diff --git a/.github/workflows/validate.yml b/.github/workflows/validate.yml index 13bf7f6..9b4a48a 100644 --- a/.github/workflows/validate.yml +++ b/.github/workflows/validate.yml @@ -15,10 +15,21 @@ jobs: steps: - uses: actions/checkout@v4 + # Same version the deploy workflows pin. test-deploy-logic.sh renders + # every environment against the chart, and without helm on PATH it + # skipped that silently - the job went green having rendered nothing. + - uses: azure/setup-helm@v4 + with: + version: v3.16.3 + - name: Install tools + env: + # renovate: datasource=github-releases depName=mikefarah/yq + YQ_VERSION: v4.44.3 run: | set -euo pipefail - sudo wget -qO /usr/local/bin/yq https://github.com/mikefarah/yq/releases/download/v4.44.3/yq_linux_amd64 + sudo wget -qO /usr/local/bin/yq \ + "https://github.com/mikefarah/yq/releases/download/${YQ_VERSION}/yq_linux_amd64" sudo chmod +x /usr/local/bin/yq pipx install check-jsonschema @@ -79,6 +90,16 @@ jobs: - name: AGENTS.md does not reference missing paths run: ./scripts/check-agents-md.sh + # The script skips its render checks when the chart cannot be pulled, so + # that it still runs on a laptop with no helm. In CI an unreachable chart + # is a failure, not a skip, or the render coverage disappears without + # anything turning red. + - name: Chart every environment renders against is reachable + run: | + set -euo pipefail + version="$(yq -r '.spec.platform.chartVersion' environments/test1/env.yaml)" + helm show chart oci://ghcr.io/eduide/charts/eduide --version "$version" >/dev/null + - name: Deploy logic tests run: ./scripts/test-deploy-logic.sh diff --git a/AGENTS.md b/AGENTS.md index fcaafac..e22c302 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -202,6 +202,23 @@ One file under `environments/`, then the GitHub Environment holding its `KUBECONFIG`. The shared Gateway listeners are derived from the manifests, so there is no second file to edit. See `docs/environments.md`. +## Dependency updates + +`renovate.json` extends the org-wide preset in EduIDE/.github. Only two things +here are versioned and both are managed: the actions in the workflows, and +`spec.platform.chartVersion` in each environment manifest. The chart version +needs a custom regex manager - `env.yaml` is an `eduide.dev/v1 Environment`, not +a `Chart.yaml` and not a values file, so no built-in manager can see it. + +**Test and staging chart bumps arrive batched. Production ones do not arrive at +all** until somebody ticks the box on the Dependency Dashboard, because bumping +`chartVersion` in a production environment is the release procedure rather than +a chore, and grouping it with the test environments would mean neither could be +reverted without the other. + +`eduide-cluster` is a `Bootstrap cluster` workflow input, not a value in a file, +so nothing bumps it. Keep it at the same version as `eduide` by hand. + ## Conventions - Bash: `set -euo pipefail`. Prefer `if` blocks over `A && B` — `set -e` has diff --git a/README.md b/README.md index 1ebb60d..46cbc65 100644 --- a/README.md +++ b/README.md @@ -11,6 +11,7 @@ environments//env.yaml how an installation is deployed environments//values.yaml how the chart is configured environments/_base.yaml chart settings identical everywhere schemas/ JSON schemas the manifests are validated against +renovate.json who may bump the chart version, and when ``` An environment is one namespace on one cluster. diff --git a/renovate.json b/renovate.json new file mode 100644 index 0000000..07f384e --- /dev/null +++ b/renovate.json @@ -0,0 +1,49 @@ +{ + "$schema": "https://docs.renovatebot.com/renovate-schema.json", + "description": [ + "Policy comes from the org preset. Only what is specific to this repo lives here.", + "There is no application code, no Dockerfile and no chart source in this repo. Two things are versioned: the GitHub Actions in .github/workflows (the preset's github-actions manager sees those) and spec.platform.chartVersion in each environments//env.yaml, which no built-in manager can read because env.yaml is an eduide.dev/v1 Environment manifest rather than a Chart.yaml or a Helm values file." + ], + + "extends": ["local>EduIDE/.github:renovate-config"], + + "customManagers": [ + { + "customType": "regex", + "description": "spec.platform.chartVersion selects which eduide chart an environment installs from oci://ghcr.io/eduide/charts. eduide-cluster is released in lockstep at the same version and is passed to Bootstrap cluster as a workflow input, so it is not pinned in a file and nothing here can bump it. Neither of the preset's custom managers matches a path in this repo, so it does not matter whether this list replaces or extends them.", + "managerFilePatterns": ["/^environments/[^/]+/env\\.yaml$/"], + "matchStrings": ["chartVersion:\\s*[\"']?(?[^\"'\\s]+)"], + "depNameTemplate": "ghcr.io/eduide/charts/eduide", + "datasourceTemplate": "docker", + "versioningTemplate": "semver" + } + ], + + "packageRules": [ + { + "description": "Production moves only when a human ticks it on the Dependency Dashboard. Bumping chartVersion in a production environment IS the release procedure - README says so under 'Move production' - so a PR here is not a dependency update that happens to touch production, it is a production deploy waiting for a merge. It must never appear unasked.", + "matchFileNames": [ + "environments/tum-production/**", + "environments/bonn/**", + "environments/mannheim/**" + ], + "dependencyDashboardApproval": true, + "groupName": "production chart version", + "groupSlug": "chart-prod", + "addLabels": ["production"] + }, + { + "description": "Staging and the test environments batch into one PR. Kept apart from the production group on purpose: bundling the two would mean production could not be reverted without also reverting the environments it is supposed to have been proven on first.", + "matchFileNames": [ + "environments/staging/**", + "environments/e2e-test/**", + "environments/test1/**", + "environments/test2/**", + "environments/test3/**" + ], + "groupName": "staging and test chart version", + "groupSlug": "chart-test", + "addLabels": ["staging"] + } + ] +}