mirror of
https://github.com/vhaudiquet/homeprod.git
synced 2026-09-13 12:41:13 +00:00
chore(renovate): drop self-hosted runner from this PR (merge config only)
Per review feedback: remove the self-hosted Renovate deployment (kubernetes/code/renovate/* + root kustomization wiring) from this PR and defer it to a follow-up. Keep the renovate.json config to merge now. Also drop the postUpgradeTasks SOPS re-encrypt block: it depended on the runner's boot.sh decrypt flow, and the hosted Mend app cannot run 'sops' (allowedPostUpgradeCommands). SOPS handling returns with the deployment.
This commit is contained in:
@@ -1,69 +0,0 @@
|
|||||||
#!/bin/sh
|
|
||||||
#
|
|
||||||
# Renovate runner bootstrap / entrypoint.
|
|
||||||
#
|
|
||||||
# Renovate has NO preUpgradeTasks hook (schema only exposes postUpgradeTasks),
|
|
||||||
# and postUpgradeTasks runs AFTER Renovate has already edited the dependency
|
|
||||||
# files. That matters because these `values.yaml` files are SOPS documents:
|
|
||||||
# the `sops:` metadata block carries a `mac:` that authenticates the whole
|
|
||||||
# file, so ANY edit (even to a plaintext `image.tag`) invalidates it and makes
|
|
||||||
# `sops -d` fail with a MAC/data-integrity error. You cannot decrypt the file
|
|
||||||
# *after* Renovate has touched it.
|
|
||||||
#
|
|
||||||
# So we decrypt BEFORE Renovate extracts any dependency info:
|
|
||||||
# 1. clone the repo into the exact checkout path Renovate will reuse
|
|
||||||
# 2. `sops -d -i` every values.yaml in place (plaintext, no `sops:` block)
|
|
||||||
# 3. local-commit the decrypted working tree onto the local base branch
|
|
||||||
# (NOT pushed -> encrypted blobs stay in remote git, no plaintext secrets
|
|
||||||
# ever leave the runner)
|
|
||||||
# 4. run Renovate. It now reads plaintext tags and edits plaintext files.
|
|
||||||
# postUpgradeTasks only needs `sops -e -i` (encrypt) to rebuild a valid
|
|
||||||
# SOPS document containing the bumped tag.
|
|
||||||
#
|
|
||||||
# The local commit is important: step 3 makes `git checkout <base>` restore the
|
|
||||||
# decrypted content from the LOCAL branch rather than the encrypted remote blob,
|
|
||||||
# so Renovate's branch operations don't silently resurrect the encrypted file
|
|
||||||
# and re-introduce the MAC-mismatch problem.
|
|
||||||
|
|
||||||
set -eu
|
|
||||||
|
|
||||||
# SOPS PGP private key must be available to decrypt AND to re-encrypt.
|
|
||||||
if [ -f /etc/renovate/gpg/git-renovate-gpg.key ]; then
|
|
||||||
gpg --batch --import /etc/renovate/gpg/git-renovate-gpg.key || true
|
|
||||||
fi
|
|
||||||
|
|
||||||
# Renovate stores repos under $RENOVATE_BASE_DIR/repos/<platform>/<org>/<repo>.
|
|
||||||
BASE_DIR="${RENOVATE_BASE_DIR:-/tmp/renovate}"
|
|
||||||
REPO_DIR="${BASE_DIR}/repos/github/vhaudiquet/homeprod"
|
|
||||||
REPO_URL="https://x-access-token:${RENOVATE_TOKEN}@github.com/vhaudiquet/homeprod.git"
|
|
||||||
DEFAULT_BRANCH="${DEFAULT_BRANCH:-main}"
|
|
||||||
|
|
||||||
mkdir -p "$(dirname "$REPO_DIR")"
|
|
||||||
|
|
||||||
# 1. Ensure a fresh, valid checkout of the base branch exists.
|
|
||||||
if [ -d "${REPO_DIR}/.git" ]; then
|
|
||||||
git -C "$REPO_DIR" fetch --all --prune
|
|
||||||
git -C "$REPO_DIR" -c advice.detachedHead=false checkout "$DEFAULT_BRANCH" \
|
|
||||||
&& git -C "$REPO_DIR" reset --hard "origin/${DEFAULT_BRANCH}"
|
|
||||||
else
|
|
||||||
git clone --no-tags --single-branch --branch "$DEFAULT_BRANCH" "$REPO_URL" "$REPO_DIR"
|
|
||||||
git -C "$REPO_DIR" config user.name renovate
|
|
||||||
git -C "$REPO_DIR" config user.email renovate@localhost
|
|
||||||
fi
|
|
||||||
|
|
||||||
# 2. Decrypt every values.yaml still carrying SOPS metadata (in-place).
|
|
||||||
# Skips files that are already plaintext (no `sops:` block) so the bootstrap
|
|
||||||
# is idempotent across re-runs.
|
|
||||||
find "$REPO_DIR" -name 'values.yaml' -type f \
|
|
||||||
-exec grep -l -m1 '^sops:' {} + 2>/dev/null \
|
|
||||||
| xargs -r -n1 sops -d -i
|
|
||||||
|
|
||||||
# 3. Local commit (never pushed) so Renovate's checkout of the base branch
|
|
||||||
# keeps working on decrypted files.
|
|
||||||
git -C "$REPO_DIR" add -A
|
|
||||||
if ! git -C "$REPO_DIR" diff --cached --quiet; then
|
|
||||||
git -C "$REPO_DIR" commit -m "chore(renovate): decrypt values for update (local bootstrap)" --quiet
|
|
||||||
fi
|
|
||||||
|
|
||||||
# 4. Run Renovate itself.
|
|
||||||
exec renovate "$@"
|
|
||||||
@@ -1,11 +0,0 @@
|
|||||||
{
|
|
||||||
"platform": "github",
|
|
||||||
"repositories": ["vhaudiquet/homeprod"],
|
|
||||||
"autodiscover": false,
|
|
||||||
"allowedPostUpgradeCommands": ["^sops"],
|
|
||||||
"allowedPostUpgradeCommandsEnv": ["^SOPS_"],
|
|
||||||
"onboardingConfigFileName": "renovate.json",
|
|
||||||
"dryRun": false,
|
|
||||||
"binarySource": "docker",
|
|
||||||
"schedule": ["every weekend"]
|
|
||||||
}
|
|
||||||
@@ -1,77 +0,0 @@
|
|||||||
# Self-hosted Renovate runner.
|
|
||||||
#
|
|
||||||
# Runs the managed `renovatebot/renovate` image on a schedule against the
|
|
||||||
# `vhaudiquet/homeprod` repo (see config.json). Because our `values.yaml` are
|
|
||||||
# SOPS-encrypted and must be decrypted *before* Renovate edits them (and
|
|
||||||
# re-encrypted before the PR commit), Renovate cannot run on the Mend-hosted
|
|
||||||
# app — it must be self-hosted with the sops command allow-listed
|
|
||||||
# (see config.json -> allowedPostUpgradeCommands) and the SOPS PGP private key
|
|
||||||
# loaded (renovate-gpg secret below). boot.sh performs the pre-extraction
|
|
||||||
# decrypt; postUpgradeTasks performs the re-encrypt.
|
|
||||||
apiVersion: batch/v1
|
|
||||||
kind: CronJob
|
|
||||||
metadata:
|
|
||||||
name: renovate
|
|
||||||
namespace: renovate
|
|
||||||
spec:
|
|
||||||
# Run every hour; Renovate's own "schedule": ["every weekend"] (config.json)
|
|
||||||
# gates when PRs are actually created.
|
|
||||||
schedule: "42 * * * *"
|
|
||||||
concurrencyPolicy: Forbid
|
|
||||||
successfulJobsHistoryLimit: 2
|
|
||||||
failedJobsHistoryLimit: 4
|
|
||||||
jobTemplate:
|
|
||||||
spec:
|
|
||||||
backoffLimit: 0
|
|
||||||
template:
|
|
||||||
spec:
|
|
||||||
restartPolicy: Never
|
|
||||||
tolerations:
|
|
||||||
- key: CriticalAddonsOnly
|
|
||||||
operator: Exists
|
|
||||||
containers:
|
|
||||||
- name: renovate
|
|
||||||
image: renovatebot/renovate:latest
|
|
||||||
envFrom:
|
|
||||||
- secretRef:
|
|
||||||
name: renovate-secrets
|
|
||||||
env:
|
|
||||||
- name: RENOVATE_CONFIG_FILE
|
|
||||||
value: /etc/renovate/config.json
|
|
||||||
- name: LOG_LEVEL
|
|
||||||
value: info
|
|
||||||
# boot.sh decrypts values.yaml BEFORE Renovate extracts/edits them
|
|
||||||
# (Renovate has no preUpgradeTasks hook; see boot.sh for why),
|
|
||||||
# then runs renovate. postUpgradeTasks only re-encrypts.
|
|
||||||
command:
|
|
||||||
- /bin/sh
|
|
||||||
- /etc/renovate/boot.sh
|
|
||||||
volumeMounts:
|
|
||||||
- name: config
|
|
||||||
mountPath: /etc/renovate/config.json
|
|
||||||
subPath: config.json
|
|
||||||
readOnly: true
|
|
||||||
- name: boot
|
|
||||||
mountPath: /etc/renovate/boot.sh
|
|
||||||
subPath: boot.sh
|
|
||||||
readOnly: true
|
|
||||||
- name: gpg
|
|
||||||
mountPath: /etc/renovate/gpg
|
|
||||||
readOnly: true
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
cpu: 100m
|
|
||||||
memory: 384Mi
|
|
||||||
limits:
|
|
||||||
cpu: 1000m
|
|
||||||
memory: 1Gi
|
|
||||||
volumes:
|
|
||||||
- name: config
|
|
||||||
configMap:
|
|
||||||
name: renovate-config
|
|
||||||
- name: boot
|
|
||||||
configMap:
|
|
||||||
name: renovate-config
|
|
||||||
- name: gpg
|
|
||||||
secret:
|
|
||||||
name: renovate-gpg
|
|
||||||
@@ -1,9 +0,0 @@
|
|||||||
# SOPS PGP PRIVATE key for fingerprint DC6910268E657FF70BA7EC289974494E76938DDC
|
|
||||||
#
|
|
||||||
# PLACEHOLDER — replace with the actual ASCII-armored PRIVATE key used to
|
|
||||||
# encrypt .sops.yaml files, then sops-encrypt this file before committing
|
|
||||||
# (wrap the whole file as a single value matching the `.*key` regex in
|
|
||||||
# .sops.yaml, or store it via the .pre-commit flow). Keep it out of git in
|
|
||||||
# plaintext; this is a Secret source.
|
|
||||||
#
|
|
||||||
# -----BEGIN PGP PRIVATE KEY BLOCK----- ... -----END PGP PRIVATE KEY BLOCK-----
|
|
||||||
@@ -1,23 +0,0 @@
|
|||||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
|
||||||
kind: Kustomization
|
|
||||||
namespace: renovate
|
|
||||||
resources:
|
|
||||||
- namespace.yaml
|
|
||||||
- cronjob.yaml
|
|
||||||
# Scalar Renovate env vars (token, SOPS key fingerprint, ...). Stored as a
|
|
||||||
# dotenv file and SOPS-encrypted by the .pre-commit hook (matches .env rule).
|
|
||||||
configMapGenerator:
|
|
||||||
- name: renovate-config
|
|
||||||
files:
|
|
||||||
- config.json=config.json
|
|
||||||
- boot.sh=boot.sh
|
|
||||||
secretGenerator:
|
|
||||||
- name: renovate-secrets
|
|
||||||
envs:
|
|
||||||
- renovate.env
|
|
||||||
# SOPS PGP private key needed by the renovate runner to decrypt values.yaml
|
|
||||||
# at boot and to re-encrypt them during postUpgradeTasks. Mounted into the
|
|
||||||
# pod and imported into the container gpg keyring at startup.
|
|
||||||
- name: renovate-gpg
|
|
||||||
files:
|
|
||||||
- git-renovate-gpg.key
|
|
||||||
@@ -1,4 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Namespace
|
|
||||||
metadata:
|
|
||||||
name: renovate
|
|
||||||
@@ -1,18 +0,0 @@
|
|||||||
# Self-hosted Renovate runtime secrets.
|
|
||||||
#
|
|
||||||
# FILL THESE IN. This file is SOPS-encrypted on commit by the .pre-commit hook
|
|
||||||
# (it matches the `.env` rule in .sops.yaml), and decrypted by kustomize-controller
|
|
||||||
# via flux-sops before the Secret is generated.
|
|
||||||
|
|
||||||
# Fine-grained/personal access token with read+writes:content and read:issues,
|
|
||||||
# read:pull_requests, and contents read/write on vhaudiquet/homeprod so Renovate
|
|
||||||
# can open and push PR branches.
|
|
||||||
RENOVATE_TOKEN=
|
|
||||||
|
|
||||||
# Optional: GitHub token used for public API rate-limit boosting (can be the
|
|
||||||
# same as RENOVATE_TOKEN, or a dedicated one).
|
|
||||||
GITHUB_COM_TOKEN=
|
|
||||||
|
|
||||||
# SOPS master key fingerprint used to (re-)encrypt values.yaml in this repo.
|
|
||||||
# Matches the `pgp:` entry in .sops.yaml.
|
|
||||||
SOPS_PGP_FP=DC6910268E657FF70BA7EC289974494E76938DDC
|
|
||||||
@@ -25,8 +25,6 @@ resources:
|
|||||||
- infrastructure/traefik
|
- infrastructure/traefik
|
||||||
- infrastructure/caddy
|
- infrastructure/caddy
|
||||||
- infrastructure/network/blocky
|
- infrastructure/network/blocky
|
||||||
# Code (self-hosted dev tooling)
|
|
||||||
- code/renovate
|
|
||||||
# Dev (developer platform)
|
# Dev (developer platform)
|
||||||
- dev/gitea
|
- dev/gitea
|
||||||
- dev/harbor
|
- dev/harbor
|
||||||
|
|||||||
@@ -9,16 +9,6 @@
|
|||||||
"helm-values",
|
"helm-values",
|
||||||
"helmv3"
|
"helmv3"
|
||||||
],
|
],
|
||||||
"postUpgradeTasks": {
|
|
||||||
"description": "Re-encrypt values.yaml after Renovate bumps an image tag. These files are decrypted to plaintext by the runner's boot.sh BEFORE Renovate extracts/edits them (Renovate has no preUpgradeTasks hook, and a post-edit decrypt would fail: editing a SOPS file invalidates its mac). So by the time this task runs, the file is plaintext and `sops -e -i` safely rebuilds a valid SOPS document carrying the bumped tag. branch mode re-encrypts each changed file once, after all deps on the branch are updated.",
|
|
||||||
"commands": [
|
|
||||||
"sops -e -i {{packageFile}}"
|
|
||||||
],
|
|
||||||
"fileFilters": [
|
|
||||||
"**/values.yaml"
|
|
||||||
],
|
|
||||||
"executionMode": "branch"
|
|
||||||
},
|
|
||||||
"packageRules": [
|
"packageRules": [
|
||||||
{
|
{
|
||||||
"description": "docker-compose updates",
|
"description": "docker-compose updates",
|
||||||
|
|||||||
Reference in New Issue
Block a user