Skip to content

chore(renovate): adopt the org-wide Renovate preset - #29

Merged
Mtze merged 1 commit into
mainfrom
chore/renovate-config
Aug 27, 2026
Merged

Mtze merged 1 commit into
mainfrom
chore/renovate-config

Conversation

@Mtze

@Mtze Mtze commented Aug 27, 2026 •

Copy link
Copy Markdown
Member

What and why

Adds the three-line renovate.json that points this repo at the org-wide preset in EduIDE/.github (local>EduIDE/.github:renovate-config, EduIDE/.github#4, still open - preset resolution reads that repo's default branch, so this stays inert until #4 merges and the Renovate app is installed).

Plus a short ## Renovate section in AGENTS.md, because what Renovate does to a Helm repo is not obvious and the first bot PR will look broken if nobody wrote it down.

No new CI job

The rollout plan for this repo called for adding a helm lint / helm template gate on pull_request. It is already there. .github/workflows/ci.yml runs on pull_request with permissions: contents: read and azure/setup-helm@v4 at HELM_VERSION: v3.16.3, and contains:

  • lint - helm lint over charts/*/, the AGENTS.md path guard, test-app-consistency.sh, and the chart-version-bump check
  • kubeconform - helm template on every chart, validated against real Kubernetes and CRD schemas
  • render-diff - renders base and head against all five environments and comments the diff
  • docs-drift - helm-docs regeneration check

Adding a second lint/template job would duplicate the first two for no extra signal, so this PR does not.

What Renovate will actually manage here

  • helmv3 - the dependencies: block in charts/eduide/Chart.yaml (eduide-shared-cache 0.5.3, theia-workspace-garbage-collector 0.1.0), refreshing charts/eduide/Chart.lock
  • helm-values - the image pins in charts/eduide/values.yaml and charts/eduide-cluster/values.yaml

The preset's matchPackageNames: ["ghcr.io/eduide/**", "theiacloud/**"] rule exempts our own artifacts from the 5-day quarantine, which covers both chart dependencies and the theiacloud/theia-cloud-conversion-webhook pin.

Known follow-ups, deliberately not fixed here

  1. A chart-touching Renovate PR will land red, twice over. ci.yml's "Chart version must be bumped when a chart changes" fails, because Renovate edits charts/** without bumping version:. And docs-drift fails, because helm-docs renders both the dependency table (charts/eduide/README.md:15) and the values defaults (README.md:143, charts/eduide-cluster/README.md:19) that Renovate just changed. Both need a human commit on the bot's branch. With automerge off org-wide that is arguably the correct shape - a human takes the release decision - but it should be a conscious choice, not a surprise. Documented in AGENTS.md.

  2. release.yml has no paths: filter at all. The rollout notes said it fires on push to main filtered by paths: chart/**; it does not filter, so every push to main runs it. The outcome is the same and benign: helm show chart finds the version already published and prints "Chart already published, skipping". A no-op, not a failure.

  3. dependency-review is not applicable. No package manifests in this repo - no package.json, no pom.xml, no go.mod. Nothing for the action to diff.

How it was verified

Everything below ran in a clean worktree off origin/main (89677c9), with helm v3.16.3 downloaded to match HELM_VERSION in ci.yml (the local default is helm 4, which is not what CI runs).

  • npx --yes --package renovate@44.46.7 -- renovate-config-validator --strict renovate.json - passes ("Config validated successfully against 1 file(s)").
  • ./scripts/resolve-deps.sh - resolved eduide from Chart.lock. Required first; helm template refuses without it.
  • helm lint per chart - both pass:
    • charts/eduide-cluster - 0 failed, one [INFO] Chart.yaml: icon is recommended
    • charts/eduide - 0 failed, same icon INFO, plus the expected preflightKeycloak INFO about placeholder values
  • helm template test <chart> --set keycloak.allowUnauthenticated=true (exactly how the kubeconform job invokes it) - both pass: eduide-cluster renders 14 manifests / 2440 lines, eduide renders 36 manifests / 1070 lines.
  • Worth recording: bare helm template charts/eduide fails on purpose - eduide.preflightKeycloak refuses to render on the chart's placeholder Keycloak values. A naive helm template <chart> gate would have been a permanently red check. The existing job already passes the --set.
  • ./scripts/check-agents-md.sh - passes, 7 path references check out (the new AGENTS.md section adds four).
  • npx prettier --check renovate.json - clean.
  • actionlint v1.7.7 over .github/workflows/ - clean. No workflow file is changed by this PR, so this only confirms the existing set.

Not verified: real Renovate grouping and scheduling behaviour. That needs --dry-run=full against the merged preset, which cannot run until EduIDE/.github#4 is on main.

Deployment impact

  • Changes a Helm chart (chart version bumped)
  • Changes a published image
  • Requires a config change in EduIDE-deployment
  • Requires a cluster-level change (CRDs, Gateway, ClusterRoles)
  • None of the above

No chart version bump, deliberately. Nothing under charts/ is touched, so ci.yml's bump check does not fire and there is nothing to publish. release.yml will run on the merge commit and skip both charts as already published.

Risk and rollback

Effectively zero right now: renovate.json is inert until EduIDE/.github#4 merges and the Renovate app is installed on the org. A repo extending a missing preset fails closed - no PRs - rather than doing something unexpected.

Once live, the failure mode is noisy or missing bot PRs, never an unreviewed merge: automerge and platformAutomerge are both false in the shared preset, and the CI gates described above are strict enough that a chart bump physically cannot go green without a human commit.

Rollback: revert this commit, or delete renovate.json.

Summary by CodeRabbit

  • Documentation

    • Added guidance for Renovate-managed Helm chart and values updates.
    • Documented manual chart-version and README regeneration steps.
    • Clarified the human release decision process.
  • Chores

    • Added shared Renovate configuration for automated dependency updates.

Three lines extending local>EduIDE/.github:renovate-config, plus the
AGENTS.md note on what that means for this repo.

Two managers see the charts: helmv3 on the dependencies block in
charts/eduide/Chart.yaml, helm-values on the image pins in both values
files. Neither knows to bump a chart version or regenerate the READMEs,
so a chart-touching Renovate PR lands red and needs both by hand. That
is documented rather than worked around - automerge is off org-wide, so
a human is taking the release decision either way.

No new CI job. The lint/template gate this rollout would otherwise add
is already in .github/workflows/ci.yml: helm lint over charts/*/ and a
kubeconform job that renders every chart, both on pull_request.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QLGHEpzx7D9NYHx4fCmHa9
@github-actions

Copy link
Copy Markdown

Rendered diff across all environments

No change to any rendered manifest.

For a pure refactor this is the result you want.

@coderabbitai

coderabbitai Bot commented Aug 27, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 8aab67cf-ef47-4140-b156-5f65fa6a8647

📥 Commits

Reviewing files that changed from the base of the PR and between 89677c9 and e74499f.

📒 Files selected for processing (2)
  • AGENTS.md
  • renovate.json

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The pull request adds a Renovate configuration and documents Renovate-managed Helm updates, required manual changes, README regeneration, and the release decision process.

Changes

Renovate workflow

Layer / File(s) Summary
Renovate setup and release guidance
renovate.json, AGENTS.md
renovate.json extends the shared EduIDE/.github:renovate-config preset and declares the Renovate schema. AGENTS.md documents the helmv3 and helm-values managers, manual chart-version updates, README regeneration, and non-automated release decisions.

Estimated code review effort: 1 (Trivial) | ~5 minutes

Merge Risk: ⚪ Minimal · up to e7449

This PR adds Renovate configuration and documentation without changing charts, CI, runtime behavior, or deployment configuration; it remains inert until the shared preset and app are available. No actionable merge-blocking risk remains after normal checks and review.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: adopting the organization-wide Renovate preset.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0 files. (2 skipped: 2 unsupported.)

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch chore/renovate-config

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Mtze
Mtze merged commit 27c8a4f into main Aug 27, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant