ci: adopt the shared renovate preset, and onboard new repos onto it #256
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!256
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "ci/renovate-config-tweak"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Adopts the shared Renovate preset and stops new repos from being onboarded off-policy.
This repo's config
Reduced to the preset plus what is genuinely repo-specific — the two
customManagersfor annotatedAnsible image tags and the Caddy rate-limit module ref, which exist nowhere else:
The forgejo/postgres rule was dead config
major: {enabled: false}disables majors outright, so this rule could never fire:Its intent is gated but visible. Disabling majors silently turned that into never proposed at all —
we would stop being told that a new Forgejo or Postgres major exists, which for one-major-at-a-time,
restore-drill-gated upgrades is the wrong trade. The preset now gates majors globally
(
major.dependencyDashboardApproval) instead.The rule stays, and is now deliberately redundant with that global gate: stated per-dependency,
loosening the global default can never silently un-gate the git server and the database.
Onboarding
onboardingConfigpointed atconfig:recommended, so every newly-autodiscovered repo startedoff-policy and needed a manual migration — which is how seven near-identical
renovate.jsonfiles cameto exist. It now points at
local>gitborg/gitborg-docs.Verification
renovate-config-validatoragainst Renovate 43 — the version this role deploys(
renovate_image: .../renovate:43) — passes.ansible-playbook site.yml --syntax-checkpasses.Heads up on the validator:
npxresolves 37.440.7 by default, which rejectscustomManagers[*].managerFilePatternsas a disallowed field. That is a false positive against configalready live on
main— the option postdates v37. Pin the validator to the deployed major.Merge order and apply
Merge the bitborg-docs preset PR first — until it lands this repo points at a preset that does not
exist, and a failed
local>resolution means no Renovate config at all.The
config.js.j2change needs an Ansible apply to reach the host; therenovate.jsonchange takeseffect on the next Renovate run without one.
local>resolution can only be exercised by a real run —the validator has no platform access.
Replaces the bulk of this repo's renovate config with `extends: ["local>gitborg/gitborg-docs"]`, keeping only what is genuinely repo-specific: the two customManagers for annotated Ansible image tags and the Caddy rate-limit module ref. The forgejo/postgres major-approval rule stays, and is now deliberately redundant with the preset's global `major` gate. Stated per-dependency, loosening the global default can never silently un-gate the git server and the database — which is exactly what `major: {enabled: false}` did to it: with majors disabled outright the rule became dead config, and "gated but visible on the Dependency Dashboard" silently became "never proposed at all". Also points the role's onboardingConfig at the shared preset. Onboarding onto config:recommended started every new repo off-policy and needing a manual migration, which is how seven near-identical renovate.json files came to exist. Validated against Renovate 43, the version this role deploys.