The deploy-openclaw job required a CONFIG_REPO_TOKEN secret that was never configured, causing it to fail on every CI run. Tag updates for the openclaw HelmRelease are now handled by Renovate, which detects new images in registry.johnogle.info and opens PRs against k3s-cluster-config to update manifests. The build-and-push-openclaw job remains: it builds the thin Docker image and pushes it to the registry. Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent) Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>