feat(renovate): track core container image tags via annotations (#61) #95
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!95
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "feat/61-renovate-core-image-tags"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Closes #61 — Forgejo/PostgreSQL/Caddy/ntfy image tags were invisible to Renovate (bare
config:recommendedhas no manager for Ansible variable pins), so the most security-sensitive images got zero automated update PRs.Changes
renovate.json: regexcustomManager(currentmanagerFilePatternssyntax — Renovate ≥40) matching a# renovate: datasource=... depName=...annotation directly above any*_image_tag:line inansible/group_vars/**andansible/roles/*/defaults/main.yml.forgejo_image_tag,postgres_image_tag,caddy_image_tag(group_vars) andntfy_image_tag(monitoring defaults).packageRules: Forgejo and Postgres major updates require Dependency Dashboard approval — majors follow the runbook (green restore drill, one major at a time, irreversible-forward migrations), so Renovate won't auto-open them.Spike items from the issue, resolved
dockerversioning treats the tag suffix as a compatibility constraint —17.10-trixieonly gets-trixieproposals,2.11.4-alpineonly-alpine. Default versioning in the manager isdocker(overridable per-annotation withversioning=).config.jssets noenabledManagers, so repo-levelcustomManagersrun. (The "No github.com token" warning only affects release-notes fetching, not detection.)registry_mirror_imageswhen bumped, same as today.Verification
renovate-config-validator(renovate:43 image): config validated successfully.f6c76cabc27ddd4c7ec3