mirror of
https://github.com/spantaleev/matrix-docker-ansible-deploy.git
synced 2026-08-29 20:13:13 +00:00
Anything under molecule-shared/ - the helper container images, Postgres, and the Python pins - is on the Molecule workflow's path filter, and a change to a shared file makes the detect job run every scenario rather than a subset. So an update there is already gated on the whole suite passing on its own branch, which is a stronger check than a human reading the diff. Branch push rather than a PR, matching how the housekeeping updates in this file already work: nothing to review and no email on success, and a failure still surfaces as a PR. This is also how a new Postgres major reaches us. The bump to the pin runs every scenario against it before it can merge, so if a component does not cope with the new major we find out from a failed Renovate branch rather than from a user. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SEH3vxYSQ5SV4N5z61eyGT
94 lines
3.6 KiB
JSON
94 lines
3.6 KiB
JSON
{
|
|
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
|
|
"extends": [
|
|
"config:recommended",
|
|
"helpers:pinGitHubActionDigests"
|
|
],
|
|
"labels": [
|
|
"dependencies"
|
|
],
|
|
"customManagers": [
|
|
{
|
|
"customType": "regex",
|
|
"managerFilePatterns": [
|
|
"/defaults/main.yml$/"
|
|
],
|
|
"matchStrings": [
|
|
"# renovate: datasource=(?<datasource>[a-z-.]+?) depName=(?<depName>[^\\s]+?)(?: (?:lookupName|packageName)=(?<packageName>[^\\s]+?))?(?: versioning=(?<versioning>[a-z-0-9]+?))?\\s+[A-Za-z0-9_]+?(?:_version|_tag)\\s*:\\s*[\"']?(?<currentValue>.+?)[\"']?\\s"
|
|
]
|
|
},
|
|
{
|
|
"description": "Helper container images used by the Molecule scenarios. They are pinned once in molecule-shared/vars.yml rather than inline in each role's verify.yml, so this manager keeps that single pin current.",
|
|
"customType": "regex",
|
|
"managerFilePatterns": [
|
|
"/^molecule-shared/vars\\.yml$/"
|
|
],
|
|
"matchStrings": [
|
|
"# renovate: datasource=(?<datasource>[a-z-.]+?) depName=(?<depName>[^\\s]+?)\\s+[A-Za-z0-9_]+?\\s*:\\s*[\"'][^:]+:(?<currentValue>[^\"']+)[\"']"
|
|
]
|
|
}
|
|
],
|
|
"packageRules": [
|
|
{
|
|
"ignoreUnstable": false,
|
|
"versioning": "loose",
|
|
"matchSourceUrls": [
|
|
"https://github.com/devture/com.devture.ansible.role{/,}**",
|
|
"https://github.com/mother-of-all-self-hosting{/,}**"
|
|
]
|
|
},
|
|
{
|
|
"description": "mautrix images are dual-tagged (v0.YYMM.PATCH and vYY.MM[.PATCH]). Stick to the v0 scheme: it matches the git tags (needed for self-building) and has a consistent number of components (the calver tags do not, which makes Renovate stop offering updates).",
|
|
"matchPackageNames": [
|
|
"dock.mau.dev/mautrix/**"
|
|
],
|
|
"allowedVersions": "/^v0\\./"
|
|
},
|
|
{
|
|
"description": "Automerge version bumps of roles maintained in the MASH organization and of devture roles (via branch push - no PR)",
|
|
"matchManagers": [
|
|
"ansible-galaxy"
|
|
],
|
|
"matchSourceUrls": [
|
|
"https://github.com/devture/com.devture.ansible.role{/,}**",
|
|
"https://github.com/mother-of-all-self-hosting{/,}**"
|
|
],
|
|
"automerge": true,
|
|
"automergeType": "branch"
|
|
},
|
|
{
|
|
"description": "Housekeeping updates merge via branch push (no PR, no email); a failure on the branch still surfaces as a PR. i18n/requirements.txt bumps are exercised by the Matrix i18n workflow before merging.",
|
|
"matchFileNames": [
|
|
".github/workflows/close-stale-issues.yml",
|
|
".github/workflows/i18n.yml",
|
|
".github/workflows/lock-threads.yml",
|
|
".github/workflows/matrix.yml",
|
|
".github/workflows/update-translations.yml",
|
|
"flake.lock",
|
|
"i18n/requirements.txt",
|
|
"mise.toml"
|
|
],
|
|
"automerge": true,
|
|
"automergeType": "branch"
|
|
},
|
|
{
|
|
"description": "Molecule's own dependencies merge via branch push (no PR, no email). Anything under molecule-shared/ - the helper container images, Postgres, and the Python pins - triggers the Molecule workflow, and a change to a shared file makes it run every scenario, so an update only merges once the whole suite has passed on it. A failure surfaces as a PR instead. This is how a new Postgres major reaches us: the bump runs every scenario against it before anything is merged.",
|
|
"matchFileNames": [
|
|
"molecule-shared/**",
|
|
".github/workflows/molecule.yml"
|
|
],
|
|
"automerge": true,
|
|
"automergeType": "branch"
|
|
}
|
|
],
|
|
"pre-commit": {
|
|
"enabled": true
|
|
},
|
|
"nix": {
|
|
"enabled": true,
|
|
"lockFileMaintenance": {
|
|
"enabled": true
|
|
}
|
|
}
|
|
}
|