Skip to content

fix(renovate): cap talosctl at the cluster's Talos minor - #3897

Merged
axeII merged 1 commit into
mainfrom
fix/pin-talosctl-to-cluster
Sep 7, 2026
Merged

axeII merged 1 commit into
mainfrom
fix/pin-talosctl-to-cluster

Conversation

@axeII

@axeII axeII commented Sep 7, 2026

Copy link
Copy Markdown
Owner

Follow-up to #3896. Grouping made the client/cluster skew visible — #3834 now pairs talosctl 1.14.0 with a v1.13.10 cluster in one diff — but visibility isn't prevention. This enforces it.

Two layers

1. allowedVersions cap (.renovate/allowedVersions.json5)

{
  description: "Hold talosctl at the cluster's Talos minor (talenv.yaml)",
  matchManagers: ["mise"],
  matchPackageNames: ["/talosctl/", "/siderolabs\\/talos/"],
  allowedVersions: "<1.14",
}

Renovate can no longer propose talosctl ahead of the cluster. A Talos minor upgrade becomes a deliberate step instead of arriving as a client bump.

2. A consistency check, because the cap will rot

The cap is a static string that must be raised whenever talosVersion moves. That's a comment nobody reads on the day it matters — and if it's forgotten, talosctl silently lags the cluster instead, which is the same problem inverted.

So find_mistakes.py now compares the pins directly against the cluster:

mise.toml must equal talos/talenv.yaml
talosctl ↔ talosVersion
kubectl ↔ kubernetesVersion

This catches exactly what allowedVersions cannot see: one side bumped without the other, or a stale cap after an upgrade.

Verification

Run against #3834's actual contents:

Scenario Result
talosctl 1.14.0, cluster v1.13.10 (#3834 today) ❌ exit 1 — "talosctl is 1.14.0 in mise.toml but the cluster is 1.13.10 in talos/talenv.yaml - bump both together"
talosctl 1.13.10, cluster v1.13.10 ✅ exit 0
kubectl 1.37.0, k8s v1.37.0 ✅ passes — already agree
current main ✅ exit 0, only the 2 documented warnings

just validate, just flate-test (169 passed) and pre-commit all pass.

Severity note

find_mistakes.py isn't referenced by any workflow, .pre-commit-config.yaml, or the justfile — it's invoked manually per AGENTS.md. So the new error is a strong local signal, not a merge blocker. Say the word if you'd rather it were a warning, or wired into CI as a real gate.

Merge order matters

Merge this before #3834. Renovate will then regenerate #3834 with talosctl 1.13.10 on its next run. If #3834 merges first, 1.14.0 lands and Renovate won't downgrade it — you'd be capped at a version you're already past.

I'm also pinning #3834's branch to 1.13.10 directly so the ordering can't bite either way.

Upgrade runbook (for when you do go to v1.14)

  1. Raise the cap to "<1.15" here.
  2. Let the grouped Renovate PR bump talenv.yaml, both tuppr CRs, and both mise pins together.
  3. python3 scripts/find_mistakes.py — exit 0 confirms client and cluster agree before tuppr touches a node.

Grouping made the skew visible (#3834 pairs talosctl 1.14.0 with a v1.13.10
cluster) but does not prevent it. Add allowedVersions '<1.14' so talosctl
cannot lead the cluster, making a Talos minor upgrade a deliberate step rather
than a side effect of a client bump.

The cap is static and must move with talosVersion in talos/talenv.yaml, which
is a comment nobody reads on the day it matters. So also teach
find_mistakes.py to compare the mise.toml pins against talenv.yaml directly:
talosctl vs talosVersion, kubectl vs kubernetesVersion. It errors when they
disagree, which is the case allowedVersions cannot see — one side bumped
without the other, or the cap left stale after a cluster upgrade.

Verified against #3834's current contents: exit 1 with talosctl 1.14.0 against
a v1.13.10 cluster, exit 0 once talosctl reads 1.13.10. kubectl 1.37.0 against
kubernetesVersion v1.37.0 passes, since those already agree.

The script is local-only (not wired into CI or pre-commit), so the new error
is a strong local signal rather than a merge blocker.
@bot-akira

bot-akira Bot commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

konflate — summary

Note

✅ No rendered changes.

View the full rendered diff →

konflate · rendered 53f60b4 · advisory, not a gate

@axeII
axeII merged commit b0139b6 into main Sep 7, 2026
7 checks passed
@axeII
axeII deleted the fix/pin-talosctl-to-cluster branch September 7, 2026 15:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant