Skip to content

[release/10.0] Read GitHub App credentials through WIF - #17656

Open
missymessa wants to merge 3 commits into
release/10.0from
users/mjanecke/backport-github-app-secrets-release10
Open

missymessa wants to merge 3 commits into
release/10.0from
users/mjanecke/backport-github-app-secrets-release10

Conversation

@missymessa

Copy link
Copy Markdown
Member

Intent

Make the final GitHub App token implementation available to release/10.0 consumers, including dotnet-monitor. The current branch still exposes the legacy Key Vault RSA-key contract, so flowing its latest Arcade build cannot satisfy dotnet-monitor PR #9847.

Change

Backport #17528 and its superseding fix #17541:

  • read Secret Manager's GitHub App ID and PEM private-key projections from Key Vault through WIF;
  • sign the GitHub App JWT locally with the retrieved private key;
  • expose appIdSecretName and appPrivateKeySecretName in the shared token template;
  • update OneLocBuild and its documentation to the final secret-name contract;
  • preserve the release/10.0-specific supported-project guards during conflict resolution.

Validation

  • Reviewed the complete diff against release/10.0.
  • git diff --check passes.
  • eng/common/Get-GitHubAppToken.ps1 parses successfully in PowerShell.
  • The token script and shared token step match the already merged release/11.0 backport.
  • Independent AI review found no remaining correctness, security, or logic issues.

Follow-up

After merge, use the resulting .NET 10 Eng BAR build to update dotnet-monitor, then change dotnet-monitor PR #9847 to pass the two secret names required by this contract.

missymessa and others added 3 commits October 2, 2026 10:42
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: cb83d078-4ba7-4f9f-86e5-7840b221515c
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Keep the release branch's internal and DevDiv project checks while backporting the GitHub App credential changes.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 4e96402b-01cb-4650-acf6-4ee514e5268c
Copilot AI balanced review requested due to automatic review settings October 2, 2026 17:46
@missymessa
missymessa marked this pull request as ready for review October 2, 2026 17:48

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The backport consistently applies the finalized credential contract across implementation, templates, and documentation without unresolved issues.

Review effort: Balanced
Findings: None

What changed in this PR

Backports the finalized WIF-based GitHub App credential flow to release/10.0.

Changes:

  • Retrieves App credentials from Key Vault and signs JWTs locally.
  • Updates shared OneLoc templates and migration documentation.
  • Preserves project-specific service-connection selection.
File Description
eng/​common/​Get-GitHubAppToken.ps1 Reads secrets and locally signs the App JWT.
eng/​common/​core-templates/​steps/​get-github-app-token.yml Exposes Key Vault secret-name parameters.
eng/​common/​core-templates/​job/​onelocbuild.yml Configures OneLoc’s WIF credential flow.
Documentation/​OneLocBuildGitHubApp.md Documents setup, migration, and troubleshooting.
Documentation/​OneLocBuild.md Updates the OneLoc parameter reference.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants