feat(renovate): track core container image tags via annotations (#61) #95

Sammanfogat
supernaut sammanfogade 1 incheckning från feat/61-renovate-core-image-tags in i main 2026-07-18 15:23:22 +00:00
Ägare

Closes #61 — Forgejo/PostgreSQL/Caddy/ntfy image tags were invisible to Renovate (bare config:recommended has no manager for Ansible variable pins), so the most security-sensitive images got zero automated update PRs.

Changes

  • renovate.json: regex customManager (current managerFilePatterns syntax — Renovate ≥40) matching a # renovate: datasource=... depName=... annotation directly above any *_image_tag: line in ansible/group_vars/** and ansible/roles/*/defaults/main.yml.
  • Annotations added for forgejo_image_tag, postgres_image_tag, caddy_image_tag (group_vars) and ntfy_image_tag (monitoring defaults).
  • Kanidm deliberately not annotated — its one-minor-at-a-time upgrade policy makes automated PRs a footgun (the issue's explicit opt-out case).
  • packageRules: Forgejo and Postgres major updates require Dependency Dashboard approval — majors follow the runbook (green restore drill, one major at a time, irreversible-forward migrations), so Renovate won't auto-open them.

Spike items from the issue, resolved

  • Suffixed tags: Renovate's docker versioning treats the tag suffix as a compatibility constraint — 17.10-trixie only gets -trixie proposals, 2.11.4-alpine only -alpine. Default versioning in the manager is docker (overridable per-annotation with versioning=).
  • Self-hosted pickup: the bot's config.js sets no enabledManagers, so repo-level customManagers run. (The "No github.com token" warning only affects release-notes fetching, not detection.)
  • registry-mirror interplay: Renovate queries the upstream datasource (docker.io/codeberg.org) for new tags; the mirror only matters at host pull time — no conflict. New tags must be added to registry_mirror_images when bumped, same as today.
  • Caddy vs #48 (xcaddy build): kept tracking the official image — until the custom build lands this is where security bumps come from; when #48 lands, move/adjust the annotation to the build source.

Verification

  • Regex extraction tested against the annotated files: all four tags parse with the right datasource/depName/value.
  • renovate-config-validator (renovate:43 image): config validated successfully.
  • Interaction with #63's fix: a merged Renovate tag PR now also actually deploys on the next apply (pull + restart + running-image assert).
Closes #61 — Forgejo/PostgreSQL/Caddy/ntfy image tags were invisible to Renovate (bare `config:recommended` has no manager for Ansible variable pins), so the most security-sensitive images got zero automated update PRs. ## Changes - `renovate.json`: regex `customManager` (current `managerFilePatterns` syntax — Renovate ≥40) matching a `# renovate: datasource=... depName=...` annotation directly above any `*_image_tag:` line in `ansible/group_vars/**` and `ansible/roles/*/defaults/main.yml`. - Annotations added for `forgejo_image_tag`, `postgres_image_tag`, `caddy_image_tag` (group_vars) and `ntfy_image_tag` (monitoring defaults). - **Kanidm deliberately not annotated** — its one-minor-at-a-time upgrade policy makes automated PRs a footgun (the issue's explicit opt-out case). - `packageRules`: Forgejo and Postgres **major** updates require Dependency Dashboard approval — majors follow the runbook (green restore drill, one major at a time, irreversible-forward migrations), so Renovate won't auto-open them. ## Spike items from the issue, resolved - **Suffixed tags**: Renovate's `docker` versioning treats the tag suffix as a compatibility constraint — `17.10-trixie` only gets `-trixie` proposals, `2.11.4-alpine` only `-alpine`. Default versioning in the manager is `docker` (overridable per-annotation with `versioning=`). - **Self-hosted pickup**: the bot's `config.js` sets no `enabledManagers`, so repo-level `customManagers` run. (The "No github.com token" warning only affects release-notes fetching, not detection.) - **registry-mirror interplay**: Renovate queries the upstream datasource (docker.io/codeberg.org) for new tags; the mirror only matters at host pull time — no conflict. New tags must be added to `registry_mirror_images` when bumped, same as today. - **Caddy vs #48 (xcaddy build)**: kept tracking the official image — until the custom build lands this is where security bumps come from; when #48 lands, move/adjust the annotation to the build source. ## Verification - Regex extraction tested against the annotated files: all four tags parse with the right datasource/depName/value. - `renovate-config-validator` (renovate:43 image): config validated successfully. - Interaction with #63's fix: a merged Renovate tag PR now also actually deploys on the next apply (pull + restart + running-image assert).
supernaut tvångsskickade feat/61-renovate-core-image-tags från f6c76cabc2
Alla kontroller lyckades
ci / ci (pull_request) Successful in 1m41s
till 7ddd4c7ec3
Alla kontroller lyckades
ci / ci (pull_request) Successful in 1m39s
2026-07-18 14:58:35 +00:00
Jämför
supernaut sammanfogade incheckning 792d1f7270 till main 2026-07-18 15:23:22 +00:00
supernaut tog bort grenen feat/61-renovate-core-image-tags 2026-07-18 15:23:22 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!95
Ingen beskrivning angiven.