Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions changelog.d/changed/0812-renovate-go-rust-scheduling.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
### Renovate: Go/Cargo grouping, off-hours schedule, concurrent-PR cap (ADR-0812)

- Global `schedule` changed from `"at any time"` to `"before 6am on weekdays"` (Europe/Vienna) so dependency PRs no longer compete with active work for CI slots. Vulnerability alerts retain their existing `"at any time"` override.
- Go (`gomod`) minor + patch updates are now grouped into a single weekly PR auto-merged on early Monday; major bumps remain individual and require human review.
- Cargo (`cargo`) minor + patch updates follow the same group-and-auto-merge pattern; major bumps are manual.
- `prConcurrentLimit` reduced from 12 → 10 now that Go grouping compresses many per-package PRs into one.
70 changes: 70 additions & 0 deletions docs/adr/0812-renovate-go-rust-scheduling.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,70 @@
# ADR-0812: Renovate — Go/Cargo grouping, off-hours schedule, and concurrent-PR cap

- **Status**: Accepted
- **Date**: 2026-05-29
- **Deciders**: lusoris
- **Tags**: `ci`, `build`, `deps`

## Context

The fork's `renovate.json` already had `forkProcessing: "enabled"` (required for Mend to
process fork repos), grouped GitHub Actions and pre-commit bumps, and auto-merged Python
patch updates. Three gaps remained:

1. **Schedule**: The global `schedule` was `"at any time"`, meaning Renovate could open PRs
at any hour, including business hours and weekends. With `prConcurrentLimit: 12` and the
Go module graph's many transitive packages this risked flooding the PR queue during active
work hours.

2. **Go deps not grouped**: `go.mod` had ~60 direct + indirect dependencies. Without a group
rule each bump became its own PR, overwhelming the human-review queue and burning CI
minutes on near-identical runs.

3. **Rust/Cargo deps not grouped**: The `Cargo.toml` workspace was scaffolded (ADR-0702,
ADR-0707) but had no Renovate rule, so future crate bumps would also get individual PRs.

## Decision

We will apply three changes to `renovate.json`:

1. **Global schedule** changed from `"at any time"` to `"before 6am on weekdays"`. Urgent
vulnerability alerts keep their own `"at any time"` override (already in
`vulnerabilityAlerts`).

2. **Go deps** are grouped: minor + patch updates travel as one PR auto-merged on early
Monday; major bumps are individual and require human review (module-path changes and API
breaks are common for k8s/grpc families).

3. **Cargo deps** follow the same pattern: minor + patch grouped and auto-merged; major
individual and manual.

4. **`prConcurrentLimit`** reduced from 12 to 10 to keep the queue manageable now that
the Go group rule will compress many updates into one PR.

## Alternatives considered

| Option | Pros | Cons | Why not chosen |
|---|---|---|---|
| Leave schedule as `"at any time"` | Bumps land fastest | Noisy during work hours; competes with feature PRs for CI slots | Off-hours batching is net cheaper in CI minutes |
| Auto-merge Go _major_ bumps | Fewer queue items | k8s and grpc major bumps break APIs; human sign-off needed | Too risky for production infrastructure deps |
| One group for all Go + Cargo | Maximum compression | Mixed-language bundle obscures what changed | Separate groups give clearer PR titles and blame history |

## Consequences

- **Positive**: Go and Cargo bumps arrive batched as one or two PRs per Monday morning
rather than dozens spread through the week. Schedule restriction prevents new PRs from
racing human-authored PRs for CI capacity.
- **Negative**: Minor Go/Cargo updates are delayed up to a week (until the next Monday
early-morning window). Acceptable given `minimumReleaseAge: "3 days"` already gates
recency.
- **Neutral**: `vulnerabilityAlerts` already overrides to `"at any time"` with
`minimumReleaseAge: "0 days"` — security patches are unaffected by the schedule change.

## References

- Memory entry `project_renovate_fork_processing.md` — `forkProcessing: "enabled"` rationale.
- ADR-0604 — ROCm Renovate manager (precedent for off-hours grouping pattern).
- ADR-0605 — dev-image pinned-dep managers (same manual-review pattern for GPU deps).
- `go.mod` — `github.com/VMAFx/vmafx` module with k8s/grpc/prometheus/MCP deps.
- `Cargo.toml` — workspace root with `vmafx-sys` and TAD extractor crates.
- req: "Audit renovate.json. Verify forkProcessing, avoid weekends+business hours, group Go deps, auto-merge minor+patch known-safe, major needs human approval."
1 change: 1 addition & 0 deletions docs/adr/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -778,3 +778,4 @@ ADRs may exist there for local session continuity, but the tracked
| [ADR-0810](0810-adr-0108-compliance-audit-2026-05-29.md) | ADR-0108 six-deliverables compliance audit (2026-05-29): 93 % pass rate on 5 PRs; D3 AGENTS.md gap fixes for PR #1571 (repo rename) and PR #1583 (HTTP transport) | Accepted | 2026-05-29 | docs, agents, process |
| [ADR-0811](0811-security-codeql-go-pvr.md) | Security hardening: CodeQL Go coverage, codeql-config.yml conflict resolution, Dependabot/Renovate posture | Accepted | 2026-05-29 | ci, security, codeql, go, dependabot, ossf |
| [ADR-0805](0805-lint-config-tighten-2026-05-29.md) | Lint config tightening: fix `.clang-tidy` HeaderFilterRegex (`libvmaf/` → `core/`), bump clang-format/ruff hooks, add `UP` pyupgrade rule, auto-fix 48 violations | Accepted | 2026-05-29 | lint, build, python, ci, fork-local |
| [ADR-0812](0812-renovate-go-rust-scheduling.md) | Renovate — Go/Cargo grouping, off-hours schedule, and concurrent-PR cap | Accepted | 2026-05-29 | ci, build, deps |
36 changes: 34 additions & 2 deletions renovate.json
Original file line number Diff line number Diff line change
Expand Up @@ -8,10 +8,10 @@
":semanticCommits",
"helpers:disableTypesNodeMajor"
],
"schedule": ["at any time"],
"schedule": ["before 6am on weekdays"],
"timezone": "Europe/Vienna",
"prHourlyLimit": 0,
"prConcurrentLimit": 12,
"prConcurrentLimit": 10,
"rangeStrategy": "bump",
"commitMessagePrefix": "chore(deps):",
"branchPrefix": "renovate/",
Expand Down Expand Up @@ -66,6 +66,38 @@
"groupName": "Python (minor)",
"automerge": false
},
{
"description": "Group all Go minor + patch updates into one PR; auto-merge. k8s/grpc/proto patch bumps are low-risk; CI gates catch regressions.",
"matchManagers": ["gomod"],
"matchUpdateTypes": ["minor", "patch"],
"groupName": "Go deps (minor + patch)",
"automerge": true,
"automergeType": "pr",
"schedule": ["before 6am on Monday"]
},
{
"description": "Go major upgrades travel individually and require human review — module path and API changes.",
"matchManagers": ["gomod"],
"matchUpdateTypes": ["major"],
"groupName": "Go deps (major)",
"automerge": false
},
{
"description": "Group all Cargo (Rust) minor + patch updates; auto-merge — Rust's semantic versioning is reliable and CI catches UB/breakage.",
"matchManagers": ["cargo"],
"matchUpdateTypes": ["minor", "patch"],
"groupName": "Cargo deps (minor + patch)",
"automerge": true,
"automergeType": "pr",
"schedule": ["before 6am on Monday"]
},
{
"description": "Cargo major upgrades require human review — breaking API changes, unsafe code review.",
"matchManagers": ["cargo"],
"matchUpdateTypes": ["major"],
"groupName": "Cargo deps (major)",
"automerge": false
},
{
"description": "Renovate's own action — manual review on bumps to retain auditability of the dep-bot itself.",
"matchPackageNames": ["renovatebot/github-action"],
Expand Down
Loading