Skip to content

Add Renovate workflow for Docker base image updates (UI scope)#4919

Open
ChengYanJin wants to merge 1 commit intodevelopment/133.0from
improvement/add-renovate-dockerfile
Open

Add Renovate workflow for Docker base image updates (UI scope)#4919
ChengYanJin wants to merge 1 commit intodevelopment/133.0from
improvement/add-renovate-dockerfile

Conversation

@ChengYanJin
Copy link
Copy Markdown
Contributor

Summary

  • Add Renovate configuration to automatically update Docker base images
  • Scoped to UI-related Dockerfiles only (shell-ui/, ui/, images/metalk8s-ui/)
  • Runs on weekdays at 8am UTC with manual trigger option
  • Auto-approves Renovate PRs via /approve comment
  • Prevents CVE from outdated base layers

Test plan

  • Verify workflow runs successfully on manual trigger
  • Verify Renovate detects Dockerfile base image updates

🤖 Generated with Claude Code

Keep Docker base images up to date automatically to prevent CVE
from outdated base layers. Scoped to UI-related Dockerfiles only:
shell-ui/, ui/, images/metalk8s-ui/. Runs on weekdays at 8am UTC.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@ChengYanJin ChengYanJin requested a review from a team as a code owner May 7, 2026 14:24
@bert-e
Copy link
Copy Markdown
Contributor

bert-e commented May 7, 2026

Hello chengyanjin,

My role is to assist you with the merge of this
pull request. Please type @bert-e help to get information
on this process, or consult the user documentation.

Available options
name description privileged authored
/after_pull_request Wait for the given pull request id to be merged before continuing with the current one.
/bypass_author_approval Bypass the pull request author's approval
/bypass_build_status Bypass the build and test status
/bypass_commit_size Bypass the check on the size of the changeset TBA
/bypass_incompatible_branch Bypass the check on the source branch prefix
/bypass_jira_check Bypass the Jira issue check
/bypass_peer_approval Bypass the pull request peers' approval
/bypass_leader_approval Bypass the pull request leaders' approval
/approve Instruct Bert-E that the author has approved the pull request. ✍️
/create_pull_requests Allow the creation of integration pull requests.
/create_integration_branches Allow the creation of integration branches.
/no_octopus Prevent Wall-E from doing any octopus merge and use multiple consecutive merge instead
/unanimity Change review acceptance criteria from one reviewer at least to all reviewers
/wait Instruct Bert-E not to run until further notice.
Available commands
name description privileged
/help Print Bert-E's manual in the pull request.
/status Print Bert-E's current status in the pull request TBA
/clear Remove all comments from Bert-E from the history TBA
/retry Re-start a fresh build TBA
/build Re-start a fresh build TBA
/force_reset Delete integration branches & pull requests, and restart merge process from the beginning.
/reset Try to remove integration branches unless there are commits on them which do not appear on the source branch.

Status report is not available.

@bert-e
Copy link
Copy Markdown
Contributor

bert-e commented May 7, 2026

Waiting for approval

The following approvals are needed before I can proceed with the merge:

  • the author

  • 2 peers

Peer approvals must include at least 1 approval from the following list:

@scality scality deleted a comment from claude Bot May 7, 2026
@scality scality deleted a comment from claude Bot May 7, 2026
@scality scality deleted a comment from claude Bot May 7, 2026
@ChengYanJin
Copy link
Copy Markdown
Contributor Author

/approve

@bert-e
Copy link
Copy Markdown
Contributor

bert-e commented May 7, 2026

Waiting for approval

The following approvals are needed before I can proceed with the merge:

  • the author

  • 2 peers

Peer approvals must include at least 1 approval from the following list:

The following options are set: approve

@g-carre
Copy link
Copy Markdown
Contributor

g-carre commented May 7, 2026

Renovate dry-run output

Two PRs would be opened (only dockerfile manager is enabled).

improvement/renovate-nginx-1.x — Update nginx Docker tag to v1.30.0

File From To Type
shell-ui/Dockerfile nginx:1.28.0-alpine nginx:1.30.0-alpine minor
images/metalk8s-ui/Dockerfile nginx:1.15.8 nginx:1.30.0 minor

improvement/renovate-node-22.x — Update Node.js to v22

File From To Type
ui/Dockerfile node:20-alpine3.19 node:22-alpine3.19 major
shell-ui/Dockerfile node:20-alpine3.19 node:22-alpine3.19 major

Notes

  • images/metalk8s-ui/Dockerfile is on nginx 1.15.8 (2019-era). Labeled "minor" because the major doesn't change, but it spans ~15 stable releases — worth careful smoke-testing
    of asset serving, TLS, and HTTP/2 behavior.
  • Node v20 → v22 is a real major bump. Typical breakage points: native module rebuilds, crypto legacy provider deprecations, fetch/streams semantics changes. Run the test suite
    against the new image before merging.
  • Stats: 3 Dockerfiles, 4 deps total, folded into 2 grouped PRs.
Optional: bundle into a single PR

Add this to renovate.json packageRules:

{                        
  "matchManagers": ["dockerfile"],
  "groupName": "ui-base-images"
}

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants