mirror of
https://github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin.git
synced 2026-07-21 19:48:59 +02:00
* ⬆️ bump example image versions to latest stable Align every docker-compose and Helm-values example on the same set: - Traefik v3.0.0 / v3.5.0 → v3.7.1 - Crowdsec v1.6.1-2 / v1.6.8 / latest → v1.7.8 - Plugin pin v1.3.0 / v1.4.5 / v1.5.0 → v1.6.0 No env / volume changes needed: every Crowdsec example already mounts /var/lib/crowdsec/data, so the v1.7 strict volume check is already satisfied (CROWDSEC_BYPASS_DB_VOLUME_CHECK is only required when running without persistence, as in the E2E suite). * 🤖 chore: adopt Renovate (weekly, self-hosted) to replace manual version bumps Automate the kind of bump this PR did by hand. Renovate covers what Dependabot could not reach here: - example docker-compose image tags (traefik / crowdsec) — native manager; - the plugin self-pin (`experimental.plugins.bouncer.version=` in compose args and `version:` in the Traefik Helm values) — customManager, github-tags; - the Crowdsec/Traefik image tags in the Helm values (no `repository` key, so matched by file) — customManager, docker; - the pinned Traefik binary in the e2e mock suite (`TRAEFIK_VERSION`) — customManager, github-releases; - go.mod + GitHub Actions — native managers (this is why we drop Dependabot: running both would open duplicate PRs). Runs weekly via a self-hosted workflow (Mondays 04:00 UTC, plus manual dispatch). Needs a RENOVATE_TOKEN secret (documented in the workflow). Renovate PRs trigger the existing e2e CI, so a Traefik/Crowdsec bump is validated to actually boot and bounce before merge. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * 🔒 ci: pin Go to 1.22 (yaegi ceiling) and cap Renovate's Go updates The plugin is interpreted by yaegi, bundled in Traefik. Even the latest Traefik (v3.7.1) ships yaegi v0.16.1, which only supports Go 1.22 — so the plugin's real ceiling is Go 1.22 on every current Traefik, regardless of the Go version Traefik itself is built with. - main.yml: build/test on Go 1.22 (was 1.23) so `go build`/`go test` reject newer stdlib early; yaegi v0.16.1 stays the required yaegi_test guard. - renovate.json: cap the go.mod `go`/`toolchain` directive at `<1.23` so Renovate keeps deps/actions/toolchain current but never pushes the plugin past what yaegi supports. Raise the cap when Traefik ships a newer yaegi. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * 🐛 ci(renovate): stop ignoring examples/ and tests/ so custom managers run config:recommended ships a default ignorePaths that excludes **/examples/** and **/tests/** (and **/vendor/**). That silently disabled 4 of the 5 custom managers and all example/helm coverage this PR adds — Renovate only saw the root docker-compose, go.mod and workflows. Override ignorePaths to keep only vendor/node_modules. Verified via `renovate --platform=local --dry-run=full`: package files detected go from 7 -> 32, and every custom manager now extracts its dep (plugin self-pin across 11 compose files, traefik/crowdsec helm tags, e2e TRAEFIK_VERSION pin). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * ⏪ chore: drop one-time example version bumps, let Renovate own them The manual version catch-up across the example docker-compose files and the Helm values is now redundant: Renovate (this PR) covers all of them via its native docker-compose/docker managers plus the custom managers for the plugin self-pin and the e2e Traefik binary. Reverting these files to keep the PR a clean "adopt Renovate" change; Renovate will open the bump PRs itself. Note: examples/tls-auth uses crowdsecurity/crowdsec:latest again — Renovate does not pin rolling tags, so that one stays floating unless pinned separately. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * 📌 examples(tls-auth): pin crowdsec to v1.6.8 instead of :latest Rolling `latest` tags aren't reproducible and Renovate can't manage them. v1.6.8 is already the crowdsec tag used in the root docker-compose files and, unlike the `-2` build-suffixed tags, Renovate bumps it (→ v1.7.8). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * 📌 examples: normalize crowdsec v1.6.1-2 -> v1.6.8 so Renovate can manage it Renovate's docker versioning won't advance a build-suffixed tag (v1.6.1-2) to a clean release (v1.7.8), so those 8 examples would have stayed frozen. v1.6.8 is already used in the root compose files and Renovate bumps it. Also updated the captcha README snippet to match its compose. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * 🍱 group all + no dashboard + branch prefix --------- Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> Co-authored-by: maxlerebourg <maxlerebourg@gmail.com>
81 lines
2.4 KiB
YAML
81 lines
2.4 KiB
YAML
name: Main
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
on:
|
|
push:
|
|
branches:
|
|
- main
|
|
pull_request:
|
|
|
|
jobs:
|
|
|
|
main:
|
|
name: Main Process
|
|
runs-on: ubuntu-latest
|
|
env:
|
|
# Keep in sync with go.mod. Capped at 1.22 because the plugin is run by
|
|
# yaegi (bundled in Traefik) and even Traefik v3.7.1 ships yaegi v0.16.1,
|
|
# which only supports Go 1.22. Building on the floor makes go build / go
|
|
# test reject newer stdlib before yaegi_test does.
|
|
GO_VERSION: 1.22
|
|
GOLANGCI_LINT_VERSION: v1.63.4
|
|
# yaegi_test guard — pin to the version current Traefik bundles.
|
|
YAEGI_VERSION: v0.16.1
|
|
CGO_ENABLED: 0
|
|
defaults:
|
|
run:
|
|
working-directory: ${{ github.workspace }}/go/src/github.com/${{ github.repository }}
|
|
|
|
steps:
|
|
|
|
# https://github.com/marketplace/actions/setup-go-environment
|
|
- name: Set up Go ${{ env.GO_VERSION }}
|
|
uses: actions/setup-go@v6
|
|
with:
|
|
go-version: ${{ env.GO_VERSION }}
|
|
|
|
# https://github.com/marketplace/actions/checkout
|
|
- name: Check out code
|
|
uses: actions/checkout@v7
|
|
with:
|
|
path: go/src/github.com/${{ github.repository }}
|
|
fetch-depth: 0
|
|
|
|
# https://github.com/marketplace/actions/cache
|
|
- name: Cache Go modules
|
|
uses: actions/cache@v6
|
|
with:
|
|
path: ${{ github.workspace }}/go/pkg/mod
|
|
key: ${{ runner.os }}-go-${{ hashFiles('**/go.sum') }}
|
|
restore-keys: |
|
|
${{ runner.os }}-go-
|
|
|
|
# https://golangci-lint.run/usage/install#other-ci
|
|
- name: Install golangci-lint ${{ env.GOLANGCI_LINT_VERSION }}
|
|
run: curl -sSfL https://raw.githubusercontent.com/golangci/golangci-lint/master/install.sh | sh -s -- -b $(go env GOPATH)/bin ${GOLANGCI_LINT_VERSION}
|
|
|
|
- name: Install Yaegi ${{ env.YAEGI_VERSION }}
|
|
run: curl -sfL https://raw.githubusercontent.com/traefik/yaegi/master/install.sh | bash -s -- -b $(go env GOPATH)/bin ${YAEGI_VERSION}
|
|
|
|
- name: Setup GOPATH
|
|
run: go env -w GOPATH=${{ github.workspace }}/go
|
|
|
|
- name: Check and get dependencies
|
|
run: |
|
|
go mod tidy
|
|
git diff --exit-code go.mod
|
|
# git diff --exit-code go.sum
|
|
go mod download
|
|
go mod vendor
|
|
# git diff --exit-code ./vendor/
|
|
|
|
- name: Lint and Tests
|
|
run: make
|
|
|
|
- name: Run tests with Yaegi
|
|
run: make yaegi_test
|
|
env:
|
|
GOPATH: ${{ github.workspace }}/go
|