diff --git a/renovate/k8s/configmap.yaml b/renovate/k8s/configmap.yaml index f839ba5..b5a70a2 100644 --- a/renovate/k8s/configmap.yaml +++ b/renovate/k8s/configmap.yaml @@ -19,6 +19,9 @@ data: "dependencyDashboard": true, "prCreation": "immediate", "labels": ["dependencies", "automated"], + "docker-compose": { + "managerFilePatterns": ["renovate/renovate-compose.yaml"] + }, "helm-values": { "managerFilePatterns": ["/k8s/.+values\\.ya?ml$/"] }, @@ -29,7 +32,7 @@ data: { "customType": "regex", "description": "singlesource: playwright npm version pinned in npx command (k8s + compose)", - "managerFilePatterns": ["^edu_master/k8s/playwright\\.yaml$", "^edu_master/compose\\.yaml$"], + "managerFilePatterns": ["edu_master/k8s/playwright.yaml", "edu_master/compose.yaml"], "matchStrings": ["playwright@(?\\d+\\.\\d+\\.\\d+)"], "datasourceTemplate": "npm", "depNameTemplate": "playwright" @@ -37,15 +40,24 @@ data: { "customType": "regex", "description": "singlesource: PLAYWRIGHT_VERSION file", - "managerFilePatterns": ["^edu_master/PLAYWRIGHT_VERSION$"], - "matchStrings": ["^(?\\d+\\.\\d+\\.\\d+)$"], + "managerFilePatterns": ["edu_master/PLAYWRIGHT_VERSION"], + "matchStrings": ["^(?\\d+\\.\\d+\\.\\d+)(?:\\r?\\n)?$"], "datasourceTemplate": "pypi", "depNameTemplate": "playwright" }, + { + "customType": "regex", + "description": "singlesource: playwright Python client version pinned in Dockerfile ARG", + "managerFilePatterns": ["edu_master/webinar-checker/Dockerfile"], + "matchStrings": ["(?:^|\\n)ARG PLAYWRIGHT_VERSION=(?\\d+\\.\\d+\\.\\d+)(?:\\r?\\n|$)"], + "datasourceTemplate": "pypi", + "depNameTemplate": "playwright", + "versioningTemplate": "pep440" + }, { "customType": "regex", "description": "kube-prometheus-stack chart version pinned in the deploy workflow", - "managerFilePatterns": ["^\\.gitea/workflows/deploy-lib\\.sh$"], + "managerFilePatterns": [".gitea/workflows/deploy-lib.sh"], "matchStrings": ["\\|prometheus-community/kube-prometheus-stack\\|prometheus\\|(?[0-9.]+)\\|"], "datasourceTemplate": "helm", "depNameTemplate": "kube-prometheus-stack", @@ -54,7 +66,7 @@ data: { "customType": "regex", "description": "grafana/loki chart version pinned in the deploy workflow", - "managerFilePatterns": ["^\\.gitea/workflows/deploy-lib\\.sh$"], + "managerFilePatterns": [".gitea/workflows/deploy-lib.sh"], "matchStrings": ["\\|grafana/loki\\|prometheus\\|(?[0-9.]+)\\|"], "datasourceTemplate": "helm", "depNameTemplate": "loki", @@ -63,7 +75,7 @@ data: { "customType": "regex", "description": "grafana/alloy chart version pinned in the deploy workflow", - "managerFilePatterns": ["^\\.gitea/workflows/deploy-lib\\.sh$"], + "managerFilePatterns": [".gitea/workflows/deploy-lib.sh"], "matchStrings": ["\\|grafana/alloy\\|prometheus\\|(?[0-9.]+)\\|"], "datasourceTemplate": "helm", "depNameTemplate": "alloy", @@ -72,7 +84,7 @@ data: { "customType": "regex", "description": "actionlint version used by the ci workflow", - "managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"], + "managerFilePatterns": [".gitea/workflows/tool-versions.env"], "matchStrings": ["(?:^|\\n)ACTIONLINT_VERSION=\"(?[0-9.]+)\""], "datasourceTemplate": "github-tags", "depNameTemplate": "rhysd/actionlint" @@ -80,7 +92,7 @@ data: { "customType": "regex", "description": "shellcheck version used by the ci workflow", - "managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"], + "managerFilePatterns": [".gitea/workflows/tool-versions.env"], "matchStrings": ["(?:^|\\n)SHELLCHECK_VERSION=\"(?[0-9.]+)\""], "datasourceTemplate": "github-tags", "depNameTemplate": "koalaman/shellcheck" @@ -88,7 +100,7 @@ data: { "customType": "regex", "description": "kubeconform version used by the ci workflow", - "managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"], + "managerFilePatterns": [".gitea/workflows/tool-versions.env"], "matchStrings": ["(?:^|\\n)KUBECONFORM_VERSION=\"(?[0-9.]+)\""], "datasourceTemplate": "github-tags", "depNameTemplate": "yannh/kubeconform" @@ -96,7 +108,7 @@ data: { "customType": "regex", "description": "uv version used to build the pytest venv", - "managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"], + "managerFilePatterns": [".gitea/workflows/tool-versions.env"], "matchStrings": ["(?:^|\\n)UV_VERSION=\"(?[0-9.]+)\""], "datasourceTemplate": "github-tags", "depNameTemplate": "astral-sh/uv" @@ -104,7 +116,7 @@ data: { "customType": "regex", "description": "prettier version used by the ci workflow", - "managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"], + "managerFilePatterns": [".gitea/workflows/tool-versions.env"], "matchStrings": ["(?:^|\\n)PRETTIER_VERSION=\"(?[0-9.]+)\""], "datasourceTemplate": "npm", "depNameTemplate": "prettier" @@ -112,7 +124,7 @@ data: { "customType": "regex", "description": "ruff version used by the ci workflow", - "managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"], + "managerFilePatterns": [".gitea/workflows/tool-versions.env"], "matchStrings": ["(?:^|\\n)RUFF_VERSION=\"(?[0-9.]+)\""], "datasourceTemplate": "pypi", "depNameTemplate": "ruff" @@ -120,7 +132,7 @@ data: { "customType": "regex", "description": "pip-audit version used by the ci workflow", - "managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"], + "managerFilePatterns": [".gitea/workflows/tool-versions.env"], "matchStrings": ["(?:^|\\n)PIP_AUDIT_VERSION=\"(?[0-9.]+)\""], "datasourceTemplate": "pypi", "depNameTemplate": "pip-audit" @@ -128,7 +140,7 @@ data: { "customType": "regex", "description": "yamllint version used by the ci workflow", - "managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"], + "managerFilePatterns": [".gitea/workflows/tool-versions.env"], "matchStrings": ["(?:^|\\n)YAMLLINT_VERSION=\"(?[0-9.]+)\""], "datasourceTemplate": "pypi", "depNameTemplate": "yamllint" @@ -136,7 +148,7 @@ data: { "customType": "regex", "description": "hadolint version used by the ci workflow", - "managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"], + "managerFilePatterns": [".gitea/workflows/tool-versions.env"], "matchStrings": ["(?:^|\\n)HADOLINT_VERSION=\"(?[0-9.]+)\""], "datasourceTemplate": "github-tags", "depNameTemplate": "hadolint/hadolint" @@ -144,7 +156,7 @@ data: { "customType": "regex", "description": "node version the ci workflow runs npm with", - "managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"], + "managerFilePatterns": [".gitea/workflows/tool-versions.env"], "matchStrings": ["(?:^|\\n)NODE_VERSION=\"(?[0-9.]+)\""], "datasourceTemplate": "node", "depNameTemplate": "node" @@ -152,7 +164,7 @@ data: { "customType": "regex", "description": "stakater/reloader chart version pinned in the deploy workflow", - "managerFilePatterns": ["^\\.gitea/workflows/deploy-lib\\.sh$"], + "managerFilePatterns": [".gitea/workflows/deploy-lib.sh"], "matchStrings": ["\\|stakater/reloader\\|reloader\\|(?[0-9.]+)\\|"], "datasourceTemplate": "helm", "depNameTemplate": "reloader", @@ -161,7 +173,7 @@ data: ], "packageRules": [ { - "description": "Automerge digest and patch updates - safe by definition, review adds nothing, keeps the renovate queue and the deploy line short. Specific no-automerge rules below still override this for playwright, helm and majors.", + "description": "Automerge ordinary digest and patch updates after successful checks; specific manual-review rules below override this.", "matchUpdateTypes": ["digest", "patch"], "automerge": true }, @@ -172,6 +184,12 @@ data: "groupSlug": "all-minor", "automerge": false }, + { + "description": "Group ordinary patch updates; the specific groups and manual-review rules below take precedence", + "matchUpdateTypes": ["patch"], + "groupName": "all patch updates", + "groupSlug": "all-patch" + }, { "description": "Keep private homelab images unchanged", "matchDatasources": ["docker"], @@ -196,7 +214,7 @@ data: "automerge": false }, { - "description": "CI runs npm on the node the panel image is built from - the NODE_VERSION pin in tool-versions.env and node:22-alpine in the Dockerfile are the same dependency and move as one", + "description": "Keep CI Node runtime updates in a separate, manually reviewed group", "matchPackageNames": ["node"], "groupName": "node runtime", "groupSlug": "node", @@ -205,6 +223,8 @@ data: { "description": "Helm chart bumps change PVC fields and admission behaviour, keep them reviewable", "matchDatasources": ["helm"], + "groupName": "Helm chart {{depName}}", + "groupSlug": "helm-{{depName}}", "automerge": false }, { @@ -213,12 +233,6 @@ data: "dependencyDashboardApproval": true, "automerge": false }, - { - "description": "Group patch updates from all sources - automerge still applies via the digest/patch rule above (helm/playwright stay manual via their own rules)", - "matchUpdateTypes": ["patch"], - "groupName": "all patch updates", - "groupSlug": "all-patch" - }, { "description": "Python Y-bumps break compat (3.11->3.12->3.13->3.14) - keep the base image out of the shared minor/patch groups, review every bump separately. Placed last so its groupName wins.", "matchDatasources": ["docker"], diff --git a/renovate/renovate-compose.yaml b/renovate/renovate-compose.yaml index 0d63628..f0f5442 100644 --- a/renovate/renovate-compose.yaml +++ b/renovate/renovate-compose.yaml @@ -2,7 +2,7 @@ services: renovate: # Kept in step with renovate/k8s/cronjob.yaml by the "renovate self-update" # package rule in renovate/renovate.json. - image: renovate/renovate:44.115.9 + image: renovate/renovate:44.136.0 container_name: renovate restart: "no" env_file: diff --git a/renovate/renovate.json b/renovate/renovate.json index c74bbd4..b65f8bd 100644 --- a/renovate/renovate.json +++ b/renovate/renovate.json @@ -8,6 +8,9 @@ "dependencyDashboard": true, "prCreation": "immediate", "labels": ["dependencies", "automated"], + "docker-compose": { + "managerFilePatterns": ["renovate/renovate-compose.yaml"] + }, "helm-values": { "managerFilePatterns": ["/k8s/.+values\\.ya?ml$/"] }, @@ -18,7 +21,7 @@ { "customType": "regex", "description": "singlesource: playwright npm version pinned in npx command (k8s + compose)", - "managerFilePatterns": ["^edu_master/k8s/playwright\\.yaml$", "^edu_master/compose\\.yaml$"], + "managerFilePatterns": ["edu_master/k8s/playwright.yaml", "edu_master/compose.yaml"], "matchStrings": ["playwright@(?\\d+\\.\\d+\\.\\d+)"], "datasourceTemplate": "npm", "depNameTemplate": "playwright" @@ -26,15 +29,24 @@ { "customType": "regex", "description": "singlesource: PLAYWRIGHT_VERSION file", - "managerFilePatterns": ["^edu_master/PLAYWRIGHT_VERSION$"], - "matchStrings": ["^(?\\d+\\.\\d+\\.\\d+)$"], + "managerFilePatterns": ["edu_master/PLAYWRIGHT_VERSION"], + "matchStrings": ["^(?\\d+\\.\\d+\\.\\d+)(?:\\r?\\n)?$"], "datasourceTemplate": "pypi", "depNameTemplate": "playwright" }, + { + "customType": "regex", + "description": "singlesource: playwright Python client version pinned in Dockerfile ARG", + "managerFilePatterns": ["edu_master/webinar-checker/Dockerfile"], + "matchStrings": ["(?:^|\\n)ARG PLAYWRIGHT_VERSION=(?\\d+\\.\\d+\\.\\d+)(?:\\r?\\n|$)"], + "datasourceTemplate": "pypi", + "depNameTemplate": "playwright", + "versioningTemplate": "pep440" + }, { "customType": "regex", "description": "kube-prometheus-stack chart version pinned in the deploy workflow", - "managerFilePatterns": ["^\\.gitea/workflows/deploy-lib\\.sh$"], + "managerFilePatterns": [".gitea/workflows/deploy-lib.sh"], "matchStrings": ["\\|prometheus-community/kube-prometheus-stack\\|prometheus\\|(?[0-9.]+)\\|"], "datasourceTemplate": "helm", "depNameTemplate": "kube-prometheus-stack", @@ -43,7 +55,7 @@ { "customType": "regex", "description": "grafana/loki chart version pinned in the deploy workflow", - "managerFilePatterns": ["^\\.gitea/workflows/deploy-lib\\.sh$"], + "managerFilePatterns": [".gitea/workflows/deploy-lib.sh"], "matchStrings": ["\\|grafana/loki\\|prometheus\\|(?[0-9.]+)\\|"], "datasourceTemplate": "helm", "depNameTemplate": "loki", @@ -52,7 +64,7 @@ { "customType": "regex", "description": "grafana/alloy chart version pinned in the deploy workflow", - "managerFilePatterns": ["^\\.gitea/workflows/deploy-lib\\.sh$"], + "managerFilePatterns": [".gitea/workflows/deploy-lib.sh"], "matchStrings": ["\\|grafana/alloy\\|prometheus\\|(?[0-9.]+)\\|"], "datasourceTemplate": "helm", "depNameTemplate": "alloy", @@ -61,7 +73,7 @@ { "customType": "regex", "description": "actionlint version used by the ci workflow", - "managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"], + "managerFilePatterns": [".gitea/workflows/tool-versions.env"], "matchStrings": ["(?:^|\\n)ACTIONLINT_VERSION=\"(?[0-9.]+)\""], "datasourceTemplate": "github-tags", "depNameTemplate": "rhysd/actionlint" @@ -69,7 +81,7 @@ { "customType": "regex", "description": "shellcheck version used by the ci workflow", - "managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"], + "managerFilePatterns": [".gitea/workflows/tool-versions.env"], "matchStrings": ["(?:^|\\n)SHELLCHECK_VERSION=\"(?[0-9.]+)\""], "datasourceTemplate": "github-tags", "depNameTemplate": "koalaman/shellcheck" @@ -77,7 +89,7 @@ { "customType": "regex", "description": "kubeconform version used by the ci workflow", - "managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"], + "managerFilePatterns": [".gitea/workflows/tool-versions.env"], "matchStrings": ["(?:^|\\n)KUBECONFORM_VERSION=\"(?[0-9.]+)\""], "datasourceTemplate": "github-tags", "depNameTemplate": "yannh/kubeconform" @@ -85,7 +97,7 @@ { "customType": "regex", "description": "uv version used to build the pytest venv", - "managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"], + "managerFilePatterns": [".gitea/workflows/tool-versions.env"], "matchStrings": ["(?:^|\\n)UV_VERSION=\"(?[0-9.]+)\""], "datasourceTemplate": "github-tags", "depNameTemplate": "astral-sh/uv" @@ -93,7 +105,7 @@ { "customType": "regex", "description": "prettier version used by the ci workflow", - "managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"], + "managerFilePatterns": [".gitea/workflows/tool-versions.env"], "matchStrings": ["(?:^|\\n)PRETTIER_VERSION=\"(?[0-9.]+)\""], "datasourceTemplate": "npm", "depNameTemplate": "prettier" @@ -101,7 +113,7 @@ { "customType": "regex", "description": "ruff version used by the ci workflow", - "managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"], + "managerFilePatterns": [".gitea/workflows/tool-versions.env"], "matchStrings": ["(?:^|\\n)RUFF_VERSION=\"(?[0-9.]+)\""], "datasourceTemplate": "pypi", "depNameTemplate": "ruff" @@ -109,7 +121,7 @@ { "customType": "regex", "description": "pip-audit version used by the ci workflow", - "managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"], + "managerFilePatterns": [".gitea/workflows/tool-versions.env"], "matchStrings": ["(?:^|\\n)PIP_AUDIT_VERSION=\"(?[0-9.]+)\""], "datasourceTemplate": "pypi", "depNameTemplate": "pip-audit" @@ -117,7 +129,7 @@ { "customType": "regex", "description": "yamllint version used by the ci workflow", - "managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"], + "managerFilePatterns": [".gitea/workflows/tool-versions.env"], "matchStrings": ["(?:^|\\n)YAMLLINT_VERSION=\"(?[0-9.]+)\""], "datasourceTemplate": "pypi", "depNameTemplate": "yamllint" @@ -125,7 +137,7 @@ { "customType": "regex", "description": "hadolint version used by the ci workflow", - "managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"], + "managerFilePatterns": [".gitea/workflows/tool-versions.env"], "matchStrings": ["(?:^|\\n)HADOLINT_VERSION=\"(?[0-9.]+)\""], "datasourceTemplate": "github-tags", "depNameTemplate": "hadolint/hadolint" @@ -133,7 +145,7 @@ { "customType": "regex", "description": "node version the ci workflow runs npm with", - "managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"], + "managerFilePatterns": [".gitea/workflows/tool-versions.env"], "matchStrings": ["(?:^|\\n)NODE_VERSION=\"(?[0-9.]+)\""], "datasourceTemplate": "node", "depNameTemplate": "node" @@ -141,7 +153,7 @@ { "customType": "regex", "description": "stakater/reloader chart version pinned in the deploy workflow", - "managerFilePatterns": ["^\\.gitea/workflows/deploy-lib\\.sh$"], + "managerFilePatterns": [".gitea/workflows/deploy-lib.sh"], "matchStrings": ["\\|stakater/reloader\\|reloader\\|(?[0-9.]+)\\|"], "datasourceTemplate": "helm", "depNameTemplate": "reloader", @@ -150,7 +162,7 @@ ], "packageRules": [ { - "description": "Automerge digest and patch updates - safe by definition, review adds nothing, keeps the renovate queue and the deploy line short. Specific no-automerge rules below still override this for playwright, helm and majors.", + "description": "Automerge ordinary digest and patch updates after successful checks; specific manual-review rules below override this.", "matchUpdateTypes": ["digest", "patch"], "automerge": true }, @@ -161,6 +173,12 @@ "groupSlug": "all-minor", "automerge": false }, + { + "description": "Group ordinary patch updates; the specific groups and manual-review rules below take precedence", + "matchUpdateTypes": ["patch"], + "groupName": "all patch updates", + "groupSlug": "all-patch" + }, { "description": "Keep private homelab images unchanged", "matchDatasources": ["docker"], @@ -185,7 +203,7 @@ "automerge": false }, { - "description": "CI runs npm on the node the panel image is built from - the NODE_VERSION pin in tool-versions.env and node:22-alpine in the Dockerfile are the same dependency and move as one", + "description": "Keep CI Node runtime updates in a separate, manually reviewed group", "matchPackageNames": ["node"], "groupName": "node runtime", "groupSlug": "node", @@ -194,6 +212,8 @@ { "description": "Helm chart bumps change PVC fields and admission behaviour, keep them reviewable", "matchDatasources": ["helm"], + "groupName": "Helm chart {{depName}}", + "groupSlug": "helm-{{depName}}", "automerge": false }, { @@ -202,12 +222,6 @@ "dependencyDashboardApproval": true, "automerge": false }, - { - "description": "Group patch updates from all sources - automerge still applies via the digest/patch rule above (helm/playwright stay manual via their own rules)", - "matchUpdateTypes": ["patch"], - "groupName": "all patch updates", - "groupSlug": "all-patch" - }, { "description": "Python Y-bumps break compat (3.11->3.12->3.13->3.14) - keep the base image out of the shared minor/patch groups, review every bump separately. Placed last so its groupName wins.", "matchDatasources": ["docker"],