{ "$schema": "https://docs.renovatebot.com/renovate-schema.json", "extends": ["config:recommended", ":dependencyDashboard"], "enabledManagers": ["dockerfile", "docker-compose", "kubernetes", "helm-values", "custom.regex"], "onboarding": false, "requireConfig": "optional", "autodiscover": false, "dependencyDashboard": true, "prCreation": "immediate", "labels": ["dependencies", "automated"], "helm-values": { "managerFilePatterns": ["/k8s/.+values\\.ya?ml$/"] }, "kubernetes": { "managerFilePatterns": ["/k8s/.+\\.ya?ml$/"] }, "customManagers": [ { "customType": "regex", "description": "singlesource: playwright npm version pinned in npx command (k8s + compose)", "managerFilePatterns": ["^edu_master/k8s/playwright\\.yaml$", "^edu_master/compose\\.yaml$"], "matchStrings": ["playwright@(?\\d+\\.\\d+\\.\\d+)"], "datasourceTemplate": "npm", "depNameTemplate": "playwright" }, { "customType": "regex", "description": "singlesource: PLAYWRIGHT_VERSION file", "managerFilePatterns": ["^edu_master/PLAYWRIGHT_VERSION$"], "matchStrings": ["^(?\\d+\\.\\d+\\.\\d+)$"], "datasourceTemplate": "pypi", "depNameTemplate": "playwright" }, { "customType": "regex", "description": "kube-prometheus-stack chart version pinned in the deploy workflow", "managerFilePatterns": ["^\\.gitea/workflows/deploy-lib\\.sh$"], "matchStrings": ["\\|prometheus-community/kube-prometheus-stack\\|prometheus\\|(?[0-9.]+)\\|"], "datasourceTemplate": "helm", "depNameTemplate": "kube-prometheus-stack", "registryUrlTemplate": "https://prometheus-community.github.io/helm-charts" }, { "customType": "regex", "description": "grafana/loki chart version pinned in the deploy workflow", "managerFilePatterns": ["^\\.gitea/workflows/deploy-lib\\.sh$"], "matchStrings": ["\\|grafana/loki\\|prometheus\\|(?[0-9.]+)\\|"], "datasourceTemplate": "helm", "depNameTemplate": "loki", "registryUrlTemplate": "https://grafana.github.io/helm-charts" }, { "customType": "regex", "description": "grafana/alloy chart version pinned in the deploy workflow", "managerFilePatterns": ["^\\.gitea/workflows/deploy-lib\\.sh$"], "matchStrings": ["\\|grafana/alloy\\|prometheus\\|(?[0-9.]+)\\|"], "datasourceTemplate": "helm", "depNameTemplate": "alloy", "registryUrlTemplate": "https://grafana.github.io/helm-charts" }, { "customType": "regex", "description": "actionlint version used by the ci workflow", "managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"], "matchStrings": ["(?:^|\\n)ACTIONLINT_VERSION=\"(?[0-9.]+)\""], "datasourceTemplate": "github-tags", "depNameTemplate": "rhysd/actionlint" }, { "customType": "regex", "description": "shellcheck version used by the ci workflow", "managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"], "matchStrings": ["(?:^|\\n)SHELLCHECK_VERSION=\"(?[0-9.]+)\""], "datasourceTemplate": "github-tags", "depNameTemplate": "koalaman/shellcheck" }, { "customType": "regex", "description": "kubeconform version used by the ci workflow", "managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"], "matchStrings": ["(?:^|\\n)KUBECONFORM_VERSION=\"(?[0-9.]+)\""], "datasourceTemplate": "github-tags", "depNameTemplate": "yannh/kubeconform" }, { "customType": "regex", "description": "uv version used to build the pytest venv", "managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"], "matchStrings": ["(?:^|\\n)UV_VERSION=\"(?[0-9.]+)\""], "datasourceTemplate": "github-tags", "depNameTemplate": "astral-sh/uv" }, { "customType": "regex", "description": "prettier version used by the ci workflow", "managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"], "matchStrings": ["(?:^|\\n)PRETTIER_VERSION=\"(?[0-9.]+)\""], "datasourceTemplate": "npm", "depNameTemplate": "prettier" }, { "customType": "regex", "description": "ruff version used by the ci workflow", "managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"], "matchStrings": ["(?:^|\\n)RUFF_VERSION=\"(?[0-9.]+)\""], "datasourceTemplate": "pypi", "depNameTemplate": "ruff" }, { "customType": "regex", "description": "pip-audit version used by the ci workflow", "managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"], "matchStrings": ["(?:^|\\n)PIP_AUDIT_VERSION=\"(?[0-9.]+)\""], "datasourceTemplate": "pypi", "depNameTemplate": "pip-audit" }, { "customType": "regex", "description": "yamllint version used by the ci workflow", "managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"], "matchStrings": ["(?:^|\\n)YAMLLINT_VERSION=\"(?[0-9.]+)\""], "datasourceTemplate": "pypi", "depNameTemplate": "yamllint" }, { "customType": "regex", "description": "hadolint version used by the ci workflow", "managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"], "matchStrings": ["(?:^|\\n)HADOLINT_VERSION=\"(?[0-9.]+)\""], "datasourceTemplate": "github-tags", "depNameTemplate": "hadolint/hadolint" }, { "customType": "regex", "description": "node version the ci workflow runs npm with", "managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"], "matchStrings": ["(?:^|\\n)NODE_VERSION=\"(?[0-9.]+)\""], "datasourceTemplate": "node", "depNameTemplate": "node" }, { "customType": "regex", "description": "stakater/reloader chart version pinned in the deploy workflow", "managerFilePatterns": ["^\\.gitea/workflows/deploy-lib\\.sh$"], "matchStrings": ["\\|stakater/reloader\\|reloader\\|(?[0-9.]+)\\|"], "datasourceTemplate": "helm", "depNameTemplate": "reloader", "registryUrlTemplate": "https://stakater.github.io/stakater-charts" } ], "packageRules": [ { "description": "Automerge digest and patch updates - safe by definition, review adds nothing, keeps the renovate queue and the deploy line short. Specific no-automerge rules below still override this for playwright, helm and majors.", "matchUpdateTypes": ["digest", "patch"], "automerge": true }, { "description": "Group all minor updates into one reviewable PR - placed before the specific groups below so playwright/node/renovate keep their own lockstep groups (later groupName wins)", "matchUpdateTypes": ["minor"], "groupName": "all minor updates", "groupSlug": "all-minor", "automerge": false }, { "description": "Keep private homelab images unchanged", "matchDatasources": ["docker"], "matchPackageNames": ["/gcr\\.forust\\.xyz\\/forust\\/.+/"], "enabled": false }, { "description": "singlesource playwright - use whichever version is found, keep docker+pypi+npm in sync", "matchPackageNames": ["playwright", "mcr.microsoft.com/playwright"], "groupName": "playwright singlesource", "groupSlug": "playwright" }, { "description": "playwright must not automerge - version skew breaks the WS handshake (checker.py:1523 vs playwright.yaml:20)", "matchPackageNames": ["playwright", "mcr.microsoft.com/playwright"], "automerge": false }, { "description": "Renovate updates itself in lockstep across the CronJob and the Compose file", "matchPackageNames": ["renovate/renovate"], "groupName": "renovate self-update", "automerge": false }, { "description": "CI runs npm on the node the panel image is built from - the NODE_VERSION pin in tool-versions.env and node:22-alpine in the Dockerfile are the same dependency and move as one", "matchPackageNames": ["node"], "groupName": "node runtime", "groupSlug": "node", "automerge": false }, { "description": "Helm chart bumps change PVC fields and admission behaviour, keep them reviewable", "matchDatasources": ["helm"], "automerge": false }, { "description": "Require approval for major upgrades", "matchUpdateTypes": ["major"], "dependencyDashboardApproval": true, "automerge": false }, { "description": "Group patch updates from all sources - automerge still applies via the digest/patch rule above (helm/playwright stay manual via their own rules)", "matchUpdateTypes": ["patch"], "groupName": "all patch updates", "groupSlug": "all-patch" }, { "description": "Python Y-bumps break compat (3.11->3.12->3.13->3.14) - keep the base image out of the shared minor/patch groups, review every bump separately. Placed last so its groupName wins.", "matchDatasources": ["docker"], "matchPackageNames": ["python"], "groupName": "python base image", "groupSlug": "python", "automerge": false }, { "description": "Rolling/floating tags (streaming stack, nextcloud beta, kubectl latest) - never automerge, every bump is a manual review. Placed last so automerge:false wins over the shared digest/patch rule.", "matchDatasources": ["docker"], "matchPackageNames": [ "lscr.io/linuxserver/jellyfin", "lscr.io/linuxserver/qbittorrent", "lscr.io/linuxserver/sonarr", "lscr.io/linuxserver/radarr", "lscr.io/linuxserver/prowlarr", "lscr.io/linuxserver/bazarr", "ghcr.io/seerr-team/seerr", "fallenbagel/jellyseerr", "ghcr.io/lampac-nextgen/lampac", "ghcr.io/nextcloud-releases/all-in-one", "alpine/kubectl" ], "groupName": "floating images - manual", "groupSlug": "floating-manual", "automerge": false } ] }