Skip to content

fix(ci): safely restore v2 Hidi Docker dependencies from approved feed - #892

Merged
Vincent Biret (baywet) merged 1 commit into
support/v2from
gavinbarron-hidi-v2-docker-restore
Oct 9, 2026
Merged

Vincent Biret (baywet) merged 1 commit into
support/v2from
gavinbarron-hidi-v2-docker-restore

Conversation

@gavinbarron

@gavinbarron Gavin Barron (gavinbarron) commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Port only the safe Docker feed restore behavior from microsoft/OpenAPI.NET#3107 and the destination main follow-up #890 to support/v2, based on merged #883/#888 at ba2f31f47d9fb84b30df2f67cbe98c5d26fc69f5.

  • Add an optional BuildKit nuget_config secret mount to the existing Docker publish command. Local and GitHub Actions builds without a secret retain default NuGet sources and public signing.
  • Authenticate the single protected stable container job to the approved GraphDeveloperExperiences_Public feed. Write the XML-escaped job token only into a unique agent-temp config outside the build context/artifacts, restrict permissions to 0600 before writing credentials, pass it through --secret, clear the inherited token environment, and remove the file in finally.
  • Fail explicitly on missing token or failed ACR login, platform setup, BuildX creation, or Docker build/push. Document feed/environment owner authorization requirements.

Exactly three files change. Preserve Hidi 2.12.2/2.x, .NET 8, dependencies, public signing identities, HidiDockerContext artifact shape and explicit Dockerfile/context inputs, ACR service connection, docker-images-deploy approvals, stable own-version + latest tags, linux/amd64 + linux/arm64/v8, and existing ESRP/1ES NuGet publishing contracts. No main-only features or preview publishers are imported.

Validation

  • YAML parse and PowerShell AST parse passed. Normalized pipeline is identical to the v2 base outside the added container authentication and AzureCLI credential script; version/dependency/framework/signing/publisher contracts are unchanged.
  • Parent-owned mock harness: all six scenarios passed (success, missing token, ACR login failure, platform setup failure, BuildX creation failure, build failure), covering approved-feed-only XML escaping, empty file with owner-only permissions before credential write, unique agent-temp path, inherited-token clearing, explicit context/identity, and cleanup. No native Azure or Docker commands were invoked by that harness.
  • Staged public-only context: 207 files, exactly two validated public keys, no credential config; Docker-equivalent dotnet publish using the existing flags and Hidi --help passed. Published Hidi remains 2.12.2/net8.0; both strong-name identities match their existing public keys.
  • Exact-head v2 PR CI run 37963211352 passed for 34aae7388fcf02b0e0e83d845cf7c9101d5734f8: actual no-push/no-secret Docker image build and container --help, Windows executable, 91 Hidi tests, 1,279 OData tests, and pack/install/transform smoke checks. Continuous Deployment was skipped. This demonstrates optional-mount compatibility, not credentialed official feed/signing/publishing.
  • Main fix(hidi): authenticate official Docker restores via BuildKit secrets #890's actual no-secret Docker check also passed in run 37961910809; this v2 PR has its own independent proof above.

Release safety

hidiPublishingEnabled remains false. No image/package/release was published, private signing key added, permission granted, environment created, or shared Docker daemon/emulation started. Official pipeline 759 remains awaiting owner-controlled Azure authorization; credentialed official restore/signing/publishing has not been verified. Normal owner review and checks are required; do not auto-merge or enable publishers as part of this PR.

Port optional BuildKit NuGet configuration handoff from OpenAPI.NET source PR #3107 and destination main PR #890. Preserve support/v2 versions, stable container inputs/tags, signing and NuGet contracts, and the disabled publisher gate.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 4cd742a5-166f-4750-8370-5359a09a7a4d
@gavinbarron
Gavin Barron (gavinbarron) requested a review from a team as a code owner October 9, 2026 17:00
@sonarqubecloud

sonarqubecloud Bot commented Oct 9, 2026

Copy link
Copy Markdown

@baywet
Vincent Biret (baywet) merged commit e7372e4 into support/v2 Oct 9, 2026
44 checks passed
@baywet
Vincent Biret (baywet) deleted the gavinbarron-hidi-v2-docker-restore branch October 9, 2026 17:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants