chore(renovate): adopt the org-wide Renovate preset - #29
Conversation
Three lines extending local>EduIDE/.github:renovate-config, plus the AGENTS.md note on what that means for this repo. Two managers see the charts: helmv3 on the dependencies block in charts/eduide/Chart.yaml, helm-values on the image pins in both values files. Neither knows to bump a chart version or regenerate the READMEs, so a chart-touching Renovate PR lands red and needs both by hand. That is documented rather than worked around - automerge is off org-wide, so a human is taking the release decision either way. No new CI job. The lint/template gate this rollout would otherwise add is already in .github/workflows/ci.yml: helm lint over charts/*/ and a kubeconform job that renders every chart, both on pull_request. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QLGHEpzx7D9NYHx4fCmHa9
Rendered diff across all environmentsNo change to any rendered manifest. For a pure refactor this is the result you want. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (2)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe pull request adds a Renovate configuration and documents Renovate-managed Helm updates, required manual changes, README regeneration, and the release decision process. ChangesRenovate workflow
Estimated code review effort: 1 (Trivial) | ~5 minutes Merge Risk: ⚪ Minimal · up to This PR adds Renovate configuration and documentation without changing charts, CI, runtime behavior, or deployment configuration; it remains inert until the shared preset and app are available. No actionable merge-blocking risk remains after normal checks and review. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
Full details: Docstring CoverageExplanation No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0 files. (2 skipped: 2 unsupported.) ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
What and why
Adds the three-line
renovate.jsonthat points this repo at the org-wide preset inEduIDE/.github(local>EduIDE/.github:renovate-config, EduIDE/.github#4, still open - preset resolution reads that repo's default branch, so this stays inert until #4 merges and the Renovate app is installed).Plus a short
## Renovatesection inAGENTS.md, because what Renovate does to a Helm repo is not obvious and the first bot PR will look broken if nobody wrote it down.No new CI job
The rollout plan for this repo called for adding a
helm lint/helm templategate onpull_request. It is already there..github/workflows/ci.ymlruns onpull_requestwithpermissions: contents: readandazure/setup-helm@v4atHELM_VERSION: v3.16.3, and contains:lint-helm lintovercharts/*/, the AGENTS.md path guard,test-app-consistency.sh, and the chart-version-bump checkkubeconform-helm templateon every chart, validated against real Kubernetes and CRD schemasrender-diff- renders base and head against all five environments and comments the diffdocs-drift- helm-docs regeneration checkAdding a second lint/template job would duplicate the first two for no extra signal, so this PR does not.
What Renovate will actually manage here
helmv3- thedependencies:block incharts/eduide/Chart.yaml(eduide-shared-cache0.5.3,theia-workspace-garbage-collector0.1.0), refreshingcharts/eduide/Chart.lockhelm-values- the image pins incharts/eduide/values.yamlandcharts/eduide-cluster/values.yamlThe preset's
matchPackageNames: ["ghcr.io/eduide/**", "theiacloud/**"]rule exempts our own artifacts from the 5-day quarantine, which covers both chart dependencies and thetheiacloud/theia-cloud-conversion-webhookpin.Known follow-ups, deliberately not fixed here
A chart-touching Renovate PR will land red, twice over.
ci.yml's "Chart version must be bumped when a chart changes" fails, because Renovate editscharts/**without bumpingversion:. Anddocs-driftfails, because helm-docs renders both the dependency table (charts/eduide/README.md:15) and the values defaults (README.md:143,charts/eduide-cluster/README.md:19) that Renovate just changed. Both need a human commit on the bot's branch. With automerge off org-wide that is arguably the correct shape - a human takes the release decision - but it should be a conscious choice, not a surprise. Documented inAGENTS.md.release.ymlhas nopaths:filter at all. The rollout notes said it fires on push to main filtered bypaths: chart/**; it does not filter, so every push tomainruns it. The outcome is the same and benign:helm show chartfinds the version already published and prints "Chart already published, skipping". A no-op, not a failure.dependency-reviewis not applicable. No package manifests in this repo - nopackage.json, nopom.xml, nogo.mod. Nothing for the action to diff.How it was verified
Everything below ran in a clean worktree off
origin/main(89677c9), with helm v3.16.3 downloaded to matchHELM_VERSIONinci.yml(the local default is helm 4, which is not what CI runs).npx --yes --package renovate@44.46.7 -- renovate-config-validator --strict renovate.json- passes ("Config validated successfully against 1 file(s)")../scripts/resolve-deps.sh- resolvededuidefromChart.lock. Required first;helm templaterefuses without it.helm lintper chart - both pass:charts/eduide-cluster- 0 failed, one[INFO] Chart.yaml: icon is recommendedcharts/eduide- 0 failed, same icon INFO, plus the expectedpreflightKeycloakINFO about placeholder valueshelm template test <chart> --set keycloak.allowUnauthenticated=true(exactly how thekubeconformjob invokes it) - both pass:eduide-clusterrenders 14 manifests / 2440 lines,eduiderenders 36 manifests / 1070 lines.helm template charts/eduidefails on purpose -eduide.preflightKeycloakrefuses to render on the chart's placeholder Keycloak values. A naivehelm template <chart>gate would have been a permanently red check. The existing job already passes the--set../scripts/check-agents-md.sh- passes, 7 path references check out (the new AGENTS.md section adds four).npx prettier --check renovate.json- clean.actionlintv1.7.7 over.github/workflows/- clean. No workflow file is changed by this PR, so this only confirms the existing set.Not verified: real Renovate grouping and scheduling behaviour. That needs
--dry-run=fullagainst the merged preset, which cannot run until EduIDE/.github#4 is onmain.Deployment impact
versionbumped)No chart version bump, deliberately. Nothing under
charts/is touched, soci.yml's bump check does not fire and there is nothing to publish.release.ymlwill run on the merge commit and skip both charts as already published.Risk and rollback
Effectively zero right now:
renovate.jsonis inert until EduIDE/.github#4 merges and the Renovate app is installed on the org. A repo extending a missing preset fails closed - no PRs - rather than doing something unexpected.Once live, the failure mode is noisy or missing bot PRs, never an unreviewed merge:
automergeandplatformAutomergeare bothfalsein the shared preset, and the CI gates described above are strict enough that a chart bump physically cannot go green without a human commit.Rollback: revert this commit, or delete
renovate.json.Summary by CodeRabbit
Documentation
Chores