fix(renovate): point the depName annotations at the current registry host #396

Sammanfogat
supernaut sammanfogade 1 incheckning från fix/renovate-depname-registry-host in i main 2026-08-06 07:51:33 +00:00
Ägare

Closes #395. Comments only — no apply needed, verified inert (--check → changed=0 on both hosts).

The fix

-# renovate: datasource=docker depName=git.gitborg.se/bitborg/gitborg-auth-reconciler
+# renovate: datasource=docker depName=git.bitborg.se/bitborg/gitborg-auth-reconciler

-# renovate: datasource=docker depName=git.gitborg.se/bitborg/gitborg-reconcile-trigger
+# renovate: datasource=docker depName=git.bitborg.se/bitborg/gitborg-reconcile-trigger

Only the host segment moved. bitborg/gitborg-* is still a LEGACY-PIN and stays until §3.

What was broken

bitborg_registry_host moved to git.bitborg.se on 2026-08-05. Both image values template that
variable and followed it. The annotations two lines above are plain comments, so they did not — and
the same change had just turned git.gitborg.se into a redirect-only vhost. Registry lookups do
not survive a cross-host redirect (the very mechanism that forced the host to move), so Renovate
returned no-result for both.

Both are deliberately pinned-tag images — no :latest, no AutoUpdate=registry, because the
reconciler mutates real entitlements — and the comment beside bitborg_reconciler_image states the
update path outright: "Renovate opens the pinned-bump PR." So the tracking was the update
mechanism, and it had been off since 08-05 with no signal beyond a collapsed > ⚠️ Warning block
inside the Dependency Dashboard, an issue that is off-board by design.

The structural half

A depName cannot derive from bitborg_registry_host: Renovate reads these as raw comments and
Ansible never templates them, so the duplication is not removable — only documentable. Added a
consumers note beside the variable recording that these two do not move with it, what it cost
when they didn't, and the check for next time:

rg 'depName=' ansible/

That is the point worth keeping. Grepping for the variable name finds every templated consumer and
misses exactly the ones that break silently.

Verification

  • rg 'depName=git\.gitborg\.se' ansible/ → no matches; the other five annotations target
    codeberg.org / docker.io / github-releases and are unaffected.
  • --syntax-check clean.
  • site.yml --check → changed=0 failed=0 on both hosts, confirming this renders nothing.

Renovate picks the annotations up on its next scheduled run. Acceptance is on the dashboard, not
here:
the two lookup failures should disappear and both packages should show a resolved current
tag — the warning going away is not by itself proof it is tracking again.

Closes #395. **Comments only — no apply needed**, verified inert (`--check` → `changed=0` on both hosts). ## The fix ```diff -# renovate: datasource=docker depName=git.gitborg.se/bitborg/gitborg-auth-reconciler +# renovate: datasource=docker depName=git.bitborg.se/bitborg/gitborg-auth-reconciler -# renovate: datasource=docker depName=git.gitborg.se/bitborg/gitborg-reconcile-trigger +# renovate: datasource=docker depName=git.bitborg.se/bitborg/gitborg-reconcile-trigger ``` Only the **host** segment moved. `bitborg/gitborg-*` is still a `LEGACY-PIN` and stays until §3. ## What was broken `bitborg_registry_host` moved to `git.bitborg.se` on 2026-08-05. Both image *values* template that variable and followed it. The annotations two lines above are plain comments, so they did not — and the same change had just turned `git.gitborg.se` into a **redirect-only vhost**. Registry lookups do not survive a cross-host redirect (the very mechanism that forced the host to move), so Renovate returned `no-result` for both. Both are deliberately pinned-tag images — no `:latest`, no `AutoUpdate=registry`, because the reconciler mutates real entitlements — and the comment beside `bitborg_reconciler_image` states the update path outright: *"Renovate opens the pinned-bump PR."* So the tracking **was** the update mechanism, and it had been off since 08-05 with no signal beyond a collapsed `> ⚠️ Warning` block inside the Dependency Dashboard, an issue that is off-board by design. ## The structural half A `depName` cannot derive from `bitborg_registry_host`: Renovate reads these as raw comments and Ansible never templates them, so the duplication is not removable — only documentable. Added a consumers note beside the variable recording that these two do **not** move with it, what it cost when they didn't, and the check for next time: ```bash rg 'depName=' ansible/ ``` That is the point worth keeping. Grepping for the variable name finds every templated consumer and misses exactly the ones that break silently. ## Verification - `rg 'depName=git\.gitborg\.se' ansible/` → no matches; the other five annotations target codeberg.org / docker.io / github-releases and are unaffected. - `--syntax-check` clean. - `site.yml --check` → `changed=0 failed=0` on **both** hosts, confirming this renders nothing. Renovate picks the annotations up on its next scheduled run. **Acceptance is on the dashboard, not here:** the two lookup failures should disappear *and* both packages should show a resolved current tag — the warning going away is not by itself proof it is tracking again.
supernaut lade till 1 incheckning 2026-08-06 07:44:46 +00:00
fix(renovate): point the depName annotations at the current registry host
Alla kontroller lyckades
ci / ci (pull_request) Successful in 1m35s
6aac7d36a1
Renovate had silently stopped tracking the reconciler and the
reconcile-trigger shim. bitborg_registry_host moved to git.bitborg.se on
2026-08-05 and both image VALUES followed it, but the `# renovate:
depName=` annotations two lines above kept naming git.gitborg.se — which
that same change had turned into a redirect-only vhost. Registry lookups
do not survive a cross-host redirect, so Renovate answered `no-result`
for both.

That mattered more than a stale comment usually would: both are
deliberately pinned-tag images (no :latest, no AutoUpdate) because the
reconciler mutates real entitlements, and their entire update mechanism
is the pinned-bump PR Renovate opens. Nothing failed and nothing alerted
— the only trace was a collapsed warning block inside the Dependency
Dashboard, which is off-board by design.

Also records the annotations as consumers beside bitborg_registry_host.
They cannot derive from it: a Renovate annotation is a plain comment, so
Ansible never templates it and nothing fails when it drifts. Hand-tracking
is structural here, so the next host move needs `rg 'depName=' ansible/`
rather than a grep for the variable.

Only the HOST segment moved. The org+repo segment is still a LEGACY-PIN
and stays until §3.

Comments only — verified inert, both hosts changed=0.

Closes #395.
supernaut tvångsskickade fix/renovate-depname-registry-host från 6aac7d36a1
Alla kontroller lyckades
ci / ci (pull_request) Successful in 1m35s
till 279280109a
Alla kontroller lyckades
ci / ci (pull_request) Successful in 1m32s
2026-08-06 07:49:05 +00:00
Jämför
supernaut sammanfogade incheckning 04435b8a96 till main 2026-08-06 07:51:33 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!396
Ingen beskrivning angiven.