fix(renovate): group mise's talosctl and kubectl with the talos group - #3896
Merged
Merged
Conversation
The Talos group matches on datasource, but mise pins talosctl and kubectl via the aqua backend, whose datasource is neither docker nor github-releases. The existing rule could not reach them, so they opened as standalone feat(deps) PRs (#3893, #3891) while the cluster upgrade sat in #3834. That is how talosctl came to propose 1.14.0 while #3834 only moves the cluster to v1.13.10 — a full minor of client/cluster skew, in two PRs that never had to be looked at together. Add a second rule with the same groupName scoped to matchManagers: ["mise"], so the client tools travel with the cluster version they target. Datasource is deliberately not constrained, since that is precisely what failed. Note github: backend tools (flate, yayamlls) already resolve to the github-releases datasource and were unaffected.
Contributor
konflate — summaryNote ✅ No rendered changes. konflate · rendered |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes the split you spotted between #3893 (talosctl) and #3834 (talos group).
Why they didn't group
The Talos rule matches on datasource:
/talosctl/was already in the list — but mise pinstalosctlandkubectlvia the aqua backend, and Renovate gives those a datasource that is neitherdockernorgithub-releases. The rule could never reach them.The labels prove it:
github:renovate/mise,renovate/github-releasefeat(github-release)aqua:renovate/miseonlyfeat(deps)← fell throughaqua:renovate/miseonlyfeat(deps)← fell throughSo my
github-releasesaddition in #3889 was correct but only ever helpedflateandyayamlls.The consequence
talosctl proposed 1.14.0 while #3834 only moves the cluster to v1.13.10 — a full minor of client/cluster skew, in two PRs that never had to be reviewed together. (For the record: v1.14.0 is a genuine stable release,
prerelease: false; siderolabs just reused beta changelog text in the release body, which reads misleadingly.)The fix
A second rule with the same
groupName, scoped by manager rather than datasource:Datasource is deliberately left unconstrained here — constraining it is exactly what failed.
kubectlis included because the existing group already covers/kubelet/(thekubernetesVersionintalenv.yaml), so the client belongs with it.Effect: the client tools travel in the same PR as the cluster version they target, so a skew like 1.14.0-vs-v1.13.10 is visible in one diff instead of split across two.
Verification
.renovate/groups.json5parses (13 packageRules, both talos rules resolving togroupName: "talos").just validate,just flate-test(169 passed),pre-commitall pass.Renovate config changes can't be fully proven until the next run — expect #3893 and #3891 to be superseded by a combined talos group PR.
Optional follow-up
If you'd rather talosctl never lead the cluster, an
allowedVersionsconstraint could cap it at thetalenv.yamlminor. I didn't add it — grouping makes the skew visible, and a hard cap is one more thing to keep in sync.