diff --git a/.github/renovate.json b/.github/renovate.json index 00bc7a77e..aadc6b88b 100644 --- a/.github/renovate.json +++ b/.github/renovate.json @@ -4,7 +4,43 @@ "github>rancher/renovate-config#release" ], "baseBranchPatterns": [ - "main" + "main", + "v2.15", + "v2.14", + "v2.13", + "v2.12", + "v2.11" + ], + "packageRules": [ + { + "matchBaseBranches": ["main"], + "extends": ["github>rancher/renovate-config//rancher-main#release"] + }, + { + "description": "Apply Rancher 2.15 update constraints to branch v2.15.", + "matchBaseBranches": ["v2.15"], + "extends": ["github>rancher/renovate-config//rancher-2.15#release"] + }, + { + "description": "Apply Rancher 2.14 update constraints to branch v2.14.", + "matchBaseBranches": ["v2.14"], + "extends": ["github>rancher/renovate-config//rancher-2.14#release"] + }, + { + "description": "Apply Rancher 2.13 update constraints to branch v2.13.", + "matchBaseBranches": ["v2.13"], + "extends": ["github>rancher/renovate-config//rancher-2.13#release"] + }, + { + "description": "Apply Rancher 2.12 update constraints to branch v2.12.", + "matchBaseBranches": ["v2.12"], + "extends": ["github>rancher/renovate-config//rancher-2.12#release"] + }, + { + "description": "Apply Rancher 2.11 update constraints to branch v2.11.", + "matchBaseBranches": ["v2.11"], + "extends": ["github>rancher/renovate-config//rancher-2.11#release"] + } ], "prHourlyLimit": 2 } diff --git a/.github/workflows/renovate-vault.yml b/.github/workflows/renovate-vault.yml index e9e9ad0a0..81e1fae3b 100644 --- a/.github/workflows/renovate-vault.yml +++ b/.github/workflows/renovate-vault.yml @@ -36,28 +36,29 @@ on: required: false default: "null" type: string - extendsPreset: - description: "Override renovate extends preset (default: 'github>rancher/renovate-config#release')." - required: false - default: "github>rancher/renovate-config#release" - type: string schedule: - cron: '30 4,6 * * 1-5' -permissions: - contents: read - id-token: write +permissions: {} jobs: call-workflow: - uses: rancher/renovate-config/.github/workflows/renovate-vault.yml@a2fdde843b32ac3423f7a37c3211deadff0df147 # release + permissions: + contents: read + id-token: write # Required for Vault OIDC authentication. + # https://github.com/rancher/renovate-config/releases + uses: rancher/renovate-config/.github/workflows/renovate-vault.yml@b20e059a3642b4f6add6f9db276349daca5ea54e # v1.0.10 + # Note: github.event.inputs. with '||' fallbacks is used across all inputs + # so that scheduled cron runs (where github.event.inputs is null) safely default. with: - configMigration: ${{ inputs.configMigration || 'true' }} - logLevel: ${{ inputs.logLevel || 'info' }} - overrideSchedule: ${{ github.event.inputs.overrideSchedule == 'true' && '{''schedule'':null}' || '' }} - renovateConfig: ${{ inputs.renovateConfig || '.github/renovate.json' }} - minimumReleaseAge: ${{ inputs.minimumReleaseAge || 'null' }} - extendsPreset: ${{ inputs.extendsPreset || 'github>rancher/renovate-config#release' }} + configMigration: ${{ github.event.inputs.configMigration || 'true' }} + logLevel: ${{ github.event.inputs.logLevel || 'info' }} + overrideSchedule: ${{ github.event.inputs.overrideSchedule || 'false' }} + renovateConfig: ${{ github.event.inputs.renovateConfig || '.github/renovate.json' }} + minimumReleaseAge: ${{ github.event.inputs.minimumReleaseAge || 'null' }} secrets: + # Optional: RENOVATE_FORK_GH_TOKEN allows this action to run on repository forks where + # Vault/App token generation is unavailable. Defaulting to '' allows the caller to + # fall back gracefully on standard runs without failing secret evaluation. override-token: "${{ secrets.RENOVATE_FORK_GH_TOKEN || '' }}"