ci / lint-compose (push) Successful in 9s
ci / lint-actionlint (push) Successful in 4s
ci / lint-shellcheck (push) Successful in 6s
ci / lint-prettier (push) Successful in 11s
ci / lint-ruff (push) Successful in 5s
ci / lint-yaml (push) Successful in 9s
ci / lint-dockerfiles (push) Successful in 5s
ci / validate (push) Successful in 6s
renovate-ci / validate-renovate (push) Successful in 10s
ci / build (push) Successful in 17s
Renovate: group all minor updates and all patch updates into reviewable PRs. Crowdsec: whitelist static VPS IP. Remove stale cloudflared/k8s/active marker.
213 lines
8.9 KiB
JSON
213 lines
8.9 KiB
JSON
{
|
|
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
|
|
"extends": ["config:recommended", ":dependencyDashboard"],
|
|
"enabledManagers": ["dockerfile", "docker-compose", "kubernetes", "helm-values", "custom.regex"],
|
|
"onboarding": false,
|
|
"requireConfig": "optional",
|
|
"autodiscover": false,
|
|
"dependencyDashboard": true,
|
|
"prCreation": "immediate",
|
|
"labels": ["dependencies", "automated"],
|
|
"helm-values": {
|
|
"managerFilePatterns": ["/k8s/.+values\\.ya?ml$/"]
|
|
},
|
|
"kubernetes": {
|
|
"managerFilePatterns": ["/k8s/.+\\.ya?ml$/"]
|
|
},
|
|
"customManagers": [
|
|
{
|
|
"customType": "regex",
|
|
"description": "singlesource: playwright npm version pinned in npx command (k8s + compose)",
|
|
"managerFilePatterns": ["^edu_master/k8s/playwright\\.yaml$", "^edu_master/compose\\.yaml$"],
|
|
"matchStrings": ["playwright@(?<currentValue>\\d+\\.\\d+\\.\\d+)"],
|
|
"datasourceTemplate": "npm",
|
|
"depNameTemplate": "playwright"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "singlesource: PLAYWRIGHT_VERSION file",
|
|
"managerFilePatterns": ["^edu_master/PLAYWRIGHT_VERSION$"],
|
|
"matchStrings": ["^(?<currentValue>\\d+\\.\\d+\\.\\d+)$"],
|
|
"datasourceTemplate": "pypi",
|
|
"depNameTemplate": "playwright"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "kube-prometheus-stack chart version pinned in the deploy workflow",
|
|
"managerFilePatterns": ["^\\.gitea/workflows/deploy-lib\\.sh$"],
|
|
"matchStrings": ["\\|prometheus-community/kube-prometheus-stack\\|prometheus\\|(?<currentValue>[0-9.]+)\\|"],
|
|
"datasourceTemplate": "helm",
|
|
"depNameTemplate": "kube-prometheus-stack",
|
|
"registryUrlTemplate": "https://prometheus-community.github.io/helm-charts"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "grafana/loki chart version pinned in the deploy workflow",
|
|
"managerFilePatterns": ["^\\.gitea/workflows/deploy-lib\\.sh$"],
|
|
"matchStrings": ["\\|grafana/loki\\|prometheus\\|(?<currentValue>[0-9.]+)\\|"],
|
|
"datasourceTemplate": "helm",
|
|
"depNameTemplate": "loki",
|
|
"registryUrlTemplate": "https://grafana.github.io/helm-charts"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "grafana/alloy chart version pinned in the deploy workflow",
|
|
"managerFilePatterns": ["^\\.gitea/workflows/deploy-lib\\.sh$"],
|
|
"matchStrings": ["\\|grafana/alloy\\|prometheus\\|(?<currentValue>[0-9.]+)\\|"],
|
|
"datasourceTemplate": "helm",
|
|
"depNameTemplate": "alloy",
|
|
"registryUrlTemplate": "https://grafana.github.io/helm-charts"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "actionlint version used by the ci workflow",
|
|
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
|
"matchStrings": ["(?:^|\\n)ACTIONLINT_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
|
"datasourceTemplate": "github-tags",
|
|
"depNameTemplate": "rhysd/actionlint"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "shellcheck version used by the ci workflow",
|
|
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
|
"matchStrings": ["(?:^|\\n)SHELLCHECK_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
|
"datasourceTemplate": "github-tags",
|
|
"depNameTemplate": "koalaman/shellcheck"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "kubeconform version used by the ci workflow",
|
|
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
|
"matchStrings": ["(?:^|\\n)KUBECONFORM_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
|
"datasourceTemplate": "github-tags",
|
|
"depNameTemplate": "yannh/kubeconform"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "uv version used to build the pytest venv",
|
|
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
|
"matchStrings": ["(?:^|\\n)UV_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
|
"datasourceTemplate": "github-tags",
|
|
"depNameTemplate": "astral-sh/uv"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "prettier version used by the ci workflow",
|
|
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
|
"matchStrings": ["(?:^|\\n)PRETTIER_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
|
"datasourceTemplate": "npm",
|
|
"depNameTemplate": "prettier"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "ruff version used by the ci workflow",
|
|
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
|
"matchStrings": ["(?:^|\\n)RUFF_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
|
"datasourceTemplate": "pypi",
|
|
"depNameTemplate": "ruff"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "pip-audit version used by the ci workflow",
|
|
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
|
"matchStrings": ["(?:^|\\n)PIP_AUDIT_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
|
"datasourceTemplate": "pypi",
|
|
"depNameTemplate": "pip-audit"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "yamllint version used by the ci workflow",
|
|
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
|
"matchStrings": ["(?:^|\\n)YAMLLINT_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
|
"datasourceTemplate": "pypi",
|
|
"depNameTemplate": "yamllint"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "hadolint version used by the ci workflow",
|
|
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
|
"matchStrings": ["(?:^|\\n)HADOLINT_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
|
"datasourceTemplate": "github-tags",
|
|
"depNameTemplate": "hadolint/hadolint"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "node version the ci workflow runs npm with",
|
|
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
|
"matchStrings": ["(?:^|\\n)NODE_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
|
"datasourceTemplate": "node",
|
|
"depNameTemplate": "node"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "stakater/reloader chart version pinned in the deploy workflow",
|
|
"managerFilePatterns": ["^\\.gitea/workflows/deploy-lib\\.sh$"],
|
|
"matchStrings": ["\\|stakater/reloader\\|reloader\\|(?<currentValue>[0-9.]+)\\|"],
|
|
"datasourceTemplate": "helm",
|
|
"depNameTemplate": "reloader",
|
|
"registryUrlTemplate": "https://stakater.github.io/stakater-charts"
|
|
}
|
|
],
|
|
"packageRules": [
|
|
{
|
|
"description": "Automerge digest and patch updates - safe by definition, review adds nothing, keeps the renovate queue and the deploy line short. Specific no-automerge rules below still override this for playwright, helm and majors.",
|
|
"matchUpdateTypes": ["digest", "patch"],
|
|
"automerge": true
|
|
},
|
|
{
|
|
"description": "Group all minor updates into one reviewable PR - placed before the specific groups below so playwright/node/renovate keep their own lockstep groups (later groupName wins)",
|
|
"matchUpdateTypes": ["minor"],
|
|
"groupName": "all minor updates",
|
|
"groupSlug": "all-minor",
|
|
"automerge": false
|
|
},
|
|
{
|
|
"description": "Keep private homelab images unchanged",
|
|
"matchDatasources": ["docker"],
|
|
"matchPackageNames": ["/gcr\\.forust\\.xyz\\/forust\\/.+/"],
|
|
"enabled": false
|
|
},
|
|
{
|
|
"description": "singlesource playwright - use whichever version is found, keep docker+pypi+npm in sync",
|
|
"matchPackageNames": ["playwright", "mcr.microsoft.com/playwright"],
|
|
"groupName": "playwright singlesource",
|
|
"groupSlug": "playwright"
|
|
},
|
|
{
|
|
"description": "playwright must not automerge - version skew breaks the WS handshake (checker.py:1523 vs playwright.yaml:20)",
|
|
"matchPackageNames": ["playwright", "mcr.microsoft.com/playwright"],
|
|
"automerge": false
|
|
},
|
|
{
|
|
"description": "Renovate updates itself in lockstep across the CronJob and the Compose file",
|
|
"matchPackageNames": ["renovate/renovate"],
|
|
"groupName": "renovate self-update",
|
|
"automerge": false
|
|
},
|
|
{
|
|
"description": "CI runs npm on the node the panel image is built from - the NODE_VERSION pin in tool-versions.env and node:22-alpine in the Dockerfile are the same dependency and move as one",
|
|
"matchPackageNames": ["node"],
|
|
"groupName": "node runtime",
|
|
"groupSlug": "node",
|
|
"automerge": false
|
|
},
|
|
{
|
|
"description": "Helm chart bumps change PVC fields and admission behaviour, keep them reviewable",
|
|
"matchDatasources": ["helm"],
|
|
"automerge": false
|
|
},
|
|
{
|
|
"description": "Require approval for major upgrades",
|
|
"matchUpdateTypes": ["major"],
|
|
"dependencyDashboardApproval": true,
|
|
"automerge": false
|
|
},
|
|
{
|
|
"description": "Group patch updates from all sources - automerge still applies via the digest/patch rule above (helm/playwright stay manual via their own rules)",
|
|
"matchUpdateTypes": ["patch"],
|
|
"groupName": "all patch updates",
|
|
"groupSlug": "all-patch"
|
|
}
|
|
]
|
|
}
|