The config lived in renovate.json at the repo root while everything else Renovate-related sat under renovate/, and renovate/config.js was a second, unused source of truth. Both are gone: renovate/renovate.json is now the only config file. Because the CronJob in the cluster cannot read the repository, its ConfigMap carries an inlined copy of the config. That copy is generated, and sync-renovate-configmap.sh --check now fails the build when it drifts from the source file. The workflows also stop carrying a copy of the renovate/renovate image tag. They read it from renovate/k8s/cronjob.yaml, so the version validated in CI is the version that actually runs in the cluster. ci.yaml validates the config with renovate-config-validator, checks the generated ConfigMap, and kubeconforms the CronJob's own manifests.
59 lines
1.8 KiB
YAML
59 lines
1.8 KiB
YAML
apiVersion: batch/v1
|
|
kind: CronJob
|
|
metadata:
|
|
name: renovate
|
|
namespace: renovate
|
|
spec:
|
|
schedule: "17 */6 * * *"
|
|
concurrencyPolicy: Forbid
|
|
successfulJobsHistoryLimit: 2
|
|
failedJobsHistoryLimit: 3
|
|
jobTemplate:
|
|
spec:
|
|
backoffLimit: 1
|
|
template:
|
|
spec:
|
|
restartPolicy: Never
|
|
containers:
|
|
- name: renovate
|
|
image: renovate/renovate:44.115.9
|
|
env:
|
|
- name: RENOVATE_PLATFORM
|
|
value: gitea
|
|
- name: RENOVATE_ENDPOINT
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: renovate-secrets
|
|
key: RENOVATE_ENDPOINT
|
|
- name: RENOVATE_TOKEN
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: renovate-secrets
|
|
key: RENOVATE_TOKEN
|
|
- name: RENOVATE_REPOSITORIES
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: renovate-secrets
|
|
key: RENOVATE_REPOSITORIES
|
|
- name: RENOVATE_CONFIG_FILE
|
|
value: /opt/renovate/renovate.json
|
|
- name: RENOVATE_BASE_DIR
|
|
value: /tmp/renovate
|
|
- name: RENOVATE_GITHUB_COM_TOKEN
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: renovate-secrets
|
|
key: RENOVATE_GITHUB_COM_TOKEN
|
|
optional: true
|
|
- name: LOG_LEVEL
|
|
value: info
|
|
volumeMounts:
|
|
- name: config
|
|
mountPath: /opt/renovate/renovate.json
|
|
subPath: renovate.json
|
|
readOnly: true
|
|
volumes:
|
|
- name: config
|
|
configMap:
|
|
name: renovate-config
|