ci: adopt the shared renovate preset, and onboard new repos onto it #256

Sammanfogat
supernaut sammanfogade 2 incheckningar från ci/renovate-config-tweak in i main 2026-07-30 15:18:56 +00:00
Ägare

Adopts the shared Renovate preset and stops new repos from being onboarded off-policy.

This repo's config

Reduced to the preset plus what is genuinely repo-specific — the two customManagers for annotated
Ansible image tags and the Caddy rate-limit module ref, which exist nowhere else:

"extends": ["local>gitborg/gitborg-docs"],
"customManagers": [ /* unchanged */ ],
"packageRules": [ /* forgejo + postgres major approval */ ]

The forgejo/postgres rule was dead config

major: {enabled: false} disables majors outright, so this rule could never fire:

{
  "description": "Major bumps of the git server and the database follow the runbook...
                  hold them behind Dependency Dashboard approval instead of auto-opening PRs.",
  "matchDepNames": ["codeberg.org/forgejo/forgejo", "docker.io/library/postgres"],
  "matchUpdateTypes": ["major"],
  "dependencyDashboardApproval": true
}

Its intent is gated but visible. Disabling majors silently turned that into never proposed at all —
we would stop being told that a new Forgejo or Postgres major exists, which for one-major-at-a-time,
restore-drill-gated upgrades is the wrong trade. The preset now gates majors globally
(major.dependencyDashboardApproval) instead.

The rule stays, and is now deliberately redundant with that global gate: stated per-dependency,
loosening the global default can never silently un-gate the git server and the database.

Onboarding

onboardingConfig pointed at config:recommended, so every newly-autodiscovered repo started
off-policy and needed a manual migration — which is how seven near-identical renovate.json files came
to exist. It now points at local>gitborg/gitborg-docs.

Verification

  • renovate-config-validator against Renovate 43 — the version this role deploys
    (renovate_image: .../renovate:43) — passes.
  • ansible-playbook site.yml --syntax-check passes.

Heads up on the validator: npx resolves 37.440.7 by default, which rejects
customManagers[*].managerFilePatterns as a disallowed field. That is a false positive against config
already live on main — the option postdates v37. Pin the validator to the deployed major.

Merge order and apply

Merge the bitborg-docs preset PR first — until it lands this repo points at a preset that does not
exist, and a failed local> resolution means no Renovate config at all.

The config.js.j2 change needs an Ansible apply to reach the host; the renovate.json change takes
effect on the next Renovate run without one. local> resolution can only be exercised by a real run —
the validator has no platform access.

Adopts the shared Renovate preset and stops new repos from being onboarded off-policy. ## This repo's config Reduced to the preset plus what is genuinely repo-specific — the two `customManagers` for annotated Ansible image tags and the Caddy rate-limit module ref, which exist nowhere else: ```json "extends": ["local>gitborg/gitborg-docs"], "customManagers": [ /* unchanged */ ], "packageRules": [ /* forgejo + postgres major approval */ ] ``` ## The forgejo/postgres rule was dead config `major: {enabled: false}` disables majors outright, so this rule could never fire: ```json { "description": "Major bumps of the git server and the database follow the runbook... hold them behind Dependency Dashboard approval instead of auto-opening PRs.", "matchDepNames": ["codeberg.org/forgejo/forgejo", "docker.io/library/postgres"], "matchUpdateTypes": ["major"], "dependencyDashboardApproval": true } ``` Its intent is *gated but visible*. Disabling majors silently turned that into *never proposed at all* — we would stop being told that a new Forgejo or Postgres major exists, which for one-major-at-a-time, restore-drill-gated upgrades is the wrong trade. The preset now gates majors globally (`major.dependencyDashboardApproval`) instead. The rule stays, and is now **deliberately redundant** with that global gate: stated per-dependency, loosening the global default can never silently un-gate the git server and the database. ## Onboarding `onboardingConfig` pointed at `config:recommended`, so every newly-autodiscovered repo started off-policy and needed a manual migration — which is how seven near-identical `renovate.json` files came to exist. It now points at `local>gitborg/gitborg-docs`. ## Verification - `renovate-config-validator` against **Renovate 43** — the version this role deploys (`renovate_image: .../renovate:43`) — passes. - `ansible-playbook site.yml --syntax-check` passes. Heads up on the validator: `npx` resolves **37.440.7** by default, which rejects `customManagers[*].managerFilePatterns` as a disallowed field. That is a false positive against config already live on `main` — the option postdates v37. Pin the validator to the deployed major. ## Merge order and apply **Merge the bitborg-docs preset PR first** — until it lands this repo points at a preset that does not exist, and a failed `local>` resolution means no Renovate config at all. The `config.js.j2` change needs an Ansible apply to reach the host; the `renovate.json` change takes effect on the next Renovate run without one. `local>` resolution can only be exercised by a real run — the validator has no platform access.
supernaut lade till 2 incheckningar 2026-07-30 15:13:32 +00:00
ci: adopt the shared renovate preset, and onboard new repos onto it
Alla kontroller lyckades
ci / ci (pull_request) Successful in 1m31s
d1205027c3
Replaces the bulk of this repo's renovate config with
`extends: ["local>gitborg/gitborg-docs"]`, keeping only what is genuinely
repo-specific: the two customManagers for annotated Ansible image tags and the
Caddy rate-limit module ref.

The forgejo/postgres major-approval rule stays, and is now deliberately redundant
with the preset's global `major` gate. Stated per-dependency, loosening the global
default can never silently un-gate the git server and the database — which is
exactly what `major: {enabled: false}` did to it: with majors disabled outright
the rule became dead config, and "gated but visible on the Dependency Dashboard"
silently became "never proposed at all".

Also points the role's onboardingConfig at the shared preset. Onboarding onto
config:recommended started every new repo off-policy and needing a manual
migration, which is how seven near-identical renovate.json files came to exist.

Validated against Renovate 43, the version this role deploys.
supernaut sammanfogade incheckning 0ac68b6498 till main 2026-07-30 15:18:56 +00:00
supernaut tog bort grenen ci/renovate-config-tweak 2026-07-30 15:18:56 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!256
Ingen beskrivning angiven.