The config lived in renovate.json at the repo root while everything else Renovate-related sat under renovate/, and renovate/config.js was a second, unused source of truth. Both are gone: renovate/renovate.json is now the only config file. Because the CronJob in the cluster cannot read the repository, its ConfigMap carries an inlined copy of the config. That copy is generated, and sync-renovate-configmap.sh --check now fails the build when it drifts from the source file. The workflows also stop carrying a copy of the renovate/renovate image tag. They read it from renovate/k8s/cronjob.yaml, so the version validated in CI is the version that actually runs in the cluster. ci.yaml validates the config with renovate-config-validator, checks the generated ConfigMap, and kubeconforms the CronJob's own manifests.
56 lines
1.7 KiB
Bash
Executable File
56 lines
1.7 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# Regenerates renovate/k8s/configmap.yaml from renovate/renovate.json.
|
|
#
|
|
# renovate/renovate.json is the single source of truth: the CronJob, the Compose
|
|
# file and the renovate-run workflow all mount that exact file. A ConfigMap cannot
|
|
# read a file from the repository, so the same bytes are inlined here as a literal
|
|
# block. This script keeps the copy honest:
|
|
#
|
|
# .gitea/workflows/sync-renovate-configmap.sh # rewrite in place
|
|
# .gitea/workflows/sync-renovate-configmap.sh --check # fail if out of date
|
|
#
|
|
# renovate-ci runs the --check form on every PR and push, so a config change that
|
|
# forgets to regenerate the ConfigMap cannot be merged.
|
|
set -euo pipefail
|
|
|
|
here="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
|
repo="$(git -C "$here" rev-parse --show-toplevel)"
|
|
|
|
src="$repo/renovate/renovate.json"
|
|
dst="$repo/renovate/k8s/configmap.yaml"
|
|
[ -f "$src" ] || {
|
|
echo "missing $src" >&2
|
|
exit 1
|
|
}
|
|
|
|
render() {
|
|
cat <<'HEADER'
|
|
# GENERATED FILE - do not edit by hand.
|
|
# Source: renovate/renovate.json
|
|
# Regenerate: .gitea/workflows/sync-renovate-configmap.sh
|
|
# Verify: .gitea/workflows/sync-renovate-configmap.sh --check
|
|
apiVersion: v1
|
|
kind: ConfigMap
|
|
metadata:
|
|
name: renovate-config
|
|
namespace: renovate
|
|
data:
|
|
renovate.json: |
|
|
HEADER
|
|
sed 's/^/ /' "$src"
|
|
}
|
|
|
|
if [ "${1:-}" = "--check" ]; then
|
|
if ! diff -u "$dst" <(render) >/dev/null 2>&1; then
|
|
echo "ERROR: $dst is out of sync with renovate/renovate.json"
|
|
echo "Run: .gitea/workflows/sync-renovate-configmap.sh"
|
|
diff -u "$dst" <(render) || true
|
|
exit 1
|
|
fi
|
|
echo "renovate/k8s/configmap.yaml is in sync with renovate/renovate.json"
|
|
exit 0
|
|
fi
|
|
|
|
render >"$dst"
|
|
echo "wrote $dst"
|