chore(release): patch v0.60.1 cherry-picks - #12833
Conversation
## Description `Radius.Compute/containerImages` builds run in an in-cluster BuildKit that is compiled for the runner's architecture (amd64 on standard GitHub-hosted runners). When an app leaves `build.platforms` unset, the recipe defaults to a multi-arch build (`linux/amd64,linux/arm64`), so the arm64 half is produced under QEMU emulation, which is roughly an order of magnitude slower and prone to emulation crashes (see the analysis on #12595). This PR lets the Azure and AWS deploy workflows build only the platform(s) the target cluster actually runs, while preserving multi-arch when it is genuinely needed. This is the upstream half of the contract in radius-project/ai-extensions#300. ## Contract Two template placeholders on the Azure and AWS `run-rad-commands` workflows, rendered by the extension: | Placeholder | Extension default | | --- | --- | | `{{TARGET_CLUSTER_ARCH_MODE}}` | `${{ vars.RADIUS_BUILD_ARCH_MODE \|\| 'detect' }}` | | `{{TARGET_CLUSTER_ARCH_FALLBACK_PLATFORMS}}` | `${{ vars.RADIUS_BUILD_PLATFORMS \|\| 'linux/amd64,linux/arm64' }}` | ## Behavior Resolved by `compute-build-platforms.sh`, invoked by the shared `run-rad-commands` action after the target kubeconfig is configured and before the app is built/deployed: | Mode | Cluster | Result | | --- | --- | --- | | `detect` | single-arch | build that one platform (no emulation) | | `detect` | mixed / undetermined | fallback platform list | | explicit list (contains `/`, e.g. `linux/amd64`) | n/a | honored verbatim, no detection | | empty / unsubstituted placeholder | n/a | feature off, recipe default applies (existing behavior) | The computed list is exported as `RADIUS_EFFECTIVE_BUILD_PLATFORMS` and injected as `--parameters platforms=<list>` only when the app declares a `platforms` parameter and it was not already supplied via `RADIUS_DEPLOY_PARAMS`, flowing through the same conditional path as the existing `app-image` parameter. Apps that do not declare `platforms`, and templates that do not render the placeholders, are unaffected. **Mixed-arch is a first-class outcome, not an error.** A cluster with both amd64 and arm64 nodes resolves to the fallback multi-arch list so images stay portable; only single-arch clusters drop to a single platform to skip emulation. ## Design notes - Kept the contract small and explicit. Recognized modes are `detect`, an explicit platform list, or empty/placeholder (off). An unrecognized keyword fails safe to the fallback list with a warning, documented in the workflow and script comments. - Detection uses `kubectl get nodes -o jsonpath=...nodeInfo.architecture`; a failed probe degrades to empty, which the resolver treats as "undetermined" and maps to the fallback. - No Radius runtime/CLI changes; this is entirely in the deploy workflow templates, the shared composite action, and a helper script. ## Testing - `make test-build-platforms` — new `compute-build-platforms_test.sh`: mode/detection/override/fallback matrix (single-arch, mixed-arch, unknown-arch, x86_64/aarch64 aliases, normalization, unrecognized mode), plus assertions that both workflows carry the placeholders and wire the inputs, and that the action declares the inputs and runs the helper. - `make test-run-rad-commands-action` — extended `deploy-parameters_test.sh`: `platforms` is injected only when declared, skipped when no effective list was computed, and never overrides a `RADIUS_DEPLOY_PARAMS`-supplied value. - `shellcheck` clean on all shell; all three modified YAML files parse. ## Files | File | Change | | --- | --- | | `.github/extension/actions/run-rad-commands/compute-build-platforms.sh` | New: resolves effective build platforms from mode/fallback/detected arches | | `.github/extension/actions/run-rad-commands/compute-build-platforms_test.sh` | New: unit + wiring tests | | `.github/extension/actions/run-rad-commands/action.yml` | New `build-arch-mode` / `build-fallback-platforms` inputs; detection step exporting `RADIUS_EFFECTIVE_BUILD_PLATFORMS` | | `.github/extension/actions/run-rad-commands/deploy-parameters.sh` | Inject `platforms` when the app declares it and a list was computed | | `.github/extension/actions/run-rad-commands/deploy-parameters_test.sh` | Coverage for the injection | | `.github/extension/run-rad-commands-azure.yml` / `-aws.yml` | Placeholders + pass the two inputs to `run-rad-commands` | | `build/test.mk` | `test-build-platforms` target, added to `test` | ## Related - radius-project/ai-extensions#300 - #12595 --------- Signed-off-by: Sylvain Niles <sylvainniles@microsoft.com> (cherry picked from commit 6882b5f) Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
…ng) (#12721) ## Summary These deploy workflow templates are rendered by substituting `{{...}}` placeholders. For the architecture placeholders, the tooling injects a GitHub Actions expression whose string-literal default is **single-quoted** (GHA requires single quotes for string literals): ``` ${{ vars.RADIUS_BUILD_ARCH_MODE || 'detect' }} ``` But these templates wrapped the placeholder scalar in **single** quotes: ```yaml TARGET_CLUSTER_ARCH_MODE: '{{TARGET_CLUSTER_ARCH_MODE}}' ``` After substitution the quotes nest and YAML terminates the scalar early, producing invalid YAML: ```yaml TARGET_CLUSTER_ARCH_MODE: '${{ vars.RADIUS_BUILD_ARCH_MODE || 'detect' }}' ``` Every Azure and AWS deploy dispatch then failed with `HTTP 422: failed to parse workflow ... error in your yaml syntax`. ## Fix In both `.github/extension/run-rad-commands-azure.yml` and `.github/extension/run-rad-commands-aws.yml`, the two architecture placeholder scalars are changed from single to **double** quotes: ```yaml TARGET_CLUSTER_ARCH_MODE: "{{TARGET_CLUSTER_ARCH_MODE}}" TARGET_CLUSTER_ARCH_FALLBACK_PLATFORMS: "{{TARGET_CLUSTER_ARCH_FALLBACK_PLATFORMS}}" ``` The rendered result then becomes valid YAML — the outer double quotes safely contain the inner single-quoted GHA string literal: ```yaml TARGET_CLUSTER_ARCH_MODE: "${{ vars.RADIUS_BUILD_ARCH_MODE || 'detect' }}" ``` The other single-quoted scalars (`APP_FILE: '{{APP_FILE}}'`, `default: '{{ENV}}'`, `environment: ${{ inputs.environment || '{{ENV}}' }}`) inject plain values that contain no single quotes, so they remain valid and are left unchanged. ## Verification - Both provider files parse as valid YAML. - Simulated the substitution (`{{TARGET_CLUSTER_ARCH_MODE}}` → `${{ vars.RADIUS_BUILD_ARCH_MODE || 'detect' }}` and `{{TARGET_CLUSTER_ARCH_FALLBACK_PLATFORMS}}` → `${{ vars.RADIUS_BUILD_PLATFORMS || 'linux/amd64,linux/arm64' }}`) in temp copies of each file and confirmed they still parse as valid YAML, with the GHA expression preserved intact as the string value. ## Related - Regression introduced by the single-quoting in #12640 Signed-off-by: sk593 <shruthikumar@microsoft.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> (cherry picked from commit af04438) Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
…ates (#12733) Bumps the github-actions group with 4 updates in the / directory: [github/codeql-action/init](https://github.com/github/codeql-action), [github/codeql-action/autobuild](https://github.com/github/codeql-action), [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) and [github/codeql-action/analyze](https://github.com/github/codeql-action). Updates `github/codeql-action/init` from 4.37.6 to 4.37.7 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/github/codeql-action/releases">github/codeql-action/init's releases</a>.</em></p> <blockquote> <h2>v4.37.7</h2> <ul> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3">2.26.3</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4085">#4085</a></li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md">github/codeql-action/init's changelog</a>.</em></p> <blockquote> <h1>CodeQL Action Changelog</h1> <p>See the <a href="https://github.com/github/codeql-action/releases">releases page</a> for the relevant changes to the CodeQL CLI and language packs.</p> <h2>[UNRELEASED]</h2> <p>No user facing changes.</p> <h2>4.37.7 - 13 Aug 2026</h2> <ul> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3">2.26.3</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4085">#4085</a></li> </ul> <h2>4.37.6 - 04 Aug 2026</h2> <ul> <li>Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to <code>.github/codeql-config.yml</code> to align it with the suggested path that is used elsewhere. <a href="https://redirect.github.com/github/codeql-action/pull/4070">#4070</a></li> </ul> <h2>4.37.5 - 03 Aug 2026</h2> <ul> <li>Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the <code>init</code> Action instead of falling back to downloading the bundle before extracting it. <a href="https://redirect.github.com/github/codeql-action/pull/4061">#4061</a></li> </ul> <h2>4.37.4 - 29 Jul 2026</h2> <ul> <li>This version of the CodeQL Action adds support for the <code>tools</code> input for the <code>codeql-action/init</code> step to be specified using a <code>github-codeql-tools</code> <a href="https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization">repository property</a>. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to <code>toolcache</code> to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for <code>tools</code> in the workflow definition always takes precedence unless the value of the repository property starts with <code>!</code>. <a href="https://redirect.github.com/github/codeql-action/pull/4037">#4037</a></li> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2">2.26.2</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4051">#4051</a></li> </ul> <h2>4.37.3 - 22 Jul 2026</h2> <p>No user facing changes.</p> <h2>4.37.2 - 21 Jul 2026</h2> <ul> <li>The new address format for the <code>config-file</code> input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the <code>remote=</code> prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. <a href="https://redirect.github.com/github/codeql-action/pull/4023">#4023</a></li> <li>The CodeQL Action can now make use of <a href="https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries">configured private registries</a> in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. <a href="https://redirect.github.com/github/codeql-action/pull/4007">#4007</a></li> </ul> <h2>4.37.1 - 16 Jul 2026</h2> <ul> <li><em>Upcoming breaking change</em>: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. <a href="https://redirect.github.com/github/codeql-action/pull/3956">#3956</a></li> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.1">2.26.1</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4019">#4019</a></li> </ul> <h2>4.37.0 - 08 Jul 2026</h2> <ul> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.0">2.26.0</a>. <a href="https://redirect.github.com/github/codeql-action/pull/3995">#3995</a></li> <li>In addition to the existing input format, the <code>config-file</code> input for the <code>codeql-action/init</code> step will soon support a new <code>[owner/]repo[@ref][:path]</code> format. All components except the repository name are optional. If omitted, <code>owner</code> defaults to the same owner as the repository the analysis is running for, <code>ref</code> to <code>main</code>, and <code>path</code> to <code>.github/codeql-action.yaml</code>. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. <a href="https://redirect.github.com/github/codeql-action/pull/3973">#3973</a></li> </ul> <h2>4.36.3 - 01 Jul 2026</h2> <p>No user facing changes.</p> <h2>4.36.2 - 04 Jun 2026</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/github/codeql-action/commit/ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd"><code>ff2f1c6</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4093">#4093</a> from github/update-v4.37.7-be7a3dbb8</li> <li><a href="https://github.com/github/codeql-action/commit/951a133f96aa2114dd747e9e437305335d0bde16"><code>951a133</code></a> Update changelog for v4.37.7</li> <li><a href="https://github.com/github/codeql-action/commit/be7a3dbb8147b82cd6d27e0707105b36aa190fc1"><code>be7a3db</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4087">#4087</a> from github/dependabot/npm_and_yarn/npm-minor-0aa561...</li> <li><a href="https://github.com/github/codeql-action/commit/9310334b11405b305d9444edfa56cd86e2f1e4fe"><code>9310334</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4086">#4086</a> from github/mbg/thread-action-state-to-codeql</li> <li><a href="https://github.com/github/codeql-action/commit/b4d8a54218a8792de9af2f6f32e33af899ca5212"><code>b4d8a54</code></a> Rebuild</li> <li><a href="https://github.com/github/codeql-action/commit/ab5db2519c3344f2fa61c711fa2d6ad135829200"><code>ab5db25</code></a> Bump the npm-minor group across 1 directory with 8 updates</li> <li><a href="https://github.com/github/codeql-action/commit/38055a3c3cf3979323eaf70fc6c73a8690250bde"><code>38055a3</code></a> Drop <code>logger</code> from <code>databaseInitCluster</code> in interface</li> <li><a href="https://github.com/github/codeql-action/commit/1f87aed5e66849f0c43ae147377cc77f2d98ac99"><code>1f87aed</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4085">#4085</a> from github/update-bundle/codeql-bundle-v2.26.3</li> <li><a href="https://github.com/github/codeql-action/commit/dc1b98ad1c2f13ccf9fc33fb82f32fc76f944253"><code>dc1b98a</code></a> Make <code>logger</code> available to <code>getCodeQLForCmd</code></li> <li><a href="https://github.com/github/codeql-action/commit/6f0220ee37121218af472efbde25f06907a4da4f"><code>6f0220e</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4084">#4084</a> from github/navntoft/bump-undici</li> <li>Additional commits viewable in <a href="https://github.com/github/codeql-action/compare/5595ccaf912efad79be6eef63a5619ff05969be3...ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd">compare view</a></li> </ul> </details> <br /> Updates `github/codeql-action/autobuild` from 4.37.6 to 4.37.7 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/github/codeql-action/releases">github/codeql-action/autobuild's releases</a>.</em></p> <blockquote> <h2>v4.37.7</h2> <ul> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3">2.26.3</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4085">#4085</a></li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md">github/codeql-action/autobuild's changelog</a>.</em></p> <blockquote> <h1>CodeQL Action Changelog</h1> <p>See the <a href="https://github.com/github/codeql-action/releases">releases page</a> for the relevant changes to the CodeQL CLI and language packs.</p> <h2>[UNRELEASED]</h2> <p>No user facing changes.</p> <h2>4.37.7 - 13 Aug 2026</h2> <ul> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3">2.26.3</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4085">#4085</a></li> </ul> <h2>4.37.6 - 04 Aug 2026</h2> <ul> <li>Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to <code>.github/codeql-config.yml</code> to align it with the suggested path that is used elsewhere. <a href="https://redirect.github.com/github/codeql-action/pull/4070">#4070</a></li> </ul> <h2>4.37.5 - 03 Aug 2026</h2> <ul> <li>Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the <code>init</code> Action instead of falling back to downloading the bundle before extracting it. <a href="https://redirect.github.com/github/codeql-action/pull/4061">#4061</a></li> </ul> <h2>4.37.4 - 29 Jul 2026</h2> <ul> <li>This version of the CodeQL Action adds support for the <code>tools</code> input for the <code>codeql-action/init</code> step to be specified using a <code>github-codeql-tools</code> <a href="https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization">repository property</a>. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to <code>toolcache</code> to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for <code>tools</code> in the workflow definition always takes precedence unless the value of the repository property starts with <code>!</code>. <a href="https://redirect.github.com/github/codeql-action/pull/4037">#4037</a></li> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2">2.26.2</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4051">#4051</a></li> </ul> <h2>4.37.3 - 22 Jul 2026</h2> <p>No user facing changes.</p> <h2>4.37.2 - 21 Jul 2026</h2> <ul> <li>The new address format for the <code>config-file</code> input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the <code>remote=</code> prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. <a href="https://redirect.github.com/github/codeql-action/pull/4023">#4023</a></li> <li>The CodeQL Action can now make use of <a href="https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries">configured private registries</a> in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. <a href="https://redirect.github.com/github/codeql-action/pull/4007">#4007</a></li> </ul> <h2>4.37.1 - 16 Jul 2026</h2> <ul> <li><em>Upcoming breaking change</em>: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. <a href="https://redirect.github.com/github/codeql-action/pull/3956">#3956</a></li> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.1">2.26.1</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4019">#4019</a></li> </ul> <h2>4.37.0 - 08 Jul 2026</h2> <ul> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.0">2.26.0</a>. <a href="https://redirect.github.com/github/codeql-action/pull/3995">#3995</a></li> <li>In addition to the existing input format, the <code>config-file</code> input for the <code>codeql-action/init</code> step will soon support a new <code>[owner/]repo[@ref][:path]</code> format. All components except the repository name are optional. If omitted, <code>owner</code> defaults to the same owner as the repository the analysis is running for, <code>ref</code> to <code>main</code>, and <code>path</code> to <code>.github/codeql-action.yaml</code>. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. <a href="https://redirect.github.com/github/codeql-action/pull/3973">#3973</a></li> </ul> <h2>4.36.3 - 01 Jul 2026</h2> <p>No user facing changes.</p> <h2>4.36.2 - 04 Jun 2026</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/github/codeql-action/commit/ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd"><code>ff2f1c6</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4093">#4093</a> from github/update-v4.37.7-be7a3dbb8</li> <li><a href="https://github.com/github/codeql-action/commit/951a133f96aa2114dd747e9e437305335d0bde16"><code>951a133</code></a> Update changelog for v4.37.7</li> <li><a href="https://github.com/github/codeql-action/commit/be7a3dbb8147b82cd6d27e0707105b36aa190fc1"><code>be7a3db</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4087">#4087</a> from github/dependabot/npm_and_yarn/npm-minor-0aa561...</li> <li><a href="https://github.com/github/codeql-action/commit/9310334b11405b305d9444edfa56cd86e2f1e4fe"><code>9310334</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4086">#4086</a> from github/mbg/thread-action-state-to-codeql</li> <li><a href="https://github.com/github/codeql-action/commit/b4d8a54218a8792de9af2f6f32e33af899ca5212"><code>b4d8a54</code></a> Rebuild</li> <li><a href="https://github.com/github/codeql-action/commit/ab5db2519c3344f2fa61c711fa2d6ad135829200"><code>ab5db25</code></a> Bump the npm-minor group across 1 directory with 8 updates</li> <li><a href="https://github.com/github/codeql-action/commit/38055a3c3cf3979323eaf70fc6c73a8690250bde"><code>38055a3</code></a> Drop <code>logger</code> from <code>databaseInitCluster</code> in interface</li> <li><a href="https://github.com/github/codeql-action/commit/1f87aed5e66849f0c43ae147377cc77f2d98ac99"><code>1f87aed</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4085">#4085</a> from github/update-bundle/codeql-bundle-v2.26.3</li> <li><a href="https://github.com/github/codeql-action/commit/dc1b98ad1c2f13ccf9fc33fb82f32fc76f944253"><code>dc1b98a</code></a> Make <code>logger</code> available to <code>getCodeQLForCmd</code></li> <li><a href="https://github.com/github/codeql-action/commit/6f0220ee37121218af472efbde25f06907a4da4f"><code>6f0220e</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4084">#4084</a> from github/navntoft/bump-undici</li> <li>Additional commits viewable in <a href="https://github.com/github/codeql-action/compare/5595ccaf912efad79be6eef63a5619ff05969be3...ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd">compare view</a></li> </ul> </details> <br /> Updates `github/codeql-action/upload-sarif` from 4.37.6 to 4.37.7 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/github/codeql-action/releases">github/codeql-action/upload-sarif's releases</a>.</em></p> <blockquote> <h2>v4.37.7</h2> <ul> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3">2.26.3</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4085">#4085</a></li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md">github/codeql-action/upload-sarif's changelog</a>.</em></p> <blockquote> <h1>CodeQL Action Changelog</h1> <p>See the <a href="https://github.com/github/codeql-action/releases">releases page</a> for the relevant changes to the CodeQL CLI and language packs.</p> <h2>[UNRELEASED]</h2> <p>No user facing changes.</p> <h2>4.37.7 - 13 Aug 2026</h2> <ul> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3">2.26.3</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4085">#4085</a></li> </ul> <h2>4.37.6 - 04 Aug 2026</h2> <ul> <li>Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to <code>.github/codeql-config.yml</code> to align it with the suggested path that is used elsewhere. <a href="https://redirect.github.com/github/codeql-action/pull/4070">#4070</a></li> </ul> <h2>4.37.5 - 03 Aug 2026</h2> <ul> <li>Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the <code>init</code> Action instead of falling back to downloading the bundle before extracting it. <a href="https://redirect.github.com/github/codeql-action/pull/4061">#4061</a></li> </ul> <h2>4.37.4 - 29 Jul 2026</h2> <ul> <li>This version of the CodeQL Action adds support for the <code>tools</code> input for the <code>codeql-action/init</code> step to be specified using a <code>github-codeql-tools</code> <a href="https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization">repository property</a>. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to <code>toolcache</code> to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for <code>tools</code> in the workflow definition always takes precedence unless the value of the repository property starts with <code>!</code>. <a href="https://redirect.github.com/github/codeql-action/pull/4037">#4037</a></li> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2">2.26.2</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4051">#4051</a></li> </ul> <h2>4.37.3 - 22 Jul 2026</h2> <p>No user facing changes.</p> <h2>4.37.2 - 21 Jul 2026</h2> <ul> <li>The new address format for the <code>config-file</code> input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the <code>remote=</code> prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. <a href="https://redirect.github.com/github/codeql-action/pull/4023">#4023</a></li> <li>The CodeQL Action can now make use of <a href="https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries">configured private registries</a> in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. <a href="https://redirect.github.com/github/codeql-action/pull/4007">#4007</a></li> </ul> <h2>4.37.1 - 16 Jul 2026</h2> <ul> <li><em>Upcoming breaking change</em>: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. <a href="https://redirect.github.com/github/codeql-action/pull/3956">#3956</a></li> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.1">2.26.1</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4019">#4019</a></li> </ul> <h2>4.37.0 - 08 Jul 2026</h2> <ul> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.0">2.26.0</a>. <a href="https://redirect.github.com/github/codeql-action/pull/3995">#3995</a></li> <li>In addition to the existing input format, the <code>config-file</code> input for the <code>codeql-action/init</code> step will soon support a new <code>[owner/]repo[@ref][:path]</code> format. All components except the repository name are optional. If omitted, <code>owner</code> defaults to the same owner as the repository the analysis is running for, <code>ref</code> to <code>main</code>, and <code>path</code> to <code>.github/codeql-action.yaml</code>. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. <a href="https://redirect.github.com/github/codeql-action/pull/3973">#3973</a></li> </ul> <h2>4.36.3 - 01 Jul 2026</h2> <p>No user facing changes.</p> <h2>4.36.2 - 04 Jun 2026</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/github/codeql-action/commit/ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd"><code>ff2f1c6</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4093">#4093</a> from github/update-v4.37.7-be7a3dbb8</li> <li><a href="https://github.com/github/codeql-action/commit/951a133f96aa2114dd747e9e437305335d0bde16"><code>951a133</code></a> Update changelog for v4.37.7</li> <li><a href="https://github.com/github/codeql-action/commit/be7a3dbb8147b82cd6d27e0707105b36aa190fc1"><code>be7a3db</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4087">#4087</a> from github/dependabot/npm_and_yarn/npm-minor-0aa561...</li> <li><a href="https://github.com/github/codeql-action/commit/9310334b11405b305d9444edfa56cd86e2f1e4fe"><code>9310334</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4086">#4086</a> from github/mbg/thread-action-state-to-codeql</li> <li><a href="https://github.com/github/codeql-action/commit/b4d8a54218a8792de9af2f6f32e33af899ca5212"><code>b4d8a54</code></a> Rebuild</li> <li><a href="https://github.com/github/codeql-action/commit/ab5db2519c3344f2fa61c711fa2d6ad135829200"><code>ab5db25</code></a> Bump the npm-minor group across 1 directory with 8 updates</li> <li><a href="https://github.com/github/codeql-action/commit/38055a3c3cf3979323eaf70fc6c73a8690250bde"><code>38055a3</code></a> Drop <code>logger</code> from <code>databaseInitCluster</code> in interface</li> <li><a href="https://github.com/github/codeql-action/commit/1f87aed5e66849f0c43ae147377cc77f2d98ac99"><code>1f87aed</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4085">#4085</a> from github/update-bundle/codeql-bundle-v2.26.3</li> <li><a href="https://github.com/github/codeql-action/commit/dc1b98ad1c2f13ccf9fc33fb82f32fc76f944253"><code>dc1b98a</code></a> Make <code>logger</code> available to <code>getCodeQLForCmd</code></li> <li><a href="https://github.com/github/codeql-action/commit/6f0220ee37121218af472efbde25f06907a4da4f"><code>6f0220e</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4084">#4084</a> from github/navntoft/bump-undici</li> <li>Additional commits viewable in <a href="https://github.com/github/codeql-action/compare/5595ccaf912efad79be6eef63a5619ff05969be3...ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd">compare view</a></li> </ul> </details> <br /> Updates `github/codeql-action/analyze` from 4.37.6 to 4.37.7 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/github/codeql-action/releases">github/codeql-action/analyze's releases</a>.</em></p> <blockquote> <h2>v4.37.7</h2> <ul> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3">2.26.3</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4085">#4085</a></li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md">github/codeql-action/analyze's changelog</a>.</em></p> <blockquote> <h1>CodeQL Action Changelog</h1> <p>See the <a href="https://github.com/github/codeql-action/releases">releases page</a> for the relevant changes to the CodeQL CLI and language packs.</p> <h2>[UNRELEASED]</h2> <p>No user facing changes.</p> <h2>4.37.7 - 13 Aug 2026</h2> <ul> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3">2.26.3</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4085">#4085</a></li> </ul> <h2>4.37.6 - 04 Aug 2026</h2> <ul> <li>Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to <code>.github/codeql-config.yml</code> to align it with the suggested path that is used elsewhere. <a href="https://redirect.github.com/github/codeql-action/pull/4070">#4070</a></li> </ul> <h2>4.37.5 - 03 Aug 2026</h2> <ul> <li>Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the <code>init</code> Action instead of falling back to downloading the bundle before extracting it. <a href="https://redirect.github.com/github/codeql-action/pull/4061">#4061</a></li> </ul> <h2>4.37.4 - 29 Jul 2026</h2> <ul> <li>This version of the CodeQL Action adds support for the <code>tools</code> input for the <code>codeql-action/init</code> step to be specified using a <code>github-codeql-tools</code> <a href="https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization">repository property</a>. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to <code>toolcache</code> to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for <code>tools</code> in the workflow definition always takes precedence unless the value of the repository property starts with <code>!</code>. <a href="https://redirect.github.com/github/codeql-action/pull/4037">#4037</a></li> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2">2.26.2</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4051">#4051</a></li> </ul> <h2>4.37.3 - 22 Jul 2026</h2> <p>No user facing changes.</p> <h2>4.37.2 - 21 Jul 2026</h2> <ul> <li>The new address format for the <code>config-file</code> input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the <code>remote=</code> prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. <a href="https://redirect.github.com/github/codeql-action/pull/4023">#4023</a></li> <li>The CodeQL Action can now make use of <a href="https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries">configured private registries</a> in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. <a href="https://redirect.github.com/github/codeql-action/pull/4007">#4007</a></li> </ul> <h2>4.37.1 - 16 Jul 2026</h2> <ul> <li><em>Upcoming breaking change</em>: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. <a href="https://redirect.github.com/github/codeql-action/pull/3956">#3956</a></li> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.1">2.26.1</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4019">#4019</a></li> </ul> <h2>4.37.0 - 08 Jul 2026</h2> <ul> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.0">2.26.0</a>. <a href="https://redirect.github.com/github/codeql-action/pull/3995">#3995</a></li> <li>In addition to the existing input format, the <code>config-file</code> input for the <code>codeql-action/init</code> step will soon support a new <code>[owner/]repo[@ref][:path]</code> format. All components except the repository name are optional. If omitted, <code>owner</code> defaults to the same owner as the repository the analysis is running for, <code>ref</code> to <code>main</code>, and <code>path</code> to <code>.github/codeql-action.yaml</code>. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. <a href="https://redirect.github.com/github/codeql-action/pull/3973">#3973</a></li> </ul> <h2>4.36.3 - 01 Jul 2026</h2> <p>No user facing changes.</p> <h2>4.36.2 - 04 Jun 2026</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/github/codeql-action/commit/ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd"><code>ff2f1c6</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4093">#4093</a> from github/update-v4.37.7-be7a3dbb8</li> <li><a href="https://github.com/github/codeql-action/commit/951a133f96aa2114dd747e9e437305335d0bde16"><code>951a133</code></a> Update changelog for v4.37.7</li> <li><a href="https://github.com/github/codeql-action/commit/be7a3dbb8147b82cd6d27e0707105b36aa190fc1"><code>be7a3db</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4087">#4087</a> from github/dependabot/npm_and_yarn/npm-minor-0aa561...</li> <li><a href="https://github.com/github/codeql-action/commit/9310334b11405b305d9444edfa56cd86e2f1e4fe"><code>9310334</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4086">#4086</a> from github/mbg/thread-action-state-to-codeql</li> <li><a href="https://github.com/github/codeql-action/commit/b4d8a54218a8792de9af2f6f32e33af899ca5212"><code>b4d8a54</code></a> Rebuild</li> <li><a href="https://github.com/github/codeql-action/commit/ab5db2519c3344f2fa61c711fa2d6ad135829200"><code>ab5db25</code></a> Bump the npm-minor group across 1 directory with 8 updates</li> <li><a href="https://github.com/github/codeql-action/commit/38055a3c3cf3979323eaf70fc6c73a8690250bde"><code>38055a3</code></a> Drop <code>logger</code> from <code>databaseInitCluster</code> in interface</li> <li><a href="https://github.com/github/codeql-action/commit/1f87aed5e66849f0c43ae147377cc77f2d98ac99"><code>1f87aed</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4085">#4085</a> from github/update-bundle/codeql-bundle-v2.26.3</li> <li><a href="https://github.com/github/codeql-action/commit/dc1b98ad1c2f13ccf9fc33fb82f32fc76f944253"><code>dc1b98a</code></a> Make <code>logger</code> available to <code>getCodeQLForCmd</code></li> <li><a href="https://github.com/github/codeql-action/commit/6f0220ee37121218af472efbde25f06907a4da4f"><code>6f0220e</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4084">#4084</a> from github/navntoft/bump-undici</li> <li>Additional commits viewable in <a href="https://github.com/github/codeql-action/compare/5595ccaf912efad79be6eef63a5619ff05969be3...ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (cherry picked from commit 7c6de04) Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
…ts and applications types (#12728) ## Summary Adds `--preview` support to `rad resource list` so environment- and application-scoped listing works with the `Radius.Core/environments` and `Radius.Core/applications` resource types. `rad resource list` is now wired through `wirePreviewSubcommand`, matching the pattern used by the `rad env` and `rad app` commands. In preview mode, the runner resolves fully-qualified `Radius.Core` resource IDs instead of bare names, and validates applications against the `Radius.Core` applications client. ## Reason for change [#12481](#12481) made the `[resourceType]` argument optional so `rad resource list` could list all resources in an environment or application. That path only worked for legacy resources. `cli.RequireEnvironmentName` reduces the workspace environment to its name, and `ListResourcesInEnvironment` re-qualifies a bare name as `Applications.Core/environments`. Filtering is exact, case-insensitive ID equality, so resources referencing `Radius.Core/environments` were silently excluded and the command returned an empty list. `-a` had the same problem, since it qualified names as `Applications.Core/applications` and validated existence through the legacy `GetApplication`. Legacy and preview environments/applications may share a name, so the client deliberately does not match both ID forms at once — that would merge results from two distinct resources. Instead, the caller supplies the exact ID it wants filtered. Fixes: #12609 ## How to test Requires a preview environment (`rad env create <env> --preview`) and a deployed preview application. ```bash # All resources in the default (Radius.Core) environment rad resource list --preview # All resources in a specific preview environment rad resource list -e my-env --preview # Typed listing scoped to a preview environment rad resource list Radius.Compute/containers -e my-env --preview # All resources in a preview application rad resource list -a my-app --preview # Full Radius.Core resource IDs are accepted rad resource list -a /planes/radius/local/resourceGroups/my-rg/providers/Radius.Core/applications/my-app --preview # RADIUS_PREVIEW=true activates preview mode RADIUS_PREVIEW=true rad resource list ``` Verify that legacy behavior is unchanged when `--preview` is omitted, and that a legacy `Applications.Core` ID passed to `-e`/`-a` under `--preview` is rejected with a clear message. ## File change summary | File | Summary of change | | ---- | ----------------- | | `cmd/rad/cmd/root.go` | Wires `rad resource list` through `wirePreviewSubcommand` so `--preview` and `RADIUS_PREVIEW=true` route to the preview runner. | | `cmd/rad/cmd/root_test.go` | Adds `Test_ResourceList_ExposesPreviewFlag`, asserting the assembled command tree exposes `--preview` on `rad resource list`. | | `pkg/cli/cmd/resource/list/list.go` | Adds `NewPreviewCommand` and a `Preview` field on the runner, sharing one implementation. In preview mode, resolves `Radius.Core` environment/application IDs (preserving full IDs, qualifying bare names, rejecting non-`Radius.Core` IDs), validates applications via the `Radius.Core` applications client, and passes full IDs to the list methods. Renames `EnvironmentName` to `EnvironmentNameOrID` to reflect that it may hold a full ID. | | `pkg/cli/cmd/resource/list/list_test.go` | Adds `Test_ValidatePreview` for environment/application ID resolution and legacy-ID rejection, plus `Test_Run` preview subtests covering typed/untyped environment and application listing and the missing-application error. Updates existing tests for the renamed field. | | `pkg/cli/clients/clients.go` | Documents on the interface that bare names target `Applications.Core` and that a full resource ID is needed for other types. | | `pkg/cli/clients/management.go` | Adds the same clarification to the four list method implementations. No behavior change. | | `pkg/cli/clients/management_test.go` | Adds a `fullyQualifyID` case asserting a full `Radius.Core` ID is preserved verbatim — the property the preview command depends on. | --------- Signed-off-by: lakshmimsft <ljavadekar@microsoft.com> (cherry picked from commit ca7b5a3) Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
# Description `Test_RadiusCore_AzureMySql_PortalLink` fails in the scheduled long-running test (LRT) during cleanup because the test deletes its environment and recipe pack before deleting the application. Application deletion cascades into the recipe-backed `Radius.Data/mySqlDatabases` resource, whose delete operation still needs the environment configuration to run `terraform destroy`; the missing environment produces an `Internal` error wrapping `NotFound`. ## Why pull request CI did not catch it The cloud and non-cloud functional workflows set `RADIUS_TEST_FAST_CLEANUP=true`, which starts deletion in background goroutines and discards their errors. The LRT uses standard cleanup on a persistent cluster and therefore surfaces the failure. The LRT also executes tests from the current official release rather than `main`, so the released test must be temporarily skipped until a release includes this fix. ## Changes - Reorder the MySQL portal-link test resources so the application and database are deleted before the environment and recipe pack. - Add `validation.ResourcesInDeletionOrder`, which orders teardown as applications, application-scoped resources, environments, then recipe packs while preserving declaration order within each group. - Make cleanup safe when a test step has a nil resource set. - Add table-driven unit coverage for ordering, stable groups, case-insensitive type matching, nil and empty inputs, unknown resource types, and input preservation. - Correct the functional-test cleanup documentation and document dependency-ordered teardown. - Skip `Test_RadiusCore_AzureMySql_PortalLink` in the released LRT suite until a release contains the fix. ## Validation - The target test passed with `RADIUS_TEST_FAST_CLEANUP=false` in 271 seconds. That cloud run later failed only on unrelated AWS deletion assertions: https://github.com/radius-project/radius/actions/runs/32422259142 - The complete branch LRT against v0.60 succeeded with the temporary released-test skip, including diagnostics and persistent-cluster cleanup: https://github.com/radius-project/radius/actions/runs/32425245273 - Unit tests, lint, builds, CodeQL, dependency review, and the remaining functional suites pass. - The latest `corerp-cloud` run and its failed-job rerun were red only because the unrelated `Test_AWS_LogsLogGroup` AWS deletion waiter reported an already-absent resource as still present; neither failure involved the MySQL portal-link test or the changed cleanup ordering. ## Type of change - This pull request fixes a bug in Radius and has an approved issue (#12701). Fixes: #12701 ## Contributor checklist - [x] Existing functional tests updated as required by this change. - [x] Unit tests added for the cleanup-order helper. - [x] Contributor documentation updated. - [x] The standard-cleanup path and released LRT workflow validated. --------- Signed-off-by: Brooke Hamilton <45323234+brooke-hamilton@users.noreply.github.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 96688135-b4f9-4f97-aac0-d8487b109bb3 (cherry picked from commit 2eac7c1) Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
<!-- Thank you for contributing to Radius! Please fill out each section below so reviewers have the context they need. Sections marked optional can be removed if they do not apply. --> ## Summary <!-- Provide a concise description of what this PR does. --> Keeps the Azure workload identity assertion valid for the whole lifetime of a `rad` operation. The fix has two halves, and neither is sufficient on its own: - **Reader side (Go).** `pkg/azure/credential` now builds the workload identity credential from `ClientAssertionCredential` with a callback that reads the mounted token file on every exchange, instead of `WorkloadIdentityCredential`. When authentication still fails it reports the assertion's expiry rather than an empty error detail. - **Writer side (workflows).** A shared `refresh-azure-oidc-token.sh` re-mints the GitHub OIDC assertion, updates the `azure-oidc-token` Secret, and restarts its consumers before an Azure operation, then refreshes the Secret every two minutes while that operation runs. It is wired into both `run-rad-commands` and `delete-resource`. > [!NOTE] > This branch also carries an independent tooling commit, `04a448eb0`, that adds `# yaml-language-server: $schema=` headers and `---` document starts to 18 `.github/extension/` YAML files. It changes no behavior and is listed separately in the file table below. Happy to move it to its own PR if you would rather keep this one to the fix. ## Reason for change <!-- Explain why this change is needed. If it addresses a GitHub issue, link it below so it is automatically closed when this PR merges (optional). --> Three consecutive Azure deploys failed after roughly ten minutes with `ClientAssertionCredential authentication failed` and an empty detail. Two separate causes had to be addressed: 1. **The mounted assertion went stale.** The workflows projected a single GitHub OIDC assertion into the `azure-oidc-token` Secret and never refreshed it. A GitHub Actions OIDC token expires after 5 minutes (the [documented example token](https://docs.github.com/en/actions/concepts/security/openid-connect) has `exp - iat = 300`), so any longer operation outlived its assertion, and a plain Secret volume never mints a new one. 2. **Rotating the Secret alone does not fix the Go path.** `azidentity` v1.14's `WorkloadIdentityCredential` caches assertion file contents for 10 minutes, which outlives a 5-minute token. A Go consumer could therefore keep presenting an expired assertion even after the file was rewritten. The .NET Bicep deployment engine and the Terraform `azurerm` provider read the token file with their own caching, so Secret rotation is what covers them, while the Go change covers `applications-rp` and `dynamic-rp`. ## How to test <!-- Describe the steps a reviewer can take to verify these changes. --> ```bash # Token rotation behavior, request timeouts, secret non-leakage, # idle cancellation, and action/workflow wiring make test-azure-oidc-refresh # Existing deploy-parameter behavior for the shared command action make test-run-rad-commands-action # Azure credential package go vet ./pkg/azure/credential CGO_ENABLED=1 go test -race ./pkg/azure/credential -count=1 ``` All of the above pass on this branch, as do `shellcheck`, `shfmt -d -i 4 -ci`, `yamllint`, and `markdownlint-cli2` on the changed files. Not covered locally: an end-to-end Azure deploy running longer than ten minutes against a federated environment. That is the scenario the fix targets, and it requires a real workflow run. ## File change summary <!-- Summarize the change made in each file that was modified. --> | File | Summary of change | | ---- | ----------------- | | `pkg/azure/credential/ucpcredentials.go` | Build the workload identity credential from `ClientAssertionCredential` with a per-exchange token-file read; fail fast when no token file is configured; report an expired assertion's expiry on authentication failure. | | `pkg/azure/credential/ucpcredentials_test.go` | Cover rotated-assertion reads, the missing token file error, and expired, malformed, and unexpired diagnostic cases. | | `.github/extension/scripts/refresh-azure-oidc-token.sh` | New shared rotator. `--prepare` re-mints the assertion, updates the Secret, and restarts consumers; `--watch` refreshes every two minutes with bounded request timeouts and an interruptible idle sleep. | | `.github/extension/scripts/refresh-azure-oidc-token_test.sh` | New test using fake `curl`/`kubectl`: refresh and restart behavior, finite timeouts, no token in stdout, idle cancellation, and action/workflow wiring including validation ordering. | | `.github/extension/actions/run-rad-commands/action.yml` | Add the `azure-oidc-token-refresh` input, start rotation only after the allowed-command check, and stop the watcher during cleanup. | | `.github/extension/actions/delete-resource/action.yml` | Apply the same rotation lifecycle so long deletes keep a valid assertion. | | `.github/extension/run-rad-commands-azure.yml`, `.github/extension/delete-azure.yml` | Enable rotation when `AZURE_CLIENT_ID` is set. | | `build/test.mk` | Add the `test-azure-oidc-refresh` target and include it in `test`. | | `.github/extension/README.md`, `eng/design-notes/environments/2026-06-repo-radius-deploy-workflow.md` | Document the 5-minute token lifetime, the two-sided fix, and the rejected alternatives. | | 18 files under `.github/extension/` (commit `04a448eb0`) | Tooling only: add a YAML schema reference and `---` document start. No behavior change. | --------- Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com> Co-authored-by: Shruthi Kumar <42750942+sk593@users.noreply.github.com> (cherry picked from commit b4ebe2f) Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
This pull request introduces live deployment progress reporting for Radius application deploys and adds a new artifact uploader utility. The main changes include a new polling mechanism to track deployment state in real time, a TypeScript-based uploader for workflow artifacts, and comprehensive tests for these new components. Additionally, the documentation and artifact publication logic have been updated to reflect these enhancements. **Live deployment progress reporting:** - Added a polling mechanism in `progress.sh` that tracks resource state during an application deploy, periodically publishing snapshots as workflow artifacts named with the environment, application, run ID, and slot. These artifacts are rotated and retained for one day, enabling real-time updates in the deployment UI. [[1]](diffhunk://#diff-857e0051f96486cef37db831a9ffe0727d48299af34bc7cfe75469739c599280R1-R185) [[2]](diffhunk://#diff-9ffca9bbb740e6e3e003daa22deb59536b4b096ab1ddd047a7d6d46be9402e0fR108-R121) - Updated the documentation in `.github/extension/README.md` to describe the live progress polling, artifact naming, retention, and the new behavior for resource status reporting and environment variable redaction. **Artifact uploader utility:** - Introduced a new TypeScript uploader in `artifact-uploader/src/upload.ts` that uploads deployment progress files as workflow artifacts, with support for replacing existing artifacts in a slot. This uploader is invoked by the polling script and is tested with a dedicated test suite. [[1]](diffhunk://#diff-ae5b5d478c231b09d80b4987f820263a30dc8680888b0bc08d9f9f80a5f770cfR1-R88) [[2]](diffhunk://#diff-a700b201269f466163b174bf16c71b5b94dae7ae8595197b129897a73a2e7296R1-R75) - Added a `package.json` and `tsconfig.json` for the uploader, specifying dependencies, build, and test scripts. [[1]](diffhunk://#diff-075c2e1e822d686a2151f37d642794d20de545b5dd4e70199d2d77c159bffd42R1-R18) [[2]](diffhunk://#diff-9f8f41f417bd5054f4309fe0d1fa5858a5ae9cf993cf03f89057be366cf5fadfR1-R10) **Testing and integration:** - Added a shell test script `progress_test.sh` to validate the polling, artifact upload, slot rotation, and error handling logic in various scenarios. - Updated `publish-deploy-status/action.yml` to source the new `progress.sh` script, integrating live progress reporting into the deploy workflow.<!-- Thank you for contributing to Radius! Please fill out each section below so reviewers have the context they need. Sections marked optional can be removed if they do not apply. --> ## Summary <!-- Provide a concise description of what this PR does. --> ## Reason for change <!-- Explain why this change is needed. If it addresses a GitHub issue, link it below so it is automatically closed when this PR merges (optional). --> Fixes #<!-- issue number (optional) --> ## How to test <!-- Describe the steps a reviewer can take to verify these changes. --> ## File change summary <!-- Summarize the change made in each file that was modified. --> | File | Summary of change | | ---- | ----------------- | | | | --------- Signed-off-by: Nithya Subramanian <nithyasu@microsoft.com> (cherry picked from commit e30a259) Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
## Summary Set an explicit `/language:go/tool:gosec` category on the GoSec SARIF upload so its code-scanning configuration identity remains stable across workflow and matrix refactors. GoSec SARIF uploads previously omitted `category`, so GitHub generated the code-scanning configuration identity from workflow, job, and matrix metadata. The initial matrix language was `custom-go`; commit `9e6699472c647e59de864eea259326ea677a61c2` in PR #10985 renamed it to `custom-gosec`. GitHub treated that rename as a new configuration, leaving the old `custom-go` configuration stale and producing the repository-level warning that GoSec results may be out of date. The explicit stable category decouples the uploaded configuration identity from internal matrix labels, preventing future matrix or job refactors from orphaning GoSec configurations. ## Migration The first upload with `/language:go/tool:gosec` creates the stable configuration. After that upload succeeds, the superseded implicit `custom-gosec` configuration can be deleted once from the code-scanning UI. The already-stale `custom-go` configuration requires a separate one-time cleanup. ## Validation - `pnpm exec prettier --check .github/workflows/codeql.yml` - `git diff --check` - Confirmed `github/codeql-action/upload-sarif@v4.37.7` declares the `category` input Signed-off-by: Brooke Hamilton <45323234+brooke-hamilton@users.noreply.github.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> (cherry picked from commit 3c7dfec) Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
…ing (#12765) ## Summary Attempts to fix the intermittent `Test_AWS_LogsLogGroup` failures in the `corerp-cloud` functional test job by making AWS resource cleanup actually wait for the CloudControl delete to finish, and by making the post-delete existence check retry on transient errors instead of giving up after the first one. ## Reason for change `Test_AWS_LogsLogGroup` has been failing intermittently in `corerp-cloud` since #12706 (`chore(deps): bump the go-deps group`, merged 2026-08-18), which moved `github.com/aws/aws-sdk-go-v2/service/cloudcontrol` from `v1.32.4` to `v1.32.5`. Example failure: [run 32398057952](https://github.com/radius-project/radius/actions/runs/32398057952/job/96521782534) ``` rptest.go:572: failed to delete radiusfunctionaltest-b143eea2-...: failed to delete resource radiusfunctionaltest-b143eea2-... after 5m0s: not found: WaiterLogger rptest.go:589: checking existence of resource radiusfunctionaltest-b143eea2-... failed with err: operation error CloudControl: GetResource, https response error StatusCode: 400, InvalidRequestException: AWS::Logs::LogGroup Handler returned status FAILED: Log group cannot be found. rptest.go:599: Error: Should be true Messages: AWS resource radiusfunctionaltest-b143eea2-... was present, should be not found ``` ## How to test The affected test only runs against real AWS in the `corerp-cloud` functional test job, so the primary verification is CI: 1. Confirm `Run corerp-cloud functional tests` passes, and that `Test_AWS_LogsLogGroup` no longer logs `not found: WaiterLogger`. 2. Confirm the cleanup log now shows the waiter actually polling before `validating deletion of AWS resource ... (attempt 1/5)` is reached. The waiter regression itself can be reproduced locally without AWS credentials, against the versions pinned in `go.mod` (`cloudcontrol v1.32.5`, `smithy-go v1.27.7`) — the failure happens while building the middleware stack, before any credentials are used: ```go c := cloudcontrol.NewFromConfig(aws.Config{ Region: "us-west-2", Credentials: credentials.NewStaticCredentialsProvider("AKIAFAKE", "fake", ""), }) tok := "faketoken" // Before this change: returns "not found: WaiterLogger" immediately. before := cloudcontrol.NewResourceRequestSuccessWaiter(c, func(o *cloudcontrol.ResourceRequestSuccessWaiterOptions) { o.LogWaitAttempts = true }) fmt.Println(before.Wait(ctx, &cloudcontrol.GetResourceRequestStatusInput{RequestToken: &tok}, 300*time.Second)) // After this change: actually issues the request (fails only on the fake credentials). after := cloudcontrol.NewResourceRequestSuccessWaiter(c) fmt.Println(after.Wait(ctx, &cloudcontrol.GetResourceRequestStatusInput{RequestToken: &tok}, 300*time.Second)) ``` ## File change summary | File | Summary of change | | ---- | ----------------- | | `test/validation/aws.go` | Removed `LogWaitAttempts = true` from the `ResourceRequestSuccess` waiter in `DeleteAWSResource` so the waiter builds its middleware stack successfully and genuinely waits up to 5 minutes for the delete. Added a comment recording why the option must stay off. | | `test/rp/rptest.go` | AWS deletion validation now retries on error across all `AWSDeletionRetryLimit` attempts instead of breaking on the first one, skips the trailing sleep on the final attempt, and includes the last observed error in the `require.Truef` failure message via a new `lastErr` variable. | --------- Signed-off-by: lakshmimsft <ljavadekar@microsoft.com> (cherry picked from commit 787b6ca) Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
…xtension actions (#12775) ## Summary `run-rad-commands` on `@main` was bricked by an unclosed `cleanup()` function in the composite action shell block, causing immediate `bash` parse failure before any `rad` command could run. This PR restores the missing brace and adds a CI guard that syntax-checks all extension action `run: |` blocks. - **Action runtime fix** - Close `cleanup()` before `trap cleanup EXIT` in `run-rad-commands/action.yml` so the script parses and executes. - **Regression prevention** - Add a shell test that extracts every `.github/extension/actions/**/action.yml` `run: |` block and validates each with `bash -n`. - **CI wiring** - Add `test-extension-action-shell-syntax` target and include it in the top-level `test` target. ```bash cleanup() { # ... write_result } trap cleanup EXIT ``` ## Reason for change A single missing `}` in the composite action shell block made the deploy path non-functional for workflows pinned to `@main`. YAML/action linting did not catch this class of failure; explicit shell parsing is required. ## How to test Run the focused shell regression checks: ```bash make test-run-rad-commands-action make test-extension-action-shell-syntax ``` ## File change summary | File | Summary of change | | ---- | ----------------- | | `.github/extension/actions/run-rad-commands/action.yml` | Restored the missing closing brace for `cleanup()` before `trap cleanup EXIT` in the `Run rad commands` shell block. | | `.github/extension/actions/action-shell-syntax_test.sh` | Added a new regression test that parses all extension action `run: |` blocks and runs `bash -n` on each extracted script body. | | `build/test.mk` | Added `test-extension-action-shell-syntax` target and wired it into the aggregate `test` target so CI enforces the syntax gate. | <!-- START COPILOT CODING AGENT SUFFIX --> - Fixes #12773 --------- Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: sk593 <42750942+sk593@users.noreply.github.com> (cherry picked from commit f841849) Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
## Summary - forward the deployed application Bicep file to `rad app graph` - enforce `APP_FILE` positional argument forwarding in the publisher action test stub ## Testing - `make test-publish-deploy-status test-extension-action-shell-syntax` ## Graph diff Graph diff unavailable because this repository has no `.radius/app.bicep`; no graph markdown was generated. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> (cherry picked from commit 415d5b9) Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
## Summary Add exact resolved output resource IDs to every live and terminal deployment progress entry while preserving modeled Radius identity and the schema-v1 contract. Reuse one normalizer for both publishers. ## Reason for change Progress events identify modeled Radius resources, while the deployed graph nests concrete cloud and Kubernetes resources under `outputResources`. The additive `outputResourceIds` field gives consumers an authoritative correlation key without inferring provider types or inventing a primary output. ## How to test ```sh make test-deploy-progress test-publish-deploy-status test-extension-action-shell-syntax pnpm exec markdown-table-formatter ".github/extension/README.md" --check pnpm exec markdownlint-cli2 ".github/extension/README.md" --config "./.github/linters/.markdownlint-cli2.yaml" ``` ## File change summary | File | Summary of change | | ---- | ----------------- | | `.github/extension/actions/deploy-progress/progress.sh` | Emit sorted, deduplicated `outputResourceIds` from resolved resource metadata. | | `.github/extension/actions/publish-deploy-status/action.yml` | Reuse the shared normalizer for terminal payloads. | | Progress publisher tests | Cover exact IDs, ordering, deduplication, empty arrays, and unchanged statuses. | | `.github/extension/README.md` | Document modeled and resolved identity semantics and schema-v1 compatibility. | Signed-off-by: Nithya Subramanian <nithyasu@microsoft.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> (cherry picked from commit a1d9760) Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
<!-- Thank you for contributing to Radius! Please fill out each section below so reviewers have the context they need. Sections marked optional can be removed if they do not apply. --> ## Summary <!-- Provide a concise description of what this PR does. --> Replace the custom tool-update pull request script with the repository's pinned `peter-evans/create-pull-request` v8 action. The updater now writes the complete PR body, including links to adopted tool releases, while the workflow preserves GitHub App signing, DCO signoff, fixed-branch updates, fork-safe behavior, and verification enforcement. ## Reason for change <!-- Explain why this change is needed. If it addresses a GitHub issue, link it below so it is automatically closed when this PR merges (optional). --> The custom shell implementation duplicated branch, commit, and pull request management already provided by the action used elsewhere in this repository. Delegating that behavior removes self-maintained automation without losing signed commits or release-note context. ## How to test <!-- Describe the steps a reviewer can take to verify these changes. --> The following checks passed: - `go test ./internal/tooling ./cmd/tool-updater` - `go vet ./internal/tooling ./cmd/tool-updater` - `actionlint ./.github/workflows/update-tools.yaml` - `make --no-print-directory -nB update-tools TOOL_UPDATE_PR_BODY_OUTPUT=tool-update-pr-body.md` - `pnpm exec markdown-table-formatter "internal/tooling/README.md" --check` - `pnpm exec markdownlint-cli2 "internal/tooling/README.md" --config "./.github/linters/.markdownlint-cli2.yaml"` - `git diff --check` ## File change summary <!-- Summarize the change made in each file that was modified. --> | File | Summary of change | | ---- | ----------------- | | `.github/scripts/update-tools-pr.sh` | Remove custom branch, commit, and PR management. | | `.github/scripts/update-tools-pr_test.sh` | Remove the obsolete shell fixture. | | `.github/workflows/update-tools.yaml` | Use the pinned PR action with the App token, signing, DCO, generated body, and verification guard. | | `build/test.mk` | Remove the deleted shell test target. | | `build/tools.mk` | Forward the optional PR body output path to the updater. | | `build/tools.yaml` | Add Terraform's GitHub repository for release links. | | `cmd/tool-updater/main.go` | Add `--pr-body-output` and write the generated Markdown body. | | `cmd/tool-updater/main_test.go` | Test writing the PR body file. | | `internal/tooling/README.md` | Document PR body generation and action-managed automation. | | `internal/tooling/updater.go` | Track adopted versions and render release-linked PR Markdown. | | `internal/tooling/updater_test.go` | Cover release URLs and full PR body rendering. | --------- Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com> (cherry picked from commit 14a21bd) Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
## Summary Updates the canonical Repo Radius Azure credential-verification workflow so newly-created role assignments can propagate without skipping end-to-end verification. `azure/login` now authenticates at tenant scope with the action's exact `allow-no-subscriptions: true` input. The next step checks subscription visibility immediately, refreshes Azure CLI account state on every attempt, compares the configured subscription ID with `jq`, and selects it before the existing Azure credential, AKS, and GHCR checks continue unchanged. A step-level 12-minute timeout bounds the wall clock if an Azure CLI refresh hangs. ## Reason for change This supersedes [radius-project/ai-extensions#444](radius-project/ai-extensions#444). That PR avoids the propagation race by suppressing the immediate verification dispatch in the frontend after it creates a Contributor role assignment. Skipping the dispatch removes the end-to-end signal and puts Azure-specific workflow timing policy in the wrong repository. Handling propagation in `.github/extension/verify-azure.yml` keeps verification enabled and makes the canonical upstream workflow responsible for its own Azure subscription-visibility semantics. The retry is bounded and is not a fixed startup delay: - Check immediately after OIDC login. - Retry up to 23 attempts with 5, 10, 20, then 30-second capped delays (10 minutes 5 seconds of total waiting before the final check). - Run `az account list --refresh` on every attempt without printing its JSON response. - Select only the configured subscription after an exact, case-insensitive ID match. - Apply a 12-minute step timeout so a hung CLI call cannot fall through to GitHub's multi-hour job default. Genuine OIDC, client, tenant, or federated-credential errors still fail immediately in `azure/login`. A missing subscription variable fails before discovery starts, and a direct nonzero exit from `az account list --refresh` fails immediately under `set -euo pipefail`. Azure CLI can internally absorb some subscription-discovery exceptions and return successfully with cached tenant-level state; persistent discovery failure therefore reaches the same bounded no-visible-subscription timeout as RBAC propagation or a missing role assignment. The timeout diagnostic names all three possibilities. ## How to test Exact focused validation run after the review fixes: - `make test-verify-azure` — passed (`Azure verification workflow tests passed`). - `shellcheck --rcfile .github/linters/.shellcheckrc .github/extension/verify-azure_test.sh` — passed with no findings. - `ruby -e "require 'yaml'; data=YAML.load_file('.github/extension/verify-azure.yml'); abort 'missing jobs' unless data['jobs']; puts 'workflow structure parsed'"` — passed (`workflow structure parsed`). - `npx --yes markdown-table-formatter@1.7.0 '.github/extension/README.md' 'docs/contributing/contributing-deploy-environments.md' --check` — passed; no formatting changes required. - `npx --yes markdownlint-cli2@0.23.2 '.github/extension/README.md' 'docs/contributing/contributing-deploy-environments.md' --config './.github/linters/.markdownlint-cli2.yaml'` — passed with 0 issues. - `npx --yes cspell@9.6.1 lint --config ./.github/linters/.cspell.yml --no-progress '.github/extension/README.md' 'docs/contributing/contributing-deploy-environments.md'` — passed with 0 issues. The deterministic workflow test extracts and executes the real retry `run:` block with stubbed `az` and `sleep` commands. It covers immediate visibility, case-insensitive safe matching, missing configuration, delayed visibility and exponential backoff, a retry budget of at least 10 minutes, timeout without selecting a different subscription, direct Azure CLI failure, and the `azure/login` input contract. Its named wait-step assertion also pins `timeout-minutes: 12` and the exact `AZURE_SUBSCRIPTION_ID: ${{ vars.AZURE_SUBSCRIPTION_ID }}` environment mapping. ## File change summary | File | Summary of change | | ---- | ----------------- | | `.github/extension/verify-azure.yml` | Authenticates without requiring immediate subscription visibility, then refreshes, retries for at least 10 minutes, matches, and selects the configured subscription under a 12-minute hard timeout. | | `.github/extension/verify-azure_test.sh` | Adds deterministic behavior tests and named-step contract assertions for login inputs, retry duration, timeout, and subscription-variable wiring. | | `build/test.mk` | Adds the focused test target to the standard unit-test prerequisites. | | `.github/extension/README.md` | Documents tenant-scope login, bounded propagation/discovery retry, hard timeout, selection, and failure behavior. | | `docs/contributing/contributing-deploy-environments.md` | Updates the contributor workflow and troubleshooting guidance for Azure RBAC propagation and subscription-discovery failure. | --------- Signed-off-by: Ryan Waite <ryanwjwaite@outlook.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: acc4d5a9-1134-4c5b-9f8f-7f8cd1ad6bed (cherry picked from commit a87146c) Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
## Summary Update the repository's Go toolchain version to 1.27.0 in the root module and the nested test modules that pin Go. ## Reason for change This keeps the repo aligned with the newer Go toolchain version required by the current build and test environment. ## How to test - Verify the version pins in the Go modules are consistent across the repo. - Run the relevant repository build or test workflow as needed for the updated Go toolchain. ## File change summary | File | Summary of change | | ---- | ----------------- | | go.mod | Bump the Go version directive to 1.27.0. | | test/magpiego/go.mod | Bump the Go version directive to 1.27.0. | | test/testrp/go.mod | Bump the Go version directive to 1.27.0. | --------- Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com> (cherry picked from commit 073ca3c) Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
## Summary Make successful Helm install and upgrade completion the authoritative Radius readiness contract. - Add an HTTPS UCP pod probe so UCP does not join Service endpoints before it is listening. - Add a mandatory `post-install,post-upgrade` hook that waits for `/apis/api.ucp.dev/v1alpha3` through kube-apiserver. - Reuse the Radius `pre-upgrade` binary via a new `wait-for-control-plane` subcommand with least-privilege RBAC, bounded retries, and retained failure diagnostics. ## Reason for change Helm does not check Kubernetes `APIService` readiness. It can return while UCP is serving but kube-apiserver still reports the recreated Radius APIService as unavailable: ```text t=+6ms podReady=1/1 apiserviceAvailable=False api=503 t=+3182ms podReady=1/1 apiserviceAvailable=False api=503 t=+4540ms podReady=1/1 apiserviceAvailable=True api=SERVING ``` The pod probe and Helm hook cover different readiness boundaries. The pod probe prevents routing to a process that is not listening; the hook verifies the full client path through kube-apiserver, the aggregation controller, APIService, Service, TLS, and UCP. A pod probe cannot wait on APIService availability because the APIService itself requires a Ready endpoint, which would create a circular dependency. The hook image follows the current build through this precedence: explicit readiness override, explicit non-default pre-upgrade image, then a `pre-upgrade` image derived from UCP's registry and tag. Template-local defaults preserve direct Helm `--reuse-values` upgrades from older charts. Related to #11841. ## How to test Deterministic checks: ```text go test ./cmd/pre-upgrade/... ./pkg/cli/cmd/install/kubernetes/... -count=1 go vet ./cmd/pre-upgrade/... ./pkg/cli/cmd/install/kubernetes/... go build ./cmd/pre-upgrade/... make test-helm ``` Live kind validation with images built from this branch confirmed: - Fresh install, reinstall, and upgrade all returned with the aggregated endpoint immediately serving. - Deleting the APIService caused two retryable 404s; the hook succeeded after restoration. - A forced timeout reported the last error and retained the failed Job. - Main's existing upgrade test passed 3/3 unmodified with this hook. - Removing only this hook reproduced the original one-503/idle-timeout failure exactly. All current CI checks pass, including cloud install legs and `upgrade-noncloud`. ## File change summary | File | Summary of change | | ---- | ----------------- | | `cmd/pre-upgrade/cmd/root.go` | Preserve preflight behavior while adding subcommand dispatch. | | `cmd/pre-upgrade/cmd/wait_for_control_plane.go` | Poll the aggregated Radius API with bounded retries and error classification. | | `cmd/pre-upgrade/cmd/wait_for_control_plane_test.go` | Cover retry, timeout, authorization, request-path, and command behavior. | | `deploy/Chart/templates/control-plane-readiness/*` | Add the mandatory Helm hook Job, ServiceAccount, and least-privilege RBAC. | | `deploy/Chart/templates/ucp/deployment.yaml` | Add the direct HTTPS UCP readiness probe. | | `deploy/Chart/values.yaml` | Configure hook image and timing with backward-compatible defaults. | | `deploy/Chart/tests/*readiness_test.yaml` | Verify UCP and Helm readiness rendering, RBAC, image precedence, and old-value compatibility. | | `deploy/Chart/templates/networkpolicies.yaml` | Correct probe/network-policy guidance. | | `pkg/cli/cmd/install/kubernetes/kubernetes.go` | Document that successful Helm completion guarantees aggregated API readiness. | PR #12790 is stacked on this PR and contains the upgrade-test cleanup/optimization. After this PR merges, retarget #12790 to `main`. --------- Signed-off-by: Brooke Hamilton <45323234+brooke-hamilton@users.noreply.github.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3d57d783-88ae-4d44-a75d-0dedb3eb2039 (cherry picked from commit 5e1f94c) Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
## Summary - derive custom recipe-pack identities from the compiled authored Bicep instead of a global before/after list diff - preserve existing environment recipe packs while attaching only the exact authored packs on first and restored-state redeploys - add composite-action regression coverage and update the Repo Radius workflow documentation ## Testing - `make test-apply-custom-recipe-packs` - `shellcheck .github/extension/actions/apply-custom-recipe-packs/apply-custom-recipe-packs_test.sh` Resolves radius-project/ai-extensions#323 --------- Signed-off-by: sk593 <shruthikumar@microsoft.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> (cherry picked from commit 1fd650a) Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
…ll kubernetes (#12829) ## Summary Reverts the default resource group and environment creation that `rad install kubernetes` performed, returning it to a barebones control-plane install. Also removes the `--preview` flag from this command, since its only effect was selecting the resource type (and default recipe pack) for the default environment that is no longer created. After this change: - `rad install kubernetes` installs the Radius control plane . - No `default` resource group, no `default` environment, no default recipe pack, and no environment targeting the `default` Kubernetes namespace. This reverts the behavior introduced by #11870 (shipped in v0.59.0) and the `--preview` flag added on top of it by #12504 (shipped in v0.60.0). Unrelated changes that landed in the same files since then are preserved: the `t.Context()` test modernization from #12523 and the current `docs.radapp.io` architecture URL. ## Reason for change `rad install kubernetes` silently provisioning a default environment and recipe packs is undesirable for anyone who intends to customize environments, namespaces, or recipe packs — notably the GitHub Copilot app integration, where a default environment targeting the `default` Kubernetes namespace conflicts with the intended setup. Opinionated initialization belongs in `rad init`, where users expect an onboarding flow with defaults preset. This restores a clean separation of responsibilities: - `rad install kubernetes` — install the control plane only. - `rad init` — install and/or initialize Radius with default resources and recipe packs. Fixes #12827 ## How to test Manual, against a clean cluster: rad install kubernetes rad group show default # expect: not found rad env show default # expect: not found rad init # still creates the default group, environment, and recipe pack rad group show default # expect: exists rad env show default # expect: exists Also confirm rad install kubernetes --preview now reports unknown flag: --preview , and that the existing install flags ( --reinstall , --chart , --set , --set-file , --kubecontext , --skip-contour-install , and the --contour-* flags) are unchanged. | File | Summary of change | | ---- | ----------------- | | `pkg/cli/cmd/install/kubernetes/kubernetes.go` | Removed `createDefaultGroupAndEnvironment`, `ensureDefaultResourceGroup`, `ensureDefaultEnvironment`, and `ensureDefaultEnvironmentPreview`, along with the `--preview` flag and the `ConnectionFactory`, `KubernetesInterface`, `Preview`, and `RadiusCoreClientFactory` runner fields. `Run` now returns after `Helm.InstallRadius`. Added help text stating the command installs the control plane only and pointing to `rad init` for defaults. | | `pkg/cli/cmd/install/kubernetes/kubernetes_test.go` | Removed mock expectations for default group/environment/recipe-pack creation. Each install test now asserts the full `Output.Writes` sequence exactly, so any reintroduced default-resource logging fails the test. Retains the `t.Context()` usage from #12523. | | `.github/extension/actions/restore-state/action.yml` | Updated a now-inaccurate comment claiming `rad install kubernetes` creates the `default` resource group. Behavior is unchanged — the action already creates the group explicitly. | Note for follow-up: Check for docs update to reflect updated changes. --------- Signed-off-by: lakshmimsft <ljavadekar@microsoft.com> (cherry picked from commit 19376c3) Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
….1 (#12831) Patch release `v0.60.1` for channel `0.60`. ## Backported PRs Listed in cherry-pick (topological) order. **Gap filler** = not requested for the patch, but included because it touched the same region of a shared file between `release/0.60` and a requested commit. Without it the cherry-pick has no common merge base and conflicts. | # | Commit | PR | Role | | --- | --- | --- | --- | | 1 | `6882b5fdf` | #12640 | Requested | | 2 | `af0443809` | #12721 | Requested | | 3 | `7c6de043d` | #12733 | **Gap filler** — `.github/workflows/codeql.yml` | | 4 | `ca7b5a3e7` | #12728 | Requested | | 5 | `2eac7c1f1` | #12702 | Requested | | 6 | `b4ebe2f28` | #12751 | Requested | | 7 | `e30a2594d` | #12727 | Requested | | 8 | `3c7dfecd6` | #12769 | **Gap filler** — `.github/workflows/codeql.yml` | | 9 | `787b6ca1a` | #12765 | **Gap filler** — `build/test.mk` | | 10 | `f84184955` | #12775 | Requested | | 11 | `415d5b9c2` | #12779 | Requested | | 12 | `a1d976013` | #12782 | Requested | | 13 | `14a21bd0d` | #12786 | **Gap filler** — `build/test.mk` | | 14 | `a87146c77` | #12764 | **Gap filler** — `build/test.mk` | | 15 | `073ca3cfa` | #12758 | Requested | | 16 | `5e1f94c13` | #12785 | **Gap filler** — `pkg/cli/cmd/install/kubernetes/kubernetes.go` | | 17 | `1fd650af5` | #12742 | Requested | | 18 | `19376c3f3` | #12829 | Requested | Five of the six gap fillers are CI/test-only. #12785 is not: it adds a Helm `control-plane-readiness` Job, a `pre-upgrade wait-for-control-plane` command, UCP readiness probes, and a NetworkPolicy change. It is required for #12829 to apply. ## Validation Full chain dry-run cherry-picked onto `release/0.60` with zero conflicts. `go build ./...` clean; `pkg/cli/cmd/install/kubernetes`, `cmd/pre-upgrade/cmd`, `pkg/cli/...`, `pkg/graph/...`, and `test/validation` all pass. --------- Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com> (cherry picked from commit e5938bf) Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
bc598d4 to
2c2bb79
Compare
Dependency ReviewThe following issues were found:
|
Radius functional test overviewClick here to see the test run details
Test Status⌛ Building Radius and pushing container images for functional tests... |
Codecov Report❌ Patch coverage is Additional details and impacted files@@ Coverage Diff @@
## release/0.60 #12833 +/- ##
================================================
+ Coverage 54.17% 59.34% +5.16%
================================================
Files 770 774 +4
Lines 51085 45765 -5320
================================================
- Hits 27677 27157 -520
+ Misses 20797 18608 -2189
+ Partials 2611 0 -2611 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Functional Tests - ucp-cloud4 tests 4 ✅ 35s ⏱️ Results for commit 2c2bb79. ♻️ This comment has been updated with latest results. |
Cherry-picks the
v0.60.1backport set plus the version/release-notes commit ontorelease/0.60.Gap filler = not requested for the patch, included only so the cherry-pick chain has a common merge base and applies without conflicts.
6882b5fdfaf04438097c6de043d.github/workflows/codeql.ymlca7b5a3e72eac7c1f1b4ebe2f28e30a2594d3c7dfecd6.github/workflows/codeql.yml787b6ca1abuild/test.mkf84184955415d5b9c2a1d97601314a21bd0dbuild/test.mka87146c77build/test.mk073ca3cfa5e1f94c13pkg/cli/cmd/install/kubernetes/kubernetes.go(required by #12829)1fd650af519376c3f3All 18 apply with zero conflicts.
go build ./...clean; unit tests pass.