Commit Graph
11904 Commits
Author SHA1 Message Date
Slavi Pantaleev 08ce234f08 Reserve Renovate slots for automerge branches 2026-08-30 16:04:28 +03:00
Slavi Pantaleev 394298649d Smoke-test Renovate runner updates 2026-08-30 15:57:43 +03:00
mdad-renovate[bot]GitHubmdad-renovate[bot] <322784800+mdad-renovate[bot]@users.noreply.github.com>
b3dcbe863c Lock file maintenance (#5577)
Co-authored-by: mdad-renovate[bot] <322784800+mdad-renovate[bot]@users.noreply.github.com>
2026-08-30 12:50:53 +00:00
mdad-renovate[bot]GitHubmdad-renovate[bot] <322784800+mdad-renovate[bot]@users.noreply.github.com>
cd9e14b9b9 Update matrix-renovate-runner Docker tag to v44.52.0 (#5578)
Co-authored-by: mdad-renovate[bot] <322784800+mdad-renovate[bot]@users.noreply.github.com>
2026-08-30 12:45:35 +00:00
Slavi Pantaleev ec0cecdf13 Pause automatic translation updates 2026-08-30 15:41:18 +03:00
Slavi Pantaleev 5b9d02fb26 Automerge Nix lock file maintenance 2026-08-30 15:35:38 +03:00
Slavi Pantaleev eed42a69bc Run Renovate from GitHub Actions 2026-08-30 15:17:49 +03:00
renovate[bot]andGitHub 543b85adb7 Update dependency traefik_certs_dumper to v2.11.4-1 2026-08-30 10:06:38 +00:00
renovate[bot]andGitHub c36b4989bb Update dependency sphinx-intl to v2.4.0 2026-08-30 06:39:57 +00:00
Slavi Pantaleev 7ef29e3d2d Throttle Renovate requests to mau.dev 2026-08-30 09:37:50 +03:00
renovate[bot]andGitHub d4176d1a67 Update dependency sable to v1.21.0-2 2026-08-29 22:11:48 +00:00
renovate[bot]andGitHub 9d64b48011 Update dependency prometheus_postgres_exporter to v0.20.1-1 2026-08-29 19:02:10 +00:00
renovate[bot]andGitHub 8ccabc46ec Update dependency linkify-it-py to v2.2.0 2026-08-29 13:46:46 +00:00
Slavi Pantaleev 61cd97c105 Test matrix-bot-draupnir with Molecule 2026-08-29 16:45:23 +03:00
Slavi Pantaleev abd3edb669 Test mautrix-meta-instagram with Molecule 2026-08-29 16:45:05 +03:00
Slavi Pantaleev 494589c5af Test matrix-bot-maubot with Molecule 2026-08-29 16:44:48 +03:00
Slavi Pantaleev dec548eb6a Fix Maubot custom URL prefixes 2026-08-29 16:17:09 +03:00
Slavi Pantaleev d8ab746f69 Fix Draupnir for all uninstall path 2026-08-29 16:11:43 +03:00
Slavi Pantaleev 7ce8338281 Fix Draupnir's default Traefik network 2026-08-29 16:10:27 +03:00
Slavi Pantaleev a01df4cc7d Test matrix-client-element with Molecule 2026-08-29 12:55:45 +03:00
Slavi Pantaleev e6ac1dfb94 Test matrix-ketesa with Molecule 2026-08-29 12:54:39 +03:00
Slavi Pantaleev 3f52a5fac7 Test matrix-synapse with Molecule 2026-08-29 12:53:30 +03:00
Slavi Pantaleev f6d33e25ea Use Element's configured port in Traefik labels 2026-08-29 12:17:29 +03:00
Slavi Pantaleev 1d13446c14 Update auxiliary role to v2.0.0-0 2026-08-29 09:00:34 +03:00
Slavi Pantaleev af43d8feaa Document diagnosable Molecule assertions 2026-08-29 08:55:29 +03:00
Slavi Pantaleev c7ac899e0b Test matrix-bridge-mautrix-telegram with Molecule 2026-08-29 08:55:29 +03:00
Slavi Pantaleev 893a3eff4b Test matrix-bridge-mautrix-signal with Molecule 2026-08-29 08:55:29 +03:00
Slavi Pantaleev c5ca73ec93 Test matrix-bridge-postmoogle with Molecule 2026-08-29 08:55:29 +03:00
renovate[bot]andGitHub 0b4fc7998a Update dependency ntfy to v2.28.0-0 2026-08-28 20:39:39 +00:00
renovate[bot]andGitHub 465256ecdb Update docker.io/curlimages/curl Docker tag to v8.21.0 2026-08-28 15:35:05 +00:00
renovate[bot]andGitHub 8c884efd62 Update dependency molecule to v26.8.0 2026-08-28 10:46:52 +00:00
renovate[bot]andGitHub 0c2a007dbd Update dependency ansible to v14.3.1 2026-08-28 05:52:13 +00:00
renovate[bot]andGitHub 90c67d6b47 Update docker.io/library/python Docker tag to v3.14 2026-08-28 03:15:45 +00:00
renovate[bot]andGitHub fe4a32ad7c Update dependency molecule-plugins to v26.7.15 2026-08-28 00:01:57 +00:00
Slavi PantaleevandClaude Opus 5 f6ce120653 Stop running Dependabot alongside Renovate
Both were updating `github-actions` daily, so both proposed the same bumps.
actions/setup-python v7 arrived twice within an hour: Renovate as #5575, Dependabot
as #5576.

Renovate is the one to keep. It pins actions to digests via
`helpers:pinGitHubActionDigests`, so master carries
`actions/setup-python@5fda3b9... # v7`, while Dependabot proposes a bare `@v7` and
would undo that pinning. Renovate's bumps also merge on a branch once CI has run
them, whereas Dependabot's sit outside every automerge rule here and need a human
for each one.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SEH3vxYSQ5SV4N5z61eyGT
2026-08-27 22:10:56 +03:00
renovate[bot]andSlavi Pantaleev 3d381ba790 Update actions/setup-python action to v7 2026-08-27 21:49:55 +03:00
Slavi PantaleevandClaude Opus 5 6cc5de4f19 Run the i18n workflow when the i18n workflow itself changes
Its `paths` filter listed `i18n/**` but not the workflow file, so a change to the
workflow - an action bump, say - triggered nothing. Those bumps automerge on a
branch, so they were merging with nothing having run them.

The Molecule workflow already lists itself for this reason. `update-translations.yml`
cannot do the same: it only runs on pushes to master, and it holds `contents: write`
and `pull-requests: write` to open translation PRs, so running it from a dependency
branch would be worse than not exercising it. Its bumps stay unexercised on purpose,
and a broken one shows up as a failed translations run rather than as anything users
see.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SEH3vxYSQ5SV4N5z61eyGT
2026-08-27 21:41:49 +03:00
Slavi PantaleevandClaude Opus 5 5e9a20a3d2 Correct what the baibot OpenAI API key comment claims
It read "The API key is intentionally not required. Some OpenAI-compatible APIs
do not require a key", while validate_config.yml fails when the key is empty and
the provider is enabled. Enabling the provider against a keyless endpoint stopped
with "You need to define a required configuration setting".

baibot is the authority here, and it agrees with the validation rather than the
comment: `openai::Config` takes `api_key: String`, whereas the provider whose key
really is optional is a different one, `openai_compat`, with
`api_key: Option<String>`. So the comment described a real baibot feature, just
not this provider's.

The validation stays as it is; the comment now says what the code does, and
points at the provider the keyless case belongs to.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SEH3vxYSQ5SV4N5z61eyGT
2026-08-27 21:39:26 +03:00
Slavi PantaleevandClaude Opus 5 928f5d9525 Drop the unreachable Instagram branch from the mautrix-meta-messenger image tag
The image tag prefixed `ig-` when `..._meta_mode` was `instagram`, but this role
does not accept that mode any more: `..._database_suffix` and
`..._bridge_username_prefix` map only `facebook`, `facebook-tor` and `messenger`,
so `instagram` raises an undefined-key error long before the tag is rendered.

Instagram has been a separate bridge since v26.07 and is handled by
matrix-bridge-mautrix-meta-instagram, which hardcodes the prefix. Left over from
before that split.

The comment stays, reworded: both bridges still share a container image
repository, so an `ig-` prefix on a tag here would mean this role had pulled the
other bridge's image - which is what the Molecule scenario asserts against.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SEH3vxYSQ5SV4N5z61eyGT
2026-08-27 18:40:35 +03:00
Slavi PantaleevandClaude Opus 5 31a9d21ca7 Write down what the first wave of Molecule scenarios taught us
Eight scenarios in, the same few things keep deciding whether a scenario is
worth having, and none of them were obvious beforehand:

- Falsify every assertion, not just enough to see red. One control asserted that
  a component emitted no DEBUG records from a module and passed just as happily
  with that module set to `debug`, because it emits none on a first run either
  way. Green for the wrong reason, and only breaking it deliberately showed that.
- `ActiveState == active` with `NRestarts == 0` can both hold while a component
  is completely broken, when it catches its errors and retries rather than
  exiting. Two of the eight behave that way.
- Startup lines are the oldest in the journal, so tailing loses them. Grep, and
  strip ANSI first.
- Parse rendered configuration and assert on structure, so a value under the
  wrong key cannot pass.
- `molecule converge` on a running instance does not restart the container, so a
  falsification can pass for that reason alone.

Also documents that a role's scenario obliges it to join the automerge list, and
that prek enforces the two staying in step.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SEH3vxYSQ5SV4N5z61eyGT
2026-08-27 18:25:26 +03:00
Slavi PantaleevandClaude Opus 5 15429f4a90 Fix the Draupnir Renovate annotations so updates are found again
The annotation read `depName=depName=ghcr.io/...`, so Renovate looked up a
package literally named `depName=ghcr.io/the-draupnir-project/draupnir` and found
nothing. Both Draupnir roles have been invisible to Renovate since v3.0.0 landed
in April, and the dependency dashboard has been reporting it as a repository
problem the whole time:

  Failed to look up docker package
  depName=ghcr.io/the-draupnir-project/draupnir: no-result

Checked every other annotation under roles/custom/ for the same shape; these two
were the only ones.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SEH3vxYSQ5SV4N5z61eyGT
2026-08-27 18:19:02 +03:00
Slavi PantaleevandClaude Opus 5 2d258cf0e0 Automerge patch bumps of components whose role has a Molecule scenario
A component bump touches that role's defaults/main.yml, which is on the Molecule
workflow's path filter, so the change-detection job runs that role's scenario.
The bump therefore only merges once the new version has actually been started on
the configuration the role renders. That is a real gate, and a stronger one than
a human reading a version number in a diff.

Patch only. A minor carries behaviour changes that no static rule can judge - the
MASH fleet tried a minor-automerge preset across 21 stateless roles and reverted
all of them, because reading a given release's notes is what decides it, and that
is a job for a human or an agent rather than a config file.

Branch push rather than a PR, as with the other automerge rules here.

The list has to stay in step with the roles that actually have a scenario, so
bin/check-molecule-automerge-list.py enforces it from prek. The direction that
matters is a role keeping automerge after losing its scenario: bumps would then
merge with nothing exercising them. It reports the harmless direction too, since
a role gaining a scenario without being listed is usually an oversight.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SEH3vxYSQ5SV4N5z61eyGT
2026-08-27 18:18:13 +03:00
Slavi PantaleevandClaude Opus 5 8e53dbf940 Automerge Molecule's own dependency updates
Anything under molecule-shared/ - the helper container images, Postgres, and the
Python pins - is on the Molecule workflow's path filter, and a change to a shared
file makes the detect job run every scenario rather than a subset. So an update
there is already gated on the whole suite passing on its own branch, which is a
stronger check than a human reading the diff.

Branch push rather than a PR, matching how the housekeeping updates in this file
already work: nothing to review and no email on success, and a failure still
surfaces as a PR.

This is also how a new Postgres major reaches us. The bump to the pin runs every
scenario against it before it can merge, so if a component does not cope with the
new major we find out from a failed Renovate branch rather than from a user.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SEH3vxYSQ5SV4N5z61eyGT
2026-08-27 18:02:53 +03:00
Slavi PantaleevandClaude Opus 5 db4eb94058 Set PGDATA explicitly in the Molecule Postgres container, like the role does
The scenarios worked around Postgres 18's data layout change by mounting the
tmpfs at /var/lib/postgresql. The postgres role solved the same problem
differently and better, when it bit us there: it sets PGDATA explicitly, and to
/data rather than anywhere beneath /var/lib/postgresql, because that path is a
VOLUME in the official image and nothing can be mounted under it.

Doing the same here means the scenarios exercise the layout the role actually
deploys, and that a future image changing its own default cannot move the data
directory out from under them.

Ref: https://github.com/docker-library/postgres/pull/1259

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SEH3vxYSQ5SV4N5z61eyGT
2026-08-27 18:02:53 +03:00
Slavi PantaleevandClaude Opus 5 85f80a3c7e Test the Molecule scenarios against Postgres rather than sqlite
`group_vars/matrix_servers` selects postgres whenever postgres is enabled, which
is the default, so postgres is what essentially every deployment runs. The
scenarios were testing sqlite - a path almost nobody is on.

How little that path is used is not a guess: the mautrix-meta bridges could not
start at all under sqlite, and nobody reported it. Testing the engine users are
actually on is worth more than keeping coverage of the one they are not, so no
scenario is left behind on sqlite.

Four of the eight scenarios have a database and are converted; the other four
have none and are untouched.

molecule-shared/tasks/postgres.yml stands Postgres up on the scenario's network,
with the data directory on a tmpfs since it is thrown away with the container.
The image is pinned at the major the postgres role deploys to new installations
and left to Renovate: when a new major lands, the PR bumping that pin runs every
scenario against it, which is the earliest warning we get that a component does
not cope.

Each scenario gives its database and user names that differ from the role's
defaults, so the component reaching the database proves the role built its
connection string out of them. The assertions moved from "a file appeared at the
path we configured" to "these tables exist", which is strictly stronger: tables
can only appear once the component has resolved the hostname, authenticated with
the credentials the role rendered, and run its migrations to completion.

Costs about 10 seconds per affected scenario (115s to 125s locally for
mautrix-whatsapp), on jobs that run in parallel.

Gotcha worth recording: since Postgres 18 the image puts PGDATA in a versioned
subdirectory and refuses to start if it finds a mount at the old
/var/lib/postgresql/data, so the tmpfs is mounted at /var/lib/postgresql.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SEH3vxYSQ5SV4N5z61eyGT
2026-08-27 18:02:53 +03:00
Slavi PantaleevandClaude Opus 5 c447e1528b Reword the Molecule scenario comments
They were hard-wrapped at 80 characters, broke mid-parenthesis, and spent lines
restating what the code below them does.

Rewrapped at natural boundaries instead, with the narration dropped and only the
reasons, gotchas and surprises kept. Section dividers stay - they delineate long
plays rather than narrate them.

Comments only; no scenario behaviour changes.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SEH3vxYSQ5SV4N5z61eyGT
2026-08-27 18:02:53 +03:00
Slavi PantaleevandClaude Opus 5 e2d3be504e Add just molecule-clean
`just molecule` leaves a shared virtualenv of over 500 MB under var/, plus a
~7 MB Ansible home per role that has a scenario. Neither is reclaimed by
anything today.

`--idle-days N` limits it to what has not been touched recently, so it can be
run unattended without taking the cache out from under a scenario being worked
on right now.

The two directories are named explicitly rather than globbed: var/ holds other
things and must never be removed wholesale.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SEH3vxYSQ5SV4N5z61eyGT
2026-08-27 18:02:53 +03:00
Slavi PantaleevandClaude Opus 5 6ad1c9b031 Stop calling hookshot a mautrix bridge in a task name
Hookshot is not one; the name was copied from a mautrix role.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SEH3vxYSQ5SV4N5z61eyGT
2026-08-27 18:02:53 +03:00
Slavi PantaleevandClaude Opus 5 1751246cd1 Point the hookshot jira_oauth_uri deprecation at the right variable
The renamed-variable table mapped `matrix_bridge_hookshot_jira_oauth_uri` to
`..._jira_oauth_client_secret`, the entry above it. Anyone hitting the
deprecation was told to rename their setting to a variable that means something
else entirely; the URI's replacement is `..._jira_oauth_redirect_uri`.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SEH3vxYSQ5SV4N5z61eyGT
2026-08-27 18:02:53 +03:00
Slavi PantaleevandClaude Opus 5 0500127456 Fix the sqlite database URI for the mautrix-meta bridges
Both roles derived `..._appservice_database_uri` as `'sqlite:///' + <path>`.
mautrix-go hands that string to go-sqlite3 as a filename rather than parsing it
as a URL, so the bridge cannot open its database and dies at startup:

  FTL Failed to initialize database
      error="... unable to open database file: no such file or directory"

Every other mautrix bridge role here passes the bare in-container path.

This has stayed hidden because group_vars/matrix_servers selects postgres
whenever postgres is enabled, which is the default - so almost nobody reaches
the sqlite branch. Anyone who does gets a bridge that never starts.

Found by the mautrix-meta-messenger Molecule scenario, which runs sqlite
deliberately. The scenario's override is dropped and its assertion now compares
the rendered URI against the path the role defines, so the derived value is
what is under test rather than the scenario's own.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SEH3vxYSQ5SV4N5z61eyGT
2026-08-27 18:02:53 +03:00