From 341dde72a4a0586752c269ad2abd8b02b197dabe Mon Sep 17 00:00:00 2001 From: Matthias Linhuber Date: Thu, 27 Aug 2026 17:23:40 +0200 Subject: [PATCH] chore(renovate): adopt the org preset and manage the chart version Adds this repo to the org-wide Renovate rollout, and closes the gap that made the existing validation job weaker than it looks. The repo no longer matches the shape the shared preset was written for. `deployments/*/values.yaml` and the `preloading.images` lists it targets with a custom manager were deleted in #111 and #113 - preload images are derived from `appDefinitions.apps` in the chart now, and there are no chart sources here at all since 2.0.0. That manager, and the preset's `deployments/**` package rule, match nothing in this repo. Both are inert rather than wrong; raising it against EduIDE/.github separately. So the only versioned things left here are the actions in the workflows and `spec.platform.chartVersion` in each environment manifest. The second needs a custom manager: env.yaml is an eduide.dev/v1 Environment, so neither helmv3 nor helm-values can read it. Verified the regex matches exactly once per environment, 8 of 8, and does not touch values.yaml or _base.yaml. Production is separated from staging and test by path. Bumping chartVersion in a production environment is not a chore that happens to touch production - it is the documented release procedure, so it waits behind a Dependency Dashboard tick. Grouping it with the test environments would produce one PR that cannot be reverted for production without also reverting the environments it was meant to be proven on. Verified the two rules partition all eight manifests with none left over. Also installs helm in the validation job. test-deploy-logic.sh renders every environment against the published chart, but helm was never on the runner, so that section printed SKIP and the job went green having rendered nothing - the README's claim that CI "renders every environment" was not true. An unreachable chart is now a failure in CI and still a skip on a laptop. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01QLGHEpzx7D9NYHx4fCmHa9 --- .github/workflows/validate.yml | 23 +++++++++++++++- AGENTS.md | 17 ++++++++++++ README.md | 1 + renovate.json | 49 ++++++++++++++++++++++++++++++++++ 4 files changed, 89 insertions(+), 1 deletion(-) create mode 100644 renovate.json diff --git a/.github/workflows/validate.yml b/.github/workflows/validate.yml index 13bf7f6..9b4a48a 100644 --- a/.github/workflows/validate.yml +++ b/.github/workflows/validate.yml @@ -15,10 +15,21 @@ jobs: steps: - uses: actions/checkout@v4 + # Same version the deploy workflows pin. test-deploy-logic.sh renders + # every environment against the chart, and without helm on PATH it + # skipped that silently - the job went green having rendered nothing. + - uses: azure/setup-helm@v4 + with: + version: v3.16.3 + - name: Install tools + env: + # renovate: datasource=github-releases depName=mikefarah/yq + YQ_VERSION: v4.44.3 run: | set -euo pipefail - sudo wget -qO /usr/local/bin/yq https://github.com/mikefarah/yq/releases/download/v4.44.3/yq_linux_amd64 + sudo wget -qO /usr/local/bin/yq \ + "https://github.com/mikefarah/yq/releases/download/${YQ_VERSION}/yq_linux_amd64" sudo chmod +x /usr/local/bin/yq pipx install check-jsonschema @@ -79,6 +90,16 @@ jobs: - name: AGENTS.md does not reference missing paths run: ./scripts/check-agents-md.sh + # The script skips its render checks when the chart cannot be pulled, so + # that it still runs on a laptop with no helm. In CI an unreachable chart + # is a failure, not a skip, or the render coverage disappears without + # anything turning red. + - name: Chart every environment renders against is reachable + run: | + set -euo pipefail + version="$(yq -r '.spec.platform.chartVersion' environments/test1/env.yaml)" + helm show chart oci://ghcr.io/eduide/charts/eduide --version "$version" >/dev/null + - name: Deploy logic tests run: ./scripts/test-deploy-logic.sh diff --git a/AGENTS.md b/AGENTS.md index fcaafac..e22c302 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -202,6 +202,23 @@ One file under `environments/`, then the GitHub Environment holding its `KUBECONFIG`. The shared Gateway listeners are derived from the manifests, so there is no second file to edit. See `docs/environments.md`. +## Dependency updates + +`renovate.json` extends the org-wide preset in EduIDE/.github. Only two things +here are versioned and both are managed: the actions in the workflows, and +`spec.platform.chartVersion` in each environment manifest. The chart version +needs a custom regex manager - `env.yaml` is an `eduide.dev/v1 Environment`, not +a `Chart.yaml` and not a values file, so no built-in manager can see it. + +**Test and staging chart bumps arrive batched. Production ones do not arrive at +all** until somebody ticks the box on the Dependency Dashboard, because bumping +`chartVersion` in a production environment is the release procedure rather than +a chore, and grouping it with the test environments would mean neither could be +reverted without the other. + +`eduide-cluster` is a `Bootstrap cluster` workflow input, not a value in a file, +so nothing bumps it. Keep it at the same version as `eduide` by hand. + ## Conventions - Bash: `set -euo pipefail`. Prefer `if` blocks over `A && B` — `set -e` has diff --git a/README.md b/README.md index 1ebb60d..46cbc65 100644 --- a/README.md +++ b/README.md @@ -11,6 +11,7 @@ environments//env.yaml how an installation is deployed environments//values.yaml how the chart is configured environments/_base.yaml chart settings identical everywhere schemas/ JSON schemas the manifests are validated against +renovate.json who may bump the chart version, and when ``` An environment is one namespace on one cluster. diff --git a/renovate.json b/renovate.json new file mode 100644 index 0000000..07f384e --- /dev/null +++ b/renovate.json @@ -0,0 +1,49 @@ +{ + "$schema": "https://docs.renovatebot.com/renovate-schema.json", + "description": [ + "Policy comes from the org preset. Only what is specific to this repo lives here.", + "There is no application code, no Dockerfile and no chart source in this repo. Two things are versioned: the GitHub Actions in .github/workflows (the preset's github-actions manager sees those) and spec.platform.chartVersion in each environments//env.yaml, which no built-in manager can read because env.yaml is an eduide.dev/v1 Environment manifest rather than a Chart.yaml or a Helm values file." + ], + + "extends": ["local>EduIDE/.github:renovate-config"], + + "customManagers": [ + { + "customType": "regex", + "description": "spec.platform.chartVersion selects which eduide chart an environment installs from oci://ghcr.io/eduide/charts. eduide-cluster is released in lockstep at the same version and is passed to Bootstrap cluster as a workflow input, so it is not pinned in a file and nothing here can bump it. Neither of the preset's custom managers matches a path in this repo, so it does not matter whether this list replaces or extends them.", + "managerFilePatterns": ["/^environments/[^/]+/env\\.yaml$/"], + "matchStrings": ["chartVersion:\\s*[\"']?(?[^\"'\\s]+)"], + "depNameTemplate": "ghcr.io/eduide/charts/eduide", + "datasourceTemplate": "docker", + "versioningTemplate": "semver" + } + ], + + "packageRules": [ + { + "description": "Production moves only when a human ticks it on the Dependency Dashboard. Bumping chartVersion in a production environment IS the release procedure - README says so under 'Move production' - so a PR here is not a dependency update that happens to touch production, it is a production deploy waiting for a merge. It must never appear unasked.", + "matchFileNames": [ + "environments/tum-production/**", + "environments/bonn/**", + "environments/mannheim/**" + ], + "dependencyDashboardApproval": true, + "groupName": "production chart version", + "groupSlug": "chart-prod", + "addLabels": ["production"] + }, + { + "description": "Staging and the test environments batch into one PR. Kept apart from the production group on purpose: bundling the two would mean production could not be reverted without also reverting the environments it is supposed to have been proven on first.", + "matchFileNames": [ + "environments/staging/**", + "environments/e2e-test/**", + "environments/test1/**", + "environments/test2/**", + "environments/test3/**" + ], + "groupName": "staging and test chart version", + "groupSlug": "chart-test", + "addLabels": ["staging"] + } + ] +}