Skip to content

fix(hidi): authenticate official Docker restores via BuildKit secrets - #890

Merged
Vincent Biret (baywet) merged 1 commit into
mainfrom
gavinbarron-hidi-docker-restore-handoff
Oct 9, 2026
Merged

Vincent Biret (baywet) merged 1 commit into
mainfrom
gavinbarron-hidi-docker-restore-handoff

Conversation

@gavinbarron

Copy link
Copy Markdown
Contributor

Summary

Reconcile the Hidi-only Docker restore change introduced after the MAIN migration export by microsoft/OpenAPI.NET#3107 (source commit e1a75437b76ebfc7c9eb446e9fd0b59a21afb14b). This follows the merged destination migration #884; it does not copy the source core ESRP pipeline or retire source MAIN publishing.

  • Add an optional BuildKit nuget_config mount at /app/hidi/NuGet.Config; local/GitHub Actions builds without a secret retain default NuGet sources.
  • Authenticate both existing official stable/preview container jobs with NuGetAuthenticate@1 and the existing Azure DevOps job identity. Write the XML-escaped job token into a unique owner-only config under Agent.TempDirectory, pass it through docker buildx --secret, and delete it in finally on success or failure. Missing tokens and native failures fail explicitly.
  • Keep configs out of the repository, HidiDockerContext, published artifacts, logs, and image layers; document the handoff in the Hidi README.

Only Dockerfile, .azure-pipelines/hidi-release.yml, and src/Microsoft.OpenApi.Hidi/readme.md change. Publishing flags remain false. Protected environments, service connections/approvals, artifact-only release inputs (no checkout), public-only Hidi/OData signing, exact stable/preview tags, independent 3.x baseline, framework/dependencies and CLI output contracts are unchanged. No permission grants, real publishing, or auto-merge.

Validation

  • Hidi tests: 107 passed.
  • Docker-equivalent public-sign dotnet publish, CLI help, default OpenAPI 3.2 and CSDL OpenAPI 3.0 output smoke checks passed.
  • YAML parsing, all inline PowerShell AST parsing, CRLF-aware diff checks, and comparisons preserving the original pipeline/GHA contracts passed; unchanged GHA workflow passed actionlint.
  • Executed the official context-staging script: 207 files, two validated public-only signing keys, no NuGet config/private signing resources/build outputs/Git metadata.
  • Independent mock-only validation of both exact AzureCLI scripts: 12 scenarios (success, missing token, ACR login failure, platform setup failure, BuildX creation failure, and build failure). Verified XML escaping, only the approved central feed, owner-only permission setup before writing credentials, unique temp paths outside the context, exact secret/tag arguments, explicit failure propagation, and config/environment cleanup. No real Azure/Docker commands or credentials were used in these mocks.

Pending release readiness

The local Docker daemon is unavailable, so no actual Docker build or push is claimed. The existing PR CI no-push Docker job must verify the optional mount's real no-secret compatibility. Official signed-artifact readiness remains pending resource authorization; no signed release artifacts have been verified here. Normal review/CI acceptance is required before source MAIN publisher retirement. The equivalent destination support/v2 follow-up is separate and is not included in this PR.

Port hidi-only restore authentication from OpenAPI.NET#3107 using optional BuildKit secrets and private temporary configurations. Keep publishing gates disabled and leave library release behavior unchanged.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: c631d217-9378-4cee-8c7e-761043ff3ae5
@sonarqubecloud

sonarqubecloud Bot commented Oct 9, 2026

Copy link
Copy Markdown

@baywet
Vincent Biret (baywet) merged commit a86a146 into main Oct 9, 2026
45 checks passed
@baywet
Vincent Biret (baywet) deleted the gavinbarron-hidi-docker-restore-handoff branch October 9, 2026 17:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants