Files
homelab/renovate
renovate-bot 75dff1fe9a
deploy / validate (push) Skipped
renovate-ci / validate-renovate (push) Skipped
ci / lint-yaml (push) Successful in 2s
ci / lint-dockerfiles (push) Successful in 1s
ci / validate (push) Successful in 1s
ci / build (push) Skipped
ci / lint-prettier (pull_request) Successful in 2s
ci / lint-ruff (pull_request) Successful in 1s
ci / lint-prettier (push) Successful in 3s
ci / lint-ruff (push) Successful in 1s
ci / lint-yaml (pull_request) Successful in 2s
ci / lint-dockerfiles (pull_request) Successful in 0s
ci / validate (pull_request) Successful in 1s
ci / build (pull_request) Skipped
renovate-ci / validate-renovate (pull_request) Successful in 27s
chore(deps): update renovate/renovate docker tag to v44.112.2
2026-09-24 10:18:52 +00:00
..

Renovate for Gitea

Renovate runs as a Kubernetes CronJob and creates container image update pull requests in Gitea. It does not deploy changes itself.

Kubernetes

Create a dedicated Gitea user named renovate-bot, create a repository access token, and grant it repository read/write plus issue read/write permissions. Add read:packages if Renovate must inspect private Gitea registry images.

Create the ignored Secret locally; never commit the PAT:

cp renovate/k8s/secrets.yaml.example renovate/k8s/secrets.yaml
$EDITOR renovate/k8s/secrets.yaml
kubectl apply -f renovate/k8s/namespace.yaml
kubectl apply -f renovate/k8s/secrets.yaml
kubectl apply -f renovate/k8s/configmap.yaml
kubectl apply -f renovate/k8s/cronjob.yaml

The renovate/k8s/active marker makes the normal deployment workflow include the namespace, ConfigMap, and CronJob. The Secret is intentionally excluded from Git and must be applied separately after every new cluster.

Run it immediately instead of waiting for the six-hour schedule.

Two options, both use the same renovate/config.js:

kubectl create job --from=cronjob/renovate renovate-manual-$(date +%s) -n renovate

or the renovate-run Actions workflow (Actions tab → renovate-run → Run workflow). It runs renovate/renovate:44.103.0 on the self-hosted runner via Docker. Required Actions secrets (repo or org settings):

  • RENOVATE_TOKEN — renovate-bot PAT (repository + issue read/write).
  • RENOVATE_GITHUB_COM_TOKEN — optional, for changelogs and GitHub rate limits.

Inputs: repositories (default forust/homelab), log_level (info/debug). Only one run at a time (concurrency group renovate-run), same as the CronJob Forbid policy.

Inspect runs with:

kubectl get cronjob,jobs,pods -n renovate
kubectl logs -n renovate job/<job-name>

RENOVATE_GITHUB_COM_TOKEN is optional but recommended for changelogs and GitHub API rate limits. Set it in the Kubernetes Secret if available.

Compose

Copy .env.example to .env, set the PAT, and run:

docker compose -f renovate-compose.yaml run --rm renovate

The Compose file is intentionally named renovate-compose.yaml, so the repository's automatic deployment discovery does not start it accidentally.

How updates flow

Renovate scans both compose.yaml files and Kubernetes manifests, opens a branch and PR with image tag changes, and waits for CI. After merge, the existing deployment workflow applies Kubernetes changes or redeploys Compose stacks. Renovate never updates running workloads directly.