Shared Renovate preset for all Alysia repos
Find a file
Valentin LAMBOLEY-DEPOIRE 5b3a2797d8 feat: shared Renovate preset with Pumpkin, CI-template and velocity policies
Schedule Monday pre-6am Paris, renovate label, patch automerge on green CI, grouped human-review PRs for the Pumpkin pin, velocity proxy and TEMPLATE_REV. Runner config and token procedures documented in README.
2026-10-08 16:12:52 +00:00
default.json feat: shared Renovate preset with Pumpkin, CI-template and velocity policies 2026-10-08 16:12:52 +00:00
README.md feat: shared Renovate preset with Pumpkin, CI-template and velocity policies 2026-10-08 16:12:52 +00:00

renovate-config

Shared Renovate preset for all Alysia repos on https://git.zeto.fr.

Consumer repos opt in with a renovate.json at their root:

{
  "$schema": "https://docs.renovatebot.com/renovate-schema.json",
  "extends": ["local>alysia/renovate-config"]
}

(The onboarding PR proposes exactly this file; merge it to activate.)

Policy (default.json)

Rule Effect
schedule: before 6am on monday, timezone: Europe/Paris Branches/PRs open Monday pre-6am Paris only
labels: [renovate] Every Renovate PR carries the renovate label
prHourlyLimit: 4 At most 4 new PRs per hour (raise at fleet rollout)
lockFileMaintenance Enabled (Cargo.lock refresh PRs, manual merge)
platformAutomerge: false Renovate merges itself only after observing green CI; the platform never merges on its behalf
Automerge patch updates from cargo + dockerfile managers merge once CI is green; everything else is human review
pumpkin-pin group Pumpkin-MC/Pumpkin + pumpkin-plugin-api travel as one PR, never automerged (re-pin checklist in the PR body; smoke must stay green)
velocity group infra/velocity/** + proxy/velocity-mover/** (Dockerfile layers, mover pom) travel together, human review
ci-template group TEMPLATE_REV bumps travel as one PR per repo, human review (re-vendor, never patch locally)

Managers

Built in: cargo (all Cargo.toml, git deps included where resolvable), dockerfile (FROM tags), docker-compose (image: tags and digests), maven (velocity mover pom), rust-toolchain (rust-toolchain.toml channel).

Custom (customManagers, customType: regex):

Pin file Tracks Notes
`(^ /)pins.toml (rev+version`) github-tags Pumpkin-MC/Pumpkin
TEMPLATE_REV in .github/workflows/*.yml, ci.yml.*, justfile.ci forgejo-tags alysia/alysia-ci-templates on https://git.zeto.fr (tpl- prefix stripped) The templates repo itself is excluded from its own example pins.
pumpkin-plugin-api git rev in Cargo manifests — (no independent lookup) Rides the grouped pumpkin-pin PR; set it to the new rev in the same PR. vendor-freshness CI fails loudly on mismatch, so desync cannot land silently.

Deliberately manual (no suitable Renovate datasource; both fail loud on drift):

  • BOTMARK_REV (commit SHA, no usable version anchor in-repo; BotMark tags exist but nothing records the version next to the SHA — the compat patch git apply fails loudly on drift).
  • Velocity ARG VELOCITY_VERSION/VELOCITY_BUILD/VELOCITY_SHA256 triple (PaperMC fill API has no Renovate datasource; sha256sum -c in the Dockerfile fails loudly on drift).
  • ${VAR:-default} image defaults in infra/docker-compose.yml (env indirection is invisible to the docker-compose manager; alysia/* defaults mirror in-repo builds and must move with them, never independently).

Runner

  • Where: zeto@192.168.1.91, user zeto. Config /brumefer/renovate/config.js (sandbox scope: repositories: ["alysia/alysia-libs"]), token in /brumefer/renovate/renovate.env (0600, never committed).
  • What: podman run docker.io/renovate/renovate:44 (major-floating slim image, re-pulled before each run), host cargo/rustup mounted for Cargo lockfile updates, cache in /brumefer/renovate/cache.
  • When: systemd user timer renovate.timer, Mondays 03:30 UTC (always before 6am Paris, summer and winter); the preset schedule gates branch/PR creation on top.
  • Operate:
    • status: systemctl --user status renovate.timer renovate.service
    • logs: journalctl --user -u renovate.service (add --since "last monday")
    • run now: systemctl --user start renovate.service (branches/PRs still obey the preset schedule)
    • enable weekly: systemctl --user enable --now renovate.timer
  • Token: Forgejo user Settings → Applications → Generate New Token, name renovate-<repo>, scopes write:repository + write:issue, then printf 'RENOVATE_TOKEN=%s\n' '<token>' > /brumefer/renovate/renovate.env && chmod 600 it. Token auth cannot mint tokens via API (Forgejo answers auth method not allowed), so this step is UI-only. Optional: add GITHUB_COM_TOKEN=<read-only PAT> on the hostRules line of config.js if api.github.com rate limits appear in logs.

Registry tokens (REGISTRY_TOKEN)

CI pushes images only when the repo carries a REGISTRY_TOKEN secret; without it the push steps log a skip and the build stays the verified artifact. Target state: one machine user, one token per repo.

  • Create the machine user (admin, once): Forgejo Site Administration → User Accounts → Create (username e.g. alysia-ci-push, non-admin), or POST /admin/users with basic auth (token auth is rejected for this too).
  • Grant write per image repo: repo Settings → Collaborators → add alysia-ci-push with write, or PUT /repos/{owner}/{repo}/collaborators/{user} {"permission": "push"}.
  • Mint one token per repo (as alysia-ci-push, UI-only): Settings → Applications → Generate New Token, name registry-<repo>, scopes read:package + write:package (singular — write:packages is rejected).
  • Store it: repo Settings → Secrets → Actions → REGISTRY_TOKEN, or PUT /repos/{owner}/{repo}/actions/secrets/REGISTRY_TOKEN {"data": "<token>"}.
  • Decision: 1 token per repo, not 1 org token. Forgejo user tokens are user-wide, so repo scoping comes from the machine user's collaborator grants; per-repo tokens add independent rotation/revocation for the cost of one mint call each, and the secret is already per-repo.

Rollout checklist

  1. Sandbox alysia/alysia-libs: onboarding PR → merge → first ci-template PR (tpl-v0.1.0 → tpl-v0.1.1).
  2. Extend repositories in /brumefer/renovate/config.js repo by repo (never autodiscover-all).
  3. At fleet scale: raise prHourlyLimit, add branch protection requiring green CI, mint a dedicated renovate bot user, drop patch automerge at the first real player.