fix(renovate): decrypt values BEFORE renovate edits them (retract broken post-bump round-trip)

The prior postUpgradeTasks command 'sops -d ... && sops -e' was wrong:
Renovate has no preUpgradeTasks hook, and postUpgradeTasks runs AFTER
Renovate rewrites the file. These values.yaml are SOPS documents whose
sops.mac authenticates the whole file, so editing a plaintext image.tag
invalidates the MAC and 'sops -d' then fails (data-integrity error). The
claimed decrypt-after-bump therefore could never work.

boot.sh now decrypts every values.yaml in the checkout BEFORE Renovate
extracts/edits them, committing the decrypted tree locally (never pushed,
so no plaintext secrets enter remote git). postUpgradeTasks is reduced to
'sops -e -i' only (the file is already plaintext when Renovate edits it).

Validated: kustomize build passes for the whole kubernetes/ tree.
This commit is contained in:
2026-08-26 19:58:55 +02:00
committed by vhaudiquet
parent 5bf07a2fff
commit 1623b2ea7d
4 changed files with 93 additions and 17 deletions
+4 -3
View File
@@ -10,13 +10,14 @@ configMapGenerator:
- name: renovate-config
files:
- config.json=config.json
- boot.sh=boot.sh
secretGenerator:
- name: renovate-secrets
envs:
- renovate.env
# SOPS PGP private key needed by the renovate runner to re-encrypt
# values.yaml during postUpgradeTasks. Mounted into the pod and imported
# into the container gpg keyring at startup.
# SOPS PGP private key needed by the renovate runner to decrypt values.yaml
# at boot and to re-encrypt them during postUpgradeTasks. Mounted into the
# pod and imported into the container gpg keyring at startup.
- name: renovate-gpg
files:
- git-renovate-gpg.key