Skip to content

Commit 9788bad

Browse files
build(wrapper): install only what the wrapper pipeline uses (main) (#3758)
* build(wrapper): install only what the wrapper pipeline uses The pipeline reused install-tools.yml wholesale, which is the AutoRest toolchain - Node, the private npm feed, AutoRest, Rush and a full rush rebuild - none of which the wrapper build touches, and it installs .NET 8/6 while the generator targets net10.0. The build step then failed because Build-WrapperModule.ps1 refuses to run without the kiota CLI on PATH even under -SkipKiota. Installs the .NET 10 SDK, feed auth, and kiota explicitly. * build(wrapper): route NuGet through the internal feed under network isolation api.nuget.org is not reliably reachable from the 1ES pool, so the kiota tool install failed loading the service index - and the module restore would have failed the same way one step later. Writes a pipeline-local nuget.config that puts the MSGraph_PowerShell_V3_Build feed (whose upstream proxies nuget.org) first with nuget.org as fallback, used by every restore on the run. NuGetAuthenticate supplies the credentials; the kiota step also retries. * build(wrapper): feed-only NuGet sources under network isolation dotnet tool install probes the service index of every configured source and fails hard if any is unreachable, so keeping nuget.org as a fallback defeated the routing entirely. The pipeline config now lists only the internal feed, whose upstream proxies nuget.org, and the install ignores failed sources. * build(wrapper): run the full generation chain at pipeline time Per review: the pipeline now generates the kiota client from the committed OpenAPI docs and the wrappers on top, then compiles - the whole process is built and tested end to end on every run, and a run can never fail on committed clients lagging the docs. Clients remain committed to the repo for reviewable diffs and clean local checkouts. * build(wrapper): suppress credscan false positives in generated synchronization models The kiota-generated model for Graph's synchronizationSecret entity enumerates the API's secret-key names (Oauth2ClientSecret and similar) as enum member strings, which trips CSCAN-GENERAL0120 in four modules and breaks the guardian post-analysis. Schema vocabulary from the OpenAPI document, not secret values - same class of suppression the file already carries for generated examples.
1 parent a8c4465 commit 9788bad

2 files changed

Lines changed: 59 additions & 2 deletions

File tree

‎.azure-pipelines/config/credscan/credscan-suppressions.json‎

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -73,6 +73,15 @@
7373
"tools\\Tests\\loadEnv.md"
7474
],
7575
"_justification": "[ToolsTest] Examples contain random values recognized as secret"
76+
},
77+
{
78+
"file": [
79+
"src\\Applications\\wrapper\\v1.0\\Client\\Models\\SynchronizationSecret.cs",
80+
"src\\Groups\\wrapper\\v1.0\\Client\\Models\\SynchronizationSecret.cs",
81+
"src\\Identity.DirectoryManagement\\wrapper\\v1.0\\Client\\Models\\SynchronizationSecret.cs",
82+
"src\\Users\\wrapper\\v1.0\\Client\\Models\\SynchronizationSecret.cs"
83+
],
84+
"_justification": "[Wrapper] Kiota-generated model for Graph's synchronizationSecret entity enumerates the API's secret-key names (Oauth2ClientSecret and similar) as enum member strings; these are schema vocabulary from the OpenAPI document, not secret values"
7685
}
7786
]
7887
}

‎.azure-pipelines/wrapper-release.yml‎

Lines changed: 50 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -74,7 +74,51 @@ extends:
7474
- script: git submodule update --init --recursive
7575
displayName: Initialize submodules
7676

77-
- template: .azure-pipelines/common-templates/install-tools.yml@self
77+
# Deliberately NOT install-tools.yml: that template is the AutoRest toolchain - Node,
78+
# the private npm feed, AutoRest, Rush and a full rush rebuild - none of which this
79+
# pipeline uses. The wrapper modules compile from committed sources, so the whole
80+
# toolchain is the .NET SDK, feed auth for restore, and the kiota CLI.
81+
- task: UseDotNet@2
82+
displayName: Use .NET SDK 10
83+
retryCountOnTaskFailure: 2
84+
inputs:
85+
version: 10.x
86+
- task: NuGetAuthenticate@1
87+
# Under 1ES network isolation api.nuget.org is not reliably reachable, so every restore
88+
# on this pipeline - the kiota tool below and the module build after it - resolves
89+
# through the team's own feed first, whose upstream proxies nuget.org. The config is
90+
# written at the sources root so dotnet picks it up everywhere; NuGetAuthenticate above
91+
# supplies the credentials.
92+
- task: PowerShell@2
93+
displayName: Route NuGet through the internal feed
94+
inputs:
95+
targetType: inline
96+
pwsh: true
97+
script: |
98+
$cfg = @'
99+
<?xml version="1.0" encoding="utf-8"?>
100+
<configuration>
101+
<packageSources>
102+
<clear />
103+
<add key="MSGraphV3" value="https://pkgs.dev.azure.com/microsoftgraph/Graph%20Developer%20Experiences/_packaging/MSGraph_PowerShell_V3_Build/nuget/v3/index.json" />
104+
</packageSources>
105+
</configuration>
106+
'@
107+
Set-Content -Path '$(Build.SourcesDirectory)/nuget.config' -Value $cfg -Encoding utf8
108+
Write-Host "wrote $(Build.SourcesDirectory)/nuget.config"
109+
# Build-WrapperModule.ps1 refuses to run without kiota on PATH even under -SkipKiota
110+
# (the guard is unconditional), and future -Generate runs need it anyway.
111+
- task: PowerShell@2
112+
displayName: Install kiota CLI
113+
retryCountOnTaskFailure: 2
114+
inputs:
115+
targetType: inline
116+
pwsh: true
117+
workingDirectory: $(Build.SourcesDirectory)
118+
script: |
119+
dotnet tool install --global Microsoft.OpenApi.Kiota --configfile '$(Build.SourcesDirectory)/nuget.config' --ignore-failed-sources
120+
if ($LASTEXITCODE -ne 0) { throw "kiota install failed with exit code $LASTEXITCODE" }
121+
Write-Host "##vso[task.prependpath]$env:USERPROFILE\.dotnet\tools"
78122
- template: .azure-pipelines/common-templates/security-pre-checks.yml@self
79123

80124
# Version and prerelease go to the script directly (-ModuleVersion/-Prerelease); the
@@ -92,7 +136,11 @@ extends:
92136
ArtifactsLocation = '$(Build.ArtifactStagingDirectory)'
93137
ModuleVersion = '${{ parameters.PackageVersion }}'
94138
Prerelease = '$(WrapperPrerelease)'
95-
SkipKiota = $true
139+
# Deliberately NOT -SkipKiota: the pipeline runs the whole chain - kiota client
140+
# generation from the committed OpenAPI docs, wrapper generation on top, then
141+
# compile - so a change in any step is built and tested end to end, and the run
142+
# can never fail on committed clients lagging the docs. Clients are still
143+
# committed to the repo for reviewable diffs and clean local checkouts.
96144
Pack = $true
97145
}
98146
& '$(Build.SourcesDirectory)/tools/Build-WrapperModule.ps1' @params

0 commit comments

Comments
 (0)