The config lived in renovate.json at the repo root while everything else Renovate-related sat under renovate/, and renovate/config.js was a second, unused source of truth. Both are gone: renovate/renovate.json is now the only config file. Because the CronJob in the cluster cannot read the repository, its ConfigMap carries an inlined copy of the config. That copy is generated, and sync-renovate-configmap.sh --check now fails the build when it drifts from the source file. The workflows also stop carrying a copy of the renovate/renovate image tag. They read it from renovate/k8s/cronjob.yaml, so the version validated in CI is the version that actually runs in the cluster. ci.yaml validates the config with renovate-config-validator, checks the generated ConfigMap, and kubeconforms the CronJob's own manifests.
74 lines
2.4 KiB
YAML
74 lines
2.4 KiB
YAML
name: renovate-ci
|
|
|
|
on:
|
|
pull_request:
|
|
push:
|
|
branches:
|
|
- main
|
|
workflow_dispatch:
|
|
|
|
jobs:
|
|
validate-renovate:
|
|
runs-on: [self-hosted, linux, arch, homelab]
|
|
timeout-minutes: 20
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
|
|
|
|
# renovate/k8s/cronjob.yaml is the single source of truth for the image tag,
|
|
# so the same version that runs in the cluster is the one validated here.
|
|
- name: Resolve the deployed Renovate image
|
|
id: image
|
|
shell: bash
|
|
run: |
|
|
set -euo pipefail
|
|
image="$(sed -n 's|.*image:[[:space:]]*\(renovate/renovate:[^[:space:]]*\).*|\1|p' \
|
|
renovate/k8s/cronjob.yaml | head -1)"
|
|
if [ -z "$image" ]; then
|
|
echo "::error::no renovate/renovate image found in renovate/k8s/cronjob.yaml"
|
|
exit 1
|
|
fi
|
|
echo "using $image"
|
|
echo "image=$image" >> "$GITHUB_OUTPUT"
|
|
|
|
- name: Validate Renovate repository config
|
|
shell: bash
|
|
run: |
|
|
set -euo pipefail
|
|
docker run --rm \
|
|
-v "$PWD/renovate:/opt/renovate:ro" \
|
|
-e RENOVATE_CONFIG_FILE=/opt/renovate/renovate.json \
|
|
"${{ steps.image.outputs.image }}" \
|
|
renovate-config-validator /opt/renovate/renovate.json
|
|
|
|
# The CronJob cannot read the repository, so renovate/k8s/configmap.yaml
|
|
# carries an inlined copy of the config. Fail if it no longer matches.
|
|
- name: Check the generated Renovate ConfigMap
|
|
shell: bash
|
|
run: |
|
|
set -euo pipefail
|
|
./.gitea/workflows/sync-renovate-configmap.sh --check
|
|
|
|
- name: Validate Renovate Kubernetes manifests
|
|
shell: bash
|
|
run: |
|
|
set -euo pipefail
|
|
tools_dir="$(bash .gitea/workflows/install-ci-tools.sh kubeconform)"
|
|
export PATH="$tools_dir:$PATH"
|
|
kubeconform \
|
|
-strict \
|
|
-ignore-missing-schemas \
|
|
-summary \
|
|
renovate/k8s/namespace.yaml \
|
|
renovate/k8s/configmap.yaml \
|
|
renovate/k8s/cronjob.yaml
|
|
|
|
- name: Validate Renovate Compose file
|
|
shell: bash
|
|
run: |
|
|
set -euo pipefail
|
|
source .gitea/workflows/compose-lint.sh
|
|
mapfile -t safe_flags < <(compose_safe_flags)
|
|
validate_compose_file renovate/renovate-compose.yaml \
|
|
${safe_flags[@]+"${safe_flags[@]}"}
|