From dc4ae52f76935cdd47d58ec42d1685159a645c2c Mon Sep 17 00:00:00 2001 From: Serge Gatezh <2880401+gatezh@users.noreply.github.com> Date: Fri, 14 Aug 2026 12:37:29 -0700 Subject: [PATCH 1/3] docs: describe the four agent tools as pinned, not always-latest MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit #116 pinned rtk, ralphex, the Claude Code CLI and agent-browser as Renovate-managed ARGs, but only the rebuild-cadence wording was corrected. The version-pinning claims were left behind, so several places still told readers these tools float at "latest". - ralphex-fe: replace the three "latest" rows with the pinned versions, and add an Automatic Rebuilds section — the image had no rebuild-trigger docs at all, which is why the stale rows never surfaced in a "daily" grep. Note that an agent-tool bump overwrites the bun-hugo tag instead of minting a new one, since the version tag derives from Bun and Hugo only. - claude-code: drop "Always-latest from GitHub Releases" and "pre-installed at latest"; correct AGENT_BROWSER_VERSION's default and document the three build args that #116 added but never listed. - root: document the Renovate path above the manual dispatch path, and say plainly what stays manual (base images, Bun/Hugo). Refs #119 --- README.md | 9 +++++++++ claude-code/README.md | 12 +++++++++--- ralphex-fe/README.md | 22 +++++++++++++++++++--- 3 files changed, 37 insertions(+), 6 deletions(-) diff --git a/README.md b/README.md index eec5415..36572e1 100644 --- a/README.md +++ b/README.md @@ -152,6 +152,15 @@ Images from this repository are built and published to GitHub Container Registry ## Updating Image Versions +### Automatically, via Renovate + +The agent tooling in the `claude-code` and `ralphex-fe` images — `rtk`, `ralphex`, the Claude Code +CLI, and `agent-browser` — is pinned as `ARG`s carrying `# renovate:` annotations. Renovate watches +their releases and opens a single grouped bump PR when one ships; CI verifies it, it auto-merges, and +that merge rebuilds the affected images. No upstream release means no PR and no rebuild. Scope and +grouping live in [`.github/renovate.json5`](./.github/renovate.json5); the Dependency Dashboard +issue tracks what is pending. Everything else — including base images and Bun/Hugo — stays manual. + ### Via GitHub UI Some images have automated update workflows that allow you to update dependency versions without manually editing Dockerfiles: diff --git a/claude-code/README.md b/claude-code/README.md index 5ce2eef..173c0e9 100644 --- a/claude-code/README.md +++ b/claude-code/README.md @@ -19,7 +19,7 @@ Projects consume these pre-built images and control their own tool versions via | Shell | Fish, Starship, fzf | Built-in syntax highlighting, autosuggestions, completions | | Tools | git-delta, gh CLI, jq, nano, vim, wget, unzip, less, man-db, procps, openssh-client | Standard dev utilities (`openssh-client` provides `ssh`/`ssh-keygen` — enables SSH-format commit signing) | | Mise | The tool manager itself (not the tools) | Projects run `mise install` at container creation for their tool versions | -| rtk, ralphex | Always-latest from GitHub Releases | Dev infrastructure (like Claude Code) — no version pinning needed in projects | +| rtk, ralphex | Pinned `ARG`s, bumped by Renovate on each GitHub release | Dev infrastructure (like Claude Code) — the image tracks the versions so projects don't have to | | Claude Code | npm global install | npm avoids rate limiting that affects the native installer in parallel CI builds | **Both targets:** system Chromium + `fonts-freefont-ttf` (used by Playwright and the Playwright MCP plugin via `/usr/bin/chromium`) @@ -76,7 +76,7 @@ Projects consuming these images need the following files in their repository. ### Required: `.mise.toml` (project root) -Only pin tools that affect project stability — dev infrastructure (rtk, ralphex, Claude Code) is pre-installed in the image at latest. See [`mise.toml`](mise.toml) for a template. +Only pin tools that affect project stability — dev infrastructure (rtk, ralphex, Claude Code) is pre-installed in the image, which tracks their releases for you. See [`mise.toml`](mise.toml) for a template. ### Optional: `.devcontainer/init-plugins.sh` @@ -405,7 +405,13 @@ cat ~/.claude/plugins/cache/claude-plugins-official/playwright/*/.mcp.json | Arg | Default | Description | |-----|---------|-------------| | `GIT_DELTA_VERSION` | `0.18.2` | git-delta version | -| `AGENT_BROWSER_VERSION` | `latest` | agent-browser version (default target only) | +| `RTK_VERSION` | `0.43.0` | rtk version (Renovate-managed) | +| `RALPHEX_VERSION` | `1.6.0` | ralphex version (Renovate-managed) | +| `CLAUDE_CODE_VERSION` | `2.1.216` | Claude Code CLI version (Renovate-managed) | +| `AGENT_BROWSER_VERSION` | `0.32.3` | agent-browser version, default target only (Renovate-managed) | + +The four Renovate-managed args carry `# renovate:` annotations in the Dockerfile; edit them by +hand only for a local build. Bumps land as auto-merged PRs — see [Automatic Rebuilds](#automatic-rebuilds). ## Building Locally / Local Fallback diff --git a/ralphex-fe/README.md b/ralphex-fe/README.md index f248aed..d233faa 100644 --- a/ralphex-fe/README.md +++ b/ralphex-fe/README.md @@ -16,11 +16,15 @@ This is a standalone image, not a devcontainer. | Go | for Hugo Modules | | Python 3 | system | | Playwright + Chromium | native Debian | -| Claude Code CLI | latest | -| RTK | latest (GitHub Releases) | -| Ralphex | latest (GitHub Releases) | +| Claude Code CLI | 2.1.216 (pinned) | +| RTK | 0.43.0 (pinned) | +| Ralphex | 1.6.0 (pinned) | | Git, ripgrep, jq, curl, wget | system | +The pinned versions live as `ARG`s in the Dockerfile and are kept current by Renovate — see +[Automatic Rebuilds](#automatic-rebuilds). Bun and Hugo are bumped manually via the +`update-and-build-ralphex-fe.yml` workflow. + ## Usage ### Via ralphex docker-wrapper @@ -63,6 +67,18 @@ docker build -t ralphex-fe:test ralphex-fe/ Note: this image deviates from the standalone convention of a single primary version tag because it bundles multiple independently-versioned tools. +## Automatic Rebuilds + +The image rebuilds when one of its pinned tools — Claude Code, rtk, or ralphex — publishes a +new release: Renovate opens a version-bump PR against the `ARG`s in the Dockerfile, CI verifies +it, it auto-merges, and that merge triggers the build. No upstream release means no rebuild — +there is no longer a daily cron. Manual rebuilds run from the "Run workflow" button on +**Build ralphex-fe** in the Actions tab. + +Because the version tag is derived from Bun and Hugo only, an agent-tool bump refreshes +`latest` and *overwrites* the existing `bun{VERSION}-hugo{VERSION}` tag rather than creating a +new one. Pull `latest` if you want the current agent tools. + ## Architecture / Provenance | File / Pattern | Source | From 5e3e203d869a32c8de2611c485625c5b89f531fe Mon Sep 17 00:00:00 2001 From: Serge Gatezh <2880401+gatezh@users.noreply.github.com> Date: Fri, 14 Aug 2026 12:50:08 -0700 Subject: [PATCH 2/3] docs: note the Mend Interactive-mode requirement for Renovate MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Installing the app with "All repositories" defaults the repo to Silent mode (dryRun=lookup): Renovate scans and lists updates in the developer portal but creates no PRs and no issues — including the Dependency Dashboard and any config-warning issue. A correct config then looks indistinguishable from a broken one, which is exactly how this repo presented after #116 landed. Record the portal fix and the reason a config change can't substitute for it: mode is overridden by dryRun, which is admin-level. Refs #119 --- README.md | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/README.md b/README.md index 36572e1..0e9ee43 100644 --- a/README.md +++ b/README.md @@ -161,6 +161,14 @@ that merge rebuilds the affected images. No upstream release means no PR and no grouping live in [`.github/renovate.json5`](./.github/renovate.json5); the Dependency Dashboard issue tracks what is pending. Everything else — including base images and Bun/Hugo — stays manual. +> **Setup requirement — the Mend app must be in Interactive mode.** Installing the Renovate app +> with "All repositories" makes Mend default the repo to **Silent** mode (`dryRun=lookup`), where +> it scans and shows updates in the [developer portal](https://developer.mend.io/) but opens no +> PRs and creates no issues — not even the Dependency Dashboard, and not even a config-warning +> issue. The symptom is a correct config that appears to do nothing. Fix it in the portal under +> *Repo Engine Settings → Dependency Updates (Renovate)*; setting `mode` in `renovate.json5` +> cannot override it, because `dryRun` takes precedence over `mode`. + ### Via GitHub UI Some images have automated update workflows that allow you to update dependency versions without manually editing Dockerfiles: From 06b52751b3e606214fa0e39da5537b66cd5a3c23 Mon Sep 17 00:00:00 2001 From: Serge Gatezh <2880401+gatezh@users.noreply.github.com> Date: Fri, 14 Aug 2026 13:11:26 -0700 Subject: [PATCH 3/3] docs: name the actual Mend portal toggles, not "Interactive mode" MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Renovate's docs say to switch to "Interactive mode", but the Mend portal has no such control — it exposes a Silent mode toggle plus Automated PRs, Require config file, and Create onboarding PRs. Give the four toggle values so this is actionable from the UI as it exists. Refs #119 --- README.md | 23 ++++++++++++++++------- 1 file changed, 16 insertions(+), 7 deletions(-) diff --git a/README.md b/README.md index 0e9ee43..fff3e7c 100644 --- a/README.md +++ b/README.md @@ -161,13 +161,22 @@ that merge rebuilds the affected images. No upstream release means no PR and no grouping live in [`.github/renovate.json5`](./.github/renovate.json5); the Dependency Dashboard issue tracks what is pending. Everything else — including base images and Bun/Hugo — stays manual. -> **Setup requirement — the Mend app must be in Interactive mode.** Installing the Renovate app -> with "All repositories" makes Mend default the repo to **Silent** mode (`dryRun=lookup`), where -> it scans and shows updates in the [developer portal](https://developer.mend.io/) but opens no -> PRs and creates no issues — not even the Dependency Dashboard, and not even a config-warning -> issue. The symptom is a correct config that appears to do nothing. Fix it in the portal under -> *Repo Engine Settings → Dependency Updates (Renovate)*; setting `mode` in `renovate.json5` -> cannot override it, because `dryRun` takes precedence over `mode`. +> **Setup requirement — Mend portal toggles.** Installing the Renovate app with "All repositories" +> makes Mend default the repo to **Silent mode** (`dryRun=lookup`), where it scans and shows updates +> in the [developer portal](https://developer.mend.io/) but opens no PRs and creates no issues — not +> even the Dependency Dashboard, and not even a config-warning issue. The symptom is a correct +> config that appears to do nothing. In the portal, under *Repo Engine Settings → Dependency +> Updates*, set: +> +> | Toggle | Value | +> |--------|-------| +> | Silent mode | **off** | +> | Automated PRs | **on** | +> | Require config file | on — with an all-repositories install, this is what keeps Renovate off repos that have no config | +> | Create onboarding PRs | off — this repo already has a config, so no onboarding PR is needed | +> +> Setting `mode` in `renovate.json5` cannot substitute for the Silent-mode toggle, because `dryRun` +> takes precedence over `mode` and is admin-level. ### Via GitHub UI