Live graph support - #12727
Live graph support#12727
Conversation
There was a problem hiding this comment.
Pull request overview
This pull request adds live deployment progress reporting for Radius application deploys by polling resource state during rad deploy and publishing sequenced deploy-progress.json snapshots as workflow artifacts. It also adds a defense-in-depth graph sanitization layer to ensure Radius.Core preview graphs omit container environment-variable maps before any serialization or artifact publication.
Changes:
- Add a Go sanitization helper that deep-clones graph properties and omits
properties.containers[*].envforRadius.Compute/containers, wired into both runtime and modeled Radius.Core preview graph producers with tests. - Introduce
deploy-progress/progress.shand integrate it intorun-rad-commandsandpublish-deploy-statusto support live polling, slot rotation, and terminal sequence handoff (plus action-level shell tests). - Add a bundled TypeScript artifact uploader (via
@actions/artifact) with unit tests and a newmake test-deploy-progresstarget.
Reviewed changes
Copilot reviewed 20 out of 24 changed files in this pull request and generated 2 comments.
Show a summary per file
| File | Description |
|---|---|
| specs/005-live-deploy-graph/spec.md | Feature specification for live deploy graph progress, sequencing, artifact naming, and env sanitization requirements. |
| specs/005-live-deploy-graph/plan.md | Implementation plan spanning CLI/graph safety, action-side polling, uploader, and test strategy. |
| pkg/graph/sanitization/properties.go | New helper to deep-clone properties and omit container env maps. |
| pkg/graph/sanitization/properties_test.go | Unit tests validating env omission and non-mutation of inputs. |
| pkg/corerp/frontend/controller/applications/v20250801preview/graph_util.go | Apply sanitization to runtime Radius.Core preview graph projection. |
| pkg/corerp/frontend/controller/applications/v20250801preview/graph_util_test.go | Test ensuring runtime graph output omits container env maps. |
| pkg/cli/graph/modeled.go | Apply sanitization to modeled Radius.Core preview graph output. |
| pkg/cli/graph/modeled_test.go | Test ensuring modeled graph output omits container env maps. |
| build/test.mk | Add test-deploy-progress and include it in make test. |
| .github/extension/README.md | Document live polling behavior, artifact ring naming/retention, sequence handoff, and env omission guarantee. |
| .github/extension/actions/run-rad-commands/deploy-parameters_test.sh | Assert action wiring sources progress helper and wraps deploy paths with start/stop/cleanup. |
| .github/extension/actions/run-rad-commands/action.yml | Source progress helper, configure uploader path, and wrap app deploy with live polling start/stop and EXIT cleanup. |
| .github/extension/actions/publish-deploy-status/publish-deploy-status_test.sh | Extend tests to enforce --preview resource listing, sequence handoff, and env omission in deploy-graph.json. |
| .github/extension/actions/publish-deploy-status/action.yml | Use shared helpers, switch status source to rad resource list --preview, add sanitized warning on failures, and set terminal sequence. |
| .github/extension/actions/deploy-progress/progress.sh | New polling/normalization/uploader orchestration for live progress artifacts and sequence checkpointing. |
| .github/extension/actions/deploy-progress/progress_test.sh | Shell test validating slot rotation, checkpoint behavior, and artifact name sanitization. |
| .github/extension/actions/deploy-progress/artifact-uploader/tsconfig.json | TS config for the uploader. |
| .github/extension/actions/deploy-progress/artifact-uploader/src/upload.ts | Upload implementation using @actions/artifact with optional slot deletion. |
| .github/extension/actions/deploy-progress/artifact-uploader/src/upload_test.ts | Unit tests for uploader behavior (slot replacement and deletion failures). |
| .github/extension/actions/deploy-progress/artifact-uploader/pnpm-lock.yaml | Locked dependencies for the uploader. |
| .github/extension/actions/deploy-progress/artifact-uploader/package.json | Scripts to test and bundle the uploader with ncc and license output. |
| .github/extension/actions/deploy-progress/artifact-uploader/dist/package.json | Mark bundled output as ESM (type: module). |
Files not reviewed (1)
- .github/extension/actions/deploy-progress/artifact-uploader/pnpm-lock.yaml: Generated file
💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
sk593
left a comment
There was a problem hiding this comment.
Three findings remain relevant on the latest head.
Codecov Report❌ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## main #12727 +/- ##
==========================================
+ Coverage 54.45% 54.46% +0.01%
==========================================
Files 770 771 +1
Lines 51415 51446 +31
==========================================
+ Hits 27998 28022 +24
- Misses 20794 20799 +5
- Partials 2623 2625 +2 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Poll Radius.Core resources during application deploys and publish changed snapshots through a bounded artifact ring. Bundle the official artifact client, preserve terminal sequence ordering, and add focused tests and documentation.
Signed-off-by: Nithya Subramanian <nithyasu@microsoft.com>
Signed-off-by: Nithya Subramanian <nithyasu@microsoft.com>
Signed-off-by: Nithya Subramanian <nithyasu@microsoft.com>
Signed-off-by: Nithya Subramanian <nithyasu@microsoft.com>
Signed-off-by: Nithya Subramanian <nithyasu@microsoft.com>
Signed-off-by: Nithya Subramanian <nithyasu@microsoft.com>
Wait for active progress uploads before final publication, verify serialized graph environment redaction across edge-case shapes, and redact artifact runtime credentials from uploader errors. Signed-off-by: Nithya Subramanian <nithyasu@microsoft.com>
Radius functional test overviewClick here to see the test run details
Test Status⌛ Building Radius and pushing container images for functional tests... |
….1 (#12831) Patch release `v0.60.1` for channel `0.60`. ## Backported PRs Listed in cherry-pick (topological) order. **Gap filler** = not requested for the patch, but included because it touched the same region of a shared file between `release/0.60` and a requested commit. Without it the cherry-pick has no common merge base and conflicts. | # | Commit | PR | Role | | --- | --- | --- | --- | | 1 | `6882b5fdf` | #12640 | Requested | | 2 | `af0443809` | #12721 | Requested | | 3 | `7c6de043d` | #12733 | **Gap filler** — `.github/workflows/codeql.yml` | | 4 | `ca7b5a3e7` | #12728 | Requested | | 5 | `2eac7c1f1` | #12702 | Requested | | 6 | `b4ebe2f28` | #12751 | Requested | | 7 | `e30a2594d` | #12727 | Requested | | 8 | `3c7dfecd6` | #12769 | **Gap filler** — `.github/workflows/codeql.yml` | | 9 | `787b6ca1a` | #12765 | **Gap filler** — `build/test.mk` | | 10 | `f84184955` | #12775 | Requested | | 11 | `415d5b9c2` | #12779 | Requested | | 12 | `a1d976013` | #12782 | Requested | | 13 | `14a21bd0d` | #12786 | **Gap filler** — `build/test.mk` | | 14 | `a87146c77` | #12764 | **Gap filler** — `build/test.mk` | | 15 | `073ca3cfa` | #12758 | Requested | | 16 | `5e1f94c13` | #12785 | **Gap filler** — `pkg/cli/cmd/install/kubernetes/kubernetes.go` | | 17 | `1fd650af5` | #12742 | Requested | | 18 | `19376c3f3` | #12829 | Requested | Five of the six gap fillers are CI/test-only. #12785 is not: it adds a Helm `control-plane-readiness` Job, a `pre-upgrade wait-for-control-plane` command, UCP readiness probes, and a NetworkPolicy change. It is required for #12829 to apply. ## Validation Full chain dry-run cherry-picked onto `release/0.60` with zero conflicts. `go build ./...` clean; `pkg/cli/cmd/install/kubernetes`, `cmd/pre-upgrade/cmd`, `pkg/cli/...`, `pkg/graph/...`, and `test/validation` all pass. --------- Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
This pull request introduces live deployment progress reporting for Radius application deploys and adds a new artifact uploader utility. The main changes include a new polling mechanism to track deployment state in real time, a TypeScript-based uploader for workflow artifacts, and comprehensive tests for these new components. Additionally, the documentation and artifact publication logic have been updated to reflect these enhancements. **Live deployment progress reporting:** - Added a polling mechanism in `progress.sh` that tracks resource state during an application deploy, periodically publishing snapshots as workflow artifacts named with the environment, application, run ID, and slot. These artifacts are rotated and retained for one day, enabling real-time updates in the deployment UI. [[1]](diffhunk://#diff-857e0051f96486cef37db831a9ffe0727d48299af34bc7cfe75469739c599280R1-R185) [[2]](diffhunk://#diff-9ffca9bbb740e6e3e003daa22deb59536b4b096ab1ddd047a7d6d46be9402e0fR108-R121) - Updated the documentation in `.github/extension/README.md` to describe the live progress polling, artifact naming, retention, and the new behavior for resource status reporting and environment variable redaction. **Artifact uploader utility:** - Introduced a new TypeScript uploader in `artifact-uploader/src/upload.ts` that uploads deployment progress files as workflow artifacts, with support for replacing existing artifacts in a slot. This uploader is invoked by the polling script and is tested with a dedicated test suite. [[1]](diffhunk://#diff-ae5b5d478c231b09d80b4987f820263a30dc8680888b0bc08d9f9f80a5f770cfR1-R88) [[2]](diffhunk://#diff-a700b201269f466163b174bf16c71b5b94dae7ae8595197b129897a73a2e7296R1-R75) - Added a `package.json` and `tsconfig.json` for the uploader, specifying dependencies, build, and test scripts. [[1]](diffhunk://#diff-075c2e1e822d686a2151f37d642794d20de545b5dd4e70199d2d77c159bffd42R1-R18) [[2]](diffhunk://#diff-9f8f41f417bd5054f4309fe0d1fa5858a5ae9cf993cf03f89057be366cf5fadfR1-R10) **Testing and integration:** - Added a shell test script `progress_test.sh` to validate the polling, artifact upload, slot rotation, and error handling logic in various scenarios. - Updated `publish-deploy-status/action.yml` to source the new `progress.sh` script, integrating live progress reporting into the deploy workflow.<!-- Thank you for contributing to Radius! Please fill out each section below so reviewers have the context they need. Sections marked optional can be removed if they do not apply. --> ## Summary <!-- Provide a concise description of what this PR does. --> ## Reason for change <!-- Explain why this change is needed. If it addresses a GitHub issue, link it below so it is automatically closed when this PR merges (optional). --> Fixes #<!-- issue number (optional) --> ## How to test <!-- Describe the steps a reviewer can take to verify these changes. --> ## File change summary <!-- Summarize the change made in each file that was modified. --> | File | Summary of change | | ---- | ----------------- | | | | --------- Signed-off-by: Nithya Subramanian <nithyasu@microsoft.com> (cherry picked from commit e30a259) Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
….1 (#12831) Patch release `v0.60.1` for channel `0.60`. ## Backported PRs Listed in cherry-pick (topological) order. **Gap filler** = not requested for the patch, but included because it touched the same region of a shared file between `release/0.60` and a requested commit. Without it the cherry-pick has no common merge base and conflicts. | # | Commit | PR | Role | | --- | --- | --- | --- | | 1 | `6882b5fdf` | #12640 | Requested | | 2 | `af0443809` | #12721 | Requested | | 3 | `7c6de043d` | #12733 | **Gap filler** — `.github/workflows/codeql.yml` | | 4 | `ca7b5a3e7` | #12728 | Requested | | 5 | `2eac7c1f1` | #12702 | Requested | | 6 | `b4ebe2f28` | #12751 | Requested | | 7 | `e30a2594d` | #12727 | Requested | | 8 | `3c7dfecd6` | #12769 | **Gap filler** — `.github/workflows/codeql.yml` | | 9 | `787b6ca1a` | #12765 | **Gap filler** — `build/test.mk` | | 10 | `f84184955` | #12775 | Requested | | 11 | `415d5b9c2` | #12779 | Requested | | 12 | `a1d976013` | #12782 | Requested | | 13 | `14a21bd0d` | #12786 | **Gap filler** — `build/test.mk` | | 14 | `a87146c77` | #12764 | **Gap filler** — `build/test.mk` | | 15 | `073ca3cfa` | #12758 | Requested | | 16 | `5e1f94c13` | #12785 | **Gap filler** — `pkg/cli/cmd/install/kubernetes/kubernetes.go` | | 17 | `1fd650af5` | #12742 | Requested | | 18 | `19376c3f3` | #12829 | Requested | Five of the six gap fillers are CI/test-only. #12785 is not: it adds a Helm `control-plane-readiness` Job, a `pre-upgrade wait-for-control-plane` command, UCP readiness probes, and a NetworkPolicy change. It is required for #12829 to apply. ## Validation Full chain dry-run cherry-picked onto `release/0.60` with zero conflicts. `go build ./...` clean; `pkg/cli/cmd/install/kubernetes`, `cmd/pre-upgrade/cmd`, `pkg/cli/...`, `pkg/graph/...`, and `test/validation` all pass. --------- Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com> (cherry picked from commit e5938bf) Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
This pull request introduces live deployment progress reporting for Radius application deploys and adds a new artifact uploader utility. The main changes include a new polling mechanism to track deployment state in real time, a TypeScript-based uploader for workflow artifacts, and comprehensive tests for these new components. Additionally, the documentation and artifact publication logic have been updated to reflect these enhancements. **Live deployment progress reporting:** - Added a polling mechanism in `progress.sh` that tracks resource state during an application deploy, periodically publishing snapshots as workflow artifacts named with the environment, application, run ID, and slot. These artifacts are rotated and retained for one day, enabling real-time updates in the deployment UI. [[1]](diffhunk://#diff-857e0051f96486cef37db831a9ffe0727d48299af34bc7cfe75469739c599280R1-R185) [[2]](diffhunk://#diff-9ffca9bbb740e6e3e003daa22deb59536b4b096ab1ddd047a7d6d46be9402e0fR108-R121) - Updated the documentation in `.github/extension/README.md` to describe the live progress polling, artifact naming, retention, and the new behavior for resource status reporting and environment variable redaction. **Artifact uploader utility:** - Introduced a new TypeScript uploader in `artifact-uploader/src/upload.ts` that uploads deployment progress files as workflow artifacts, with support for replacing existing artifacts in a slot. This uploader is invoked by the polling script and is tested with a dedicated test suite. [[1]](diffhunk://#diff-ae5b5d478c231b09d80b4987f820263a30dc8680888b0bc08d9f9f80a5f770cfR1-R88) [[2]](diffhunk://#diff-a700b201269f466163b174bf16c71b5b94dae7ae8595197b129897a73a2e7296R1-R75) - Added a `package.json` and `tsconfig.json` for the uploader, specifying dependencies, build, and test scripts. [[1]](diffhunk://#diff-075c2e1e822d686a2151f37d642794d20de545b5dd4e70199d2d77c159bffd42R1-R18) [[2]](diffhunk://#diff-9f8f41f417bd5054f4309fe0d1fa5858a5ae9cf993cf03f89057be366cf5fadfR1-R10) **Testing and integration:** - Added a shell test script `progress_test.sh` to validate the polling, artifact upload, slot rotation, and error handling logic in various scenarios. - Updated `publish-deploy-status/action.yml` to source the new `progress.sh` script, integrating live progress reporting into the deploy workflow.<!-- Thank you for contributing to Radius! Please fill out each section below so reviewers have the context they need. Sections marked optional can be removed if they do not apply. --> ## Summary <!-- Provide a concise description of what this PR does. --> ## Reason for change <!-- Explain why this change is needed. If it addresses a GitHub issue, link it below so it is automatically closed when this PR merges (optional). --> Fixes #<!-- issue number (optional) --> ## How to test <!-- Describe the steps a reviewer can take to verify these changes. --> ## File change summary <!-- Summarize the change made in each file that was modified. --> | File | Summary of change | | ---- | ----------------- | | | | --------- Signed-off-by: Nithya Subramanian <nithyasu@microsoft.com> (cherry picked from commit e30a259) Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
….1 (#12831) Patch release `v0.60.1` for channel `0.60`. ## Backported PRs Listed in cherry-pick (topological) order. **Gap filler** = not requested for the patch, but included because it touched the same region of a shared file between `release/0.60` and a requested commit. Without it the cherry-pick has no common merge base and conflicts. | # | Commit | PR | Role | | --- | --- | --- | --- | | 1 | `6882b5fdf` | #12640 | Requested | | 2 | `af0443809` | #12721 | Requested | | 3 | `7c6de043d` | #12733 | **Gap filler** — `.github/workflows/codeql.yml` | | 4 | `ca7b5a3e7` | #12728 | Requested | | 5 | `2eac7c1f1` | #12702 | Requested | | 6 | `b4ebe2f28` | #12751 | Requested | | 7 | `e30a2594d` | #12727 | Requested | | 8 | `3c7dfecd6` | #12769 | **Gap filler** — `.github/workflows/codeql.yml` | | 9 | `787b6ca1a` | #12765 | **Gap filler** — `build/test.mk` | | 10 | `f84184955` | #12775 | Requested | | 11 | `415d5b9c2` | #12779 | Requested | | 12 | `a1d976013` | #12782 | Requested | | 13 | `14a21bd0d` | #12786 | **Gap filler** — `build/test.mk` | | 14 | `a87146c77` | #12764 | **Gap filler** — `build/test.mk` | | 15 | `073ca3cfa` | #12758 | Requested | | 16 | `5e1f94c13` | #12785 | **Gap filler** — `pkg/cli/cmd/install/kubernetes/kubernetes.go` | | 17 | `1fd650af5` | #12742 | Requested | | 18 | `19376c3f3` | #12829 | Requested | Five of the six gap fillers are CI/test-only. #12785 is not: it adds a Helm `control-plane-readiness` Job, a `pre-upgrade wait-for-control-plane` command, UCP readiness probes, and a NetworkPolicy change. It is required for #12829 to apply. ## Validation Full chain dry-run cherry-picked onto `release/0.60` with zero conflicts. `go build ./...` clean; `pkg/cli/cmd/install/kubernetes`, `cmd/pre-upgrade/cmd`, `pkg/cli/...`, `pkg/graph/...`, and `test/validation` all pass. --------- Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com> (cherry picked from commit e5938bf) Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
This pull request introduces live deployment progress reporting for Radius application deploys and adds a new artifact uploader utility. The main changes include a new polling mechanism to track deployment state in real time, a TypeScript-based uploader for workflow artifacts, and comprehensive tests for these new components. Additionally, the documentation and artifact publication logic have been updated to reflect these enhancements.
Live deployment progress reporting:
progress.shthat tracks resource state during an application deploy, periodically publishing snapshots as workflow artifacts named with the environment, application, run ID, and slot. These artifacts are rotated and retained for one day, enabling real-time updates in the deployment UI. [1] [2].github/extension/README.mdto describe the live progress polling, artifact naming, retention, and the new behavior for resource status reporting and environment variable redaction.Artifact uploader utility:
artifact-uploader/src/upload.tsthat uploads deployment progress files as workflow artifacts, with support for replacing existing artifacts in a slot. This uploader is invoked by the polling script and is tested with a dedicated test suite. [1] [2]package.jsonandtsconfig.jsonfor the uploader, specifying dependencies, build, and test scripts. [1] [2]Testing and integration:
progress_test.shto validate the polling, artifact upload, slot rotation, and error handling logic in various scenarios.publish-deploy-status/action.ymlto source the newprogress.shscript, integrating live progress reporting into the deploy workflow.Summary
Reason for change
Fixes #
How to test
File change summary