Renovate: track core container image tags (Forgejo/Postgres/Caddy/ntfy) #61

Stängd
öppnade 2026-07-10 12:21:33 +00:00 av supernaut · 0 kommentarer
Ägare

The container image tags for our core services are not tracked by Renovate, so
Forgejo/PostgreSQL/Caddy/ntfy security updates have to be found and bumped by hand (e.g.
build/forgejo-v15.0.4). This is a gap against ADR 0023, which states Renovate "opens update PRs."

Why

renovate.json is a bare config:recommended. That preset ships no manager for arbitrary
variable assignments, so these tags are invisible to Renovate — the Dependency Dashboard (#15)
detects only ansible-galaxy, Dockerfiles, npm and terraform deps. The affected pins:

  • ansible/group_vars/all/vars.yml — forgejo_image_tag, postgres_image_tag, caddy_image_tag
  • ansible/roles/monitoring/defaults/main.yml — ntfy_image_tag

These are the most security-sensitive images on the estate (the git server, the DB, the edge proxy,
the alert-push service), and right now they get zero automated update PRs.

Proposed fix

Add a customManagers (regex) block to renovate.json driven by
# renovate: datasource=docker depName=<image> annotation comments placed above each
*_image_tag line. The annotation approach lets us opt in per image — importantly it lets us
exclude Kanidm, whose role defaults require manual one-minor-at-a-time upgrades.

Sketch:

"customManagers": [
  {
    "customType": "regex",
    "fileMatch": [
      "ansible/group_vars/.+\\.ya?ml$",
      "ansible/roles/.+/defaults/.+\\.ya?ml$"
    ],
    "matchStrings": [
      "# renovate: datasource=(?<datasource>\\S+) depName=(?<depName>\\S+)( versioning=(?<versioning>\\S+))?\\s+\\w+_image_tag:\\s*\"(?<currentValue>[^\"]+)\""
    ],
    "datasourceTemplate": "docker"
  }
]

Spike / risks to verify before merging config

  • Suffixed tags (17.10-trixie, 2.11.4-alpine) confuse Renovate's default docker versioning.
    Verify per-image versioning/allowedVersions so Renovate stays on the correct variant
    (-trixie, -alpine) and doesn't propose bare or wrong-suffix tags.
  • Confirm the self-hosted Renovate run picks up customManagers (it needs release-note fetching;
    the dashboard already warns "No github.com token configured").
  • Confirm interplay with the registry-mirror role — mirrored tags must resolve for the datasource.
  • Caddy is slated to become a custom xcaddy build (#48); decide whether to track the official
    image at all or wait for that.

Dependency Dashboard: #15
Related: #48 (custom Caddy build)

Labels: area/ci, type/task

The container image tags for our core services are **not tracked by Renovate**, so Forgejo/PostgreSQL/Caddy/ntfy security updates have to be found and bumped by hand (e.g. `build/forgejo-v15.0.4`). This is a gap against ADR 0023, which states Renovate "opens update PRs." ## Why `renovate.json` is a bare `config:recommended`. That preset ships no manager for arbitrary variable assignments, so these tags are invisible to Renovate — the Dependency Dashboard (#15) detects only ansible-galaxy, Dockerfiles, npm and terraform deps. The affected pins: - `ansible/group_vars/all/vars.yml` — `forgejo_image_tag`, `postgres_image_tag`, `caddy_image_tag` - `ansible/roles/monitoring/defaults/main.yml` — `ntfy_image_tag` These are the most security-sensitive images on the estate (the git server, the DB, the edge proxy, the alert-push service), and right now they get zero automated update PRs. ## Proposed fix Add a `customManagers` (regex) block to `renovate.json` driven by `# renovate: datasource=docker depName=<image>` annotation comments placed above each `*_image_tag` line. The annotation approach lets us **opt in per image** — importantly it lets us *exclude* Kanidm, whose role defaults require manual one-minor-at-a-time upgrades. Sketch: ```jsonc "customManagers": [ { "customType": "regex", "fileMatch": [ "ansible/group_vars/.+\\.ya?ml$", "ansible/roles/.+/defaults/.+\\.ya?ml$" ], "matchStrings": [ "# renovate: datasource=(?<datasource>\\S+) depName=(?<depName>\\S+)( versioning=(?<versioning>\\S+))?\\s+\\w+_image_tag:\\s*\"(?<currentValue>[^\"]+)\"" ], "datasourceTemplate": "docker" } ] ``` ## Spike / risks to verify before merging config - **Suffixed tags** (`17.10-trixie`, `2.11.4-alpine`) confuse Renovate's default docker versioning. Verify per-image `versioning`/`allowedVersions` so Renovate stays on the correct variant (`-trixie`, `-alpine`) and doesn't propose bare or wrong-suffix tags. - Confirm the self-hosted Renovate run picks up `customManagers` (it needs release-note fetching; the dashboard already warns "No github.com token configured"). - Confirm interplay with the `registry-mirror` role — mirrored tags must resolve for the datasource. - Caddy is slated to become a custom `xcaddy` build (#48); decide whether to track the official image at all or wait for that. Dependency Dashboard: #15 Related: #48 (custom Caddy build) Labels: area/ci, type/task
supernaut refererade till detta ärende från en incheckning 2026-07-29 19:55:58 +00:00
supernaut refererade till detta ärende från en incheckning 2026-07-29 21:23:51 +00:00
supernaut refererade till detta ärende från en incheckning 2026-08-03 09:41:34 +00:00
supernaut refererade till detta ärende från en incheckning 2026-08-03 09:41:34 +00:00
Logga in för att delta i denna konversation.
Ingen milstolpe
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra#61
Ingen beskrivning angiven.