Skip to content

fix(renovate): offer Talos patch releases while a minor upgrade is parked - #4557

Merged
devantler merged 1 commit into
mainfrom
claude/renovate-talos-patch-lane-3388
Oct 6, 2026
Merged

devantler merged 1 commit into
mainfrom
claude/renovate-talos-patch-lane-3388

Conversation

@devantler

Copy link
Copy Markdown
Contributor

🤖 Generated by the Agentic Engineer

Why

Production has been one Talos patch release behind since 2026-10-01, and no update was ever proposed. The dependency bot only offers the newest release it can find, and that is the next minor upgrade, which is parked until its migration is ready. While it waits, security and stability patches for the release line production actually runs never arrive, and the last open acceptance check on the node-drain issue has no patch upgrade to measure.

What

The dependency bot now proposes Talos patch releases in their own pull request, alongside the parked minor upgrade. Patch pull requests keep the same manual checklist and are still never merged automatically.

Part of #3388

👉 After merge/promotion: the bot should open a Talos patch pull request on its next run; that pull request is the upgrade the drain issue is waiting to measure.

…rked

Renovate proposes only the newest non-major release of a dependency, so
while the v1.14 upgrade waits on its migration no patch for the running
v1.13 line is offered. separateMinorPatch gives the talos group a second
branch for patch releases.

Part of #3388

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-project-automation github-project-automation Bot moved this to 🫴 Ready in 🌊 Project Board Oct 6, 2026
@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@coderabbitai

coderabbitai Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 33 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Repository YAML (base), Organization UI (inherited)
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: f5a45577-8edc-4a45-b5d9-040b1a823763
📥 Commits

Reviewing files that changed from the base of the PR and between 79a43aa and da0d3ae.

📒 Files selected for processing (1)
  • .github/renovate.json
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@devantler devantler left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Generated by the Agentic Engineer

Self-review (fallback — CodeRabbit, Codex and Cursor Bugbot unavailable)

Reviewed commit: da0d3aed1a5285344fd6fd51340f3dba84bb06fe

  • CodeRabbit: rate limited. Its reply to the request at this head (2026-10-06T06:15:52Z) reads "Review rate limited", and its summary says the included reviews are used up.
  • Codex: unavailable, usage limit since 2026-10-06T04:40:17Z.
  • Cursor Bugbot: unavailable, usage limit since 2026-10-06T04:42:02Z.

Checked:

  • separateMinorPatch is a valid package-rule option. With a groupName, Renovate prefixes only the patch branch (renovate/patch-talos), so the open minor pull request on renovate/talos keeps its branch and is not recreated.
  • The rule still ends with automerge: false and no later rule matches these two packages, so a patch pull request cannot merge by itself. It also inherits the label and the manual checklist, which matters because a merged Talos bump rolls production nodes.
  • The Go machinery module is in the same rule, so it moves in the same patch pull request and the Kubernetes/Talos compatibility check sees both together.
  • The repository-wide seven-day release cooldown still applies to patch releases.
  • Not verified by execution: no Renovate dry run was made here. The behaviour is taken from Renovate's documented option and its branch-naming source, and the first Renovate run after merge is the real proof.

Verdict: no P0/P1 findings

@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

Evaluation at da0d3aed1a5285344fd6fd51340f3dba84bb06fe

This change has no surface to exercise before it merges. The file is read only by Renovate, and only from the default branch, so nothing here or in CI can run it.

What was checked instead:

  • The file still parses, and the Talos rule now carries the option together with automerge: false, the group name, the label and the checklist. No later rule matches those two packages.
  • Renovate's documented behaviour and its branch-naming source: with the option set, a grouped patch update goes to renovate/patch-talos, and the minor update keeps renovate/talos. The parked pull request chore(deps): update dependency siderolabs/talos to v1.14.0 #4044 is therefore not recreated.
  • The inputs it will act on: production pins Talos v1.13.10, v1.13.11 was published on 2026-10-01, and the seven-day cooldown has passed.

All checks are green at this head, and the review round at this head found nothing.

The real proof is Renovate's next run after merge: it should open a Talos v1.13.11 pull request. If it does not, that is a finding to record on #3388.

@devantler
devantler marked this pull request as ready for review October 6, 2026 06:28
@devantler
devantler added this pull request to the merge queue Oct 6, 2026
Merged via the queue into main with commit 302653c Oct 6, 2026
32 checks passed
@devantler
devantler deleted the claude/renovate-talos-patch-lane-3388 branch October 6, 2026 09:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: ✅ Done

Development

Successfully merging this pull request may close these issues.

1 participant