Skip to content

Add protected Azure Pipelines E2E validation for GitHub merges - #29

Open
Hou (SciencePotato) wants to merge 1 commit into
mainfrom
feature/ado-e2e-pipeline
Open

Hou (SciencePotato) wants to merge 1 commit into
mainfrom
feature/ado-e2e-pipeline

Conversation

@SciencePotato

Copy link
Copy Markdown
Collaborator

Summary

  • Add an Azure DevOps / 1ES YAML pipeline hosted in this EPP GitHub repository, plus a generic onboarding guide and offline regression tests.
  • Trigger build-only CI on updates to GitHub main, including PR merges. Resolve Build.SourceVersion from the expected GitHub repository and fetch exactly that commit, rather than a later moving main. Direct pushes also trigger if branch protection permits them; batching can combine updates.
  • Keep deployment manual-only from reviewed main, opt-in, and dependent on an explicit reviewed full source SHA and approved ADO environment. Valid Function HTTP test requests use encrypted evaluation only; no provider delivery is configured.

Privacy and safety

  • No real tenant/subscription/caller IDs, internal organization links, setup journals, deployed resource names, credentials or private keys in this change.
  • Expected identity values come from a deployment-stage-only protected variable group; configure the values as secret in ADO. Automatic build jobs have no Azure deployment tasks or protected identity references.
  • Preserve independent identity checks, all-target preflight, artifact provenance, exact tenant issuers, required HTTPS/Easy Auth, provider-free targets, sanitized failure messages, Azure diagnostic-stream suppression and temporary metadata cleanup.
  • Public metadata such as app names/URLs can still appear in task output. Masking is not an absolute disclosure guarantee; restrict pipeline editors, agents, logs and artifacts.

Validation

  • Seven offline tests pass: YAML and all four embedded PowerShell blocks; GitHub source selection (17 cases); build/deployment secret boundaries; 18 mocked preflight cases including diagnostic markers and cleanup; token-acquisition diagnostic suppression; RSA/AES-GCM evaluation round trips.
  • Public-content scan and staged whitespace checks passed. All test identities are synthetic and keys are generated in memory.

Manual onboarding / limits

  • Register pipelines/deploy-cyot-e2e.yml in Azure DevOps with THIS GitHub repository as its source, not an Azure Repos mirror.
  • Configure approved 1ES template connection, pool and image defaults before enabling automatic runs. Configure the protected variable group, separate federated deployment/caller connections, approved environment and isolated test apps before manual deployment.
  • 1ES template expansion, full Linux packaging and cloud execution remain to be validated in the configured project. This PR does not register pipelines, grant permissions, provision resources or start deployments.
  • Existing GitHub Actions workflows are unchanged. This YAML is an Azure Pipelines definition, not a GitHub Actions workflow.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant