93 lines
3.2 KiB
YAML
93 lines
3.2 KiB
YAML
name: renovate-run
|
|
|
|
on:
|
|
workflow_dispatch:
|
|
inputs:
|
|
repositories:
|
|
description: "Repositories to scan (comma-separated)"
|
|
required: false
|
|
default: "forust/homelab"
|
|
log_level:
|
|
description: "Renovate log level"
|
|
required: false
|
|
default: "info"
|
|
type: choice
|
|
options:
|
|
- info
|
|
- debug
|
|
dry_run:
|
|
description: "Plan only, do not open or update PRs"
|
|
required: false
|
|
default: false
|
|
type: boolean
|
|
|
|
# Renovate writes through its own bot PAT, passed in as RENOVATE_TOKEN, so the
|
|
# Actions token is only ever used to read the checkout.
|
|
permissions:
|
|
contents: read
|
|
|
|
concurrency:
|
|
group: renovate-run
|
|
cancel-in-progress: false
|
|
|
|
jobs:
|
|
run-renovate:
|
|
runs-on: [self-hosted, linux, arch, homelab]
|
|
timeout-minutes: 60
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
|
|
|
|
# renovate/k8s/cronjob.yaml is the single source of truth for the image tag.
|
|
# Reading it here means this workflow validates and runs the exact version
|
|
# that is deployed, instead of a copy that silently goes stale.
|
|
- name: Resolve the deployed Renovate image
|
|
id: image
|
|
shell: bash
|
|
run: |
|
|
set -euo pipefail
|
|
image="$(sed -n 's|.*image:[[:space:]]*\(renovate/renovate:[^[:space:]]*\).*|\1|p' \
|
|
renovate/k8s/cronjob.yaml | head -1)"
|
|
if [ -z "$image" ]; then
|
|
echo "::error::no renovate/renovate image found in renovate/k8s/cronjob.yaml"
|
|
exit 1
|
|
fi
|
|
echo "using $image"
|
|
echo "image=$image" >> "$GITHUB_OUTPUT"
|
|
|
|
- name: Validate Renovate config
|
|
shell: bash
|
|
run: |
|
|
set -euo pipefail
|
|
docker run --rm \
|
|
-v "$PWD/renovate/renovate.json:/opt/renovate/renovate.json:ro" \
|
|
-e RENOVATE_CONFIG_FILE=/opt/renovate/renovate.json \
|
|
"${{ steps.image.outputs.image }}" \
|
|
renovate-config-validator
|
|
|
|
- name: Run Renovate
|
|
shell: bash
|
|
env:
|
|
RENOVATE_TOKEN: ${{ secrets.RENOVATE_TOKEN }}
|
|
RENOVATE_GITHUB_COM_TOKEN: ${{ secrets.RENOVATE_GITHUB_COM_TOKEN }}
|
|
RENOVATE_REPOSITORIES: ${{ inputs.repositories }}
|
|
RENOVATE_DRY_RUN: ${{ inputs.dry_run && 'full' || '' }}
|
|
LOG_LEVEL: ${{ inputs.log_level }}
|
|
run: |
|
|
set -euo pipefail
|
|
|
|
: "${RENOVATE_TOKEN:?missing RENOVATE_TOKEN secret — add a renovate-bot PAT in repo/org Actions secrets}"
|
|
|
|
docker run --rm \
|
|
-v "$PWD/renovate/renovate.json:/opt/renovate/renovate.json:ro" \
|
|
-e RENOVATE_PLATFORM=gitea \
|
|
-e RENOVATE_ENDPOINT=https://git.forust.xyz/api/v1 \
|
|
-e RENOVATE_TOKEN="$RENOVATE_TOKEN" \
|
|
-e RENOVATE_GITHUB_COM_TOKEN="${RENOVATE_GITHUB_COM_TOKEN:-}" \
|
|
-e RENOVATE_REPOSITORIES="${RENOVATE_REPOSITORIES:-forust/homelab}" \
|
|
-e RENOVATE_DRY_RUN="${RENOVATE_DRY_RUN:-}" \
|
|
-e RENOVATE_CONFIG_FILE=/opt/renovate/renovate.json \
|
|
-e RENOVATE_BASE_DIR=/tmp/renovate \
|
|
-e LOG_LEVEL="${LOG_LEVEL:-info}" \
|
|
"${{ steps.image.outputs.image }}"
|