Drop duplicated .github/workflows (helm blocks ported to .gitea deploy first). Add ci concurrency with cancel on branches, pin checkout to SHA and prettier to 3.9.8, registry layer cache for image builds. renovate-run gains config validation and dry-run input.
53 lines
1.4 KiB
YAML
53 lines
1.4 KiB
YAML
name: renovate-ci
|
|
|
|
on:
|
|
pull_request:
|
|
push:
|
|
branches:
|
|
- main
|
|
workflow_dispatch:
|
|
|
|
jobs:
|
|
validate-renovate:
|
|
runs-on: [self-hosted, linux, arch, homelab]
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
|
|
|
|
- name: Validate Renovate Compose draft
|
|
shell: bash
|
|
run: |
|
|
set -euo pipefail
|
|
trap 'rm -f renovate/.env' EXIT
|
|
printf '%s\n' \
|
|
'RENOVATE_ENDPOINT=https://gitea.example/api/v1' \
|
|
'RENOVATE_TOKEN=test-token' \
|
|
'RENOVATE_REPOSITORIES=forust/homelab' \
|
|
> renovate/.env
|
|
docker compose -f renovate/renovate-compose.yaml config --quiet
|
|
|
|
- name: Validate Kubernetes manifests
|
|
shell: bash
|
|
run: |
|
|
set -euo pipefail
|
|
docker run --rm \
|
|
-v "$PWD:/work" \
|
|
-w /work \
|
|
ghcr.io/yannh/kubeconform:latest \
|
|
-strict \
|
|
-ignore-missing-schemas \
|
|
-summary \
|
|
renovate/k8s/namespace.yaml \
|
|
renovate/k8s/configmap.yaml \
|
|
renovate/k8s/cronjob.yaml
|
|
|
|
- name: Validate Renovate repository config
|
|
shell: bash
|
|
run: |
|
|
set -euo pipefail
|
|
docker run --rm \
|
|
-v "$PWD:/work" \
|
|
-w /work \
|
|
renovate/renovate:44.97.2 \
|
|
renovate-config-validator renovate.json
|