The config lived in renovate.json at the repo root while everything else Renovate-related sat under renovate/, and renovate/config.js was a second, unused source of truth. Both are gone: renovate/renovate.json is now the only config file. Because the CronJob in the cluster cannot read the repository, its ConfigMap carries an inlined copy of the config. That copy is generated, and sync-renovate-configmap.sh --check now fails the build when it drifts from the source file. The workflows also stop carrying a copy of the renovate/renovate image tag. They read it from renovate/k8s/cronjob.yaml, so the version validated in CI is the version that actually runs in the cluster. ci.yaml validates the config with renovate-config-validator, checks the generated ConfigMap, and kubeconforms the CronJob's own manifests.
88 lines
3.1 KiB
YAML
88 lines
3.1 KiB
YAML
name: renovate-run
|
|
|
|
on:
|
|
workflow_dispatch:
|
|
inputs:
|
|
repositories:
|
|
description: "Repositories to scan (comma-separated)"
|
|
required: false
|
|
default: "forust/homelab"
|
|
log_level:
|
|
description: "Renovate log level"
|
|
required: false
|
|
default: "info"
|
|
type: choice
|
|
options:
|
|
- info
|
|
- debug
|
|
dry_run:
|
|
description: "Plan only, do not open or update PRs"
|
|
required: false
|
|
default: false
|
|
type: boolean
|
|
|
|
concurrency:
|
|
group: renovate-run
|
|
cancel-in-progress: false
|
|
|
|
jobs:
|
|
run-renovate:
|
|
runs-on: [self-hosted, linux, arch, homelab]
|
|
timeout-minutes: 60
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
|
|
|
|
# renovate/k8s/cronjob.yaml is the single source of truth for the image tag.
|
|
# Reading it here means this workflow validates and runs the exact version
|
|
# that is deployed, instead of a copy that silently goes stale.
|
|
- name: Resolve the deployed Renovate image
|
|
id: image
|
|
shell: bash
|
|
run: |
|
|
set -euo pipefail
|
|
image="$(sed -n 's|.*image:[[:space:]]*\(renovate/renovate:[^[:space:]]*\).*|\1|p' \
|
|
renovate/k8s/cronjob.yaml | head -1)"
|
|
if [ -z "$image" ]; then
|
|
echo "::error::no renovate/renovate image found in renovate/k8s/cronjob.yaml"
|
|
exit 1
|
|
fi
|
|
echo "using $image"
|
|
echo "image=$image" >> "$GITHUB_OUTPUT"
|
|
|
|
- name: Validate Renovate config
|
|
shell: bash
|
|
run: |
|
|
set -euo pipefail
|
|
docker run --rm \
|
|
-v "$PWD/renovate/renovate.json:/opt/renovate/renovate.json:ro" \
|
|
-e RENOVATE_CONFIG_FILE=/opt/renovate/renovate.json \
|
|
"${{ steps.image.outputs.image }}" \
|
|
renovate-config-validator
|
|
|
|
- name: Run Renovate
|
|
shell: bash
|
|
env:
|
|
RENOVATE_TOKEN: ${{ secrets.RENOVATE_TOKEN }}
|
|
RENOVATE_GITHUB_COM_TOKEN: ${{ secrets.RENOVATE_GITHUB_COM_TOKEN }}
|
|
RENOVATE_REPOSITORIES: ${{ inputs.repositories }}
|
|
RENOVATE_DRY_RUN: ${{ inputs.dry_run && 'full' || '' }}
|
|
LOG_LEVEL: ${{ inputs.log_level }}
|
|
run: |
|
|
set -euo pipefail
|
|
|
|
: "${RENOVATE_TOKEN:?missing RENOVATE_TOKEN secret — add a renovate-bot PAT in repo/org Actions secrets}"
|
|
|
|
docker run --rm \
|
|
-v "$PWD/renovate/renovate.json:/opt/renovate/renovate.json:ro" \
|
|
-e RENOVATE_PLATFORM=gitea \
|
|
-e RENOVATE_ENDPOINT=https://gitea.forust.xyz/api/v1 \
|
|
-e RENOVATE_TOKEN="$RENOVATE_TOKEN" \
|
|
-e RENOVATE_GITHUB_COM_TOKEN="${RENOVATE_GITHUB_COM_TOKEN:-}" \
|
|
-e RENOVATE_REPOSITORIES="${RENOVATE_REPOSITORIES:-forust/homelab}" \
|
|
-e RENOVATE_DRY_RUN="${RENOVATE_DRY_RUN:-}" \
|
|
-e RENOVATE_CONFIG_FILE=/opt/renovate/renovate.json \
|
|
-e RENOVATE_BASE_DIR=/tmp/renovate \
|
|
-e LOG_LEVEL="${LOG_LEVEL:-info}" \
|
|
"${{ steps.image.outputs.image }}"
|