Repository navigation
ci: lift the ubuntu-24.04 hold - #90
Merged
Merged
Conversation
The hold's exit condition was already met when it was written. It said to remove the rule "once the SELF-HOSTED runners have been upgraded to a Compose 5.x image" - they run v5.5.1, verified on piwine, and have for some time. So the premise was inverted. The hold was written to stop lint and deploy validating with different Compose engines, but that split is the CURRENT state: every Compose-touching job in deploy.yml is self-hosted on 5.5.1 (:67, :258, :647, :742, :760), while lint runs hosted on ubuntu-24.04 with 2.38.2. Keeping the hold perpetuates the mismatch; moving the hosted runners to 26.04 closes it. A detail that shows how invisible this was: the 2 literal `runs-on:` values Renovate could already see are deploy.yml's notify job and workflow-lint.yml - neither runs Compose at all. The 3 labels that do feed `docker compose config` were the ones it could not see, until #88. Compose 5.x compatibility was checked directly rather than assumed: `config --images` still emits one resolved ref per line on stdout; `ps -a --format json` is still NDJSON, so deploy.yml's `jq -s` health gate parses correctly; verdicts remain exit-code driven. The parsers that were genuinely fragile are fixed in #89. With #88 in place Renovate sees all 5 labels, so this produces one PR that moves them together rather than the partial migration #87 was guarding against.
Reviewer's guide (collapsed on small PRs)Reviewer's GuideLifts the Ubuntu 24.04 hold now that self-hosted runners use Compose 5.5.1 and the retained Renovate custom manager can detect all runner labels, enabling a coordinated migration rather than a partial upgrade. File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The exit condition was already met
#87 said to remove the rule "only once the SELF-HOSTED runners have been upgraded to a Compose 5.x image". They already were:
I wrote that exit condition two hours earlier against a premise that was no longer true.
The hold was preserving the split, not preventing it
docker compose config)${{ inputs.runner }}=ubuntu-24.04[self-hosted, …]Every Compose-touching job in
deploy.ymlis self-hosted (:67,:258,:647,:742,:760). The mismatch the hold existed to prevent is the current state; moving the hosted side to 26.04 takes lint from 2.38.2 to 5.x and closes it.There's a detail that shows how invisible this was. Of the 5 runner labels, the 2 literals Renovate could already see are
deploy.yml:1035(thenotify:Discord job) andworkflow-lint.yml:17(yamllint over workflow files) — neither runs Compose. The 3 it couldn't see are exactly the ones feedingdocker compose config. Renovate had visibility into only the Compose-irrelevant labels.Compose 5.x compatibility was measured, not assumed
Against v5.5.1:
config --images— still one fully-resolved ref per line on stdout, warnings on stderr, exit 0.ps -a --format json— still NDJSON, sodeploy.yml:694'sjq -s '.'still yieldsarray→objectand the health-gate selectors resolve. I had predicted this would break if 5.x switched to a top-level array; it didn't, and it has been running in production on 5.5.1 regardless.docker compose config— verdicts are exit-code driven in bothvalidate-stack.shandlint-summary.sh, unaffected by output rewording.The parsers that were genuinely fragile — the
config --imagesfail-open, theset -eabort that swallowed the failure report, and the warning filters that didn't match 5.x'slevel=warningspelling — are fixed in #89, which merged first.What happens next
With #88 in place Renovate now sees all 5 labels, so the next run raises one PR moving them together — the whole-migration PR, not the partial one #87 was guarding against. Review that PR normally; CI will lint the stacks on 26.04 with the same engine that deploys them.
Validation
renovate-config-validatorpasses, as doesscripts/linting/validate-renovate.shin repo-config--strictmode. The diff removes only the hold rule; thegithub-runnerscustomManager from #88 is retained, which is what makes lifting safe.Summary by Sourcery
Enhancements: