name: renovate-ci on: # Read the workflow from the trusted base branch. PR code runs only on the # unprivileged runner selected below. pull_request_target: paths: - "renovate/**" - ".gitea/workflows/renovate-ci.yaml" - ".gitea/workflows/sync-renovate-configmap.sh" - ".gitea/workflows/compose-lint.sh" - ".gitea/workflows/install-ci-tools.sh" - ".gitea/workflows/tool-versions.env" push: branches: - main paths: - "renovate/**" - ".gitea/workflows/renovate-ci.yaml" - ".gitea/workflows/sync-renovate-configmap.sh" - ".gitea/workflows/compose-lint.sh" - ".gitea/workflows/install-ci-tools.sh" - ".gitea/workflows/tool-versions.env" workflow_dispatch: permissions: contents: read jobs: validate-renovate: runs-on: ${{ github.event_name == 'push' && github.ref == 'refs/heads/main' && 'homelab' || 'homelab-pr' }} timeout-minutes: 20 steps: - name: Checkout repository uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 with: ref: ${{ github.event_name == 'pull_request_target' && github.event.pull_request.head.sha || github.sha }} # renovate/k8s/cronjob.yaml is the single source of truth for the version. - name: Resolve the deployed Renovate version id: image shell: bash run: | set -euo pipefail image="$(sed -n 's|.*image:[[:space:]]*\(renovate/renovate:[^[:space:]]*\).*|\1|p' \ renovate/k8s/cronjob.yaml | head -1)" if [[ ! "$image" =~ ^renovate/renovate:([0-9]+\.[0-9]+\.[0-9]+)$ ]]; then echo "::error::expected a pinned renovate/renovate semantic version in renovate/k8s/cronjob.yaml" exit 1 fi version="${BASH_REMATCH[1]}" echo "using Renovate $version" printf 'version=%s\n' "$version" >> "$GITHUB_OUTPUT" - name: Prepare pinned validation tools shell: bash run: | set -euo pipefail tools_dir="$(bash .gitea/workflows/install-ci-tools.sh kubeconform node)" echo "$tools_dir" >> "$GITHUB_PATH" - name: Validate Renovate repository config shell: bash env: RENOVATE_VERSION: ${{ steps.image.outputs.version }} run: | set -euo pipefail npm_cache="$(mktemp -d "${RUNNER_TEMP:-/tmp}/renovate-npm-cache.XXXXXXXX")" trap 'rm -rf "$npm_cache"' EXIT NPM_CONFIG_CACHE="$npm_cache" RENOVATE_CONFIG_FILE="$PWD/renovate/renovate.json" \ npm exec --yes --package="renovate@${RENOVATE_VERSION}" -- renovate-config-validator # The CronJob cannot read the repository, so renovate/k8s/configmap.yaml # carries an inlined copy of the config. Fail if it no longer matches. - name: Check the generated Renovate ConfigMap shell: bash run: | set -euo pipefail ./.gitea/workflows/sync-renovate-configmap.sh --check - name: Validate Renovate Kubernetes manifests shell: bash run: | set -euo pipefail kubeconform \ -strict \ -ignore-missing-schemas \ -summary \ renovate/k8s/namespace.yaml \ renovate/k8s/configmap.yaml \ renovate/k8s/cronjob.yaml - name: Validate Renovate Compose file shell: bash run: | set -euo pipefail source .gitea/workflows/compose-lint.sh mapfile -t safe_flags < <(compose_safe_flags) validate_compose_file renovate/renovate-compose.yaml \ ${safe_flags[@]+"${safe_flags[@]}"}