From 1c11bfaf4de14ccdaa17b1ac5200904582f4a42d Mon Sep 17 00:00:00 2001 From: Serge Gatezh <2880401+gatezh@users.noreply.github.com> Date: Wed, 9 Sep 2026 11:35:12 -0600 Subject: [PATCH] feat(ralphex-fe): let Renovate bump Bun and Hugo; drop the manual push workflow ralphex-fe has no mise, and its published tag is literally bun-hugo, so Bun and Hugo are image-level versions with nowhere else to be set. They were the only pinned ARGs in the repo without a `# renovate:` annotation, and that absence is the sole reason update-and-build-ralphex-fe.yml existed. Annotated both and grouped them as "ralphex-fe toolchain" with automerge and the same 3-day soak the non-claude agent tools get. Bun uses the npm datasource because oven-sh/bun tags releases as "bun-v1.4.2", which the existing github-releases extractVersion does not strip; the npm package publishes bare semver that matches the ARG format directly. update-and-build-ralphex-fe.yml is deleted rather than fixed. It took version inputs, rewrote the Dockerfile, and pushed the commit straight to master as github-actions[bot] -- the one direct-push path in the repo, and the reason a branch ruleset needed a bypass actor that GitHub does not offer for Actions. Renovate now covers what it did, and build-ralphex-fe.yml already has workflow_dispatch for manual rebuilds, so nothing is lost except the push-to-master. README sections that documented driving that workflow are replaced with how to force a rebuild and how to change a pinned version (edit the ARG, open a PR). Note the first Renovate PR will be a real jump: Bun 1.3.9 -> 1.4.2 and Hugo 0.156.0 -> 0.166.0. Verified: actionlint clean; hadolint clean on ralphex-fe/Dockerfile; renovate-config-validator "Config validated successfully"; and the customManager matchString exercised against both Dockerfiles in Python -- it now extracts bun/npm/1.3.9 and gohugoio/hugo/github-releases/0.156.0 alongside the four existing tools. --- .github/renovate.json5 | 12 ++ .../workflows/update-and-build-ralphex-fe.yml | 156 ------------------ README.md | 39 +---- ralphex-fe/Dockerfile | 2 + ralphex-fe/README.md | 6 +- 5 files changed, 26 insertions(+), 189 deletions(-) delete mode 100644 .github/workflows/update-and-build-ralphex-fe.yml diff --git a/.github/renovate.json5 b/.github/renovate.json5 index ec3a5e4..47f08a0 100644 --- a/.github/renovate.json5 +++ b/.github/renovate.json5 @@ -61,5 +61,17 @@ matchPackageNames: ['@anthropic-ai/claude-code'], minimumReleaseAge: null, }, + { + // ralphex-fe bakes its toolchain into the image — it has no mise, and + // its published tag is literally bun-hugo. So these are + // image-level versions, not per-project ones, and there is no other + // place to set them. Bun uses the npm datasource because oven-sh/bun + // tags releases as "bun-v1.4.2", which the github-releases extractVersion + // above does not strip. + matchPackageNames: ['bun', 'gohugoio/hugo'], + groupName: 'ralphex-fe toolchain', + automerge: true, + minimumReleaseAge: '3 days', + }, ], } diff --git a/.github/workflows/update-and-build-ralphex-fe.yml b/.github/workflows/update-and-build-ralphex-fe.yml deleted file mode 100644 index 38701a4..0000000 --- a/.github/workflows/update-and-build-ralphex-fe.yml +++ /dev/null @@ -1,156 +0,0 @@ -name: Update and Build ralphex-fe - -on: - workflow_dispatch: - inputs: - bun_version: - description: 'New Bun version (e.g., 1.3.9). Leave empty to keep current.' - required: false - type: string - hugo_version: - description: 'New Hugo version (e.g., 0.155.3). Leave empty to keep current.' - required: false - type: string - update_only: - description: 'Only update Dockerfile without building image' - required: false - default: false - type: boolean - -concurrency: - group: build-ralphex-fe-${{ github.ref }} - cancel-in-progress: true - -env: - DOCKERFILE_PATH: ralphex-fe/Dockerfile - -jobs: - update-dockerfile: - runs-on: ubuntu-latest - - permissions: - contents: write - - outputs: - versions_updated: ${{ steps.update.outputs.updated }} - bun_version: ${{ steps.update.outputs.bun_version }} - hugo_version: ${{ steps.update.outputs.hugo_version }} - - steps: - - name: Checkout repository - uses: actions/checkout@v4 - with: - token: ${{ secrets.GITHUB_TOKEN }} - - - name: Update Dockerfile versions - id: update - env: - INPUT_BUN_VERSION: ${{ inputs.bun_version }} - INPUT_HUGO_VERSION: ${{ inputs.hugo_version }} - run: | - # Read current versions - CURRENT_BUN=$(grep '^ARG BUN_VERSION=' "${{ env.DOCKERFILE_PATH }}" | cut -d'=' -f2) - CURRENT_HUGO=$(grep '^ARG HUGO_VERSION=' "${{ env.DOCKERFILE_PATH }}" | cut -d'=' -f2) - - if [ -z "$CURRENT_BUN" ] || [ -z "$CURRENT_HUGO" ]; then - echo "Error: Failed to extract current version(s) from Dockerfile" - echo " Bun: ${CURRENT_BUN:-}" - echo " Hugo: ${CURRENT_HUGO:-}" - exit 1 - fi - - echo "Current versions:" - echo " Bun: $CURRENT_BUN" - echo " Hugo: $CURRENT_HUGO" - - # Use input values or fall back to current Dockerfile values - NEW_BUN=${INPUT_BUN_VERSION:-$CURRENT_BUN} - NEW_HUGO=${INPUT_HUGO_VERSION:-$CURRENT_HUGO} - - echo "" - echo "Target versions:" - echo " Bun: $NEW_BUN" - echo " Hugo: $NEW_HUGO" - - # Update versions in Dockerfile (GNU sed syntax for Linux) - # Use | as delimiter to avoid breakage if version strings contain / - sed -i "s|^ARG BUN_VERSION=.*|ARG BUN_VERSION=$NEW_BUN|" "${{ env.DOCKERFILE_PATH }}" - sed -i "s|^ARG HUGO_VERSION=.*|ARG HUGO_VERSION=$NEW_HUGO|" "${{ env.DOCKERFILE_PATH }}" - - # Verify changes - echo "" - echo "Updated versions in Dockerfile:" - grep '^ARG BUN_VERSION=' "${{ env.DOCKERFILE_PATH }}" - grep '^ARG HUGO_VERSION=' "${{ env.DOCKERFILE_PATH }}" - - # Check if anything changed - if git diff --quiet "${{ env.DOCKERFILE_PATH }}"; then - echo "No changes detected - versions are already up to date" - echo "updated=false" >> "$GITHUB_OUTPUT" - else - echo "Changes detected - versions updated" - echo "updated=true" >> "$GITHUB_OUTPUT" - fi - - { - echo "bun_version=$NEW_BUN" - echo "hugo_version=$NEW_HUGO" - } >> "$GITHUB_OUTPUT" - - - name: Commit and push changes - if: steps.update.outputs.updated == 'true' - env: - BUN_VERSION: ${{ steps.update.outputs.bun_version }} - HUGO_VERSION: ${{ steps.update.outputs.hugo_version }} - GITHUB_ACTOR: ${{ github.actor }} - ACTOR_ID: ${{ github.actor_id }} - run: | - git config user.name "github-actions[bot]" - git config user.email "github-actions[bot]@users.noreply.github.com" - - git add "${{ env.DOCKERFILE_PATH }}" - - # [skip ci] prevents build-ralphex-fe.yml from triggering a duplicate build - git commit \ - -m "chore(ralphex-fe): update versions to Bun ${BUN_VERSION}, Hugo ${HUGO_VERSION} [skip ci]" \ - -m "Updated via GitHub Actions workflow dispatch." \ - -m "Co-Authored-By: ${GITHUB_ACTOR} <${ACTOR_ID}+${GITHUB_ACTOR}@users.noreply.github.com>" - - git push - - echo "Dockerfile updated and pushed to repository" - - - name: No changes needed - if: steps.update.outputs.updated == 'false' - run: | - echo "Dockerfile already has the requested versions - no update needed" - - build-and-push: - needs: update-dockerfile - permissions: - contents: read - packages: write - # Build if versions changed and update_only is not checked - if: ${{ needs.update-dockerfile.outputs.versions_updated == 'true' && inputs.update_only == false }} - uses: ./.github/workflows/reusable-docker-build.yml - with: - image-name: devcontainers/ralphex-fe - context: ralphex-fe - dockerfile: ralphex-fe/Dockerfile - version-tag: bun${{ needs.update-dockerfile.outputs.bun_version }}-hugo${{ needs.update-dockerfile.outputs.hugo_version }} - verify-command: 'bun --version && hugo version' - extra-verify-script: | - chromium --no-sandbox --version && \ - test "$PLAYWRIGHT_CHROMIUM_EXECUTABLE_PATH" = "/usr/bin/chromium" && \ - echo "OK: PLAYWRIGHT_CHROMIUM_EXECUTABLE_PATH is correct" || \ - (echo "FAIL: expected /usr/bin/chromium, got $PLAYWRIGHT_CHROMIUM_EXECUTABLE_PATH" && exit 1) && \ - test -x "$PLAYWRIGHT_CHROMIUM_EXECUTABLE_PATH" && \ - echo "OK: binary is executable at $PLAYWRIGHT_CHROMIUM_EXECUTABLE_PATH" || \ - (echo "FAIL: binary not executable at $PLAYWRIGHT_CHROMIUM_EXECUTABLE_PATH" && exit 1) && \ - test "$PLAYWRIGHT_SKIP_BROWSER_DOWNLOAD" = "1" && \ - echo "OK: PLAYWRIGHT_SKIP_BROWSER_DOWNLOAD=1" || \ - (echo "FAIL: got PLAYWRIGHT_SKIP_BROWSER_DOWNLOAD=$PLAYWRIGHT_SKIP_BROWSER_DOWNLOAD" && exit 1) && \ - ls /usr/share/fonts/freefont/FreeSans.ttf && \ - echo "OK: freefont found" || \ - (echo "FAIL: freefont not found" && exit 1) - secrets: inherit diff --git a/README.md b/README.md index 25de221..854fd44 100644 --- a/README.md +++ b/README.md @@ -183,43 +183,22 @@ issue tracks what is pending. Everything else — including base images and Bun/ > Setting `mode` in `renovate.json5` cannot substitute for the Silent-mode toggle, because `dryRun` > takes precedence over `mode` and is admin-level. -### Via GitHub UI +### Manual rebuilds -Some images have automated update workflows that allow you to update dependency versions without manually editing Dockerfiles: - -1. Go to **Actions** tab → Select the update workflow (e.g., "Update and Build ralphex-fe") -2. Click **Run workflow** -3. Enter new versions (e.g., Bun 1.4.0, Hugo 0.156.0) -4. Click **Run workflow** button - -The workflow will: -- Update the Dockerfile with new versions -- Commit the changes to the repository -- Build and push the updated image - -### Via GitHub CLI - -If you have the [GitHub CLI](https://cli.github.com/) installed, you can trigger updates from your terminal: +Every image has a `workflow_dispatch` trigger, so a rebuild can be forced without a code change: ```bash -# Update ralphex-fe image versions -gh workflow run update-and-build-ralphex-fe.yml \ - -f bun_version=1.4.0 \ - -f hugo_version=0.156.0 +# Rebuild one image from current master +gh workflow run build-ralphex-fe.yml -# Update without building (just commit to repo) -gh workflow run update-and-build-ralphex-fe.yml \ - -f bun_version=1.4.0 \ - -f hugo_version=0.156.0 \ - -f update_only=true - -# Check workflow status -gh run list --workflow=update-and-build-ralphex-fe.yml - -# Watch the latest run in real-time +# Check status / watch +gh run list --workflow=build-ralphex-fe.yml gh run watch ``` +To change a pinned version, edit the `ARG` in that image's Dockerfile and open a PR — the merge +triggers the build. There is no longer a workflow that rewrites Dockerfiles and pushes to `master`. + **Install GitHub CLI:** ```bash # macOS diff --git a/ralphex-fe/Dockerfile b/ralphex-fe/Dockerfile index 1cf38cc..f9a0dbf 100644 --- a/ralphex-fe/Dockerfile +++ b/ralphex-fe/Dockerfile @@ -1,6 +1,8 @@ +# renovate: datasource=npm depName=bun ARG BUN_VERSION=1.3.9 ARG DOCKER_VERSION=29.3.0 ARG GO_VERSION=1.24.4 +# renovate: datasource=github-releases depName=gohugoio/hugo ARG HUGO_VERSION=0.156.0 # ═════════════════════════════════════════════════════════════════════════════ diff --git a/ralphex-fe/README.md b/ralphex-fe/README.md index d233faa..588b702 100644 --- a/ralphex-fe/README.md +++ b/ralphex-fe/README.md @@ -21,9 +21,9 @@ This is a standalone image, not a devcontainer. | Ralphex | 1.6.0 (pinned) | | Git, ripgrep, jq, curl, wget | system | -The pinned versions live as `ARG`s in the Dockerfile and are kept current by Renovate — see -[Automatic Rebuilds](#automatic-rebuilds). Bun and Hugo are bumped manually via the -`update-and-build-ralphex-fe.yml` workflow. +All pinned versions live as `ARG`s in the Dockerfile and are kept current by Renovate — see +[Automatic Rebuilds](#automatic-rebuilds). This image has no `mise`, so its Bun and Hugo are +image-level versions rather than per-project ones; Renovate tracks them like everything else. ## Usage