05de03d1d3
Self-hosted Renovate as a weekly CronJob (Sun 04:00 Europe/Budapest) opening dependency-update PRs against admin/homelab-manifests on Gitea. Pilot is deliberately narrow: - Only the kubernetes + helm-values managers are enabled. - Default-deny packageRule; only four images may update: opengist, uptime-kuma, gokapi, cal.com. - minor/patch -> PR with Gitea native auto-merge (platformAutomerge). - major -> held for manual approval via Dependency Dashboard checkbox. Image pinned to renovate/renovate:43.197.0 (the plain tag is the minimal image; the -slim suffix was retired upstream after v37.440.x). Stateless: no Service/Ingress/PVC. Read-only root FS with a 2Gi /tmp emptyDir for git clones + cache. Secrets from existing renovate-secrets. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>