Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 2 additions & 1 deletion .github/renovate.json
Original file line number Diff line number Diff line change
Expand Up @@ -251,9 +251,10 @@
"groupName": "crossplane aws providers"
},
{
"description": "Talos Linux distribution upgrades (tracked by the custom manager above; depName siderolabs/talos). The Go module github.com/siderolabs/talos/pkg/machinery is grouped into the same PR because its version tracks the Talos release line exactly and the repository's Kubernetes/Talos compatibility check reads it, so a Talos bump that arrives without it fails that check. Renovate opens the PR automatically — the same flow as every other dependency, with no Dependency Dashboard approval gate. It is NOT automerged: the custom manager bumps the talos.version pin in ksail.prod.yaml (KSail derives the installer image from it plus the extensions list), but the Hetzner iso snapshot id in ksail.prod.yaml is not a version string and cannot be auto-derived, and a lockstep kubernetesVersion bump may be needed when Talos's supported Kubernetes range moves. CI's system-test also runs off ksail.yaml (docker), so it never boots this prod config. A maintainer completes the iso (and any kubernetesVersion) edit on the open PR, and also sets TALOSCTL_SHA256 in .github/scripts/setup-talosctl.sh: Renovate moves TALOS_VERSION there but cannot compute an asset checksum, so the CI setup step fails closed and, when the served bytes match the release's published sha256sum.txt, prints the exact value to set. prBodyNotes repeats this checklist on every Talos PR. Then merges. automerge:false is placed last so it overrides the broad talos/** and major-update automerge rules above.",
"description": "Talos Linux distribution upgrades (tracked by the custom manager above; depName siderolabs/talos). The Go module github.com/siderolabs/talos/pkg/machinery is grouped into the same PR because its version tracks the Talos release line exactly and the repository's Kubernetes/Talos compatibility check reads it, so a Talos bump that arrives without it fails that check. Renovate opens the PR automatically — the same flow as every other dependency, with no Dependency Dashboard approval gate. It is NOT automerged: the custom manager bumps the talos.version pin in ksail.prod.yaml (KSail derives the installer image from it plus the extensions list), but the Hetzner iso snapshot id in ksail.prod.yaml is not a version string and cannot be auto-derived, and a lockstep kubernetesVersion bump may be needed when Talos's supported Kubernetes range moves. CI's system-test also runs off ksail.yaml (docker), so it never boots this prod config. A maintainer completes the iso (and any kubernetesVersion) edit on the open PR, and also sets TALOSCTL_SHA256 in .github/scripts/setup-talosctl.sh: Renovate moves TALOS_VERSION there but cannot compute an asset checksum, so the CI setup step fails closed and, when the served bytes match the release's published sha256sum.txt, prints the exact value to set. prBodyNotes repeats this checklist on every Talos PR. Then merges. automerge:false is placed last so it overrides the broad talos/** and major-update automerge rules above. separateMinorPatch gives patch releases their own branch (renovate/patch-talos) beside the minor one (renovate/talos): without it Renovate proposes only the newest non-major release, so while a minor upgrade waits on a migration — v1.14 sat parked for weeks — no patch for the running release line is ever offered (#3388).",
"matchPackageNames": ["siderolabs/talos", "github.com/siderolabs/talos/pkg/machinery"],
"groupName": "talos",
"separateMinorPatch": true,
"automerge": false,
"addLabels": ["talos"],
"prBodyNotes": [
Expand Down
Loading