Automerge patch bumps of components whose role has a Molecule scenario

A component bump touches that role's defaults/main.yml, which is on the Molecule
workflow's path filter, so the change-detection job runs that role's scenario.
The bump therefore only merges once the new version has actually been started on
the configuration the role renders. That is a real gate, and a stronger one than
a human reading a version number in a diff.

Patch only. A minor carries behaviour changes that no static rule can judge - the
MASH fleet tried a minor-automerge preset across 21 stateless roles and reverted
all of them, because reading a given release's notes is what decides it, and that
is a job for a human or an agent rather than a config file.

Branch push rather than a PR, as with the other automerge rules here.

The list has to stay in step with the roles that actually have a scenario, so
bin/check-molecule-automerge-list.py enforces it from prek. The direction that
matters is a role keeping automerge after losing its scenario: bumps would then
merge with nothing exercising them. It reports the harmless direction too, since
a role gaining a scenario without being listed is usually an oversight.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SEH3vxYSQ5SV4N5z61eyGT
This commit is contained in:
Slavi Pantaleev
2026-08-27 18:18:13 +03:00
co-authored by Claude Opus 5
parent 8e53dbf940
commit 2d258cf0e0
4 changed files with 97 additions and 0 deletions
+6
View File
@@ -38,3 +38,9 @@ repos:
language: script
files: '(examples/vars\.yml|roles/custom/matrix_playbook_migration/defaults/main\.yml)'
pass_filenames: false
- id: check-molecule-automerge-list
name: Check the Molecule automerge list matches the roles that have a scenario
entry: bin/check-molecule-automerge-list.py
language: script
files: '(\.github/renovate\.json|roles/custom/[^/]+/molecule/default/molecule\.yml)'
pass_filenames: false