renovate-preflight
Checks that the Renovate GitHub App token can access the repository before Renovate starts. It reports an actionable failure instead of Renovate’s opaque authentication error.
moon run renovate-preflight:cibun tools/renovate-preflight/index.tsThe ci task runs typecheck and unit tests. The preflight command needs REPO,
RENOVATE_TOKEN, GH_TOKEN set to the same token, and gh on PATH.
Without GH_TOKEN, gh uses your own login and the probe does not test the
App token. The renovate job in
.github/workflows/renovate.yml runs it before Renovate.
Credentials
Section titled “Credentials”RENOVATE_TOKENis the per-run GitHub App installation token. The workflow also setsGH_TOKENto the same token for theghGraphQL probe.- The workflow mints the token from
vars.RENOVATE_APP_CLIENT_IDandsecrets.RENOVATE_APP_PRIVATE_KEYin themainenvironment.
Rotate
Section titled “Rotate”GitHub mints a new installation token for each workflow run; it expires after
about one hour. There is no stored RENOVATE_TOKEN to rotate. Infrastructure-as-code in the platform repo stages
RENOVATE_APP_PRIVATE_KEY and RENOVATE_APP_CLIENT_ID. To rotate the key,
a maintainer issues the new value and sets it in the platform repo’s secrets
stack, applies that stack, then applies the stack that stages the GitHub
Actions secrets. Revoke the old key in the App settings only after the
second apply. Nobody edits the Actions secret by hand.