diff --git a/README.md b/README.md index eec5415..fff3e7c 100644 --- a/README.md +++ b/README.md @@ -152,6 +152,32 @@ Images from this repository are built and published to GitHub Container Registry ## Updating Image Versions +### Automatically, via Renovate + +The agent tooling in the `claude-code` and `ralphex-fe` images — `rtk`, `ralphex`, the Claude Code +CLI, and `agent-browser` — is pinned as `ARG`s carrying `# renovate:` annotations. Renovate watches +their releases and opens a single grouped bump PR when one ships; CI verifies it, it auto-merges, and +that merge rebuilds the affected images. No upstream release means no PR and no rebuild. Scope and +grouping live in [`.github/renovate.json5`](./.github/renovate.json5); the Dependency Dashboard +issue tracks what is pending. Everything else — including base images and Bun/Hugo — stays manual. + +> **Setup requirement — Mend portal toggles.** Installing the Renovate app with "All repositories" +> makes Mend default the repo to **Silent mode** (`dryRun=lookup`), where it scans and shows updates +> in the [developer portal](https://developer.mend.io/) but opens no PRs and creates no issues — not +> even the Dependency Dashboard, and not even a config-warning issue. The symptom is a correct +> config that appears to do nothing. In the portal, under *Repo Engine Settings → Dependency +> Updates*, set: +> +> | Toggle | Value | +> |--------|-------| +> | Silent mode | **off** | +> | Automated PRs | **on** | +> | Require config file | on — with an all-repositories install, this is what keeps Renovate off repos that have no config | +> | Create onboarding PRs | off — this repo already has a config, so no onboarding PR is needed | +> +> Setting `mode` in `renovate.json5` cannot substitute for the Silent-mode toggle, because `dryRun` +> takes precedence over `mode` and is admin-level. + ### Via GitHub UI Some images have automated update workflows that allow you to update dependency versions without manually editing Dockerfiles: diff --git a/claude-code/README.md b/claude-code/README.md index 5ce2eef..173c0e9 100644 --- a/claude-code/README.md +++ b/claude-code/README.md @@ -19,7 +19,7 @@ Projects consume these pre-built images and control their own tool versions via | Shell | Fish, Starship, fzf | Built-in syntax highlighting, autosuggestions, completions | | Tools | git-delta, gh CLI, jq, nano, vim, wget, unzip, less, man-db, procps, openssh-client | Standard dev utilities (`openssh-client` provides `ssh`/`ssh-keygen` — enables SSH-format commit signing) | | Mise | The tool manager itself (not the tools) | Projects run `mise install` at container creation for their tool versions | -| rtk, ralphex | Always-latest from GitHub Releases | Dev infrastructure (like Claude Code) — no version pinning needed in projects | +| rtk, ralphex | Pinned `ARG`s, bumped by Renovate on each GitHub release | Dev infrastructure (like Claude Code) — the image tracks the versions so projects don't have to | | Claude Code | npm global install | npm avoids rate limiting that affects the native installer in parallel CI builds | **Both targets:** system Chromium + `fonts-freefont-ttf` (used by Playwright and the Playwright MCP plugin via `/usr/bin/chromium`) @@ -76,7 +76,7 @@ Projects consuming these images need the following files in their repository. ### Required: `.mise.toml` (project root) -Only pin tools that affect project stability — dev infrastructure (rtk, ralphex, Claude Code) is pre-installed in the image at latest. See [`mise.toml`](mise.toml) for a template. +Only pin tools that affect project stability — dev infrastructure (rtk, ralphex, Claude Code) is pre-installed in the image, which tracks their releases for you. See [`mise.toml`](mise.toml) for a template. ### Optional: `.devcontainer/init-plugins.sh` @@ -405,7 +405,13 @@ cat ~/.claude/plugins/cache/claude-plugins-official/playwright/*/.mcp.json | Arg | Default | Description | |-----|---------|-------------| | `GIT_DELTA_VERSION` | `0.18.2` | git-delta version | -| `AGENT_BROWSER_VERSION` | `latest` | agent-browser version (default target only) | +| `RTK_VERSION` | `0.43.0` | rtk version (Renovate-managed) | +| `RALPHEX_VERSION` | `1.6.0` | ralphex version (Renovate-managed) | +| `CLAUDE_CODE_VERSION` | `2.1.216` | Claude Code CLI version (Renovate-managed) | +| `AGENT_BROWSER_VERSION` | `0.32.3` | agent-browser version, default target only (Renovate-managed) | + +The four Renovate-managed args carry `# renovate:` annotations in the Dockerfile; edit them by +hand only for a local build. Bumps land as auto-merged PRs — see [Automatic Rebuilds](#automatic-rebuilds). ## Building Locally / Local Fallback diff --git a/ralphex-fe/README.md b/ralphex-fe/README.md index f248aed..d233faa 100644 --- a/ralphex-fe/README.md +++ b/ralphex-fe/README.md @@ -16,11 +16,15 @@ This is a standalone image, not a devcontainer. | Go | for Hugo Modules | | Python 3 | system | | Playwright + Chromium | native Debian | -| Claude Code CLI | latest | -| RTK | latest (GitHub Releases) | -| Ralphex | latest (GitHub Releases) | +| Claude Code CLI | 2.1.216 (pinned) | +| RTK | 0.43.0 (pinned) | +| Ralphex | 1.6.0 (pinned) | | Git, ripgrep, jq, curl, wget | system | +The pinned versions live as `ARG`s in the Dockerfile and are kept current by Renovate — see +[Automatic Rebuilds](#automatic-rebuilds). Bun and Hugo are bumped manually via the +`update-and-build-ralphex-fe.yml` workflow. + ## Usage ### Via ralphex docker-wrapper @@ -63,6 +67,18 @@ docker build -t ralphex-fe:test ralphex-fe/ Note: this image deviates from the standalone convention of a single primary version tag because it bundles multiple independently-versioned tools. +## Automatic Rebuilds + +The image rebuilds when one of its pinned tools — Claude Code, rtk, or ralphex — publishes a +new release: Renovate opens a version-bump PR against the `ARG`s in the Dockerfile, CI verifies +it, it auto-merges, and that merge triggers the build. No upstream release means no rebuild — +there is no longer a daily cron. Manual rebuilds run from the "Run workflow" button on +**Build ralphex-fe** in the Actions tab. + +Because the version tag is derived from Bun and Hugo only, an agent-tool bump refreshes +`latest` and *overwrites* the existing `bun{VERSION}-hugo{VERSION}` tag rather than creating a +new one. Pull `latest` if you want the current agent tools. + ## Architecture / Provenance | File / Pattern | Source |