diff --git a/.github/renovate-controller-policy.md b/.github/renovate-controller-policy.md index 2df6d8e56..e47b71b8e 100644 --- a/.github/renovate-controller-policy.md +++ b/.github/renovate-controller-policy.md @@ -33,9 +33,11 @@ For a growing app catalog, apply capacity improvements in this order: 3. Run the full Compose scan on a schedule or manually, with workflow concurrency preventing overlap. 4. Suppress historical tracks and auxiliary-only updates in `.github/renovate-docker.json`. 5. Group application images that must move together and keep multi-service updates under tested maintainer review. -6. Add persistent repository/cache storage only when the GitHub Actions cache or an external cache backend is intentionally adopted and pinned. +6. Persist the self-hosted cache with the SHA-pinned `actions/cache` step in `.github/workflows/renovate.yml`. -Setting `repositoryCache: "enabled"` alone does not persist useful state between ephemeral GitHub-hosted runners. A cache action, Redis, or S3-backed cache requires a separate dependency and operational review before adoption. +The workflow stores Renovate's public package lookup cache and repository extraction cache under `/tmp/renovate-cache`. Private package caching remains disabled. Cache writes come only from the scheduled or manually dispatched trusted workflow. + +GitHub Actions cache entries are immutable, so each run uses a unique key and restores the newest compatible prefix. The configuration hash separates policy generations, while the broader fallback retains public package lookup data after policy changes. Monitor the reported directory size and repository cache inventory to avoid churn against GitHub's default cache quota. ## Change checklist diff --git a/.github/scripts/test_renovate_app_version.py b/.github/scripts/test_renovate_app_version.py index 6a8754b72..166dcb214 100644 --- a/.github/scripts/test_renovate_app_version.py +++ b/.github/scripts/test_renovate_app_version.py @@ -195,6 +195,23 @@ class RenovateAppVersionTests(unittest.TestCase): self.assertIn("name: Check Docker Hub credentials", workflow) self.assertIn("Configure DOCKERHUB_USERNAME and DOCKERHUB_TOKEN repository secrets", workflow) + def test_self_hosted_renovate_uses_a_pinned_persistent_cache(self): + workflow = (REPO_ROOT / ".github" / "workflows" / "renovate.yml").read_text( + encoding="utf-8" + ) + + self.assertIn( + "uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0", + workflow, + ) + self.assertIn("path: /tmp/renovate-cache", workflow) + self.assertIn("${{ github.run_id }}", workflow) + self.assertIn("RENOVATE_CACHE_DIR: /tmp/renovate-cache", workflow) + self.assertIn("RENOVATE_REPOSITORY_CACHE: enabled", workflow) + self.assertIn("RENOVATE_CACHE_PRIVATE_PACKAGES: 'false'", workflow) + self.assertIn("chmod -R a+rwX /tmp/renovate-cache", workflow) + self.assertIn("du -sh /tmp/renovate-cache", workflow) + def test_hosted_and_self_hosted_renovate_have_disjoint_manager_scopes(self): hosted = json.loads((REPO_ROOT / "renovate.json").read_text(encoding="utf-8")) docker = json.loads( diff --git a/.github/workflows/renovate.yml b/.github/workflows/renovate.yml index 4c1e6a7bd..a93ccc76a 100644 --- a/.github/workflows/renovate.yml +++ b/.github/workflows/renovate.yml @@ -19,6 +19,18 @@ jobs: steps: - name: Checkout repository uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 + - name: Restore Renovate cache + uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 + with: + path: /tmp/renovate-cache + key: renovate-docker-v1-${{ runner.os }}-v43-${{ hashFiles('.github/renovate-docker.json', '.github/renovate-global.js') }}-${{ github.run_id }} + restore-keys: | + renovate-docker-v1-${{ runner.os }}-v43-${{ hashFiles('.github/renovate-docker.json', '.github/renovate-global.js') }}- + renovate-docker-v1-${{ runner.os }}-v43- + - name: Prepare Renovate cache permissions + run: | + install -d -m 0777 /tmp/renovate-cache + chmod -R a+rwX /tmp/renovate-cache - name: Check Docker Hub credentials env: RENOVATE_DOCKERHUB_TOKEN: ${{ secrets.DOCKERHUB_TOKEN }} @@ -38,4 +50,15 @@ jobs: env: RENOVATE_DOCKERHUB_TOKEN: ${{ secrets.DOCKERHUB_TOKEN }} RENOVATE_DOCKERHUB_USERNAME: ${{ secrets.DOCKERHUB_USERNAME }} + RENOVATE_CACHE_DIR: /tmp/renovate-cache + RENOVATE_CACHE_PRIVATE_PACKAGES: 'false' RENOVATE_REPOSITORIES: ${{ github.repository }} + RENOVATE_REPOSITORY_CACHE: enabled + - name: Report Renovate cache size + if: always() + run: | + if [[ -d /tmp/renovate-cache ]]; then + du -sh /tmp/renovate-cache + else + echo "Renovate cache directory was not created." + fi