mirror of
https://github.com/spantaleev/matrix-docker-ansible-deploy.git
synced 2026-08-29 12:03:14 +00:00
Three things that would not have scaled to 70 roles: - The Python and Ansible dependency pins were about to be copied into every role. They now live once in molecule-shared/, which scenarios reference relatively, so they cannot drift apart. - The helper container images used for probing were hardcoded inline. They are pinned once in molecule-shared/vars.yml, carry `# renovate:` annotations, and a custom manager in .github/renovate.json keeps them current - verified with a local Renovate dry run, which offers curl 8.11.1 -> 8.21.0 and python 3.13 -> 3.14-alpine. Seventy invisible hardcodes is the blindness class we have been removing elsewhere. - Running a scenario meant knowing the venv and cd incantation. `just molecule <role>` does it, and with no argument lists the roles that have a scenario. Molecule is deliberately not wired into prek: a run takes minutes, pulls images and needs Docker, which is fine on request and not fine per commit. docs/molecule-testing.md covers how to run and write these, including the four things a role here needs that a standalone role does not. AGENTS.md points at it rather than carrying the detail. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
85 lines
3.0 KiB
JSON
85 lines
3.0 KiB
JSON
{
|
|
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
|
|
"extends": [
|
|
"config:recommended",
|
|
"helpers:pinGitHubActionDigests"
|
|
],
|
|
"labels": [
|
|
"dependencies"
|
|
],
|
|
"customManagers": [
|
|
{
|
|
"customType": "regex",
|
|
"managerFilePatterns": [
|
|
"/defaults/main.yml$/"
|
|
],
|
|
"matchStrings": [
|
|
"# renovate: datasource=(?<datasource>[a-z-.]+?) depName=(?<depName>[^\\s]+?)(?: (?:lookupName|packageName)=(?<packageName>[^\\s]+?))?(?: versioning=(?<versioning>[a-z-0-9]+?))?\\s+[A-Za-z0-9_]+?(?:_version|_tag)\\s*:\\s*[\"']?(?<currentValue>.+?)[\"']?\\s"
|
|
]
|
|
},
|
|
{
|
|
"description": "Helper container images used by the Molecule scenarios. They are pinned once in molecule-shared/vars.yml rather than inline in each role's verify.yml, so this manager keeps that single pin current.",
|
|
"customType": "regex",
|
|
"managerFilePatterns": [
|
|
"/^molecule-shared/vars\\.yml$/"
|
|
],
|
|
"matchStrings": [
|
|
"# renovate: datasource=(?<datasource>[a-z-.]+?) depName=(?<depName>[^\\s]+?)\\s+[A-Za-z0-9_]+?\\s*:\\s*[\"'][^:]+:(?<currentValue>[^\"']+)[\"']"
|
|
]
|
|
}
|
|
],
|
|
"packageRules": [
|
|
{
|
|
"ignoreUnstable": false,
|
|
"versioning": "loose",
|
|
"matchSourceUrls": [
|
|
"https://github.com/devture/com.devture.ansible.role{/,}**",
|
|
"https://github.com/mother-of-all-self-hosting{/,}**"
|
|
]
|
|
},
|
|
{
|
|
"description": "mautrix images are dual-tagged (v0.YYMM.PATCH and vYY.MM[.PATCH]). Stick to the v0 scheme: it matches the git tags (needed for self-building) and has a consistent number of components (the calver tags do not, which makes Renovate stop offering updates).",
|
|
"matchPackageNames": [
|
|
"dock.mau.dev/mautrix/**"
|
|
],
|
|
"allowedVersions": "/^v0\\./"
|
|
},
|
|
{
|
|
"description": "Automerge version bumps of roles maintained in the MASH organization and of devture roles (via branch push - no PR)",
|
|
"matchManagers": [
|
|
"ansible-galaxy"
|
|
],
|
|
"matchSourceUrls": [
|
|
"https://github.com/devture/com.devture.ansible.role{/,}**",
|
|
"https://github.com/mother-of-all-self-hosting{/,}**"
|
|
],
|
|
"automerge": true,
|
|
"automergeType": "branch"
|
|
},
|
|
{
|
|
"description": "Housekeeping updates merge via branch push (no PR, no email); a failure on the branch still surfaces as a PR. i18n/requirements.txt bumps are exercised by the Matrix i18n workflow before merging.",
|
|
"matchFileNames": [
|
|
".github/workflows/close-stale-issues.yml",
|
|
".github/workflows/i18n.yml",
|
|
".github/workflows/lock-threads.yml",
|
|
".github/workflows/matrix.yml",
|
|
".github/workflows/update-translations.yml",
|
|
"flake.lock",
|
|
"i18n/requirements.txt",
|
|
"mise.toml"
|
|
],
|
|
"automerge": true,
|
|
"automergeType": "branch"
|
|
}
|
|
],
|
|
"pre-commit": {
|
|
"enabled": true
|
|
},
|
|
"nix": {
|
|
"enabled": true,
|
|
"lockFileMaintenance": {
|
|
"enabled": true
|
|
}
|
|
}
|
|
}
|