From 939fad4a23fc560ac28b811987a87f14e143617d Mon Sep 17 00:00:00 2001 From: mr-forust Date: Sat, 3 Oct 2026 11:57:46 +0200 Subject: [PATCH] chore(renovate,crowdsec): group minor/patch updates and whitelist VPS Renovate: group all minor updates and all patch updates into reviewable PRs. Crowdsec: whitelist static VPS IP. Remove stale cloudflared/k8s/active marker. --- cloudflared/k8s/active | 0 crowdsec/k8s/crowdsec-values.yaml | 7 +++++++ renovate/k8s/configmap.yaml | 13 ++++++++++--- renovate/renovate.json | 13 ++++++++++--- 4 files changed, 27 insertions(+), 6 deletions(-) delete mode 100644 cloudflared/k8s/active diff --git a/cloudflared/k8s/active b/cloudflared/k8s/active deleted file mode 100644 index e69de29..0000000 diff --git a/crowdsec/k8s/crowdsec-values.yaml b/crowdsec/k8s/crowdsec-values.yaml index 98d0bf3..f690dcf 100644 --- a/crowdsec/k8s/crowdsec-values.yaml +++ b/crowdsec/k8s/crowdsec-values.yaml @@ -87,6 +87,13 @@ config: - "169.254.0.0/16" - "fc00::/7" - "fe80::/10" + vps-whitelist.yaml: | + name: forust/vps-whitelist + description: "Whitelist static VPS" + whitelist: + reason: "VPS" + ip: + - "193.181.211.79" postoverflows: s01-whitelist: diff --git a/renovate/k8s/configmap.yaml b/renovate/k8s/configmap.yaml index 70b426e..574a2f9 100644 --- a/renovate/k8s/configmap.yaml +++ b/renovate/k8s/configmap.yaml @@ -165,6 +165,13 @@ data: "matchUpdateTypes": ["digest", "patch"], "automerge": true }, + { + "description": "Group all minor updates into one reviewable PR - placed before the specific groups below so playwright/node/renovate keep their own lockstep groups (later groupName wins)", + "matchUpdateTypes": ["minor"], + "groupName": "all minor updates", + "groupSlug": "all-minor", + "automerge": false + }, { "description": "Keep private homelab images unchanged", "matchDatasources": ["docker"], @@ -207,10 +214,10 @@ data: "automerge": false }, { - "description": "Group container patch updates", - "matchDatasources": ["docker"], + "description": "Group patch updates from all sources - automerge still applies via the digest/patch rule above (helm/playwright stay manual via their own rules)", "matchUpdateTypes": ["patch"], - "groupName": "container patch updates" + "groupName": "all patch updates", + "groupSlug": "all-patch" } ] } diff --git a/renovate/renovate.json b/renovate/renovate.json index cf06c02..4dc86a5 100644 --- a/renovate/renovate.json +++ b/renovate/renovate.json @@ -154,6 +154,13 @@ "matchUpdateTypes": ["digest", "patch"], "automerge": true }, + { + "description": "Group all minor updates into one reviewable PR - placed before the specific groups below so playwright/node/renovate keep their own lockstep groups (later groupName wins)", + "matchUpdateTypes": ["minor"], + "groupName": "all minor updates", + "groupSlug": "all-minor", + "automerge": false + }, { "description": "Keep private homelab images unchanged", "matchDatasources": ["docker"], @@ -196,10 +203,10 @@ "automerge": false }, { - "description": "Group container patch updates", - "matchDatasources": ["docker"], + "description": "Group patch updates from all sources - automerge still applies via the digest/patch rule above (helm/playwright stay manual via their own rules)", "matchUpdateTypes": ["patch"], - "groupName": "container patch updates" + "groupName": "all patch updates", + "groupSlug": "all-patch" } ] }