name: renovate-ci on: pull_request: push: branches: - main workflow_dispatch: jobs: validate-renovate: runs-on: [self-hosted, linux, arch, homelab] timeout-minutes: 20 steps: - name: Checkout repository uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 # renovate/k8s/cronjob.yaml is the single source of truth for the image tag, # so the same version that runs in the cluster is the one validated here. - name: Resolve the deployed Renovate image id: image shell: bash run: | set -euo pipefail image="$(sed -n 's|.*image:[[:space:]]*\(renovate/renovate:[^[:space:]]*\).*|\1|p' \ renovate/k8s/cronjob.yaml | head -1)" if [ -z "$image" ]; then echo "::error::no renovate/renovate image found in renovate/k8s/cronjob.yaml" exit 1 fi echo "using $image" echo "image=$image" >> "$GITHUB_OUTPUT" - name: Validate Renovate repository config shell: bash run: | set -euo pipefail docker run --rm \ -v "$PWD/renovate:/opt/renovate:ro" \ -e RENOVATE_CONFIG_FILE=/opt/renovate/renovate.json \ "${{ steps.image.outputs.image }}" \ renovate-config-validator /opt/renovate/renovate.json # The CronJob cannot read the repository, so renovate/k8s/configmap.yaml # carries an inlined copy of the config. Fail if it no longer matches. - name: Check the generated Renovate ConfigMap shell: bash run: | set -euo pipefail ./.gitea/workflows/sync-renovate-configmap.sh --check - name: Validate Renovate Kubernetes manifests shell: bash run: | set -euo pipefail tools_dir="$(bash .gitea/workflows/install-ci-tools.sh kubeconform)" export PATH="$tools_dir:$PATH" kubeconform \ -strict \ -ignore-missing-schemas \ -summary \ renovate/k8s/namespace.yaml \ renovate/k8s/configmap.yaml \ renovate/k8s/cronjob.yaml - name: Validate Renovate Compose file shell: bash run: | set -euo pipefail source .gitea/workflows/compose-lint.sh mapfile -t safe_flags < <(compose_safe_flags) validate_compose_file renovate/renovate-compose.yaml \ ${safe_flags[@]+"${safe_flags[@]}"}