From 14cabaf3f5621d12814691e667bbe1972a065760 Mon Sep 17 00:00:00 2001 From: Danijel Simeunovic Date: Thu, 24 Sep 2026 23:53:26 +0200 Subject: [PATCH] version bumps --- infra/base/fluent-bit/fluent-bit.yaml | 2 +- infra/base/kyverno/kyverno.yaml | 2 +- infra/base/renovate/renovate.yaml | 2 +- infra/base/sealedsecrets/sealedsecrets.yaml | 4 +- infra/base/vault/vault.yaml | 2 +- renovate.json | 66 +++++++++++++++++++++ 6 files changed, 72 insertions(+), 6 deletions(-) create mode 100644 renovate.json diff --git a/infra/base/fluent-bit/fluent-bit.yaml b/infra/base/fluent-bit/fluent-bit.yaml index 748a6b4..8cca075 100644 --- a/infra/base/fluent-bit/fluent-bit.yaml +++ b/infra/base/fluent-bit/fluent-bit.yaml @@ -17,7 +17,7 @@ spec: sources: - repoURL: https://fluent.github.io/helm-charts chart: fluent-bit - targetRevision: 0.47.10 + targetRevision: 0.58.2 helm: releaseName: fluent-bit valueFiles: diff --git a/infra/base/kyverno/kyverno.yaml b/infra/base/kyverno/kyverno.yaml index ebc2aa5..8e5334e 100644 --- a/infra/base/kyverno/kyverno.yaml +++ b/infra/base/kyverno/kyverno.yaml @@ -36,7 +36,7 @@ spec: source: chart: kyverno repoURL: https://kyverno.github.io/kyverno/ - targetRevision: v3.7.0 # Update to latest stable version + targetRevision: 3.9.1 helm: releaseName: kyverno valuesObject: diff --git a/infra/base/renovate/renovate.yaml b/infra/base/renovate/renovate.yaml index 4cf87e4..59bbb8e 100644 --- a/infra/base/renovate/renovate.yaml +++ b/infra/base/renovate/renovate.yaml @@ -17,7 +17,7 @@ spec: sources: - repoURL: ghcr.io/renovatebot/charts chart: renovate - targetRevision: "46.109.0" + targetRevision: "46.318.0" helm: releaseName: renovate valueFiles: diff --git a/infra/base/sealedsecrets/sealedsecrets.yaml b/infra/base/sealedsecrets/sealedsecrets.yaml index bd69cdf..ceebd60 100644 --- a/infra/base/sealedsecrets/sealedsecrets.yaml +++ b/infra/base/sealedsecrets/sealedsecrets.yaml @@ -16,8 +16,8 @@ spec: source: chart: sealed-secrets - repoURL: https://bitnami-labs.github.io/sealed-secrets - targetRevision: 2.16.2 # Update to latest stable version + repoURL: https://bitnami.github.io/sealed-secrets + targetRevision: 2.20.0 helm: releaseName: sealed-secrets parameters: diff --git a/infra/base/vault/vault.yaml b/infra/base/vault/vault.yaml index dfeea4e..0cb15b8 100644 --- a/infra/base/vault/vault.yaml +++ b/infra/base/vault/vault.yaml @@ -17,7 +17,7 @@ spec: sources: - repoURL: https://helm.releases.hashicorp.com chart: vault - targetRevision: "0.32.0" + targetRevision: "0.34.1" helm: releaseName: vault valueFiles: diff --git a/renovate.json b/renovate.json new file mode 100644 index 0000000..01913c2 --- /dev/null +++ b/renovate.json @@ -0,0 +1,66 @@ +{ + "$schema": "https://docs.renovatebot.com/renovate-schema.json", + "extends": [ + "config:recommended", + ":dependencyDashboard", + ":semanticCommits" + ], + "timezone": "Europe/Oslo", + "labels": ["renovate"], + "reviewers": ["danijel.simeunovic"], + + "prConcurrentLimit": 10, + "prHourlyLimit": 4, + "minimumReleaseAge": "3 days", + + "ignorePaths": [ + "**/*-sealed.yaml", + "cluster-resources/policies/**", + "private/**", + ".devbox/**" + ], + + "argocd": { + "description": "ArgoCD Applications live under infra/, apps/ and the root app-of-apps files. The manager skips any file without an argoproj.io apiVersion, so matching broadly is safe.", + "managerFilePatterns": [ + "/^_app-of-apps-.+\\.yaml$/", + "/^apps/.+\\.yaml$/", + "/^infra/.+\\.yaml$/" + ] + }, + + "helm-values": { + "description": "Values files are named -values.yaml, not the default values.yaml.", + "managerFilePatterns": ["/^infra/values/.+\\.ya?ml$/"] + }, + + "kubernetes": { + "description": "Plain manifests with inline image references. Kyverno policies are excluded via ignorePaths - their images are Go templates, not tags.", + "managerFilePatterns": [ + "/^cluster-resources/.+\\.yaml$/", + "/^apps/.+/resources/.+\\.yaml$/" + ] + }, + + "packageRules": [ + { + "description": "Every Application carries a second source pointing at this repo at HEAD for $values. HEAD is not a version.", + "matchDatasources": ["git-tags"], + "matchDepNames": ["/forteapps\\.net/"], + "enabled": false + }, + { + "description": "Platform chart majors usually carry values-schema or CRD breaks - flag them for a careful read.", + "matchFileNames": ["infra/**"], + "matchUpdateTypes": ["major"], + "labels": ["renovate", "breaking-change"], + "minimumReleaseAge": "7 days" + }, + { + "description": "Patch-level platform bumps are routine - let them through faster.", + "matchFileNames": ["infra/**"], + "matchUpdateTypes": ["patch"], + "minimumReleaseAge": "1 day" + } + ] +}