Shared Renovate preset for all Alysia repos
Schedule Monday pre-6am Paris, renovate label, patch automerge on green CI, grouped human-review PRs for the Pumpkin pin, velocity proxy and TEMPLATE_REV. Runner config and token procedures documented in README. |
||
|---|---|---|
| default.json | ||
| README.md | ||
renovate-config
Shared Renovate preset for all Alysia repos on https://git.zeto.fr.
Consumer repos opt in with a renovate.json at their root:
{
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
"extends": ["local>alysia/renovate-config"]
}
(The onboarding PR proposes exactly this file; merge it to activate.)
Policy (default.json)
| Rule | Effect |
|---|---|
schedule: before 6am on monday, timezone: Europe/Paris |
Branches/PRs open Monday pre-6am Paris only |
labels: [renovate] |
Every Renovate PR carries the renovate label |
prHourlyLimit: 4 |
At most 4 new PRs per hour (raise at fleet rollout) |
lockFileMaintenance |
Enabled (Cargo.lock refresh PRs, manual merge) |
platformAutomerge: false |
Renovate merges itself only after observing green CI; the platform never merges on its behalf |
| Automerge | patch updates from cargo + dockerfile managers merge once CI is green; everything else is human review |
pumpkin-pin group |
Pumpkin-MC/Pumpkin + pumpkin-plugin-api travel as one PR, never automerged (re-pin checklist in the PR body; smoke must stay green) |
velocity group |
infra/velocity/** + proxy/velocity-mover/** (Dockerfile layers, mover pom) travel together, human review |
ci-template group |
TEMPLATE_REV bumps travel as one PR per repo, human review (re-vendor, never patch locally) |
Managers
Built in: cargo (all Cargo.toml, git deps included where resolvable),
dockerfile (FROM tags), docker-compose (image: tags and digests),
maven (velocity mover pom), rust-toolchain (rust-toolchain.toml channel).
Custom (customManagers, customType: regex):
| Pin file | Tracks | Notes |
|---|---|---|
| `(^ | /)pins.toml (rev+version`) |
github-tags Pumpkin-MC/Pumpkin |
TEMPLATE_REV in .github/workflows/*.yml, ci.yml.*, justfile.ci |
forgejo-tags alysia/alysia-ci-templates on https://git.zeto.fr (tpl- prefix stripped) |
The templates repo itself is excluded from its own example pins. |
pumpkin-plugin-api git rev in Cargo manifests |
— (no independent lookup) | Rides the grouped pumpkin-pin PR; set it to the new rev in the same PR. vendor-freshness CI fails loudly on mismatch, so desync cannot land silently. |
Deliberately manual (no suitable Renovate datasource; both fail loud on drift):
BOTMARK_REV(commit SHA, no usable version anchor in-repo; BotMark tags exist but nothing records the version next to the SHA — the compat patchgit applyfails loudly on drift).- Velocity
ARG VELOCITY_VERSION/VELOCITY_BUILD/VELOCITY_SHA256triple (PaperMC fill API has no Renovate datasource;sha256sum -cin the Dockerfile fails loudly on drift). ${VAR:-default}image defaults ininfra/docker-compose.yml(env indirection is invisible to thedocker-composemanager;alysia/*defaults mirror in-repo builds and must move with them, never independently).
Runner
- Where:
zeto@192.168.1.91, userzeto. Config/brumefer/renovate/config.js(sandbox scope:repositories: ["alysia/alysia-libs"]), token in/brumefer/renovate/renovate.env(0600, never committed). - What:
podman run docker.io/renovate/renovate:44(major-floating slim image, re-pulled before each run), host cargo/rustup mounted for Cargo lockfile updates, cache in/brumefer/renovate/cache. - When: systemd user timer
renovate.timer, Mondays03:30 UTC(always before 6am Paris, summer and winter); the presetschedulegates branch/PR creation on top. - Operate:
- status:
systemctl --user status renovate.timer renovate.service - logs:
journalctl --user -u renovate.service(add--since "last monday") - run now:
systemctl --user start renovate.service(branches/PRs still obey the preset schedule) - enable weekly:
systemctl --user enable --now renovate.timer
- status:
- Token: Forgejo user Settings → Applications → Generate New Token,
name
renovate-<repo>, scopeswrite:repository+write:issue, thenprintf 'RENOVATE_TOKEN=%s\n' '<token>' > /brumefer/renovate/renovate.env && chmod 600it. Token auth cannot mint tokens via API (Forgejo answersauth method not allowed), so this step is UI-only. Optional: addGITHUB_COM_TOKEN=<read-only PAT>on thehostRulesline ofconfig.jsifapi.github.comrate limits appear in logs.
Registry tokens (REGISTRY_TOKEN)
CI pushes images only when the repo carries a REGISTRY_TOKEN secret;
without it the push steps log a skip and the build stays the verified artifact.
Target state: one machine user, one token per repo.
- Create the machine user (admin, once): Forgejo Site Administration →
User Accounts → Create (username e.g.
alysia-ci-push, non-admin), orPOST /admin/userswith basic auth (token auth is rejected for this too). - Grant write per image repo: repo Settings → Collaborators → add
alysia-ci-pushwithwrite, orPUT /repos/{owner}/{repo}/collaborators/{user} {"permission": "push"}. - Mint one token per repo (as
alysia-ci-push, UI-only): Settings → Applications → Generate New Token, nameregistry-<repo>, scopesread:package+write:package(singular —write:packagesis rejected). - Store it: repo Settings → Secrets → Actions →
REGISTRY_TOKEN, orPUT /repos/{owner}/{repo}/actions/secrets/REGISTRY_TOKEN {"data": "<token>"}. - Decision: 1 token per repo, not 1 org token. Forgejo user tokens are user-wide, so repo scoping comes from the machine user's collaborator grants; per-repo tokens add independent rotation/revocation for the cost of one mint call each, and the secret is already per-repo.
Rollout checklist
- Sandbox
alysia/alysia-libs: onboarding PR → merge → firstci-templatePR (tpl-v0.1.0 → tpl-v0.1.1). - Extend
repositoriesin/brumefer/renovate/config.jsrepo by repo (never autodiscover-all). - At fleet scale: raise
prHourlyLimit, add branch protection requiring green CI, mint a dedicatedrenovatebot user, drop patch automerge at the first real player.