Skip to content

Commit a8c4465

Browse files
build(wrapper): add the internal-feed release pipeline and install guide (main) (#3756)
* build(wrapper): add the internal-feed release pipeline and install guide Builds and packs the wrapper modules from committed sources, verifies packages were actually produced before signing, ESRP-signs, and publishes to the project-scoped MSGraph_PowerShell_V3_Build feed. Mirrors sdk-release.yml - same 1ES template, security templates and publish task - with no AutoRest or Node bootstrap, manual trigger only, and Publish defaulting to false so the first runs produce a drop artifact without pushing packages. The guide covers feed registration and Install-Module -AllowPrerelease for testers. * docs(wrapper): keep the install guide off main The guide rides #3753 to powershell-v3, where the wrapper modules live; main only carries the pipeline definition.
1 parent c7a6aee commit a8c4465

1 file changed

Lines changed: 149 additions & 0 deletions

File tree

Lines changed: 149 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,149 @@
1+
# Copyright (c) Microsoft Corporation. All rights reserved.
2+
# Licensed under the MIT License.
3+
4+
name: $(BuildDefinitionName)_$(SourceBranchName)_$(Date:yyyyMMdd)$(Rev:.r)
5+
6+
parameters:
7+
- name: BuildAgent
8+
default: 1es-windows-ps-compute-m
9+
displayName: Build Agent
10+
- name: PackageVersion
11+
type: string
12+
default: 3.0.0
13+
displayName: Package version
14+
- name: Sign
15+
type: boolean
16+
default: true
17+
- name: Publish
18+
type: boolean
19+
default: false
20+
- name: InternalFeed
21+
type: string
22+
# The feed is PROJECT-scoped (dev.azure.com/microsoftgraph/Graph Developer Experiences/
23+
# _artifacts/feed/MSGraph_PowerShell_V3_Build), so publishVstsFeed needs the project
24+
# qualifier - a bare feed name only resolves for organization-scoped feeds.
25+
default: Graph Developer Experiences/MSGraph_PowerShell_V3_Build
26+
displayName: Internal NuGet feed
27+
28+
variables:
29+
BuildAgent: ${{ parameters.BuildAgent }}
30+
WrapperConfiguration: Release
31+
WrapperPrerelease: alpha$(Build.BuildId)
32+
33+
trigger: none
34+
pr: none
35+
36+
resources:
37+
repositories:
38+
- repository: 1ESPipelineTemplates
39+
type: git
40+
name: 1ESPipelineTemplates/1ESPipelineTemplates
41+
ref: refs/tags/release
42+
43+
extends:
44+
template: v1/1ES.Official.PipelineTemplate.yml@1ESPipelineTemplates
45+
parameters:
46+
pool: $(BuildAgent)
47+
settings:
48+
networkIsolationPolicy: Permissive
49+
sdl:
50+
binskim:
51+
enabled: false
52+
justificationForDisabling: "Matches sdk-release.yml; BinSkim currently blocks internal-feed publishing."
53+
credscan:
54+
suppressionsFile: $(Build.SourcesDirectory)/.azure-pipelines/config/credscan/credscan-suppressions.json
55+
policheck:
56+
exclusionFile: $(Build.SourcesDirectory)/.azure-pipelines/config/policheck/policheck-exclusions.xml
57+
customBuildTags:
58+
- ES365AIMigrationTooling
59+
stages:
60+
- stage: Build
61+
displayName: Build wrapper modules
62+
jobs:
63+
- job: Wrapper_Build
64+
displayName: Generate, build, pack, and sign wrapper modules
65+
timeoutInMinutes: 840
66+
templateContext:
67+
outputs:
68+
- output: pipelineArtifact
69+
displayName: Publish wrapper module artifacts
70+
targetPath: $(Build.ArtifactStagingDirectory)
71+
artifactName: drop
72+
publishLocation: Container
73+
steps:
74+
- script: git submodule update --init --recursive
75+
displayName: Initialize submodules
76+
77+
- template: .azure-pipelines/common-templates/install-tools.yml@self
78+
- template: .azure-pipelines/common-templates/security-pre-checks.yml@self
79+
80+
# Version and prerelease go to the script directly (-ModuleVersion/-Prerelease); the
81+
# script owns package identity. Nothing here edits ModuleMetadata.json - that file
82+
# belongs to the v2 release train.
83+
- task: PowerShell@2
84+
displayName: Build and pack wrapper modules
85+
inputs:
86+
targetType: inline
87+
pwsh: true
88+
script: |
89+
$params = @{
90+
ApiVersion = 'v1.0'
91+
Configuration = '$(WrapperConfiguration)'
92+
ArtifactsLocation = '$(Build.ArtifactStagingDirectory)'
93+
ModuleVersion = '${{ parameters.PackageVersion }}'
94+
Prerelease = '$(WrapperPrerelease)'
95+
SkipKiota = $true
96+
Pack = $true
97+
}
98+
& '$(Build.SourcesDirectory)/tools/Build-WrapperModule.ps1' @params
99+
if ($LASTEXITCODE -ne 0) { throw "Wrapper build failed with exit code $LASTEXITCODE." }
100+
101+
- task: PowerShell@2
102+
displayName: Verify wrapper packages were produced
103+
inputs:
104+
targetType: inline
105+
pwsh: true
106+
script: |
107+
$packages = @(Get-ChildItem '$(Build.ArtifactStagingDirectory)' -Recurse -Filter 'Microsoft.Graph.Wrapper.*.nupkg')
108+
Write-Host "Wrapper packages produced: $($packages.Count)"
109+
$packages | ForEach-Object { Write-Host " $($_.FullName)" }
110+
if ($packages.Count -eq 0) { throw 'No wrapper packages were produced.' }
111+
112+
- template: .azure-pipelines/common-templates/guardian-analyzer.yml@self
113+
114+
- ${{ if eq(parameters.Sign, true) }}:
115+
- template: .azure-pipelines/common-templates/esrp/codesign-nuget.yml@self
116+
parameters:
117+
FolderPath: $(Build.ArtifactStagingDirectory)
118+
Pattern: Microsoft.Graph.Wrapper.*.nupkg
119+
120+
- template: .azure-pipelines/common-templates/security-post-checks.yml@self
121+
122+
- ${{ if eq(parameters.Publish, true) }}:
123+
- stage: Deploy_to_Internal_Feed
124+
displayName: Deploy wrapper packages to internal feed
125+
dependsOn: Build
126+
jobs:
127+
- deployment: DeployToInternalFeed
128+
displayName: Publish to MSGraph PowerShell V3 build feed
129+
environment: PowerShellInternalFeed
130+
templateContext:
131+
type: releaseJob
132+
isProduction: true
133+
inputs:
134+
- input: pipelineArtifact
135+
artifactName: drop
136+
targetPath: $(System.DefaultWorkingDirectory)/drop
137+
strategy:
138+
runOnce:
139+
deploy:
140+
steps:
141+
- task: 1ES.PublishNuget@1
142+
displayName: Publish wrapper packages to internal feed
143+
inputs:
144+
useDotNetTask: false
145+
packageParentPath: $(System.DefaultWorkingDirectory)
146+
packagesToPush: $(System.DefaultWorkingDirectory)/**/drop/**/Microsoft.Graph.Wrapper.*.nupkg
147+
publishVstsFeed: ${{ parameters.InternalFeed }}
148+
nuGetFeedType: internal
149+
allowPackageConflicts: false

0 commit comments

Comments
 (0)