name: renovate-run on: workflow_dispatch: inputs: repositories: description: "Repositories to scan (comma-separated)" required: false default: "forust/homelab" log_level: description: "Renovate log level" required: false default: "info" type: choice options: - info - debug dry_run: description: "Plan only, do not open or update PRs" required: false default: false type: boolean # Renovate writes through its own bot PAT, passed in as RENOVATE_TOKEN, so the # Actions token is only ever used to read the checkout. permissions: contents: read concurrency: group: renovate-run cancel-in-progress: false jobs: run-renovate: runs-on: [self-hosted, linux, arch, homelab] timeout-minutes: 60 steps: - name: Checkout repository uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 # renovate/k8s/cronjob.yaml is the single source of truth for the image tag. # Reading it here means this workflow validates and runs the exact version # that is deployed, instead of a copy that silently goes stale. - name: Resolve the deployed Renovate image id: image shell: bash run: | set -euo pipefail image="$(sed -n 's|.*image:[[:space:]]*\(renovate/renovate:[^[:space:]]*\).*|\1|p' \ renovate/k8s/cronjob.yaml | head -1)" if [ -z "$image" ]; then echo "::error::no renovate/renovate image found in renovate/k8s/cronjob.yaml" exit 1 fi echo "using $image" echo "image=$image" >> "$GITHUB_OUTPUT" - name: Validate Renovate config shell: bash run: | set -euo pipefail docker run --rm \ -v "$PWD/renovate/renovate.json:/opt/renovate/renovate.json:ro" \ -e RENOVATE_CONFIG_FILE=/opt/renovate/renovate.json \ "${{ steps.image.outputs.image }}" \ renovate-config-validator - name: Run Renovate shell: bash env: RENOVATE_TOKEN: ${{ secrets.RENOVATE_TOKEN }} RENOVATE_GITHUB_COM_TOKEN: ${{ secrets.RENOVATE_GITHUB_COM_TOKEN }} RENOVATE_REPOSITORIES: ${{ inputs.repositories }} RENOVATE_DRY_RUN: ${{ inputs.dry_run && 'full' || '' }} LOG_LEVEL: ${{ inputs.log_level }} run: | set -euo pipefail : "${RENOVATE_TOKEN:?missing RENOVATE_TOKEN secret — add a renovate-bot PAT in repo/org Actions secrets}" docker run --rm \ -v "$PWD/renovate/renovate.json:/opt/renovate/renovate.json:ro" \ -e RENOVATE_PLATFORM=gitea \ -e RENOVATE_ENDPOINT=https://gitea.forust.xyz/api/v1 \ -e RENOVATE_TOKEN="$RENOVATE_TOKEN" \ -e RENOVATE_GITHUB_COM_TOKEN="${RENOVATE_GITHUB_COM_TOKEN:-}" \ -e RENOVATE_REPOSITORIES="${RENOVATE_REPOSITORIES:-forust/homelab}" \ -e RENOVATE_DRY_RUN="${RENOVATE_DRY_RUN:-}" \ -e RENOVATE_CONFIG_FILE=/opt/renovate/renovate.json \ -e RENOVATE_BASE_DIR=/tmp/renovate \ -e LOG_LEVEL="${LOG_LEVEL:-info}" \ "${{ steps.image.outputs.image }}"