renovate: reconciler and shim untracked — depName annotations still name the redirect-only registry host #395

Stängd
öppnade 2026-08-06 07:27:44 +00:00 av supernaut · 0 kommentarer
Ägare

Renovate has stopped tracking the reconciler and the reconcile-trigger shim. It is failing silently —
the only visible symptom is a warning block inside the Dependency Dashboard (#15):

Failed to look up docker package git.gitborg.se/bitborg/gitborg-auth-reconciler: no-result
Failed to look up docker package git.gitborg.se/bitborg/gitborg-reconcile-trigger: no-result
Files affected: ansible/group_vars/all/vars.yml

Cause: a derived value moved, its duplicated literal did not

bitborg_registry_host moved to git.bitborg.se on 2026-08-05, and both image values follow it
correctly. The Renovate annotation comments directly above them still hardcode the old host:

bitborg_reconciler_image: "{{ bitborg_registry_host }}/bitborg/gitborg-auth-reconciler"
# renovate: datasource=docker depName=git.gitborg.se/bitborg/gitborg-auth-reconciler   <-- stale
bitborg_reconciler_image_tag: "v1.3.0"

bitborg_reconcile_shim_image: "{{ bitborg_registry_host }}/bitborg/gitborg-reconcile-trigger"
# renovate: datasource=docker depName=git.gitborg.se/bitborg/gitborg-reconcile-trigger  <-- stale
bitborg_reconcile_shim_image_tag: "v0.1.0"

git.gitborg.se is now a redirect-only vhost, and registry lookups do not survive a cross-host
redirect (the same mechanism that broke the deploy and forced bitborg_registry_host to move in the
first place — see the note beside that variable). So the lookup returns no-result.

Why it matters more than a stale comment usually would

These two are pinned-tag images, deliberately without :latest or AutoUpdate=registry, because
the reconciler mutates real entitlements. The comment beside bitborg_reconciler_image states the
intended update path outright: "Renovate opens the pinned-bump PR."

That is the entire update mechanism for both, and it is currently not running. Neither image will be
offered an update, and nothing alerts on it — the failure is a collapsed > ⚠️ Warning block in a bot
issue that is deliberately off-board.

Not a §3 change

The org+repo segment (bitborg/gitborg-auth-reconciler) is a genuine LEGACY-PIN and must stay
until §3 migrates the image paths. Only the host segment is wrong here, and only in the
annotation — the values already moved. This is a two-line correction that brings the comments back in
line with what they annotate, not a rename tranche.

Fix

Point both depNames at git.bitborg.se, keeping the org+repo segment pinned. Comments only — no
Ansible apply, since nothing renders them; Renovate reads them from the repo on its next run.

Consider whether depName can derive from bitborg_registry_host instead of repeating it. Renovate
annotations are plain comments and are not templated by Ansible, so probably not — in which case the
duplication is structural and worth an explicit note beside bitborg_registry_host listing the
annotations as consumers, so the next host move takes them along.

Acceptance

  • The Dependency Dashboard no longer reports lookup failures for either package.
  • Renovate resolves a current tag for both — confirmed on the dashboard's detected-dependency list,
    not merely by the warning disappearing.
Renovate has stopped tracking the reconciler and the reconcile-trigger shim. It is failing silently — the only visible symptom is a warning block inside the Dependency Dashboard (#15): ```text Failed to look up docker package git.gitborg.se/bitborg/gitborg-auth-reconciler: no-result Failed to look up docker package git.gitborg.se/bitborg/gitborg-reconcile-trigger: no-result Files affected: ansible/group_vars/all/vars.yml ``` ## Cause: a derived value moved, its duplicated literal did not `bitborg_registry_host` moved to `git.bitborg.se` on 2026-08-05, and both image values follow it correctly. The **Renovate annotation comments** directly above them still hardcode the old host: ```yaml bitborg_reconciler_image: "{{ bitborg_registry_host }}/bitborg/gitborg-auth-reconciler" # renovate: datasource=docker depName=git.gitborg.se/bitborg/gitborg-auth-reconciler <-- stale bitborg_reconciler_image_tag: "v1.3.0" bitborg_reconcile_shim_image: "{{ bitborg_registry_host }}/bitborg/gitborg-reconcile-trigger" # renovate: datasource=docker depName=git.gitborg.se/bitborg/gitborg-reconcile-trigger <-- stale bitborg_reconcile_shim_image_tag: "v0.1.0" ``` `git.gitborg.se` is now a **redirect-only vhost**, and registry lookups do not survive a cross-host redirect (the same mechanism that broke the deploy and forced `bitborg_registry_host` to move in the first place — see the note beside that variable). So the lookup returns `no-result`. ## Why it matters more than a stale comment usually would These two are **pinned-tag** images, deliberately without `:latest` or `AutoUpdate=registry`, because the reconciler mutates real entitlements. The comment beside `bitborg_reconciler_image` states the intended update path outright: *"Renovate opens the pinned-bump PR."* That is the entire update mechanism for both, and it is currently not running. Neither image will be offered an update, and nothing alerts on it — the failure is a collapsed `> ⚠️ Warning` block in a bot issue that is deliberately off-board. ## Not a §3 change The **org+repo segment** (`bitborg/gitborg-auth-reconciler`) is a genuine `LEGACY-PIN` and must stay until §3 migrates the image paths. Only the **host** segment is wrong here, and only in the annotation — the values already moved. This is a two-line correction that brings the comments back in line with what they annotate, not a rename tranche. ## Fix Point both `depName`s at `git.bitborg.se`, keeping the org+repo segment pinned. Comments only — no Ansible apply, since nothing renders them; Renovate reads them from the repo on its next run. Consider whether `depName` can derive from `bitborg_registry_host` instead of repeating it. Renovate annotations are plain comments and are not templated by Ansible, so probably not — in which case the duplication is structural and worth an explicit note beside `bitborg_registry_host` listing the annotations as consumers, so the next host move takes them along. ## Acceptance - The Dependency Dashboard no longer reports lookup failures for either package. - Renovate resolves a current tag for both — confirmed on the dashboard's detected-dependency list, not merely by the warning disappearing.
Logga in för att delta i denna konversation.
Ingen milstolpe
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra#395
Ingen beskrivning angiven.