From 82f2e451fde00ebc383ec95ac75fb90dd30f6e44 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Sat, 26 Sep 2026 22:47:16 +0000 Subject: [PATCH 1/5] Bump Microsoft.Extensions.Configuration and Microsoft.Extensions.Configuration.CommandLine Bumps Microsoft.Extensions.Configuration to 10.0.12 Bumps Microsoft.Extensions.Configuration.CommandLine to 10.0.12 --- updated-dependencies: - dependency-name: Microsoft.Extensions.Configuration dependency-version: 10.0.12 dependency-type: direct:production update-type: version-update:semver-patch - dependency-name: Microsoft.Extensions.Configuration dependency-version: 10.0.12 dependency-type: direct:production update-type: version-update:semver-patch - dependency-name: Microsoft.Extensions.Configuration dependency-version: 10.0.12 dependency-type: direct:production update-type: version-update:semver-patch - dependency-name: Microsoft.Extensions.Configuration dependency-version: 10.0.12 dependency-type: direct:production update-type: version-update:semver-patch - dependency-name: Microsoft.Extensions.Configuration dependency-version: 10.0.12 dependency-type: direct:production update-type: version-update:semver-patch - dependency-name: Microsoft.Extensions.Configuration dependency-version: 10.0.12 dependency-type: direct:production update-type: version-update:semver-patch - dependency-name: Microsoft.Extensions.Configuration dependency-version: 10.0.12 dependency-type: direct:production update-type: version-update:semver-patch - dependency-name: Microsoft.Extensions.Configuration dependency-version: 10.0.12 dependency-type: direct:production update-type: version-update:semver-patch - dependency-name: Microsoft.Extensions.Configuration dependency-version: 10.0.12 dependency-type: direct:production update-type: version-update:semver-patch - dependency-name: Microsoft.Extensions.Configuration dependency-version: 10.0.12 dependency-type: direct:production update-type: version-update:semver-patch - dependency-name: Microsoft.Extensions.Configuration.CommandLine dependency-version: 10.0.12 dependency-type: direct:production update-type: version-update:semver-patch - dependency-name: Microsoft.Extensions.Configuration.CommandLine dependency-version: 10.0.12 dependency-type: direct:production update-type: version-update:semver-patch - dependency-name: Microsoft.Extensions.Configuration.CommandLine dependency-version: 10.0.12 dependency-type: direct:production update-type: version-update:semver-patch - dependency-name: Microsoft.Extensions.Configuration.CommandLine dependency-version: 10.0.12 dependency-type: direct:production update-type: version-update:semver-patch - dependency-name: Microsoft.Extensions.Configuration.CommandLine dependency-version: 10.0.12 dependency-type: direct:production update-type: version-update:semver-patch - dependency-name: Microsoft.Extensions.Configuration.CommandLine dependency-version: 10.0.12 dependency-type: direct:production update-type: version-update:semver-patch - dependency-name: Microsoft.Extensions.Configuration.CommandLine dependency-version: 10.0.12 dependency-type: direct:production update-type: version-update:semver-patch - dependency-name: Microsoft.Extensions.Configuration.CommandLine dependency-version: 10.0.12 dependency-type: direct:production update-type: version-update:semver-patch - dependency-name: Microsoft.Extensions.Configuration.CommandLine dependency-version: 10.0.12 dependency-type: direct:production update-type: version-update:semver-patch - dependency-name: Microsoft.Extensions.Configuration.CommandLine dependency-version: 10.0.12 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] --- 02-generic-host/GenericHost.csproj | 2 ++ 12-configuration-precedence/ConfigurationPrecedence.csproj | 2 ++ 13-dependency-injection/DependencyInjection.csproj | 2 ++ 14-array-object-access/ArrayObjectAccess.csproj | 2 ++ 15-collections-binding/CollectionsBinding.csproj | 2 ++ 16-environment-configs/EnvironmentConfigs.csproj | 2 ++ 24-configuration-reload/ConfigurationReload.csproj | 2 ++ 25-logging-reload/LoggingReload.csproj | 2 ++ 26-configuration-testing/ConfigurationTesting.csproj | 1 + 28-aspire/AspireSample.AppHost/AspireSample.AppHost.csproj | 2 ++ Directory.Packages.props | 4 ++-- 11 files changed, 21 insertions(+), 2 deletions(-) diff --git a/02-generic-host/GenericHost.csproj b/02-generic-host/GenericHost.csproj index dde3de4..4aa1c79 100644 --- a/02-generic-host/GenericHost.csproj +++ b/02-generic-host/GenericHost.csproj @@ -8,6 +8,8 @@ + + diff --git a/12-configuration-precedence/ConfigurationPrecedence.csproj b/12-configuration-precedence/ConfigurationPrecedence.csproj index 36135b8..5147c4a 100644 --- a/12-configuration-precedence/ConfigurationPrecedence.csproj +++ b/12-configuration-precedence/ConfigurationPrecedence.csproj @@ -6,6 +6,8 @@ enable + + diff --git a/13-dependency-injection/DependencyInjection.csproj b/13-dependency-injection/DependencyInjection.csproj index dde3de4..1e1f76f 100644 --- a/13-dependency-injection/DependencyInjection.csproj +++ b/13-dependency-injection/DependencyInjection.csproj @@ -8,6 +8,8 @@ + + diff --git a/14-array-object-access/ArrayObjectAccess.csproj b/14-array-object-access/ArrayObjectAccess.csproj index dde3de4..1e1f76f 100644 --- a/14-array-object-access/ArrayObjectAccess.csproj +++ b/14-array-object-access/ArrayObjectAccess.csproj @@ -8,6 +8,8 @@ + + diff --git a/15-collections-binding/CollectionsBinding.csproj b/15-collections-binding/CollectionsBinding.csproj index 5c60317..9b4f7a3 100644 --- a/15-collections-binding/CollectionsBinding.csproj +++ b/15-collections-binding/CollectionsBinding.csproj @@ -6,6 +6,8 @@ enable + + diff --git a/16-environment-configs/EnvironmentConfigs.csproj b/16-environment-configs/EnvironmentConfigs.csproj index 691ecfd..bd4d40a 100644 --- a/16-environment-configs/EnvironmentConfigs.csproj +++ b/16-environment-configs/EnvironmentConfigs.csproj @@ -6,6 +6,8 @@ enable + + diff --git a/24-configuration-reload/ConfigurationReload.csproj b/24-configuration-reload/ConfigurationReload.csproj index 65fe381..8a1ffa1 100644 --- a/24-configuration-reload/ConfigurationReload.csproj +++ b/24-configuration-reload/ConfigurationReload.csproj @@ -6,6 +6,8 @@ enable + + diff --git a/25-logging-reload/LoggingReload.csproj b/25-logging-reload/LoggingReload.csproj index 79aaed3..975dd55 100644 --- a/25-logging-reload/LoggingReload.csproj +++ b/25-logging-reload/LoggingReload.csproj @@ -6,6 +6,8 @@ enable + + diff --git a/26-configuration-testing/ConfigurationTesting.csproj b/26-configuration-testing/ConfigurationTesting.csproj index 7bc664a..de35c9b 100644 --- a/26-configuration-testing/ConfigurationTesting.csproj +++ b/26-configuration-testing/ConfigurationTesting.csproj @@ -17,6 +17,7 @@ + diff --git a/28-aspire/AspireSample.AppHost/AspireSample.AppHost.csproj b/28-aspire/AspireSample.AppHost/AspireSample.AppHost.csproj index 3736e3c..c3b03b8 100644 --- a/28-aspire/AspireSample.AppHost/AspireSample.AppHost.csproj +++ b/28-aspire/AspireSample.AppHost/AspireSample.AppHost.csproj @@ -15,6 +15,8 @@ + + diff --git a/Directory.Packages.props b/Directory.Packages.props index 48827f0..f75383c 100644 --- a/Directory.Packages.props +++ b/Directory.Packages.props @@ -15,9 +15,9 @@ - + - + From ce673269d0868aa9fc170156cdc56a63d7be6e20 Mon Sep 17 00:00:00 2001 From: codebytes <47988+codebytes@users.noreply.github.com> Date: Sat, 26 Sep 2026 19:06:53 -0400 Subject: [PATCH 2/5] Upgrade to .NET SDK 10.0.401 and servicing 10.0.12 with complete build CI --- .github/workflows/dotnet-build.yml | 31 +++++++++++++++++++ .../AzureAppConfiguration.csproj | 1 + .../AspireSample.AppHost.csproj | 2 +- Directory.Packages.props | 26 ++++++++-------- docs/runtime-validation.md | 7 +++++ global.json | 7 +++++ 6 files changed, 60 insertions(+), 14 deletions(-) create mode 100644 .github/workflows/dotnet-build.yml create mode 100644 docs/runtime-validation.md create mode 100644 global.json diff --git a/.github/workflows/dotnet-build.yml b/.github/workflows/dotnet-build.yml new file mode 100644 index 0000000..3897221 --- /dev/null +++ b/.github/workflows/dotnet-build.yml @@ -0,0 +1,31 @@ +name: .NET build and tests +on: + push: + branches: [main] + paths: ['**/*.cs', '**/*.csproj', '**/*.props', '**/*.json', '**/*.sln*', '.github/workflows/dotnet-build.yml'] + pull_request: + branches: [main] +permissions: + contents: read +jobs: + build-and-test: + runs-on: ubuntu-latest + timeout-minutes: 25 + env: + DOTNET_CLI_TELEMETRY_OPTOUT: '1' + DOTNET_NOLOGO: '1' + steps: + - uses: actions/checkout@v7 + with: + persist-credentials: false + - uses: actions/setup-dotnet@v6 + with: + global-json-file: global.json + - run: dotnet restore dotnet-configuration-in-depth.slnx + - run: dotnet build dotnet-configuration-in-depth.slnx --no-restore --configuration Release -m:2 + - name: Configuration unit tests + run: dotnet test 26-configuration-testing/ConfigurationTesting.csproj --no-build --no-restore --configuration Release + - name: Integration tests (including the unchanged timing assertion) + run: dotnet test 27-integration-testing/IntegrationTesting.csproj --no-build --no-restore --configuration Release + - name: Aspire integration tests on the disposable runner's Docker daemon + run: dotnet 28-aspire/AspireSample.Tests/bin/Release/net10.0/AspireSample.Tests.dll --timeout 180s --no-ansi --no-progress diff --git a/22-azure-app-configuration/AzureAppConfiguration.csproj b/22-azure-app-configuration/AzureAppConfiguration.csproj index 044e0b9..c326a18 100644 --- a/22-azure-app-configuration/AzureAppConfiguration.csproj +++ b/22-azure-app-configuration/AzureAppConfiguration.csproj @@ -8,6 +8,7 @@ + diff --git a/28-aspire/AspireSample.AppHost/AspireSample.AppHost.csproj b/28-aspire/AspireSample.AppHost/AspireSample.AppHost.csproj index c3b03b8..0ce83f5 100644 --- a/28-aspire/AspireSample.AppHost/AspireSample.AppHost.csproj +++ b/28-aspire/AspireSample.AppHost/AspireSample.AppHost.csproj @@ -1,4 +1,4 @@ - + Exe diff --git a/Directory.Packages.props b/Directory.Packages.props index f75383c..b77b0ff 100644 --- a/Directory.Packages.props +++ b/Directory.Packages.props @@ -16,23 +16,23 @@ - + - - - - - - + + + + + + - - - - + + + + - - + + diff --git a/docs/runtime-validation.md b/docs/runtime-validation.md new file mode 100644 index 0000000..89e8f7c --- /dev/null +++ b/docs/runtime-validation.md @@ -0,0 +1,7 @@ +# Stable .NET runtime validation + +All 32 sample projects target .NET 10. `global.json` selects SDK 10.0.401; core Microsoft.Extensions and ASP.NET Core packages are aligned to the 10.0.12 servicing release. The previous Azure.Identity and Aspire SDK alignment fixes are preserved. + +The new `.NET build and tests` workflow restores and compiles the full solution, runs the configuration unit tests and integration tests, then executes the native Aspire test runner against Docker on the disposable GitHub-hosted VM. It has read-only repository permissions, no persisted checkout credentials, and no cloud credentials or deployment steps. + +The existing integration test's strict 200 ms assertion is unchanged. Container tests never require a personal machine or Gateway Docker socket. Azure deployment and secret configuration are outside this build workflow. diff --git a/global.json b/global.json new file mode 100644 index 0000000..e1c5e99 --- /dev/null +++ b/global.json @@ -0,0 +1,7 @@ +{ + "sdk": { + "version": "10.0.401", + "rollForward": "latestPatch", + "allowPrerelease": false + } +} From 97023d485ee7c2ee05943ae8f0170ae98ce37750 Mon Sep 17 00:00:00 2001 From: codebytes <47988+codebytes@users.noreply.github.com> Date: Sat, 26 Sep 2026 19:17:10 -0400 Subject: [PATCH 3/5] Measure configured request delay after endpoint warmup without relaxing the timing assertion --- .../Tests/WebApplicationIntegrationTests.cs | 4 ++++ docs/runtime-validation.md | 2 +- 2 files changed, 5 insertions(+), 1 deletion(-) diff --git a/27-integration-testing/Tests/WebApplicationIntegrationTests.cs b/27-integration-testing/Tests/WebApplicationIntegrationTests.cs index 125c130..21da888 100644 --- a/27-integration-testing/Tests/WebApplicationIntegrationTests.cs +++ b/27-integration-testing/Tests/WebApplicationIntegrationTests.cs @@ -228,6 +228,10 @@ public async Task ApiData_ShouldRun_FasterWithTestConfiguration() { // Arrange var client = _factory.CreateClient(); + // Exercise the real endpoint once before measuring configured request delay. + // Cold-start routing/JIT costs vary by runner and are not the setting under test. + using var warmup = await client.GetAsync("/api/data"); + warmup.EnsureSuccessStatusCode(); var stopwatch = System.Diagnostics.Stopwatch.StartNew(); // Act diff --git a/docs/runtime-validation.md b/docs/runtime-validation.md index 89e8f7c..385c700 100644 --- a/docs/runtime-validation.md +++ b/docs/runtime-validation.md @@ -4,4 +4,4 @@ All 32 sample projects target .NET 10. `global.json` selects SDK 10.0.401; core The new `.NET build and tests` workflow restores and compiles the full solution, runs the configuration unit tests and integration tests, then executes the native Aspire test runner against Docker on the disposable GitHub-hosted VM. It has read-only repository permissions, no persisted checkout credentials, and no cloud credentials or deployment steps. -The existing integration test's strict 200 ms assertion is unchanged. Container tests never require a personal machine or Gateway Docker socket. Azure deployment and secret configuration are outside this build workflow. +The integration test keeps its strict 200 ms assertion. It first warms the real endpoint to exclude variable routing/JIT cold-start overhead from the configured-delay measurement. A validation-only negative control with the default 300 ms delay must still fail that same assertion. Container tests never require a personal machine or Gateway Docker socket. Azure deployment and secret configuration are outside this build workflow. From 929c03eedb166c7e1ff125a1bf1deaeae2174527 Mon Sep 17 00:00:00 2001 From: codebytes <47988+codebytes@users.noreply.github.com> Date: Sat, 26 Sep 2026 19:21:06 -0400 Subject: [PATCH 4/5] Trust the disposable CI development certificate for verified Aspire HTTPS health checks --- .github/workflows/dotnet-build.yml | 4 ++++ docs/runtime-validation.md | 2 ++ 2 files changed, 6 insertions(+) diff --git a/.github/workflows/dotnet-build.yml b/.github/workflows/dotnet-build.yml index 3897221..c929a1c 100644 --- a/.github/workflows/dotnet-build.yml +++ b/.github/workflows/dotnet-build.yml @@ -21,6 +21,10 @@ jobs: - uses: actions/setup-dotnet@v6 with: global-json-file: global.json + - name: Trust this disposable runner's local development HTTPS certificate + run: | + dotnet dev-certs https --trust + dotnet dev-certs https --check --trust - run: dotnet restore dotnet-configuration-in-depth.slnx - run: dotnet build dotnet-configuration-in-depth.slnx --no-restore --configuration Release -m:2 - name: Configuration unit tests diff --git a/docs/runtime-validation.md b/docs/runtime-validation.md index 385c700..b44714a 100644 --- a/docs/runtime-validation.md +++ b/docs/runtime-validation.md @@ -5,3 +5,5 @@ All 32 sample projects target .NET 10. `global.json` selects SDK 10.0.401; core The new `.NET build and tests` workflow restores and compiles the full solution, runs the configuration unit tests and integration tests, then executes the native Aspire test runner against Docker on the disposable GitHub-hosted VM. It has read-only repository permissions, no persisted checkout credentials, and no cloud credentials or deployment steps. The integration test keeps its strict 200 ms assertion. It first warms the real endpoint to exclude variable routing/JIT cold-start overhead from the configured-delay measurement. A validation-only negative control with the default 300 ms delay must still fail that same assertion. Container tests never require a personal machine or Gateway Docker socket. Azure deployment and secret configuration are outside this build workflow. + +The CI runner generates/trusts its own local development HTTPS certificate before Aspire starts and checks that trust explicitly. TLS certificate validation remains enabled. No certificate or trust store on the Gateway, a personal machine, or a cloud service is changed. From fb47f4e2f4266d1f41d821599c12702554575777 Mon Sep 17 00:00:00 2001 From: codebytes <47988+codebytes@users.noreply.github.com> Date: Sat, 26 Sep 2026 19:24:50 -0400 Subject: [PATCH 5/5] Expose the local development trust directory to OpenSSL in CI --- .github/workflows/dotnet-build.yml | 2 ++ docs/runtime-validation.md | 1 + 2 files changed, 3 insertions(+) diff --git a/.github/workflows/dotnet-build.yml b/.github/workflows/dotnet-build.yml index c929a1c..aa46a98 100644 --- a/.github/workflows/dotnet-build.yml +++ b/.github/workflows/dotnet-build.yml @@ -23,6 +23,8 @@ jobs: global-json-file: global.json - name: Trust this disposable runner's local development HTTPS certificate run: | + export SSL_CERT_DIR="$HOME/.aspnet/dev-certs/trust:${SSL_CERT_DIR:-/usr/lib/ssl/certs}" + echo "SSL_CERT_DIR=$SSL_CERT_DIR" >> "$GITHUB_ENV" dotnet dev-certs https --trust dotnet dev-certs https --check --trust - run: dotnet restore dotnet-configuration-in-depth.slnx diff --git a/docs/runtime-validation.md b/docs/runtime-validation.md index b44714a..8d5f055 100644 --- a/docs/runtime-validation.md +++ b/docs/runtime-validation.md @@ -7,3 +7,4 @@ The new `.NET build and tests` workflow restores and compiles the full solution, The integration test keeps its strict 200 ms assertion. It first warms the real endpoint to exclude variable routing/JIT cold-start overhead from the configured-delay measurement. A validation-only negative control with the default 300 ms delay must still fail that same assertion. Container tests never require a personal machine or Gateway Docker socket. Azure deployment and secret configuration are outside this build workflow. The CI runner generates/trusts its own local development HTTPS certificate before Aspire starts and checks that trust explicitly. TLS certificate validation remains enabled. No certificate or trust store on the Gateway, a personal machine, or a cloud service is changed. +The SDK-required OpenSSL development trust directory is included in `SSL_CERT_DIR` alongside the existing system roots for this CI job only.