Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
118 changes: 100 additions & 18 deletions .azure-pipelines/hidi-release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -286,22 +286,63 @@ extends:
Write-Host "##vso[task.setvariable variable=HidiReleaseVersion]$version"
displayName: Read independent hidi version
workingDirectory: '$(Pipeline.Workspace)/hidi-docker-context'
- task: NuGetAuthenticate@1
displayName: Authenticate Docker restore to Azure Artifacts
- task: AzureCLI@2
displayName: Publish multi-platform hidi image
env:
FEED_ACCESS_TOKEN: $(System.AccessToken)
inputs:
azureSubscription: ACR Images Push Service Connection
scriptType: bash
scriptType: pscore
scriptLocation: inlineScript
workingDirectory: '$(Pipeline.Workspace)/hidi-docker-context'
inlineScript: |
set -euo pipefail
az acr login --name msgraphprodregistry
docker run --privileged --rm tonistiigi/binfmt --install all
docker buildx create --use
docker buildx build --platform linux/amd64,linux/arm64/v8 \
--tag "msgraphprodregistry.azurecr.io/public/openapi/hidi:$(HidiReleaseVersion)" \
--tag "msgraphprodregistry.azurecr.io/public/openapi/hidi:latest" \
--push .
$ErrorActionPreference = 'Stop'
$nugetConfigPath = Join-Path '$(Agent.TempDirectory)' ("hidi-docker-{0}.nuget.config" -f [Guid]::NewGuid().ToString('N'))
try {
if ([string]::IsNullOrWhiteSpace($env:FEED_ACCESS_TOKEN)) {
throw "No Azure Artifacts access token available for the Docker build."
}
New-Item -ItemType File -Path $nugetConfigPath | Out-Null
[IO.File]::SetUnixFileMode($nugetConfigPath, ([IO.UnixFileMode]::UserRead -bor [IO.UnixFileMode]::UserWrite))
$feedAccessToken = [System.Security.SecurityElement]::Escape($env:FEED_ACCESS_TOKEN)
@"
<?xml version="1.0" encoding="utf-8"?>
<configuration>
<packageSources>
<clear />
<add key="GraphDeveloperExperiences_Public" value="https://microsoftgraph.pkgs.visualstudio.com/0985d294-5762-4bc2-a565-161ef349ca3e/_packaging/GraphDeveloperExperiences_Public/nuget/v3/index.json" />
</packageSources>
<packageSourceCredentials>
<GraphDeveloperExperiences_Public>
<add key="Username" value="AzureDevOps" />
<add key="ClearTextPassword" value="$feedAccessToken" />
<add key="ValidAuthenticationTypes" value="Basic" />
</GraphDeveloperExperiences_Public>
</packageSourceCredentials>
</configuration>
"@ | Set-Content -LiteralPath $nugetConfigPath -Encoding UTF8
$env:FEED_ACCESS_TOKEN = $null
az acr login --name msgraphprodregistry
if ($LASTEXITCODE -ne 0) { throw "ACR login failed with exit code $LASTEXITCODE." }
docker run --privileged --rm tonistiigi/binfmt --install all
if ($LASTEXITCODE -ne 0) { throw "Docker platform setup failed with exit code $LASTEXITCODE." }
docker buildx create --use
if ($LASTEXITCODE -ne 0) { throw "Docker BuildX setup failed with exit code $LASTEXITCODE." }
docker buildx build --platform linux/amd64,linux/arm64/v8 `
--secret "id=nuget_config,src=$nugetConfigPath" `
--tag "msgraphprodregistry.azurecr.io/public/openapi/hidi:$(HidiReleaseVersion)" `
--tag "msgraphprodregistry.azurecr.io/public/openapi/hidi:latest" `
--push .
if ($LASTEXITCODE -ne 0) { throw "Docker build/push failed with exit code $LASTEXITCODE." }
}
finally {
$env:FEED_ACCESS_TOKEN = $null
if (Test-Path -LiteralPath $nugetConfigPath) {
Remove-Item -LiteralPath $nugetConfigPath -Force
}
}
- stage: preview
dependsOn: build
condition: and(succeeded(), eq(variables.hidiPublishingEnabled, 'true'), eq(variables.hidiPreviewPublishingEnabled, 'true'), eq(variables['Build.SourceBranch'], 'refs/heads/main'))
Expand All @@ -328,19 +369,60 @@ extends:
Write-Host "##vso[task.setvariable variable=HidiPreviewVersion]$previewVersion"
displayName: Compute independent hidi preview tag
workingDirectory: '$(Pipeline.Workspace)/hidi-docker-context'
- task: NuGetAuthenticate@1
displayName: Authenticate Docker restore to Azure Artifacts
- task: AzureCLI@2
displayName: Publish multi-platform hidi preview image
env:
FEED_ACCESS_TOKEN: $(System.AccessToken)
inputs:
azureSubscription: ACR Images Push Service Connection
scriptType: bash
scriptType: pscore
scriptLocation: inlineScript
workingDirectory: '$(Pipeline.Workspace)/hidi-docker-context'
inlineScript: |
set -euo pipefail
az acr login --name msgraphprodregistry
docker run --privileged --rm tonistiigi/binfmt --install all
docker buildx create --use
docker buildx build --platform linux/amd64,linux/arm64/v8 \
--tag "msgraphprodregistry.azurecr.io/public/openapi/hidi:$(HidiPreviewVersion)" \
--tag "msgraphprodregistry.azurecr.io/public/openapi/hidi:nightly" \
--push .
$ErrorActionPreference = 'Stop'
$nugetConfigPath = Join-Path '$(Agent.TempDirectory)' ("hidi-docker-{0}.nuget.config" -f [Guid]::NewGuid().ToString('N'))
try {
if ([string]::IsNullOrWhiteSpace($env:FEED_ACCESS_TOKEN)) {
throw "No Azure Artifacts access token available for the Docker build."
}
New-Item -ItemType File -Path $nugetConfigPath | Out-Null
[IO.File]::SetUnixFileMode($nugetConfigPath, ([IO.UnixFileMode]::UserRead -bor [IO.UnixFileMode]::UserWrite))
$feedAccessToken = [System.Security.SecurityElement]::Escape($env:FEED_ACCESS_TOKEN)
@"
<?xml version="1.0" encoding="utf-8"?>
<configuration>
<packageSources>
<clear />
<add key="GraphDeveloperExperiences_Public" value="https://microsoftgraph.pkgs.visualstudio.com/0985d294-5762-4bc2-a565-161ef349ca3e/_packaging/GraphDeveloperExperiences_Public/nuget/v3/index.json" />
</packageSources>
<packageSourceCredentials>
<GraphDeveloperExperiences_Public>
<add key="Username" value="AzureDevOps" />
<add key="ClearTextPassword" value="$feedAccessToken" />
<add key="ValidAuthenticationTypes" value="Basic" />
</GraphDeveloperExperiences_Public>
</packageSourceCredentials>
</configuration>
"@ | Set-Content -LiteralPath $nugetConfigPath -Encoding UTF8
$env:FEED_ACCESS_TOKEN = $null
az acr login --name msgraphprodregistry
if ($LASTEXITCODE -ne 0) { throw "ACR login failed with exit code $LASTEXITCODE." }
docker run --privileged --rm tonistiigi/binfmt --install all
if ($LASTEXITCODE -ne 0) { throw "Docker platform setup failed with exit code $LASTEXITCODE." }
docker buildx create --use
if ($LASTEXITCODE -ne 0) { throw "Docker BuildX setup failed with exit code $LASTEXITCODE." }
docker buildx build --platform linux/amd64,linux/arm64/v8 `
--secret "id=nuget_config,src=$nugetConfigPath" `
--tag "msgraphprodregistry.azurecr.io/public/openapi/hidi:$(HidiPreviewVersion)" `
--tag "msgraphprodregistry.azurecr.io/public/openapi/hidi:nightly" `
--push .
if ($LASTEXITCODE -ne 0) { throw "Docker build/push failed with exit code $LASTEXITCODE." }
}
finally {
$env:FEED_ACCESS_TOKEN = $null
if (Test-Path -LiteralPath $nugetConfigPath) {
Remove-Item -LiteralPath $nugetConfigPath -Force
}
}
4 changes: 3 additions & 1 deletion Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,9 @@
COPY ./tool/Microsoft.OpenApi.Hidi.public.snk ./hidi/tool/Microsoft.OpenApi.Hidi.public.snk
COPY ./README.md ./hidi/README.md
WORKDIR /app/hidi
RUN dotnet publish ./src/Microsoft.OpenApi.Hidi/Microsoft.OpenApi.Hidi.csproj -c Release -o /app/publish -p:GeneratePackageOnBuild=false -p:HidiPublicSignBuild=true
# Official CI supplies the central feed config as a secret; local builds use default NuGet sources.
RUN --mount=type=secret,id=nuget_config,target=/app/hidi/NuGet.Config \
dotnet publish ./src/Microsoft.OpenApi.Hidi/Microsoft.OpenApi.Hidi.csproj -c Release -o /app/publish -p:GeneratePackageOnBuild=false -p:HidiPublicSignBuild=true

Check warning on line 15 in Dockerfile

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Line is too long. Split it into multiple lines using backslash continuations.

See more on https://sonarcloud.io/project/issues?id=microsoft_OpenAPI.NET.OData&issues=AaEhm_pDHcxEC11hFUYW&open=AaEhm_pDHcxEC11hFUYW&pullRequest=890

FROM mcr.microsoft.com/dotnet/runtime:8.0-jammy-chiseled AS runtime
WORKDIR /app
Expand Down
11 changes: 11 additions & 0 deletions src/Microsoft.OpenApi.Hidi/readme.md
Original file line number Diff line number Diff line change
Expand Up @@ -109,6 +109,17 @@ Container jobs retain the source publisher's existing `docker-images-deploy`
environment and its approvals/checks. The destination pipeline must be authorized
for that protected environment before official publishing can be enabled.

Official container jobs authenticate to the approved
`GraphDeveloperExperiences_Public` central feed using the existing Azure DevOps
job identity. A credential-bearing NuGet config is created with owner-only
permissions in the agent temp directory, passed as the BuildKit `nuget_config`
secret, and removed in `finally`, including on build failure. It is never staged
in `HidiDockerContext`, published as an artifact, or copied into an image layer.
The destination pipeline identity must already be authorized to read the feed;
this handoff does not grant permissions or bypass service-connection approvals.
The Dockerfile secret mount is optional, so local and GitHub Actions builds
without a secret continue to use their default NuGet sources.

The migration baseline 3.10.2 is already published. Destination Hidi NuGet,
GitHub release, stable Docker and preview Docker publishing are disabled until
source cutover. The first destination stable release must advance the Hidi
Expand Down
Loading