Skip to content

docs: mark Renovate Argo CD tag tracking as done - #46

Open
AHS0003 wants to merge 1 commit into
Medical-Informatics-Platform:mainfrom
AHS0003:docs/mark-renovate-argo-tag-done
Open

AHS0003 wants to merge 1 commit into
Medical-Informatics-Platform:mainfrom
AHS0003:docs/mark-renovate-argo-tag-done

Conversation

@AHS0003

@AHS0003 AHS0003 commented Sep 26, 2026

Copy link
Copy Markdown

What

The "Open hardening TODOs" section in docs/rbac-layers.md lists Renovate
tracking of the upstream Argo CD tag as outstanding, under Operability:

Renovate (or equivalent) for the upstream Argo tag in
patches/kustomization.yaml so the sed-at-install dance in the README
becomes obsolete.

Why this is stale

This is already implemented. renovate.json5 has a customManagers regex
entry that tracks exactly this file:

{
  customType: 'regex',
  description: 'Argo CD upstream version in the kustomize remote base URL',
  managerFilePatterns: ['/^argo-setup/patches/kustomization\\.yaml$/'],
  matchStrings: ['raw\\.githubusercontent\\.com/argoproj/argo-cd/(?<currentValue>v[\\d.]+)/manifests/'],
  depNameTemplate: 'argoproj/argo-cd',
  datasourceTemplate: 'github-releases',
},

It matches the pinned tag in argo-setup/patches/kustomization.yaml
(raw.githubusercontent.com/argoproj/argo-cd/v3.3.11/manifests/ha/install.yaml)
and opens the bump PR automatically. The item just above it in the same doc
(CI diff check for upstream ClusterRoles) was marked done when it landed;
this one wasn't updated to match.

Change

Updates the TODO entry to reflect that it's done, and points to
renovate.json5 and the Bumping Argo CD procedure in
argo-setup/README.md for the manual review step (ClusterRole diff
reconciliation) that still applies after Renovate opens the bump PR.

Testing

Docs-only change no code, manifests, or CI affected. Verified the
regex in renovate.json5 against the live line in
argo-setup/patches/kustomization.yaml and confirmed it matches.

Copilot AI lite review requested due to automatic review settings September 26, 2026 19:43

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

Documentation-only update with no unresolved review issues.

Review effort: Lite
Findings: None

What changed in this PR

Updates RBAC documentation to mark Argo CD Renovate tag tracking as complete.

Changes:

  • References the Renovate configuration and upgrade procedure.
  • Retains manual ClusterRole reconciliation guidance.
File Description
docs/​rbac-layers.md Marks Argo CD Renovate tracking as completed and documents the remaining review step.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants