fix(renovate): cap talosctl at the cluster's Talos minor - #3897
Merged
Merged
Conversation
Grouping made the skew visible (#3834 pairs talosctl 1.14.0 with a v1.13.10 cluster) but does not prevent it. Add allowedVersions '<1.14' so talosctl cannot lead the cluster, making a Talos minor upgrade a deliberate step rather than a side effect of a client bump. The cap is static and must move with talosVersion in talos/talenv.yaml, which is a comment nobody reads on the day it matters. So also teach find_mistakes.py to compare the mise.toml pins against talenv.yaml directly: talosctl vs talosVersion, kubectl vs kubernetesVersion. It errors when they disagree, which is the case allowedVersions cannot see — one side bumped without the other, or the cap left stale after a cluster upgrade. Verified against #3834's current contents: exit 1 with talosctl 1.14.0 against a v1.13.10 cluster, exit 0 once talosctl reads 1.13.10. kubectl 1.37.0 against kubernetesVersion v1.37.0 passes, since those already agree. The script is local-only (not wired into CI or pre-commit), so the new error is a strong local signal rather than a merge blocker.
Contributor
konflate — summaryNote ✅ No rendered changes. konflate · rendered |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to #3896. Grouping made the client/cluster skew visible — #3834 now pairs
talosctl 1.14.0with av1.13.10cluster in one diff — but visibility isn't prevention. This enforces it.Two layers
1.
allowedVersionscap (.renovate/allowedVersions.json5)Renovate can no longer propose talosctl ahead of the cluster. A Talos minor upgrade becomes a deliberate step instead of arriving as a client bump.
2. A consistency check, because the cap will rot
The cap is a static string that must be raised whenever
talosVersionmoves. That's a comment nobody reads on the day it matters — and if it's forgotten, talosctl silently lags the cluster instead, which is the same problem inverted.So
find_mistakes.pynow compares the pins directly against the cluster:mise.tomltalos/talenv.yamltalosctltalosVersionkubectlkubernetesVersionThis catches exactly what
allowedVersionscannot see: one side bumped without the other, or a stale cap after an upgrade.Verification
Run against #3834's actual contents:
1.14.0, clusterv1.13.10(#3834 today)exit 1— "talosctl is 1.14.0 in mise.toml but the cluster is 1.13.10 in talos/talenv.yaml - bump both together"1.13.10, clusterv1.13.10exit 01.37.0, k8sv1.37.0mainexit 0, only the 2 documented warningsjust validate,just flate-test(169 passed) andpre-commitall pass.Severity note
find_mistakes.pyisn't referenced by any workflow,.pre-commit-config.yaml, or the justfile — it's invoked manually perAGENTS.md. So the new error is a strong local signal, not a merge blocker. Say the word if you'd rather it were a warning, or wired into CI as a real gate.Merge order matters
Merge this before #3834. Renovate will then regenerate #3834 with
talosctl 1.13.10on its next run. If #3834 merges first,1.14.0lands and Renovate won't downgrade it — you'd be capped at a version you're already past.I'm also pinning #3834's branch to
1.13.10directly so the ordering can't bite either way.Upgrade runbook (for when you do go to v1.14)
"<1.15"here.talenv.yaml, both tuppr CRs, and both mise pins together.python3 scripts/find_mistakes.py— exit 0 confirms client and cluster agree before tuppr touches a node.