The config lived in renovate.json at the repo root while everything else Renovate-related sat under renovate/, and renovate/config.js was a second, unused source of truth. Both are gone: renovate/renovate.json is now the only config file. Because the CronJob in the cluster cannot read the repository, its ConfigMap carries an inlined copy of the config. That copy is generated, and sync-renovate-configmap.sh --check now fails the build when it drifts from the source file. The workflows also stop carrying a copy of the renovate/renovate image tag. They read it from renovate/k8s/cronjob.yaml, so the version validated in CI is the version that actually runs in the cluster. ci.yaml validates the config with renovate-config-validator, checks the generated ConfigMap, and kubeconforms the CronJob's own manifests.
129 lines
5.1 KiB
JSON
129 lines
5.1 KiB
JSON
{
|
|
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
|
|
"extends": ["config:recommended", ":dependencyDashboard"],
|
|
"enabledManagers": ["dockerfile", "docker-compose", "kubernetes", "helm-values", "custom.regex"],
|
|
"onboarding": false,
|
|
"requireConfig": "optional",
|
|
"autodiscover": false,
|
|
"dependencyDashboard": true,
|
|
"prCreation": "immediate",
|
|
"labels": ["dependencies", "automated"],
|
|
"helm-values": {
|
|
"managerFilePatterns": ["/k8s/.+values\\.ya?ml$/"]
|
|
},
|
|
"kubernetes": {
|
|
"managerFilePatterns": ["/k8s/.+\\.ya?ml$/"]
|
|
},
|
|
"customManagers": [
|
|
{
|
|
"customType": "regex",
|
|
"description": "singlesource: playwright npm version pinned in npx command (k8s + compose)",
|
|
"managerFilePatterns": ["^edu_master/k8s/playwright\\.yaml$", "^edu_master/compose\\.yaml$"],
|
|
"matchStrings": ["playwright@(?<currentValue>\\d+\\.\\d+\\.\\d+)"],
|
|
"datasourceTemplate": "npm",
|
|
"depNameTemplate": "playwright"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "singlesource: PLAYWRIGHT_VERSION file",
|
|
"managerFilePatterns": ["^edu_master/PLAYWRIGHT_VERSION$"],
|
|
"matchStrings": ["^(?<currentValue>\\d+\\.\\d+\\.\\d+)$"],
|
|
"datasourceTemplate": "pypi",
|
|
"depNameTemplate": "playwright"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "kube-prometheus-stack chart version pinned in the deploy workflow",
|
|
"managerFilePatterns": ["^\\.gitea/workflows/deploy-lib\\.sh$"],
|
|
"matchStrings": ["\\|prometheus-community/kube-prometheus-stack\\|prometheus\\|(?<currentValue>[0-9.]+)\\|"],
|
|
"datasourceTemplate": "helm",
|
|
"depNameTemplate": "kube-prometheus-stack",
|
|
"registryUrlTemplate": "https://prometheus-community.github.io/helm-charts"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "grafana/loki chart version pinned in the deploy workflow",
|
|
"managerFilePatterns": ["^\\.gitea/workflows/deploy-lib\\.sh$"],
|
|
"matchStrings": ["\\|grafana/loki\\|prometheus\\|(?<currentValue>[0-9.]+)\\|"],
|
|
"datasourceTemplate": "helm",
|
|
"depNameTemplate": "loki",
|
|
"registryUrlTemplate": "https://grafana.github.io/helm-charts"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "grafana/alloy chart version pinned in the deploy workflow",
|
|
"managerFilePatterns": ["^\\.gitea/workflows/deploy-lib\\.sh$"],
|
|
"matchStrings": ["\\|grafana/alloy\\|prometheus\\|(?<currentValue>[0-9.]+)\\|"],
|
|
"datasourceTemplate": "helm",
|
|
"depNameTemplate": "alloy",
|
|
"registryUrlTemplate": "https://grafana.github.io/helm-charts"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "actionlint version used by the ci workflow",
|
|
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
|
"matchStrings": ["(?:^|\\n)ACTIONLINT_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
|
"datasourceTemplate": "github-tags",
|
|
"depNameTemplate": "rhysd/actionlint"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "shellcheck version used by the ci workflow",
|
|
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
|
"matchStrings": ["(?:^|\\n)SHELLCHECK_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
|
"datasourceTemplate": "github-tags",
|
|
"depNameTemplate": "koalaman/shellcheck"
|
|
},
|
|
{
|
|
"customType": "regex",
|
|
"description": "kubeconform version used by the ci workflow",
|
|
"managerFilePatterns": ["^\\.gitea/workflows/tool-versions\\.env$"],
|
|
"matchStrings": ["(?:^|\\n)KUBECONFORM_VERSION=\"(?<currentValue>[0-9.]+)\""],
|
|
"datasourceTemplate": "github-tags",
|
|
"depNameTemplate": "yannh/kubeconform"
|
|
}
|
|
],
|
|
"packageRules": [
|
|
{
|
|
"description": "Keep private homelab images unchanged",
|
|
"matchDatasources": ["docker"],
|
|
"matchPackageNames": ["/gcr\\.forust\\.xyz\\/forust\\/.+/"],
|
|
"enabled": false
|
|
},
|
|
{
|
|
"description": "singlesource playwright - use whichever version is found, keep docker+pypi+npm in sync",
|
|
"matchPackageNames": ["playwright", "mcr.microsoft.com/playwright"],
|
|
"groupName": "playwright singlesource",
|
|
"groupSlug": "playwright"
|
|
},
|
|
{
|
|
"description": "playwright must not automerge - version skew breaks the WS handshake (checker.py:1523 vs playwright.yaml:20)",
|
|
"matchPackageNames": ["playwright", "mcr.microsoft.com/playwright"],
|
|
"automerge": false
|
|
},
|
|
{
|
|
"description": "Renovate updates itself in lockstep across the CronJob and the Compose file",
|
|
"matchPackageNames": ["renovate/renovate"],
|
|
"groupName": "renovate self-update",
|
|
"automerge": false
|
|
},
|
|
{
|
|
"description": "Helm chart bumps change PVC fields and admission behaviour, keep them reviewable",
|
|
"matchDatasources": ["helm"],
|
|
"automerge": false
|
|
},
|
|
{
|
|
"description": "Require approval for major upgrades",
|
|
"matchUpdateTypes": ["major"],
|
|
"dependencyDashboardApproval": true,
|
|
"automerge": false
|
|
},
|
|
{
|
|
"description": "Group container patch updates",
|
|
"matchDatasources": ["docker"],
|
|
"matchUpdateTypes": ["patch"],
|
|
"groupName": "container patch updates"
|
|
}
|
|
]
|
|
}
|