Repository navigation
fix(renovate): offer Talos patch releases while a minor upgrade is parked - #4557
Conversation
…rked Renovate proposes only the newest non-major release of a dependency, so while the v1.14 upgrade waits on its migration no patch for the running v1.13 line is offered. separateMinorPatch gives the talos group a second branch for patch releases. Part of #3388 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coderabbitai review |
|
|
Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 33 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configuration
📒 Files selected for processing (1)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
devantler
left a comment
There was a problem hiding this comment.
🤖 Generated by the Agentic Engineer
Self-review (fallback — CodeRabbit, Codex and Cursor Bugbot unavailable)
Reviewed commit: da0d3aed1a5285344fd6fd51340f3dba84bb06fe
- CodeRabbit: rate limited. Its reply to the request at this head (2026-10-06T06:15:52Z) reads "Review rate limited", and its summary says the included reviews are used up.
- Codex: unavailable, usage limit since 2026-10-06T04:40:17Z.
- Cursor Bugbot: unavailable, usage limit since 2026-10-06T04:42:02Z.
Checked:
separateMinorPatchis a valid package-rule option. With agroupName, Renovate prefixes only the patch branch (renovate/patch-talos), so the open minor pull request onrenovate/taloskeeps its branch and is not recreated.- The rule still ends with
automerge: falseand no later rule matches these two packages, so a patch pull request cannot merge by itself. It also inherits the label and the manual checklist, which matters because a merged Talos bump rolls production nodes. - The Go machinery module is in the same rule, so it moves in the same patch pull request and the Kubernetes/Talos compatibility check sees both together.
- The repository-wide seven-day release cooldown still applies to patch releases.
- Not verified by execution: no Renovate dry run was made here. The behaviour is taken from Renovate's documented option and its branch-naming source, and the first Renovate run after merge is the real proof.
Verdict: no P0/P1 findings
Evaluation at
|
Why
Production has been one Talos patch release behind since 2026-10-01, and no update was ever proposed. The dependency bot only offers the newest release it can find, and that is the next minor upgrade, which is parked until its migration is ready. While it waits, security and stability patches for the release line production actually runs never arrive, and the last open acceptance check on the node-drain issue has no patch upgrade to measure.
What
The dependency bot now proposes Talos patch releases in their own pull request, alongside the parked minor upgrade. Patch pull requests keep the same manual checklist and are still never merged automatically.
Part of #3388
👉 After merge/promotion: the bot should open a Talos patch pull request on its next run; that pull request is the upgrade the drain issue is waiting to measure.