json" \
|
||||||
|
npm exec --yes --package="renovate@${RENOVATE_VERSION}" -- renovate-config-validator
|
||||||
|
|
||||||
# The CronJob cannot read the repository, so renovate/k8s/configmap.yaml
|
# The CronJob cannot read the repository, so renovate/k8s/configmap.yaml
|
||||||
# carries an inlined copy of the config. Fail if it no longer matches.
|
# carries an inlined copy of the config. Fail if it no longer matches.
|
||||||
@@ -70,8 +82,6 @@ jobs:
|
|||||||
shell: bash
|
shell: bash
|
||||||
run: |
|
run: |
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
tools_dir="$(bash .gitea/workflows/install-ci-tools.sh kubeconform)"
|
|
||||||
export PATH="$tools_dir:$PATH"
|
|
||||||
kubeconform \
|
kubeconform \
|
||||||
-strict \
|
-strict \
|
||||||
-ignore-missing-schemas \
|
-ignore-missing-schemas \
|
||||||
|
|||||||
@@ -32,11 +32,14 @@ concurrency:
|
|||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
run-renovate:
|
run-renovate:
|
||||||
|
if: github.ref == 'refs/heads/main'
|
||||||
runs-on: homelab
|
runs-on: homelab
|
||||||
timeout-minutes: 60
|
timeout-minutes: 60
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout repository
|
- name: Checkout repository
|
||||||
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
|
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
|
||||||
|
with:
|
||||||
|
ref: refs/heads/main
|
||||||
|
|
||||||
# renovate/k8s/cronjob.yaml is the single source of truth for the image tag.
|
# renovate/k8s/cronjob.yaml is the single source of truth for the image tag.
|
||||||
# Reading it here means this workflow validates and runs the exact version
|
# Reading it here means this workflow validates and runs the exact version
|
||||||
@@ -48,21 +51,23 @@ jobs:
|
|||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
image="$(sed -n 's|.*image:[[:space:]]*\(renovate/renovate:[^[:space:]]*\).*|\1|p' \
|
image="$(sed -n 's|.*image:[[:space:]]*\(renovate/renovate:[^[:space:]]*\).*|\1|p' \
|
||||||
renovate/k8s/cronjob.yaml | head -1)"
|
renovate/k8s/cronjob.yaml | head -1)"
|
||||||
if [ -z "$image" ]; then
|
if [[ ! "$image" =~ ^renovate/renovate:[0-9]+\.[0-9]+\.[0-9]+$ ]]; then
|
||||||
echo "::error::no renovate/renovate image found in renovate/k8s/cronjob.yaml"
|
echo "::error::expected a pinned renovate/renovate semantic version in renovate/k8s/cronjob.yaml"
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
echo "using $image"
|
echo "using $image"
|
||||||
echo "image=$image" >> "$GITHUB_OUTPUT"
|
printf 'image=%s\n' "$image" >> "$GITHUB_OUTPUT"
|
||||||
|
|
||||||
- name: Validate Renovate config
|
- name: Validate Renovate config
|
||||||
shell: bash
|
shell: bash
|
||||||
|
env:
|
||||||
|
RENOVATE_IMAGE: ${{ steps.image.outputs.image }}
|
||||||
run: |
|
run: |
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
docker run --rm \
|
docker run --rm \
|
||||||
-v "$PWD/renovate/renovate.json:/opt/renovate/renovate.json:ro" \
|
-v "$PWD/renovate/renovate.json:/opt/renovate/renovate.json:ro" \
|
||||||
-e RENOVATE_CONFIG_FILE=/opt/renovate/renovate.json \
|
-e RENOVATE_CONFIG_FILE=/opt/renovate/renovate.json \
|
||||||
"${{ steps.image.outputs.image }}" \
|
"$RENOVATE_IMAGE" \
|
||||||
renovate-config-validator
|
renovate-config-validator
|
||||||
|
|
||||||
- name: Run Renovate
|
- name: Run Renovate
|
||||||
@@ -73,6 +78,7 @@ jobs:
|
|||||||
RENOVATE_REPOSITORIES: ${{ inputs.repositories }}
|
RENOVATE_REPOSITORIES: ${{ inputs.repositories }}
|
||||||
RENOVATE_DRY_RUN: ${{ inputs.dry_run && 'full' || '' }}
|
RENOVATE_DRY_RUN: ${{ inputs.dry_run && 'full' || '' }}
|
||||||
LOG_LEVEL: ${{ inputs.log_level }}
|
LOG_LEVEL: ${{ inputs.log_level }}
|
||||||
|
RENOVATE_IMAGE: ${{ steps.image.outputs.image }}
|
||||||
run: |
|
run: |
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
|
|
||||||
@@ -89,4 +95,4 @@ jobs:
|
|||||||
-e RENOVATE_CONFIG_FILE=/opt/renovate/renovate.json \
|
-e RENOVATE_CONFIG_FILE=/opt/renovate/renovate.json \
|
||||||
-e RENOVATE_BASE_DIR=/tmp/renovate \
|
-e RENOVATE_BASE_DIR=/tmp/renovate \
|
||||||
-e LOG_LEVEL="${LOG_LEVEL:-info}" \
|
-e LOG_LEVEL="${LOG_LEVEL:-info}" \
|
||||||
"${{ steps.image.outputs.image }}"
|
"$RENOVATE_IMAGE"
|
||||||
Reference in new issue
Block a user