Renovate: track core container image tags (Forgejo/Postgres/Caddy/ntfy) #61
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra#61
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "%!s()"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
The container image tags for our core services are not tracked by Renovate, so
Forgejo/PostgreSQL/Caddy/ntfy security updates have to be found and bumped by hand (e.g.
build/forgejo-v15.0.4). This is a gap against ADR 0023, which states Renovate "opens update PRs."Why
renovate.jsonis a bareconfig:recommended. That preset ships no manager for arbitraryvariable assignments, so these tags are invisible to Renovate — the Dependency Dashboard (#15)
detects only ansible-galaxy, Dockerfiles, npm and terraform deps. The affected pins:
ansible/group_vars/all/vars.yml—forgejo_image_tag,postgres_image_tag,caddy_image_tagansible/roles/monitoring/defaults/main.yml—ntfy_image_tagThese are the most security-sensitive images on the estate (the git server, the DB, the edge proxy,
the alert-push service), and right now they get zero automated update PRs.
Proposed fix
Add a
customManagers(regex) block torenovate.jsondriven by# renovate: datasource=docker depName=<image>annotation comments placed above each*_image_tagline. The annotation approach lets us opt in per image — importantly it lets usexclude Kanidm, whose role defaults require manual one-minor-at-a-time upgrades.
Sketch:
Spike / risks to verify before merging config
17.10-trixie,2.11.4-alpine) confuse Renovate's default docker versioning.Verify per-image
versioning/allowedVersionsso Renovate stays on the correct variant(
-trixie,-alpine) and doesn't propose bare or wrong-suffix tags.customManagers(it needs release-note fetching;the dashboard already warns "No github.com token configured").
registry-mirrorrole — mirrored tags must resolve for the datasource.xcaddybuild (#48); decide whether to track the officialimage at all or wait for that.
Dependency Dashboard: #15
Related: #48 (custom Caddy build)
Labels: area/ci, type/task