From 7feede33979ad149197c25d83151e1e123355a72 Mon Sep 17 00:00:00 2001 From: Benjamin Ritter Date: Fri, 21 Aug 2026 16:27:15 +0200 Subject: [PATCH 1/4] feat: add renovate Add renovate running as a github action Updates go packages and the go version in go.mod, github actions and docker images. Signed-off-by: Benjamin Ritter --- .github/renovate.json5 | 43 +++++++++++++++++++++++++++++ .github/workflows/renovate.yaml | 49 +++++++++++++++++++++++++++++++++ Makefile | 3 ++ 3 files changed, 95 insertions(+) create mode 100644 .github/renovate.json5 create mode 100644 .github/workflows/renovate.yaml diff --git a/.github/renovate.json5 b/.github/renovate.json5 new file mode 100644 index 00000000..592d09e4 --- /dev/null +++ b/.github/renovate.json5 @@ -0,0 +1,43 @@ +{ + $schema: "https://docs.renovatebot.com/renovate-schema.json", + extends: [ + "config:recommended", + ], + labels: ["dependencies"], + postUpdateOptions: ["gomodTidy"], + packageRules: [ + { + // Make sure to update go in the Makefile, go.mod and workflows + groupName: "golang", + matchDatasources: ["docker", "golang-version"], + matchPackageNames: ["go", "golang"], + }, + { + // Make sure the K8s library versions line up + groupName: "kubernetes", + matchManagers: ["gomod"], + matchPackageNames: [ + "k8s.io/**", + "sigs.k8s.io/controller-runtime", + "sigs.k8s.io/controller-tools", + ], + }, + { + // Combine github actions updates + groupName: "github-actions", + matchManagers: ["github-actions"], + }, + ], + customManagers: [ + { + // Tool versions pinned in the Makefile, annotated with + // "# renovate: datasource=... depName=..." right above them. + // Stolen from https://docs.renovatebot.com/presets-customManagers/ + customType: "regex", + managerFilePatterns: ["/^Makefile$/"], + matchStrings: [ + "#\\s*renovate:\\s*datasource=(?\\S+)\\s+depName=(?\\S+)(?:\\s+versioning=(?\\S+))?(?:\\s+extractVersion=(?\\S+))?\\s*\\n\\s*[A-Z_]+\\s*[:?]?=\\s*(?\\S+)", + ], + }, + ], +} diff --git a/.github/workflows/renovate.yaml b/.github/workflows/renovate.yaml new file mode 100644 index 00000000..1102ab5f --- /dev/null +++ b/.github/workflows/renovate.yaml @@ -0,0 +1,49 @@ +--- +name: Renovate + +on: + schedule: + # Every day at 04:00 UTC. + - cron: '0 4 * * *' + workflow_dispatch: + inputs: + logLevel: + description: 'Renovate log level' + required: false + default: 'info' + type: choice + options: + - info + - debug + dryRun: + description: 'Run without creating branches, PRs or issues' + required: false + default: false + type: boolean + +concurrency: + group: renovate + cancel-in-progress: false + +jobs: + renovate: + runs-on: ubuntu-latest + permissions: + pull-requests: write + contents: read + steps: + - name: Renovate + uses: renovatebot/github-action@v46.2.2 + with: {} + # Needs a PAT (repo + workflow scope) or a GitHub App token, not the + # default GITHUB_TOKEN: that one may neither update files below + # .github/workflows nor trigger the CI workflows on the PRs it opens. + # Currently disabled for testing purposes + # token: ${{ secrets.RENOVATE_TOKEN }} + env: + RENOVATE_REPOSITORIES: ${{ github.repository }} + # Configuration lives in .github/renovate.json5, no onboarding PR. + RENOVATE_ONBOARDING: 'false' + RENOVATE_REQUIRE_CONFIG: 'required' + RENOVATE_DRY_RUN: ${{ inputs.dryRun && 'full' || 'null' }} + LOG_LEVEL: ${{ inputs.logLevel || 'info' }} diff --git a/Makefile b/Makefile index 8b43f025..cda65b62 100644 --- a/Makefile +++ b/Makefile @@ -16,9 +16,11 @@ BUILDDATE := $(shell date -Iseconds) VERSION := $(or ${DOCKER_TAG},latest) LOCALBIN ?= $(shell pwd)/bin CONTROLLER_GEN ?= $(LOCALBIN)/controller-gen +# renovate: datasource=go depName=sigs.k8s.io/controller-tools CONTROLLER_TOOLS_VERSION ?= v0.14.0 # Postgres operator variables for YAML download +# renovate: datasource=github-releases depName=zalando/postgres-operator POSTGRES_OPERATOR_VERSION ?= v1.15.1 POSTGRES_OPERATOR_URL ?= https://raw.githubusercontent.com/zalando/postgres-operator/$(POSTGRES_OPERATOR_VERSION)/manifests POSTGRES_CRD_URL ?= https://raw.githubusercontent.com/zalando/postgres-operator/$(POSTGRES_OPERATOR_VERSION)/charts/postgres-operator/crds/postgresqls.yaml @@ -185,6 +187,7 @@ localkube-install-crd-cwnp: crd-cwnp-for-testing: curl https://raw.githubusercontent.com/metal-stack/firewall-controller/master/config/crd/bases/metal-stack.io_clusterwidenetworkpolicies.yaml -o external/test/crd-clusterwidenetworkpolicy.yaml +# renovate: datasource=github-releases depName=kubernetes-sigs/kubebuilder extractVersion=^v(?.*)$ KUBEBUILDER_VERSION:=3.2.0 kubebuilder: ifeq (,$(wildcard ~/.kubebuilder/${KUBEBUILDER_VERSION})) From f2a603750e761e92935a192fc3fad96ea107ab61 Mon Sep 17 00:00:00 2001 From: Benjamin Ritter Date: Fri, 21 Aug 2026 16:53:00 +0200 Subject: [PATCH 2/4] fix: add zalando postgres operator versioning group Signed-off-by: Benjamin Ritter --- .github/renovate.json5 | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/.github/renovate.json5 b/.github/renovate.json5 index 592d09e4..b2bb66b3 100644 --- a/.github/renovate.json5 +++ b/.github/renovate.json5 @@ -22,6 +22,15 @@ "sigs.k8s.io/controller-tools", ], }, + { + // The zalando postgres-operator is both a go dependency and the source + // of the YAML manifests downloaded via the Makefile + groupName: "zalando postgres-operator", + matchPackageNames: [ + "github.com/zalando/postgres-operator", + "zalando/postgres-operator", + ], + }, { // Combine github actions updates groupName: "github-actions", From d1863656c5b7eeee7486f27e7b777f70b0f0e90f Mon Sep 17 00:00:00 2001 From: Benjamin Ritter Date: Fri, 21 Aug 2026 16:53:29 +0200 Subject: [PATCH 3/4] fix: fix controller-tools not being versioned together with the other k8s deps Signed-off-by: Benjamin Ritter --- .github/renovate.json5 | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/.github/renovate.json5 b/.github/renovate.json5 index b2bb66b3..a3cc5845 100644 --- a/.github/renovate.json5 +++ b/.github/renovate.json5 @@ -13,9 +13,11 @@ matchPackageNames: ["go", "golang"], }, { - // Make sure the K8s library versions line up + // Make sure the K8s library versions line up. Consciously not scoped to + // matchManagers "gomod": controller-tools is pinned in the Makefile and + // picked up by the custom manager below, so a gomod scope would leave it + // out of the group groupName: "kubernetes", - matchManagers: ["gomod"], matchPackageNames: [ "k8s.io/**", "sigs.k8s.io/controller-runtime", From 287506442f281818d139118a045e4c2cbf4f2258 Mon Sep 17 00:00:00 2001 From: Benjamin Ritter Date: Fri, 21 Aug 2026 17:01:16 +0200 Subject: [PATCH 4/4] WIP: dry-run test via github actions Signed-off-by: Benjamin Ritter --- .github/workflows/renovate.yaml | 18 +++++++++++++----- 1 file changed, 13 insertions(+), 5 deletions(-) diff --git a/.github/workflows/renovate.yaml b/.github/workflows/renovate.yaml index 1102ab5f..d17b5cb1 100644 --- a/.github/workflows/renovate.yaml +++ b/.github/workflows/renovate.yaml @@ -5,6 +5,9 @@ on: schedule: # Every day at 04:00 UTC. - cron: '0 4 * * *' + push: + branches: + - feat/renovate workflow_dispatch: inputs: logLevel: @@ -29,12 +32,16 @@ jobs: renovate: runs-on: ubuntu-latest permissions: - pull-requests: write contents: read + pull-requests: read steps: + # Only required for testing on push + - name: Checkout + uses: actions/checkout@v4 - name: Renovate uses: renovatebot/github-action@v46.2.2 - with: {} + with: + configurationFile: .github/renovate.json5 # Needs a PAT (repo + workflow scope) or a GitHub App token, not the # default GITHUB_TOKEN: that one may neither update files below # .github/workflows nor trigger the CI workflows on the PRs it opens. @@ -42,8 +49,9 @@ jobs: # token: ${{ secrets.RENOVATE_TOKEN }} env: RENOVATE_REPOSITORIES: ${{ github.repository }} - # Configuration lives in .github/renovate.json5, no onboarding PR. + RENOVATE_TOKEN: ${{ secrets.GITHUB_TOKEN }} RENOVATE_ONBOARDING: 'false' - RENOVATE_REQUIRE_CONFIG: 'required' - RENOVATE_DRY_RUN: ${{ inputs.dryRun && 'full' || 'null' }} + RENOVATE_REQUIRE_CONFIG: ${{ github.event_name == 'push' && 'optional' || 'required' }} + RENOVATE_BASE_BRANCH_PATTERNS: ${{ github.event_name == 'push' && github.ref_name || '' }} + RENOVATE_DRY_RUN: ${{ github.event_name == 'push' && 'full' || (inputs.dryRun && 'full' || 'null') }} LOG_LEVEL: ${{ inputs.logLevel || 'info' }}