Compare commits
2
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
dde5eac628 | ||
|
|
7bb4e9d872 |
No files matched your search
@@ -73,20 +73,6 @@ fi
|
||||
grep -q 'MISSING OR UNREADABLE: app/credentials' "$scratch/secrets.log"
|
||||
# API/rendering errors must not produce an empty reference list and pass.
|
||||
kubectl() { return 1; }
|
||||
if ! skip_uninstalled_vmagent_crd "$REPO/prometheus-stack/k8s/vmagent.yaml"; then
|
||||
echo 'VMAgent preflight did not skip an uninstalled CRD' >&2
|
||||
exit 1
|
||||
fi
|
||||
kubectl() { return 0; }
|
||||
if skip_uninstalled_vmagent_crd "$REPO/prometheus-stack/k8s/vmagent.yaml"; then
|
||||
echo 'VMAgent preflight skipped an installed CRD' >&2
|
||||
exit 1
|
||||
fi
|
||||
if skip_uninstalled_vmagent_crd "$REPO/prometheus-stack/k8s/victoria.yaml"; then
|
||||
echo 'VMAgent preflight skipped an unrelated manifest' >&2
|
||||
exit 1
|
||||
fi
|
||||
kubectl() { return 1; }
|
||||
if check_referenced_secrets >"$scratch/secrets.log"; then
|
||||
echo 'Secret check accepted a failed manifest render' >&2
|
||||
exit 1
|
||||
|
||||
@@ -294,11 +294,6 @@ jobs:
|
||||
echo "server-side dry-run: ${#manifests[@]} manifests, ${#kustomize_apps[@]} kustomize apps"
|
||||
failed=0
|
||||
for m in ${manifests[@]+"${manifests[@]}"}; do
|
||||
if [[ "$m" == "prometheus-stack/k8s/vmagent.yaml" ]] \
|
||||
&& ! kubectl get crd vmagents.operator.victoriametrics.com >/dev/null 2>&1; then
|
||||
echo "skip server-side dry-run until the VictoriaMetrics Operator CRD is installed: $m"
|
||||
continue
|
||||
fi
|
||||
if ! out="$(kubectl apply --dry-run=server -f "$m" 2>&1)"; then
|
||||
failed=1
|
||||
echo "::error file=${m}::$(printf '%s' "$out" | head -1)"
|
||||
@@ -338,20 +333,11 @@ jobs:
|
||||
- name: Detect changed docker-built services
|
||||
id: services
|
||||
shell: bash
|
||||
env:
|
||||
PUSH_BEFORE: ${{ github.event.before }}
|
||||
run: |
|
||||
set -euo pipefail
|
||||
base="${PUSH_BEFORE:-}"
|
||||
empty_tree="$(git hash-object -t tree /dev/null)"
|
||||
if [[ "$base" =~ ^0{40}$ ]]; then
|
||||
base="$empty_tree"
|
||||
elif [[ ! "$base" =~ ^[0-9a-fA-F]{40}$ ]] || ! git cat-file -e "${base}^{commit}" 2>/dev/null; then
|
||||
# Some Gitea push payloads expose `before` as multiple root commits
|
||||
# joined by newlines. It is not a usable diff base; use this push's
|
||||
# first parent so image changes in the current commit are still built.
|
||||
base="$(git rev-parse "${GITHUB_SHA}^" 2>/dev/null || printf '%s' "$empty_tree")"
|
||||
echo "::warning::invalid push-before value; comparing against ${base}"
|
||||
base="${{ github.event.before }}"
|
||||
if [ -z "$base" ] || [ "$base" = "0000000000000000000000000000000000000000" ]; then
|
||||
base="$(git rev-list --max-parents=0 HEAD)"
|
||||
fi
|
||||
|
||||
# A failed diff used to leave changed_files empty, which reads exactly
|
||||
|
||||
@@ -546,7 +546,6 @@ rollback_workloads() {
|
||||
# have to be declared as custom.regex managers in renovate/renovate.json.
|
||||
HELM_RELEASES=(
|
||||
"prometheus-stack|prometheus-community/kube-prometheus-stack|prometheus|86.2.3|prometheus-stack/k8s/grafana-values.yaml|prometheus-stack/k8s/active"
|
||||
"victoria-operator|victoriametrics/victoria-metrics-operator|prometheus|0.68.1|prometheus-stack/k8s/victoria-operator-values.yaml|prometheus-stack/k8s/active"
|
||||
"loki|grafana/loki|prometheus|7.3.0|loki/k8s/loki-values.yaml|loki/k8s/active"
|
||||
"alloy|grafana/alloy|prometheus|1.12.1|loki/k8s/alloy-values.yaml|loki/k8s/active"
|
||||
"reloader|stakater/reloader|reloader|2.2.17|reloader/k8s/reloader-values.yaml|reloader/k8s/active"
|
||||
@@ -558,7 +557,6 @@ helm_repo_for() {
|
||||
prometheus-community/*) echo "prometheus-community https://prometheus-community.github.io/helm-charts" ;;
|
||||
grafana/*) echo "grafana https://grafana.github.io/helm-charts" ;;
|
||||
stakater/*) echo "stakater https://stakater.github.io/stakater-charts" ;;
|
||||
victoriametrics/*) echo "victoriametrics https://victoriametrics.github.io/helm-charts" ;;
|
||||
esac
|
||||
}
|
||||
|
||||
@@ -705,9 +703,6 @@ check_referenced_secrets() {
|
||||
local missing=()
|
||||
refs=""
|
||||
for m in ${K8S_MANIFESTS[@]+"${K8S_MANIFESTS[@]}"}; do
|
||||
if skip_uninstalled_vmagent_crd "$m"; then
|
||||
continue
|
||||
fi
|
||||
objects="$(kubectl create --dry-run=client --validate=false -f "$m" -o json)" || return 1
|
||||
extracted="$(printf '%s' "$objects" | jq -r -f "$REPO/.gitea/workflows/secret-references.jq")" || return 1
|
||||
refs+="$extracted"$'\n'
|
||||
@@ -734,18 +729,6 @@ check_referenced_secrets() {
|
||||
fi
|
||||
}
|
||||
|
||||
# The VMAgent CRD is installed by the VictoriaMetrics Operator Helm release in
|
||||
# stage_apply_k8s, after this preflight stage. Skip only its dry-run until then.
|
||||
skip_uninstalled_vmagent_crd() {
|
||||
local manifest="$1"
|
||||
if [[ "$manifest" == "$REPO/prometheus-stack/k8s/vmagent.yaml" ]] \
|
||||
&& ! kubectl get crd vmagents.operator.victoriametrics.com >/dev/null 2>&1; then
|
||||
echo " skip: VMAgent CRD is installed by Helm during apply: ${manifest#"$REPO"/}"
|
||||
return 0
|
||||
fi
|
||||
return 1
|
||||
}
|
||||
|
||||
stage_validate() {
|
||||
check_prune_mode || return 1
|
||||
cd "$REPO"
|
||||
@@ -763,9 +746,6 @@ stage_validate() {
|
||||
done
|
||||
log "Validate k8s manifests (kubectl dry-run=client)"
|
||||
for m in ${K8S_MANIFESTS[@]+"${K8S_MANIFESTS[@]}"}; do
|
||||
if skip_uninstalled_vmagent_crd "$m"; then
|
||||
continue
|
||||
fi
|
||||
kubectl apply --dry-run=client -f "$m" >/dev/null
|
||||
done
|
||||
for k in ${KUSTOMIZE_APPS[@]+"${KUSTOMIZE_APPS[@]}"}; do
|
||||
@@ -773,9 +753,6 @@ stage_validate() {
|
||||
done
|
||||
log "Validate k8s manifests (kubectl dry-run=server)"
|
||||
for m in ${K8S_MANIFESTS[@]+"${K8S_MANIFESTS[@]}"}; do
|
||||
if skip_uninstalled_vmagent_crd "$m"; then
|
||||
continue
|
||||
fi
|
||||
kubectl apply --dry-run=server -f "$m" >/dev/null
|
||||
done
|
||||
for k in ${KUSTOMIZE_APPS[@]+"${KUSTOMIZE_APPS[@]}"}; do
|
||||
|
||||
@@ -138,10 +138,9 @@ jobs:
|
||||
# lets it start after a failed dependency; the needs on apply-compose are a
|
||||
# barrier, so verification begins only once both applies are done.
|
||||
verify-k8s:
|
||||
needs: [preflight, apply-k8s, apply-compose]
|
||||
needs: [apply-k8s, apply-compose]
|
||||
if: >-
|
||||
always() &&
|
||||
needs.preflight.result == 'success' &&
|
||||
needs.apply-k8s.result != 'skipped' &&
|
||||
needs.apply-compose.result != 'skipped'
|
||||
runs-on: [self-hosted, linux, arch, homelab, prod]
|
||||
@@ -184,11 +183,8 @@ jobs:
|
||||
# suppressing them on a rollback would hide the one run where the answer
|
||||
# matters most.
|
||||
smoke:
|
||||
needs: [preflight, verify-k8s]
|
||||
if: >-
|
||||
always() &&
|
||||
needs.preflight.result == 'success' &&
|
||||
needs.verify-k8s.result != 'skipped'
|
||||
needs: [verify-k8s]
|
||||
if: always() && needs.verify-k8s.result != 'skipped'
|
||||
runs-on: [self-hosted, linux, arch, homelab, prod]
|
||||
timeout-minutes: 10
|
||||
steps:
|
||||
|
||||
@@ -20,7 +20,7 @@ spec:
|
||||
spec:
|
||||
containers:
|
||||
- name: cloudflared
|
||||
image: cloudflare/cloudflared:2026.10.0
|
||||
image: cloudflare/cloudflared:2026.9.3
|
||||
imagePullPolicy: IfNotPresent
|
||||
args:
|
||||
- tunnel
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
FROM python:3.14-slim
|
||||
FROM python:3.11-slim
|
||||
|
||||
WORKDIR /app
|
||||
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
FROM python:3.14-slim
|
||||
FROM python:3.11-slim
|
||||
|
||||
WORKDIR /app
|
||||
|
||||
|
||||
@@ -71,7 +71,7 @@ spec:
|
||||
name: glance-config
|
||||
- name: glance-assets
|
||||
configMap:
|
||||
name: glance-assets
|
||||
name: glance-config
|
||||
- name: docker-socket
|
||||
hostPath:
|
||||
path: /var/run/docker.sock
|
||||
|
||||
+1
-1
@@ -1,7 +1,7 @@
|
||||
services:
|
||||
homarr:
|
||||
container_name: homarr
|
||||
image: ghcr.io/homarr-labs/homarr:v2.2.0
|
||||
image: ghcr.io/homarr-labs/homarr:v2.1.2
|
||||
restart: unless-stopped
|
||||
volumes:
|
||||
- ./appdata:/appdata
|
||||
|
||||
@@ -32,7 +32,7 @@ spec:
|
||||
serviceAccountName: homarr
|
||||
containers:
|
||||
- name: homarr
|
||||
image: ghcr.io/homarr-labs/homarr:v2.2.0
|
||||
image: ghcr.io/homarr-labs/homarr:v2.1.2
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: homarr-config
|
||||
|
||||
+1
-1
@@ -1,6 +1,6 @@
|
||||
services:
|
||||
n8n:
|
||||
image: docker.n8n.io/n8nio/n8n:2.43.0
|
||||
image: docker.n8n.io/n8nio/n8n:2.42.3
|
||||
container_name: n8n
|
||||
restart: unless-stopped
|
||||
environment:
|
||||
|
||||
+1
-1
@@ -31,7 +31,7 @@ spec:
|
||||
spec:
|
||||
containers:
|
||||
- name: n8n
|
||||
image: docker.n8n.io/n8nio/n8n:2.43.0
|
||||
image: docker.n8n.io/n8nio/n8n:2.42.3
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: n8n-config
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
services:
|
||||
netronome:
|
||||
image: ghcr.io/autobrr/netronome:v0.16.0
|
||||
image: ghcr.io/autobrr/netronome:v0.15.0
|
||||
restart: unless-stopped
|
||||
container_name: netronome
|
||||
ports:
|
||||
|
||||
@@ -34,7 +34,7 @@ spec:
|
||||
spec:
|
||||
containers:
|
||||
- name: netronome
|
||||
image: ghcr.io/autobrr/netronome:v0.16.0
|
||||
image: ghcr.io/autobrr/netronome:v0.15.0
|
||||
ports:
|
||||
- name: netronome-port
|
||||
protocol: TCP
|
||||
|
||||
@@ -1,7 +1,6 @@
|
||||
POSTGRES_ADMIN_PASSWORD=
|
||||
AUTHENTIK_DB_PASSWORD=
|
||||
GITEA_DB_PASSWORD=
|
||||
NETBOX_DB_PASSWORD=
|
||||
NETRONOME_DB_PASSWORD=
|
||||
PENPOT_DB_PASSWORD=
|
||||
STATUSPAGE_DB_PASSWORD=
|
||||
@@ -1,17 +0,0 @@
|
||||
# VictoriaMetrics
|
||||
|
||||
The `victoria-operator` Helm release converts Prometheus Operator
|
||||
`ServiceMonitor` resources into owned `VMServiceScrape` resources. The
|
||||
`VMAgent` selects converted scrapes labeled `release: prometheus-stack` in all
|
||||
namespaces and writes them to the existing single-node VictoriaMetrics
|
||||
instance. Changes to selected `ServiceMonitor` resources are reconciled
|
||||
automatically; there is no copied Prometheus scrape-config blob to regenerate.
|
||||
|
||||
The agent drops targets for the Prometheus server service to avoid duplicating
|
||||
its self-scrape. `scraper: victoria` identifies the samples ingested by this
|
||||
VMAgent.
|
||||
|
||||
The VictoriaMetrics Operator chart and its CRDs are installed before the
|
||||
Kubernetes manifests by the normal deploy workflow. On a cluster where the
|
||||
operator CRDs are not installed yet, CI skips the server-side dry-run of the
|
||||
`VMAgent` resource; the deploy installs the chart before applying that resource.
|
||||
@@ -38,8 +38,6 @@ grafana:
|
||||
|
||||
# One block covers both the dashboards and datasources sidecars (p95 91M / 80M).
|
||||
sidecar:
|
||||
datasources:
|
||||
defaultDatasourceEnabled: false
|
||||
resources:
|
||||
requests:
|
||||
memory: "96Mi"
|
||||
@@ -52,18 +50,9 @@ grafana:
|
||||
type: loki
|
||||
url: http://loki-gateway.prometheus.svc.cluster.local
|
||||
access: proxy
|
||||
- name: VictoriaMetrics
|
||||
type: prometheus
|
||||
url: http://victoria-metrics.prometheus.svc.cluster.local:8428
|
||||
access: proxy
|
||||
isDefault: true
|
||||
|
||||
prometheus:
|
||||
prometheusSpec:
|
||||
# VM trial: vmagent scrapes and remote-writes to VictoriaMetrics, so the
|
||||
# Prometheus server itself stands down. Encoded here (not a kubectl patch)
|
||||
# so helm keeps owning spec.replicas and upgrades do not conflict on it.
|
||||
replicas: 0
|
||||
retention: 60d
|
||||
retentionSize: 32GB
|
||||
storageSpec:
|
||||
|
||||
@@ -31,105 +31,3 @@ spec:
|
||||
port: 80
|
||||
tls:
|
||||
secretName: internal-wildcard-tls
|
||||
---
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRoute
|
||||
metadata:
|
||||
name: prometheus-local
|
||||
namespace: prometheus
|
||||
spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: Host(`prom.workstation.internal`) || Host(`prom.gigaforust.internal`)
|
||||
kind: Rule
|
||||
services:
|
||||
- name: prometheus-stack-kube-prom-prometheus
|
||||
port: 9090
|
||||
tls:
|
||||
secretName: internal-wildcard-tls
|
||||
---
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRoute
|
||||
metadata:
|
||||
name: alertmanager-local
|
||||
namespace: prometheus
|
||||
spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: Host(`am.workstation.internal`) || Host(`am.gigaforust.internal`)
|
||||
kind: Rule
|
||||
services:
|
||||
- name: prometheus-stack-kube-prom-alertmanager
|
||||
port: 9093
|
||||
tls:
|
||||
secretName: internal-wildcard-tls
|
||||
---
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRoute
|
||||
metadata:
|
||||
name: loki-local
|
||||
namespace: prometheus
|
||||
spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: Host(`loki.workstation.internal`) || Host(`loki.gigaforust.internal`)
|
||||
kind: Rule
|
||||
services:
|
||||
- name: loki-gateway
|
||||
port: 80
|
||||
tls:
|
||||
secretName: internal-wildcard-tls
|
||||
---
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRoute
|
||||
metadata:
|
||||
name: alloy-local
|
||||
namespace: prometheus
|
||||
spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: Host(`alloy.workstation.internal`) || Host(`alloy.gigaforust.internal`)
|
||||
kind: Rule
|
||||
services:
|
||||
- name: alloy
|
||||
port: 12345
|
||||
tls:
|
||||
secretName: internal-wildcard-tls
|
||||
---
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRoute
|
||||
metadata:
|
||||
name: victoria-local
|
||||
namespace: prometheus
|
||||
spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: Host(`victoria.workstation.internal`) || Host(`victoria.gigaforust.internal`)
|
||||
kind: Rule
|
||||
services:
|
||||
- name: victoria-metrics
|
||||
port: 8428
|
||||
tls:
|
||||
secretName: internal-wildcard-tls
|
||||
---
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRoute
|
||||
metadata:
|
||||
name: vmalert-local
|
||||
namespace: prometheus
|
||||
spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: Host(`vmalert.workstation.internal`) || Host(`vmalert.gigaforust.internal`)
|
||||
kind: Rule
|
||||
services:
|
||||
- name: vmalert
|
||||
port: 8880
|
||||
tls:
|
||||
secretName: internal-wildcard-tls
|
||||
@@ -1,12 +0,0 @@
|
||||
nameOverride: victoria-operator
|
||||
|
||||
operator:
|
||||
enable_converter_ownership: true
|
||||
|
||||
resources:
|
||||
requests:
|
||||
cpu: 50m
|
||||
memory: 96Mi
|
||||
limits:
|
||||
cpu: 200m
|
||||
memory: 256Mi
|
||||
@@ -1,79 +0,0 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: victoria-metrics
|
||||
namespace: prometheus
|
||||
spec:
|
||||
selector:
|
||||
app: victoria-metrics
|
||||
ports:
|
||||
- port: 8428
|
||||
targetPort: 8428
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata:
|
||||
name: victoria-pvc
|
||||
namespace: prometheus
|
||||
spec:
|
||||
resources:
|
||||
requests:
|
||||
storage: 10Gi
|
||||
volumeMode: Filesystem
|
||||
accessModes:
|
||||
- ReadWriteOnce
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: victoria-deployment
|
||||
namespace: prometheus
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: victoria-metrics
|
||||
strategy:
|
||||
type: Recreate
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: victoria-metrics
|
||||
spec:
|
||||
containers:
|
||||
- name: victoria
|
||||
image: victoriametrics/victoria-metrics:v1.153.0-scratch
|
||||
args:
|
||||
- -storageDataPath=/vmdata
|
||||
- -retentionPeriod=30d
|
||||
- -httpListenAddr=:8428
|
||||
ports:
|
||||
- containerPort: 8428
|
||||
readinessProbe:
|
||||
httpGet:
|
||||
path: /health
|
||||
port: 8428
|
||||
initialDelaySeconds: 15
|
||||
periodSeconds: 10
|
||||
failureThreshold: 6
|
||||
livenessProbe:
|
||||
httpGet:
|
||||
path: /health
|
||||
port: 8428
|
||||
initialDelaySeconds: 60
|
||||
periodSeconds: 30
|
||||
failureThreshold: 3
|
||||
volumeMounts:
|
||||
- name: vmdata
|
||||
mountPath: /vmdata
|
||||
resources:
|
||||
requests:
|
||||
cpu: "100m"
|
||||
memory: "256Mi"
|
||||
limits:
|
||||
cpu: "1000m"
|
||||
memory: "1Gi"
|
||||
volumes:
|
||||
- name: vmdata
|
||||
persistentVolumeClaim:
|
||||
claimName: victoria-pvc
|
||||
@@ -1,29 +0,0 @@
|
||||
apiVersion: operator.victoriametrics.com/v1beta1
|
||||
kind: VMAgent
|
||||
metadata:
|
||||
name: vmagent
|
||||
namespace: prometheus
|
||||
spec:
|
||||
image:
|
||||
tag: v1.153.0
|
||||
scrapeInterval: 30s
|
||||
externalLabels:
|
||||
scraper: victoria
|
||||
serviceScrapeNamespaceSelector: {}
|
||||
serviceScrapeSelector:
|
||||
matchLabels:
|
||||
release: prometheus-stack
|
||||
globalScrapeRelabelConfigs:
|
||||
- action: drop
|
||||
source_labels:
|
||||
- __meta_kubernetes_service_name
|
||||
regex: prometheus-stack-kube-prom-prometheus
|
||||
remoteWrite:
|
||||
- url: http://victoria-metrics.prometheus.svc.cluster.local:8428/api/v1/write
|
||||
resources:
|
||||
requests:
|
||||
cpu: 100m
|
||||
memory: 256Mi
|
||||
limits:
|
||||
cpu: "1000m"
|
||||
memory: 1Gi
|
||||
@@ -1,70 +0,0 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: vmalert
|
||||
namespace: prometheus
|
||||
spec:
|
||||
selector:
|
||||
app: vmalert
|
||||
ports:
|
||||
- port: 8880
|
||||
targetPort: 8880
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: vmalert-deployment
|
||||
namespace: prometheus
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: vmalert
|
||||
strategy:
|
||||
type: Recreate
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: vmalert
|
||||
spec:
|
||||
containers:
|
||||
- name: vmalert
|
||||
image: victoriametrics/vmalert:v1.153.0
|
||||
args:
|
||||
- -datasource.url=http://victoria-metrics.prometheus.svc.cluster.local:8428
|
||||
- -remoteWrite.url=http://victoria-metrics.prometheus.svc.cluster.local:8428
|
||||
- -notifier.url=http://prometheus-stack-kube-prom-alertmanager.prometheus.svc.cluster.local:9093
|
||||
- -rule=/etc/vm/rules/*.yaml
|
||||
- -evaluationInterval=60s
|
||||
- -httpListenAddr=:8880
|
||||
ports:
|
||||
- containerPort: 8880
|
||||
readinessProbe:
|
||||
httpGet:
|
||||
path: /metrics
|
||||
port: 8880
|
||||
initialDelaySeconds: 15
|
||||
periodSeconds: 10
|
||||
failureThreshold: 6
|
||||
livenessProbe:
|
||||
httpGet:
|
||||
path: /metrics
|
||||
port: 8880
|
||||
initialDelaySeconds: 60
|
||||
periodSeconds: 30
|
||||
failureThreshold: 3
|
||||
volumeMounts:
|
||||
- name: rules
|
||||
mountPath: /etc/vm/rules
|
||||
readOnly: true
|
||||
resources:
|
||||
requests:
|
||||
cpu: "50m"
|
||||
memory: "64Mi"
|
||||
limits:
|
||||
cpu: "200m"
|
||||
memory: "256Mi"
|
||||
volumes:
|
||||
- name: rules
|
||||
configMap:
|
||||
name: prometheus-prometheus-stack-kube-prom-prometheus-rulefiles-0
|
||||
+25
-48
@@ -19,9 +19,6 @@ data:
|
||||
"dependencyDashboard": true,
|
||||
"prCreation": "immediate",
|
||||
"labels": ["dependencies", "automated"],
|
||||
"docker-compose": {
|
||||
"managerFilePatterns": ["renovate/renovate-compose.yaml"]
|
||||
},
|
||||
"helm-values": {
|
||||
"managerFilePatterns": ["/k8s/.+values\\.ya?ml$/"]
|
||||
},
|
||||
@@ -32,7 +29,7 @@ data:
|
||||
{
|
||||
"customType": "regex",
|
||||
"description": "singlesource: playwright npm version pinned in npx command (k8s + compose)",
|
||||
"managerFilePatterns": ["edu_master/k8s/playwright.yaml", "edu_master/compose.yaml"],
|
||||
"managerFilePatterns": ["^edu_master/k8s/playwright\\.yaml$", "^edu_master/compose\\.yaml$"],
|
||||
"matchStrings": ["playwright@(?<currentValue>\\d+\\.\\d+\\.\\d+)"],
|
||||
"datasourceTemplate": "npm",
|
||||
"depNameTemplate": "playwright"
|
||||
@@ -40,42 +37,24 @@ data:
|
||||
{
|
||||
"customType": "regex",
|
||||
"description": "singlesource: PLAYWRIGHT_VERSION file",
|
||||
"managerFilePatterns": ["edu_master/PLAYWRIGHT_VERSION"],
|
||||
"matchStrings": ["^(?<currentValue>\\d+\\.\\d+\\.\\d+)(?:\\r?\\n)?$"],
|
||||
"managerFilePatterns": ["^edu_master/PLAYWRIGHT_VERSION$"],
|
||||
"matchStrings": ["^(?<currentValue>\\d+\\.\\d+\\.\\d+)$"],
|
||||
"datasourceTemplate": "pypi",
|
||||
"depNameTemplate": "playwright"
|
||||
},
|
||||
{
|
||||
"customType": "regex",
|
||||
"description": "singlesource: playwright Python client version pinned in Dockerfile ARG",
|
||||
"managerFilePatterns": ["edu_master/webinar-checker/Dockerfile"],
|
||||
"matchStrings": ["(?:^|\\n)ARG PLAYWRIGHT_VERSION=(?<currentValue>\\d+\\.\\d+\\.\\d+)(?:\\r?\\n|$)"],
|
||||
"datasourceTemplate": "pypi",
|
||||
"depNameTemplate": "playwright",
|
||||
"versioningTemplate": "pep440"
|
||||
},
|
||||
{
|
||||
"customType": "regex",
|
||||
"description": "kube-prometheus-stack chart version pinned in the deploy workflow",
|
||||
"managerFilePatterns": [".gitea/workflows/deploy-lib.sh"],
|
||||
"managerFilePatterns": ["^\\.gitea/workflows/deploy-lib\\.sh$"],
|
||||
"matchStrings": ["\\|prometheus-community/kube-prometheus-stack\\|prometheus\\|(?<currentValue>[0-9.]+)\\|"],
|
||||
"datasourceTemplate": "helm",
|
||||
"depNameTemplate": "kube-prometheus-stack",
|
||||
"registryUrlTemplate": "https://prometheus-community.github.io/helm-charts"
|
||||
},
|
||||
{
|
||||
"customType": "regex",
|
||||
"description": "VictoriaMetrics Operator chart version pinned in the deploy workflow",
|
||||
"managerFilePatterns": [".gitea/workflows/deploy-lib.sh"],
|
||||
"matchStrings": ["\\|victoriametrics/victoria-metrics-operator\\|prometheus\\|(?<currentValue>[0-9.]+)\\|"],
|
||||
"datasourceTemplate": "helm",
|
||||
"depNameTemplate": "victoria-metrics-operator",
|
||||
"registryUrlTemplate": "https://victoriametrics.github.io/helm-charts"
|
||||
},
|
||||
{
|
||||
"customType": "regex",
|
||||
"description": "grafana/loki chart version pinned in the deploy workflow",
|
||||
"managerFilePatterns": [".gitea/workflows/deploy-lib.sh"],
|
||||
"managerFilePatterns": ["^\\.gitea/workflows/deploy-lib\\.sh$"],
|
||||
"matchStrings": ["\\|grafana/loki\\|prometheus\\|(?<currentValue>[0-9.]+)\\|"],
|
||||
"datasourceTemplate": "helm",
|
||||
"depNameTemplate": "loki",
|
||||
@@ -84,7 +63,7 @@ data:
|
||||
{
|
||||
"customType": "regex",
|
||||
"description": "grafana/alloy chart version pinned in the deploy workflow",
|
||||
"managerFilePatterns": [".gitea/workflows/deploy-lib.sh"],
|
||||
"managerFilePatterns": ["^\\.gitea/workflows/deploy-lib\\.sh$"],
|
||||
"matchStrings": ["\\|grafana/alloy\\|prometheus\\|(?<currentValue>[0-9.]+)\\|"],
|
||||
"datasourceTemplate": "helm",
|
||||
"depNameTemplate": "alloy",
|
||||
@@ -93,7 +72,7 @@ data:
|
||||
{
|
||||
"customType": "regex",
|
||||
"description": "actionlint version used by the ci workflow",
|
||||
"managerFilePatterns": [".gitea/workflows/tool-versions.env"],
|
||||
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
||||
"matchStrings": ["(?:^|\\n)ACTIONLINT_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
||||
"datasourceTemplate": "github-tags",
|
||||
"depNameTemplate": "rhysd/actionlint"
|
||||
@@ -101,7 +80,7 @@ data:
|
||||
{
|
||||
"customType": "regex",
|
||||
"description": "shellcheck version used by the ci workflow",
|
||||
"managerFilePatterns": [".gitea/workflows/tool-versions.env"],
|
||||
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
||||
"matchStrings": ["(?:^|\\n)SHELLCHECK_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
||||
"datasourceTemplate": "github-tags",
|
||||
"depNameTemplate": "koalaman/shellcheck"
|
||||
@@ -109,7 +88,7 @@ data:
|
||||
{
|
||||
"customType": "regex",
|
||||
"description": "kubeconform version used by the ci workflow",
|
||||
"managerFilePatterns": [".gitea/workflows/tool-versions.env"],
|
||||
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
||||
"matchStrings": ["(?:^|\\n)KUBECONFORM_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
||||
"datasourceTemplate": "github-tags",
|
||||
"depNameTemplate": "yannh/kubeconform"
|
||||
@@ -117,7 +96,7 @@ data:
|
||||
{
|
||||
"customType": "regex",
|
||||
"description": "uv version used to build the pytest venv",
|
||||
"managerFilePatterns": [".gitea/workflows/tool-versions.env"],
|
||||
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
||||
"matchStrings": ["(?:^|\\n)UV_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
||||
"datasourceTemplate": "github-tags",
|
||||
"depNameTemplate": "astral-sh/uv"
|
||||
@@ -125,7 +104,7 @@ data:
|
||||
{
|
||||
"customType": "regex",
|
||||
"description": "prettier version used by the ci workflow",
|
||||
"managerFilePatterns": [".gitea/workflows/tool-versions.env"],
|
||||
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
||||
"matchStrings": ["(?:^|\\n)PRETTIER_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
||||
"datasourceTemplate": "npm",
|
||||
"depNameTemplate": "prettier"
|
||||
@@ -133,7 +112,7 @@ data:
|
||||
{
|
||||
"customType": "regex",
|
||||
"description": "ruff version used by the ci workflow",
|
||||
"managerFilePatterns": [".gitea/workflows/tool-versions.env"],
|
||||
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
||||
"matchStrings": ["(?:^|\\n)RUFF_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
||||
"datasourceTemplate": "pypi",
|
||||
"depNameTemplate": "ruff"
|
||||
@@ -141,7 +120,7 @@ data:
|
||||
{
|
||||
"customType": "regex",
|
||||
"description": "pip-audit version used by the ci workflow",
|
||||
"managerFilePatterns": [".gitea/workflows/tool-versions.env"],
|
||||
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
||||
"matchStrings": ["(?:^|\\n)PIP_AUDIT_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
||||
"datasourceTemplate": "pypi",
|
||||
"depNameTemplate": "pip-audit"
|
||||
@@ -149,7 +128,7 @@ data:
|
||||
{
|
||||
"customType": "regex",
|
||||
"description": "yamllint version used by the ci workflow",
|
||||
"managerFilePatterns": [".gitea/workflows/tool-versions.env"],
|
||||
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
||||
"matchStrings": ["(?:^|\\n)YAMLLINT_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
||||
"datasourceTemplate": "pypi",
|
||||
"depNameTemplate": "yamllint"
|
||||
@@ -157,7 +136,7 @@ data:
|
||||
{
|
||||
"customType": "regex",
|
||||
"description": "hadolint version used by the ci workflow",
|
||||
"managerFilePatterns": [".gitea/workflows/tool-versions.env"],
|
||||
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
||||
"matchStrings": ["(?:^|\\n)HADOLINT_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
||||
"datasourceTemplate": "github-tags",
|
||||
"depNameTemplate": "hadolint/hadolint"
|
||||
@@ -165,7 +144,7 @@ data:
|
||||
{
|
||||
"customType": "regex",
|
||||
"description": "node version the ci workflow runs npm with",
|
||||
"managerFilePatterns": [".gitea/workflows/tool-versions.env"],
|
||||
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
||||
"matchStrings": ["(?:^|\\n)NODE_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
||||
"datasourceTemplate": "node",
|
||||
"depNameTemplate": "node"
|
||||
@@ -173,7 +152,7 @@ data:
|
||||
{
|
||||
"customType": "regex",
|
||||
"description": "stakater/reloader chart version pinned in the deploy workflow",
|
||||
"managerFilePatterns": [".gitea/workflows/deploy-lib.sh"],
|
||||
"managerFilePatterns": ["^\\.gitea/workflows/deploy-lib\\.sh$"],
|
||||
"matchStrings": ["\\|stakater/reloader\\|reloader\\|(?<currentValue>[0-9.]+)\\|"],
|
||||
"datasourceTemplate": "helm",
|
||||
"depNameTemplate": "reloader",
|
||||
@@ -182,7 +161,7 @@ data:
|
||||
],
|
||||
"packageRules": [
|
||||
{
|
||||
"description": "Automerge ordinary digest and patch updates after successful checks; specific manual-review rules below override this.",
|
||||
"description": "Automerge digest and patch updates - safe by definition, review adds nothing, keeps the renovate queue and the deploy line short. Specific no-automerge rules below still override this for playwright, helm and majors.",
|
||||
"matchUpdateTypes": ["digest", "patch"],
|
||||
"automerge": true
|
||||
},
|
||||
@@ -193,12 +172,6 @@ data:
|
||||
"groupSlug": "all-minor",
|
||||
"automerge": false
|
||||
},
|
||||
{
|
||||
"description": "Group ordinary patch updates; the specific groups and manual-review rules below take precedence",
|
||||
"matchUpdateTypes": ["patch"],
|
||||
"groupName": "all patch updates",
|
||||
"groupSlug": "all-patch"
|
||||
},
|
||||
{
|
||||
"description": "Keep private homelab images unchanged",
|
||||
"matchDatasources": ["docker"],
|
||||
@@ -223,7 +196,7 @@ data:
|
||||
"automerge": false
|
||||
},
|
||||
{
|
||||
"description": "Keep CI Node runtime updates in a separate, manually reviewed group",
|
||||
"description": "CI runs npm on the node the panel image is built from - the NODE_VERSION pin in tool-versions.env and node:22-alpine in the Dockerfile are the same dependency and move as one",
|
||||
"matchPackageNames": ["node"],
|
||||
"groupName": "node runtime",
|
||||
"groupSlug": "node",
|
||||
@@ -232,8 +205,6 @@ data:
|
||||
{
|
||||
"description": "Helm chart bumps change PVC fields and admission behaviour, keep them reviewable",
|
||||
"matchDatasources": ["helm"],
|
||||
"groupName": "Helm chart {{depName}}",
|
||||
"groupSlug": "helm-{{depName}}",
|
||||
"automerge": false
|
||||
},
|
||||
{
|
||||
@@ -242,6 +213,12 @@ data:
|
||||
"dependencyDashboardApproval": true,
|
||||
"automerge": false
|
||||
},
|
||||
{
|
||||
"description": "Group patch updates from all sources - automerge still applies via the digest/patch rule above (helm/playwright stay manual via their own rules)",
|
||||
"matchUpdateTypes": ["patch"],
|
||||
"groupName": "all patch updates",
|
||||
"groupSlug": "all-patch"
|
||||
},
|
||||
{
|
||||
"description": "Python Y-bumps break compat (3.11->3.12->3.13->3.14) - keep the base image out of the shared minor/patch groups, review every bump separately. Placed last so its groupName wins.",
|
||||
"matchDatasources": ["docker"],
|
||||
|
||||
@@ -19,7 +19,7 @@ spec:
|
||||
restartPolicy: Never
|
||||
containers:
|
||||
- name: renovate
|
||||
image: renovate/renovate:44.140.0
|
||||
image: renovate/renovate:44.136.0
|
||||
env:
|
||||
- name: RENOVATE_PLATFORM
|
||||
value: gitea
|
||||
|
||||
@@ -2,7 +2,7 @@ services:
|
||||
renovate:
|
||||
# Kept in step with renovate/k8s/cronjob.yaml by the "renovate self-update"
|
||||
# package rule in renovate/renovate.json.
|
||||
image: renovate/renovate:44.136.0
|
||||
image: renovate/renovate:44.115.9
|
||||
container_name: renovate
|
||||
restart: "no"
|
||||
env_file:
|
||||
|
||||
+25
-48
@@ -8,9 +8,6 @@
|
||||
"dependencyDashboard": true,
|
||||
"prCreation": "immediate",
|
||||
"labels": ["dependencies", "automated"],
|
||||
"docker-compose": {
|
||||
"managerFilePatterns": ["renovate/renovate-compose.yaml"]
|
||||
},
|
||||
"helm-values": {
|
||||
"managerFilePatterns": ["/k8s/.+values\\.ya?ml$/"]
|
||||
},
|
||||
@@ -21,7 +18,7 @@
|
||||
{
|
||||
"customType": "regex",
|
||||
"description": "singlesource: playwright npm version pinned in npx command (k8s + compose)",
|
||||
"managerFilePatterns": ["edu_master/k8s/playwright.yaml", "edu_master/compose.yaml"],
|
||||
"managerFilePatterns": ["^edu_master/k8s/playwright\\.yaml$", "^edu_master/compose\\.yaml$"],
|
||||
"matchStrings": ["playwright@(?<currentValue>\\d+\\.\\d+\\.\\d+)"],
|
||||
"datasourceTemplate": "npm",
|
||||
"depNameTemplate": "playwright"
|
||||
@@ -29,42 +26,24 @@
|
||||
{
|
||||
"customType": "regex",
|
||||
"description": "singlesource: PLAYWRIGHT_VERSION file",
|
||||
"managerFilePatterns": ["edu_master/PLAYWRIGHT_VERSION"],
|
||||
"matchStrings": ["^(?<currentValue>\\d+\\.\\d+\\.\\d+)(?:\\r?\\n)?$"],
|
||||
"managerFilePatterns": ["^edu_master/PLAYWRIGHT_VERSION$"],
|
||||
"matchStrings": ["^(?<currentValue>\\d+\\.\\d+\\.\\d+)$"],
|
||||
"datasourceTemplate": "pypi",
|
||||
"depNameTemplate": "playwright"
|
||||
},
|
||||
{
|
||||
"customType": "regex",
|
||||
"description": "singlesource: playwright Python client version pinned in Dockerfile ARG",
|
||||
"managerFilePatterns": ["edu_master/webinar-checker/Dockerfile"],
|
||||
"matchStrings": ["(?:^|\\n)ARG PLAYWRIGHT_VERSION=(?<currentValue>\\d+\\.\\d+\\.\\d+)(?:\\r?\\n|$)"],
|
||||
"datasourceTemplate": "pypi",
|
||||
"depNameTemplate": "playwright",
|
||||
"versioningTemplate": "pep440"
|
||||
},
|
||||
{
|
||||
"customType": "regex",
|
||||
"description": "kube-prometheus-stack chart version pinned in the deploy workflow",
|
||||
"managerFilePatterns": [".gitea/workflows/deploy-lib.sh"],
|
||||
"managerFilePatterns": ["^\\.gitea/workflows/deploy-lib\\.sh$"],
|
||||
"matchStrings": ["\\|prometheus-community/kube-prometheus-stack\\|prometheus\\|(?<currentValue>[0-9.]+)\\|"],
|
||||
"datasourceTemplate": "helm",
|
||||
"depNameTemplate": "kube-prometheus-stack",
|
||||
"registryUrlTemplate": "https://prometheus-community.github.io/helm-charts"
|
||||
},
|
||||
{
|
||||
"customType": "regex",
|
||||
"description": "VictoriaMetrics Operator chart version pinned in the deploy workflow",
|
||||
"managerFilePatterns": [".gitea/workflows/deploy-lib.sh"],
|
||||
"matchStrings": ["\\|victoriametrics/victoria-metrics-operator\\|prometheus\\|(?<currentValue>[0-9.]+)\\|"],
|
||||
"datasourceTemplate": "helm",
|
||||
"depNameTemplate": "victoria-metrics-operator",
|
||||
"registryUrlTemplate": "https://victoriametrics.github.io/helm-charts"
|
||||
},
|
||||
{
|
||||
"customType": "regex",
|
||||
"description": "grafana/loki chart version pinned in the deploy workflow",
|
||||
"managerFilePatterns": [".gitea/workflows/deploy-lib.sh"],
|
||||
"managerFilePatterns": ["^\\.gitea/workflows/deploy-lib\\.sh$"],
|
||||
"matchStrings": ["\\|grafana/loki\\|prometheus\\|(?<currentValue>[0-9.]+)\\|"],
|
||||
"datasourceTemplate": "helm",
|
||||
"depNameTemplate": "loki",
|
||||
@@ -73,7 +52,7 @@
|
||||
{
|
||||
"customType": "regex",
|
||||
"description": "grafana/alloy chart version pinned in the deploy workflow",
|
||||
"managerFilePatterns": [".gitea/workflows/deploy-lib.sh"],
|
||||
"managerFilePatterns": ["^\\.gitea/workflows/deploy-lib\\.sh$"],
|
||||
"matchStrings": ["\\|grafana/alloy\\|prometheus\\|(?<currentValue>[0-9.]+)\\|"],
|
||||
"datasourceTemplate": "helm",
|
||||
"depNameTemplate": "alloy",
|
||||
@@ -82,7 +61,7 @@
|
||||
{
|
||||
"customType": "regex",
|
||||
"description": "actionlint version used by the ci workflow",
|
||||
"managerFilePatterns": [".gitea/workflows/tool-versions.env"],
|
||||
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
||||
"matchStrings": ["(?:^|\\n)ACTIONLINT_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
||||
"datasourceTemplate": "github-tags",
|
||||
"depNameTemplate": "rhysd/actionlint"
|
||||
@@ -90,7 +69,7 @@
|
||||
{
|
||||
"customType": "regex",
|
||||
"description": "shellcheck version used by the ci workflow",
|
||||
"managerFilePatterns": [".gitea/workflows/tool-versions.env"],
|
||||
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
||||
"matchStrings": ["(?:^|\\n)SHELLCHECK_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
||||
"datasourceTemplate": "github-tags",
|
||||
"depNameTemplate": "koalaman/shellcheck"
|
||||
@@ -98,7 +77,7 @@
|
||||
{
|
||||
"customType": "regex",
|
||||
"description": "kubeconform version used by the ci workflow",
|
||||
"managerFilePatterns": [".gitea/workflows/tool-versions.env"],
|
||||
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
||||
"matchStrings": ["(?:^|\\n)KUBECONFORM_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
||||
"datasourceTemplate": "github-tags",
|
||||
"depNameTemplate": "yannh/kubeconform"
|
||||
@@ -106,7 +85,7 @@
|
||||
{
|
||||
"customType": "regex",
|
||||
"description": "uv version used to build the pytest venv",
|
||||
"managerFilePatterns": [".gitea/workflows/tool-versions.env"],
|
||||
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
||||
"matchStrings": ["(?:^|\\n)UV_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
||||
"datasourceTemplate": "github-tags",
|
||||
"depNameTemplate": "astral-sh/uv"
|
||||
@@ -114,7 +93,7 @@
|
||||
{
|
||||
"customType": "regex",
|
||||
"description": "prettier version used by the ci workflow",
|
||||
"managerFilePatterns": [".gitea/workflows/tool-versions.env"],
|
||||
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
||||
"matchStrings": ["(?:^|\\n)PRETTIER_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
||||
"datasourceTemplate": "npm",
|
||||
"depNameTemplate": "prettier"
|
||||
@@ -122,7 +101,7 @@
|
||||
{
|
||||
"customType": "regex",
|
||||
"description": "ruff version used by the ci workflow",
|
||||
"managerFilePatterns": [".gitea/workflows/tool-versions.env"],
|
||||
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
||||
"matchStrings": ["(?:^|\\n)RUFF_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
||||
"datasourceTemplate": "pypi",
|
||||
"depNameTemplate": "ruff"
|
||||
@@ -130,7 +109,7 @@
|
||||
{
|
||||
"customType": "regex",
|
||||
"description": "pip-audit version used by the ci workflow",
|
||||
"managerFilePatterns": [".gitea/workflows/tool-versions.env"],
|
||||
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
||||
"matchStrings": ["(?:^|\\n)PIP_AUDIT_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
||||
"datasourceTemplate": "pypi",
|
||||
"depNameTemplate": "pip-audit"
|
||||
@@ -138,7 +117,7 @@
|
||||
{
|
||||
"customType": "regex",
|
||||
"description": "yamllint version used by the ci workflow",
|
||||
"managerFilePatterns": [".gitea/workflows/tool-versions.env"],
|
||||
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
||||
"matchStrings": ["(?:^|\\n)YAMLLINT_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
||||
"datasourceTemplate": "pypi",
|
||||
"depNameTemplate": "yamllint"
|
||||
@@ -146,7 +125,7 @@
|
||||
{
|
||||
"customType": "regex",
|
||||
"description": "hadolint version used by the ci workflow",
|
||||
"managerFilePatterns": [".gitea/workflows/tool-versions.env"],
|
||||
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
||||
"matchStrings": ["(?:^|\\n)HADOLINT_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
||||
"datasourceTemplate": "github-tags",
|
||||
"depNameTemplate": "hadolint/hadolint"
|
||||
@@ -154,7 +133,7 @@
|
||||
{
|
||||
"customType": "regex",
|
||||
"description": "node version the ci workflow runs npm with",
|
||||
"managerFilePatterns": [".gitea/workflows/tool-versions.env"],
|
||||
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
||||
"matchStrings": ["(?:^|\\n)NODE_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
||||
"datasourceTemplate": "node",
|
||||
"depNameTemplate": "node"
|
||||
@@ -162,7 +141,7 @@
|
||||
{
|
||||
"customType": "regex",
|
||||
"description": "stakater/reloader chart version pinned in the deploy workflow",
|
||||
"managerFilePatterns": [".gitea/workflows/deploy-lib.sh"],
|
||||
"managerFilePatterns": ["^\\.gitea/workflows/deploy-lib\\.sh$"],
|
||||
"matchStrings": ["\\|stakater/reloader\\|reloader\\|(?<currentValue>[0-9.]+)\\|"],
|
||||
"datasourceTemplate": "helm",
|
||||
"depNameTemplate": "reloader",
|
||||
@@ -171,7 +150,7 @@
|
||||
],
|
||||
"packageRules": [
|
||||
{
|
||||
"description": "Automerge ordinary digest and patch updates after successful checks; specific manual-review rules below override this.",
|
||||
"description": "Automerge digest and patch updates - safe by definition, review adds nothing, keeps the renovate queue and the deploy line short. Specific no-automerge rules below still override this for playwright, helm and majors.",
|
||||
"matchUpdateTypes": ["digest", "patch"],
|
||||
"automerge": true
|
||||
},
|
||||
@@ -182,12 +161,6 @@
|
||||
"groupSlug": "all-minor",
|
||||
"automerge": false
|
||||
},
|
||||
{
|
||||
"description": "Group ordinary patch updates; the specific groups and manual-review rules below take precedence",
|
||||
"matchUpdateTypes": ["patch"],
|
||||
"groupName": "all patch updates",
|
||||
"groupSlug": "all-patch"
|
||||
},
|
||||
{
|
||||
"description": "Keep private homelab images unchanged",
|
||||
"matchDatasources": ["docker"],
|
||||
@@ -212,7 +185,7 @@
|
||||
"automerge": false
|
||||
},
|
||||
{
|
||||
"description": "Keep CI Node runtime updates in a separate, manually reviewed group",
|
||||
"description": "CI runs npm on the node the panel image is built from - the NODE_VERSION pin in tool-versions.env and node:22-alpine in the Dockerfile are the same dependency and move as one",
|
||||
"matchPackageNames": ["node"],
|
||||
"groupName": "node runtime",
|
||||
"groupSlug": "node",
|
||||
@@ -221,8 +194,6 @@
|
||||
{
|
||||
"description": "Helm chart bumps change PVC fields and admission behaviour, keep them reviewable",
|
||||
"matchDatasources": ["helm"],
|
||||
"groupName": "Helm chart {{depName}}",
|
||||
"groupSlug": "helm-{{depName}}",
|
||||
"automerge": false
|
||||
},
|
||||
{
|
||||
@@ -231,6 +202,12 @@
|
||||
"dependencyDashboardApproval": true,
|
||||
"automerge": false
|
||||
},
|
||||
{
|
||||
"description": "Group patch updates from all sources - automerge still applies via the digest/patch rule above (helm/playwright stay manual via their own rules)",
|
||||
"matchUpdateTypes": ["patch"],
|
||||
"groupName": "all patch updates",
|
||||
"groupSlug": "all-patch"
|
||||
},
|
||||
{
|
||||
"description": "Python Y-bumps break compat (3.11->3.12->3.13->3.14) - keep the base image out of the shared minor/patch groups, review every bump separately. Placed last so its groupName wins.",
|
||||
"matchDatasources": ["docker"],
|
||||
|
||||
@@ -19,7 +19,7 @@ services:
|
||||
- streaming
|
||||
|
||||
qbittorrent:
|
||||
image: lscr.io/linuxserver/qbittorrent:20.04.1
|
||||
image: lscr.io/linuxserver/qbittorrent:5.2.4
|
||||
container_name: qbittorrent
|
||||
restart: unless-stopped
|
||||
environment:
|
||||
|
||||
+1
-1
@@ -1,6 +1,6 @@
|
||||
services:
|
||||
termix:
|
||||
image: ghcr.io/lukegus/termix:2.9.2
|
||||
image: ghcr.io/lukegus/termix:2.9.1
|
||||
container_name: termix
|
||||
restart: unless-stopped
|
||||
# ports:
|
||||
|
||||
@@ -31,7 +31,7 @@ spec:
|
||||
spec:
|
||||
containers:
|
||||
- name: termix
|
||||
image: ghcr.io/lukegus/termix:2.9.2
|
||||
image: ghcr.io/lukegus/termix:2.9.1
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: termix-config
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
services:
|
||||
server:
|
||||
container_name: vaultwarden-server
|
||||
image: vaultwarden/server:1.37.4
|
||||
image: vaultwarden/server:1.37.3
|
||||
restart: unless-stopped
|
||||
ports:
|
||||
- 9993:80
|
||||
|
||||
@@ -31,7 +31,7 @@ spec:
|
||||
spec:
|
||||
containers:
|
||||
- name: vaultwarden
|
||||
image: vaultwarden/server:1.37.4
|
||||
image: vaultwarden/server:1.37.3
|
||||
ports:
|
||||
- containerPort: 80
|
||||
envFrom:
|
||||
|
||||
@@ -38,7 +38,7 @@ spec:
|
||||
spec:
|
||||
containers:
|
||||
- name: xui
|
||||
image: ghcr.io/mhsanaei/3x-ui:v3.9.0
|
||||
image: ghcr.io/mhsanaei/3x-ui:v3.8.5
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: xui-config
|
||||
|
||||
Reference in new issue
Block a user