Repository navigation
chore(renovate): adopt the org preset and manage the chart version #116
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -15,10 +15,21 @@ jobs: | |
| steps: | ||
| - uses: actions/checkout@v4 | ||
|
|
||
| # Same version the deploy workflows pin. test-deploy-logic.sh renders | ||
| # every environment against the chart, and without helm on PATH it | ||
| # skipped that silently - the job went green having rendered nothing. | ||
| - uses: azure/setup-helm@v4 | ||
| with: | ||
| version: v3.16.3 | ||
|
|
||
| - name: Install tools | ||
| env: | ||
| # renovate: datasource=github-releases depName=mikefarah/yq | ||
| YQ_VERSION: v4.44.3 | ||
| run: | | ||
| set -euo pipefail | ||
| sudo wget -qO /usr/local/bin/yq https://github.com/mikefarah/yq/releases/download/v4.44.3/yq_linux_amd64 | ||
| sudo wget -qO /usr/local/bin/yq \ | ||
| "https://github.com/mikefarah/yq/releases/download/${YQ_VERSION}/yq_linux_amd64" | ||
| sudo chmod +x /usr/local/bin/yq | ||
| pipx install check-jsonschema | ||
|
|
||
|
|
@@ -79,6 +90,16 @@ jobs: | |
| - name: AGENTS.md does not reference missing paths | ||
| run: ./scripts/check-agents-md.sh | ||
|
|
||
| # The script skips its render checks when the chart cannot be pulled, so | ||
| # that it still runs on a laptop with no helm. In CI an unreachable chart | ||
| # is a failure, not a skip, or the render coverage disappears without | ||
| # anything turning red. | ||
| - name: Chart every environment renders against is reachable | ||
| run: | | ||
| set -euo pipefail | ||
| version="$(yq -r '.spec.platform.chartVersion' environments/test1/env.yaml)" | ||
| helm show chart oci://ghcr.io/eduide/charts/eduide --version "$version" >/dev/null | ||
|
Comment on lines
+100
to
+101
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win 🔎 Supported by static analysis🏁 Script executed: #!/bin/bash
set -e
printf '%s\n' '--- changed workflow hunk ---'
git diff -- .github/workflows/validate.yml
printf '%s\n' '--- workflow context ---'
sed -n '1,125p' .github/workflows/validate.yml
printf '%s\n' '--- environment manifests ---'
find environments -type f -name 'env.yaml' -print -exec sh -c "printf '%s\\n' '---' \"\$1\"; sed -n '/chartVersion/=' \"\$1\" | while IFS= read -r n; do sed -n \"\$((n-2)),\$((n+2))p\" \"\$1\"; done" sh {} \;
printf '%s\n' '--- Renovate configuration ---'
sed -n '1,220p' renovate.json
printf '%s\n' '--- related OCI pulls and GHCR authentication ---'
rg -n -C 3 'ghcr\.io|helm show chart|docker/login-action|registry' .github/workflows renovate.json environmentsRepository: EduIDE/EduIDE-deployment Length of output: 14004 🏁 Script executed: #!/bin/bash
set -e
printf '%s\n' '--- deploy logic test script ---'
sed -n '1,260p' scripts/test-deploy-logic.sh
printf '%s\n' '--- chart-version references in validation-related files ---'
rg -n -C 3 'chartVersion|helm (show|template|dependency|pull)|oci://ghcr\.io/eduide/charts/eduide' scripts .github/workflows environmentsRepository: EduIDE/EduIDE-deployment Length of output: 19439 Check every environment's chart version.
🤖 Prompt for AI Agents |
||
|
|
||
| - name: Deploy logic tests | ||
| run: ./scripts/test-deploy-logic.sh | ||
|
|
||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,49 @@ | ||
| { | ||
| "$schema": "https://docs.renovatebot.com/renovate-schema.json", | ||
| "description": [ | ||
| "Policy comes from the org preset. Only what is specific to this repo lives here.", | ||
| "There is no application code, no Dockerfile and no chart source in this repo. Two things are versioned: the GitHub Actions in .github/workflows (the preset's github-actions manager sees those) and spec.platform.chartVersion in each environments/<name>/env.yaml, which no built-in manager can read because env.yaml is an eduide.dev/v1 Environment manifest rather than a Chart.yaml or a Helm values file." | ||
|
Comment on lines
+3
to
+5
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win Document the Renovate-managed Both files state that only two versioned items are managed, but
📍 Affects 2 files
🤖 Prompt for AI Agents |
||
| ], | ||
|
|
||
| "extends": ["local>EduIDE/.github:renovate-config"], | ||
|
|
||
| "customManagers": [ | ||
| { | ||
| "customType": "regex", | ||
| "description": "spec.platform.chartVersion selects which eduide chart an environment installs from oci://ghcr.io/eduide/charts. eduide-cluster is released in lockstep at the same version and is passed to Bootstrap cluster as a workflow input, so it is not pinned in a file and nothing here can bump it. Neither of the preset's custom managers matches a path in this repo, so it does not matter whether this list replaces or extends them.", | ||
| "managerFilePatterns": ["/^environments/[^/]+/env\\.yaml$/"], | ||
| "matchStrings": ["chartVersion:\\s*[\"']?(?<currentValue>[^\"'\\s]+)"], | ||
| "depNameTemplate": "ghcr.io/eduide/charts/eduide", | ||
| "datasourceTemplate": "docker", | ||
| "versioningTemplate": "semver" | ||
| } | ||
| ], | ||
|
|
||
| "packageRules": [ | ||
| { | ||
| "description": "Production moves only when a human ticks it on the Dependency Dashboard. Bumping chartVersion in a production environment IS the release procedure - README says so under 'Move production' - so a PR here is not a dependency update that happens to touch production, it is a production deploy waiting for a merge. It must never appear unasked.", | ||
| "matchFileNames": [ | ||
| "environments/tum-production/**", | ||
| "environments/bonn/**", | ||
| "environments/mannheim/**" | ||
| ], | ||
| "dependencyDashboardApproval": true, | ||
| "groupName": "production chart version", | ||
| "groupSlug": "chart-prod", | ||
| "addLabels": ["production"] | ||
| }, | ||
| { | ||
| "description": "Staging and the test environments batch into one PR. Kept apart from the production group on purpose: bundling the two would mean production could not be reverted without also reverting the environments it is supposed to have been proven on first.", | ||
| "matchFileNames": [ | ||
| "environments/staging/**", | ||
| "environments/e2e-test/**", | ||
| "environments/test1/**", | ||
| "environments/test2/**", | ||
| "environments/test3/**" | ||
| ], | ||
| "groupName": "staging and test chart version", | ||
| "groupSlug": "chart-test", | ||
| "addLabels": ["staging"] | ||
| } | ||
| ] | ||
| } | ||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🩺 Stability & Availability | 🟠 Major | ⚡ Quick win
🔎 Supported by static analysis
🏁 Script executed:
Repository: EduIDE/EduIDE-deployment
Length of output: 20252
🏁 Script executed:
Repository: EduIDE/EduIDE-deployment
Length of output: 1331
Add GHCR authentication to the validation job.
ghcr.io/eduide/charts/eduiderequires authentication. This job grants onlycontents: readand does not runhelm registry login. Addpackages: readand log in with${{ secrets.GITHUB_TOKEN }}beforehelm show chart.🤖 Prompt for AI Agents