feat(renovate): add manual run pipeline and sync configs
ci / lint-prettier (push) Successful in 8s
ci / lint-ruff (push) Successful in 5s
ci / lint-yaml (push) Successful in 7s
ci / lint-dockerfiles (push) Successful in 4s
ci / validate (push) Successful in 5s
renovate-ci / validate-renovate (push) Successful in 1m27s
ci / build (push) Successful in 3s
ci / deploy-userbot-panel (push) Has been skipped
ci / lint-prettier (push) Successful in 8s
ci / lint-ruff (push) Successful in 5s
ci / lint-yaml (push) Successful in 7s
ci / lint-dockerfiles (push) Successful in 4s
ci / validate (push) Successful in 5s
renovate-ci / validate-renovate (push) Successful in 1m27s
ci / build (push) Successful in 3s
ci / deploy-userbot-panel (push) Has been skipped
renovate-run workflow_dispatch runs pinned renovate via docker on self-hosted runner. Sync helm-values manager into config.js/configmap, bump compose and validator pins to 44.97.2.
This commit is contained in:
1 parent
043923fc64
commit
7f0bd5f609
6 files changed
+80
-6
No files matched your search
@@ -48,5 +48,5 @@ jobs:
|
||||
docker run --rm \
|
||||
-v "$PWD:/work" \
|
||||
-w /work \
|
||||
renovate/renovate:44.83.2 \
|
||||
renovate/renovate:44.97.2 \
|
||||
renovate-config-validator renovate.json
|
||||
@@ -0,0 +1,52 @@
|
||||
name: renovate-run
|
||||
|
||||
on:
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
repositories:
|
||||
description: "Repositories to scan (comma-separated)"
|
||||
required: false
|
||||
default: "forust/homelab"
|
||||
log_level:
|
||||
description: "Renovate log level"
|
||||
required: false
|
||||
default: "info"
|
||||
type: choice
|
||||
options:
|
||||
- info
|
||||
- debug
|
||||
|
||||
concurrency:
|
||||
group: renovate-run
|
||||
cancel-in-progress: false
|
||||
|
||||
jobs:
|
||||
run-renovate:
|
||||
runs-on: [self-hosted, linux, arch, homelab]
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Run Renovate
|
||||
shell: bash
|
||||
env:
|
||||
RENOVATE_TOKEN: ${{ secrets.RENOVATE_TOKEN }}
|
||||
RENOVATE_GITHUB_COM_TOKEN: ${{ secrets.RENOVATE_GITHUB_COM_TOKEN }}
|
||||
RENOVATE_REPOSITORIES: ${{ inputs.repositories }}
|
||||
LOG_LEVEL: ${{ inputs.log_level }}
|
||||
run: |
|
||||
set -euo pipefail
|
||||
|
||||
: "${RENOVATE_TOKEN:?missing RENOVATE_TOKEN secret — add a renovate-bot PAT in repo/org Actions secrets}"
|
||||
|
||||
docker run --rm \
|
||||
-v "$PWD/renovate/config.js:/opt/renovate/config.js:ro" \
|
||||
-e RENOVATE_PLATFORM=gitea \
|
||||
-e RENOVATE_ENDPOINT=https://gitea.forust.xyz/api/v1 \
|
||||
-e RENOVATE_TOKEN="$RENOVATE_TOKEN" \
|
||||
-e RENOVATE_GITHUB_COM_TOKEN="${RENOVATE_GITHUB_COM_TOKEN:-}" \
|
||||
-e RENOVATE_REPOSITORIES="${RENOVATE_REPOSITORIES:-forust/homelab}" \
|
||||
-e RENOVATE_CONFIG_FILE=/opt/renovate/config.js \
|
||||
-e RENOVATE_BASE_DIR=/tmp/renovate \
|
||||
-e LOG_LEVEL="${LOG_LEVEL:-info}" \
|
||||
renovate/renovate:44.97.2
|
||||
+14
-1
@@ -24,12 +24,25 @@ The `renovate/k8s/active` marker makes the normal deployment workflow include
|
||||
the namespace, ConfigMap, and CronJob. The Secret is intentionally excluded
|
||||
from Git and must be applied separately after every new cluster.
|
||||
|
||||
Run it immediately instead of waiting for the six-hour schedule:
|
||||
Run it immediately instead of waiting for the six-hour schedule.
|
||||
|
||||
Two options, both use the same `renovate/config.js`:
|
||||
|
||||
```sh
|
||||
kubectl create job --from=cronjob/renovate renovate-manual-$(date +%s) -n renovate
|
||||
```
|
||||
|
||||
or the `renovate-run` Actions workflow (Actions tab → `renovate-run` →
|
||||
Run workflow). It runs `renovate/renovate:44.97.2` on the self-hosted
|
||||
runner via Docker. Required Actions secrets (repo or org settings):
|
||||
|
||||
- `RENOVATE_TOKEN` — renovate-bot PAT (repository + issue read/write).
|
||||
- `RENOVATE_GITHUB_COM_TOKEN` — optional, for changelogs and GitHub rate limits.
|
||||
|
||||
Inputs: `repositories` (default `forust/homelab`), `log_level`
|
||||
(`info`/`debug`). Only one run at a time (concurrency group
|
||||
`renovate-run`), same as the CronJob `Forbid` policy.
|
||||
|
||||
Inspect runs with:
|
||||
|
||||
```sh
|
||||
|
||||
+4
-1
@@ -1,7 +1,10 @@
|
||||
module.exports = {
|
||||
platform: 'gitea',
|
||||
endpoint: process.env.RENOVATE_ENDPOINT,
|
||||
enabledManagers: ['docker-compose', 'kubernetes'],
|
||||
enabledManagers: ['docker-compose', 'kubernetes', 'helm-values'],
|
||||
'helm-values': {
|
||||
managerFilePatterns: ['/k8s/.+values\\.ya?ml$/'],
|
||||
},
|
||||
kubernetes: {
|
||||
managerFilePatterns: ['/k8s/.+\\.ya?ml$/'],
|
||||
},
|
||||
|
||||
@@ -8,7 +8,10 @@ data:
|
||||
module.exports = {
|
||||
platform: 'gitea',
|
||||
endpoint: process.env.RENOVATE_ENDPOINT,
|
||||
enabledManagers: ['docker-compose', 'kubernetes'],
|
||||
enabledManagers: ['docker-compose', 'kubernetes', 'helm-values'],
|
||||
'helm-values': {
|
||||
managerFilePatterns: ['/k8s/.+values\\.ya?ml$/'],
|
||||
},
|
||||
kubernetes: {
|
||||
managerFilePatterns: ['/k8s/.+\\.ya?ml$/'],
|
||||
},
|
||||
@@ -22,7 +25,10 @@ data:
|
||||
dependencyDashboard: true,
|
||||
prCreation: 'immediate',
|
||||
labels: ['dependencies', 'automated'],
|
||||
extends: ['config:recommended', ':dependencyDashboard'],
|
||||
extends: [
|
||||
'config:recommended',
|
||||
':dependencyDashboard',
|
||||
],
|
||||
packageRules: [
|
||||
{
|
||||
description: 'Do not update private homelab images',
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
services:
|
||||
renovate:
|
||||
image: renovate/renovate:44.83.2
|
||||
image: renovate/renovate:44.97.2
|
||||
container_name: renovate
|
||||
restart: "no"
|
||||
env_file:
|
||||
|
||||
Reference in new issue
Block a user