From ab106e6f7ae3f7281ca00e3c44b154831f85d2e4 Mon Sep 17 00:00:00 2001 From: Tim Hardeck Date: Thu, 24 Sep 2026 06:01:35 +0200 Subject: [PATCH 1/2] Add Renovate support for release branches Configure Renovate to maintain also supported `v2.x` branches. Apply matching Rancher presets so each release gets version-specific constraints and dependency bumps stay within release policy. --- .github/renovate.json | 38 +++++++++++++++++++++++++++++++++++++- 1 file changed, 37 insertions(+), 1 deletion(-) diff --git a/.github/renovate.json b/.github/renovate.json index 00bc7a77e..aadc6b88b 100644 --- a/.github/renovate.json +++ b/.github/renovate.json @@ -4,7 +4,43 @@ "github>rancher/renovate-config#release" ], "baseBranchPatterns": [ - "main" + "main", + "v2.15", + "v2.14", + "v2.13", + "v2.12", + "v2.11" + ], + "packageRules": [ + { + "matchBaseBranches": ["main"], + "extends": ["github>rancher/renovate-config//rancher-main#release"] + }, + { + "description": "Apply Rancher 2.15 update constraints to branch v2.15.", + "matchBaseBranches": ["v2.15"], + "extends": ["github>rancher/renovate-config//rancher-2.15#release"] + }, + { + "description": "Apply Rancher 2.14 update constraints to branch v2.14.", + "matchBaseBranches": ["v2.14"], + "extends": ["github>rancher/renovate-config//rancher-2.14#release"] + }, + { + "description": "Apply Rancher 2.13 update constraints to branch v2.13.", + "matchBaseBranches": ["v2.13"], + "extends": ["github>rancher/renovate-config//rancher-2.13#release"] + }, + { + "description": "Apply Rancher 2.12 update constraints to branch v2.12.", + "matchBaseBranches": ["v2.12"], + "extends": ["github>rancher/renovate-config//rancher-2.12#release"] + }, + { + "description": "Apply Rancher 2.11 update constraints to branch v2.11.", + "matchBaseBranches": ["v2.11"], + "extends": ["github>rancher/renovate-config//rancher-2.11#release"] + } ], "prHourlyLimit": 2 } From 81fc5fa87a9e31e6d1d2f1ef35b43db1cd135014 Mon Sep 17 00:00:00 2001 From: Tim Hardeck Date: Thu, 24 Sep 2026 06:01:40 +0200 Subject: [PATCH 2/2] Update Renovate Vault workflow Align `.github/workflows/renovate-vault.yml` with the reusable workflow from `rancher/renovate-config` at `v1.0.10`. --- .github/workflows/renovate-vault.yml | 31 ++++++++++++++-------------- 1 file changed, 16 insertions(+), 15 deletions(-) diff --git a/.github/workflows/renovate-vault.yml b/.github/workflows/renovate-vault.yml index e9e9ad0a0..81e1fae3b 100644 --- a/.github/workflows/renovate-vault.yml +++ b/.github/workflows/renovate-vault.yml @@ -36,28 +36,29 @@ on: required: false default: "null" type: string - extendsPreset: - description: "Override renovate extends preset (default: 'github>rancher/renovate-config#release')." - required: false - default: "github>rancher/renovate-config#release" - type: string schedule: - cron: '30 4,6 * * 1-5' -permissions: - contents: read - id-token: write +permissions: {} jobs: call-workflow: - uses: rancher/renovate-config/.github/workflows/renovate-vault.yml@a2fdde843b32ac3423f7a37c3211deadff0df147 # release + permissions: + contents: read + id-token: write # Required for Vault OIDC authentication. + # https://github.com/rancher/renovate-config/releases + uses: rancher/renovate-config/.github/workflows/renovate-vault.yml@b20e059a3642b4f6add6f9db276349daca5ea54e # v1.0.10 + # Note: github.event.inputs. with '||' fallbacks is used across all inputs + # so that scheduled cron runs (where github.event.inputs is null) safely default. with: - configMigration: ${{ inputs.configMigration || 'true' }} - logLevel: ${{ inputs.logLevel || 'info' }} - overrideSchedule: ${{ github.event.inputs.overrideSchedule == 'true' && '{''schedule'':null}' || '' }} - renovateConfig: ${{ inputs.renovateConfig || '.github/renovate.json' }} - minimumReleaseAge: ${{ inputs.minimumReleaseAge || 'null' }} - extendsPreset: ${{ inputs.extendsPreset || 'github>rancher/renovate-config#release' }} + configMigration: ${{ github.event.inputs.configMigration || 'true' }} + logLevel: ${{ github.event.inputs.logLevel || 'info' }} + overrideSchedule: ${{ github.event.inputs.overrideSchedule || 'false' }} + renovateConfig: ${{ github.event.inputs.renovateConfig || '.github/renovate.json' }} + minimumReleaseAge: ${{ github.event.inputs.minimumReleaseAge || 'null' }} secrets: + # Optional: RENOVATE_FORK_GH_TOKEN allows this action to run on repository forks where + # Vault/App token generation is unavailable. Defaulting to '' allows the caller to + # fall back gracefully on standard runs without failing secret evaluation. override-token: "${{ secrets.RENOVATE_FORK_GH_TOKEN || '' }}"