feat: reusable Renovate config validation workflow (renovate-config-validator) #3

Merged
jcabillot merged 4 commits from feat/renovate-config-validate-workflow into main 2026-10-08 17:47:12 -04:00
Owner

But

Ajouter un workflow réutilisable qui valide statiquement un renovate.json avec renovate-config-validator (image officielle renovate/renovate:43) sans jamais lancer Renovate — pour attraper ce qui a gelé le dashboard de tf-depl-kubernetes hier (#419, champ registryUrlsTemplate interdit dans un customManagers entry → config-validation exit 5 sur TOUT le repo).

Ce que ça attrape

  • violations de schéma / champs inconnus
  • champs interdits dans customManagers[] (registryUrlsTemplate vs registryUrls)
  • packageRules / regex matchStrings malformés
  • mauvais extends / ignorePresets

Usage (dans un repo consommateur)

jobs:
  validate:
    uses: perso/gitea-pipelines/.gitea/workflows/validate.yaml@main
    secrets: inherit

Repo sans renovate.json → job vert, message "skipping validation" (non-bloquant).

Implémentation

Single job, image renovate/renovate:43, 2 steps : checkout du repo appelant + renovate-config-validator <file> (path paramétrable via input config_path, défaut renovate.json).

## But Ajouter un workflow réutilisable qui **valide statiquement** un `renovate.json` avec `renovate-config-validator` (image officielle `renovate/renovate:43`) **sans jamais lancer Renovate** — pour attraper ce qui a gelé le dashboard de tf-depl-kubernetes hier (#419, champ `registryUrlsTemplate` interdit dans un customManagers entry → config-validation exit 5 sur TOUT le repo). ## Ce que ça attrape - violations de schéma / champs inconnus - champs interdits dans `customManagers[]` (`registryUrlsTemplate` vs `registryUrls`) - packageRules / regex `matchStrings` malformés - mauvais `extends` / `ignorePresets` ## Usage (dans un repo consommateur) ```yaml jobs: validate: uses: perso/gitea-pipelines/.gitea/workflows/validate.yaml@main secrets: inherit ``` Repo sans `renovate.json` → job vert, message "skipping validation" (non-bloquant). ## Implémentation Single job, image `renovate/renovate:43`, 2 steps : checkout du repo appelant + `renovate-config-validator <file>` (path paramétrable via input `config_path`, défaut `renovate.json`).
opencodecabilloteu added 1 commit 2026-10-08 16:47:13 -04:00
New workflow_call workflow (.gitea/workflows/validate.yaml) that a consumer
repo can call to statically validate its renovate.json with
renovate-config-validator inside the official renovate/renovate image.

What it catches before Renovate runs (avoiding the dashboard-freeze class of
bug seen when an invalid config makes every extract fail):
- schema violations / unknown fields
- forbidden fields in customManagers (e.g. registryUrlsTemplate -
  registryUrls is the only allowed form)
- malformed packageRules / matchStrings regexes
- bad extends / ignorePresets references

It does NOT run Renovate and does NOT touch dependencies - just parses the
config. Non-blocking when the caller has no renovate.json.

Usage in a repo (.gitea/workflows/renovate.yaml or a dedicated workflow):

    jobs:
      validate:
        uses: perso/gitea-pipelines/.gitea/workflows/validate.yaml@main
opencodecabilloteu requested review from jcabillot 2026-10-08 16:47:21 -04:00
opencodecabilloteu added 1 commit 2026-10-08 17:09:22 -04:00
ci: PR checks with central-config validation
PR Checks / hadolint-shim (pull_request) Failing after 4s
Renovate Config Validation / validate (pull_request) Successful in 1m44s
PR Checks / validate-central-config (pull_request) Successful in 1m44s
ad0d215945
opencodecabilloteu added 1 commit 2026-10-08 17:10:07 -04:00
ci: fix PR checks (install pyyaml before parsing)
Renovate Config Validation / validate (pull_request) Successful in 13s
PR Checks / yaml-parse (pull_request) Failing after 14s
PR Checks / validate-central-config (pull_request) Successful in 13s
cb39a2bb38
opencodecabilloteu added 1 commit 2026-10-08 17:11:19 -04:00
ci: PR checks in the renovate image (pyyaml + config validator)
PR Checks / validate (pull_request) Successful in 22s
315ffb0980
jcabillot merged commit 4477bd24f3 into main 2026-10-08 17:47:12 -04:00
jcabillot deleted branch feat/renovate-config-validate-workflow 2026-10-08 17:47:16 -04:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: perso/gitea-pipelines#3