[release/10.0] Read GitHub App credentials through WIF - #17656
Open
missymessa wants to merge 3 commits into
Open
missymessa wants to merge 3 commits into
missymessa wants to merge 3 commits into
Conversation
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: cb83d078-4ba7-4f9f-86e5-7840b221515c
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Keep the release branch's internal and DevDiv project checks while backporting the GitHub App credential changes. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 4e96402b-01cb-4650-acf6-4ee514e5268c
Contributor
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The backport consistently applies the finalized credential contract across implementation, templates, and documentation without unresolved issues.
Review effort: Balanced
Findings: None
What changed in this PR
Backports the finalized WIF-based GitHub App credential flow to release/10.0.
Changes:
- Retrieves App credentials from Key Vault and signs JWTs locally.
- Updates shared OneLoc templates and migration documentation.
- Preserves project-specific service-connection selection.
| File | Description |
|---|---|
eng/common/Get-GitHubAppToken.ps1 |
Reads secrets and locally signs the App JWT. |
eng/common/core-templates/steps/get-github-app-token.yml |
Exposes Key Vault secret-name parameters. |
eng/common/core-templates/job/onelocbuild.yml |
Configures OneLoc’s WIF credential flow. |
Documentation/OneLocBuildGitHubApp.md |
Documents setup, migration, and troubleshooting. |
Documentation/OneLocBuild.md |
Updates the OneLoc parameter reference. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Intent
Make the final GitHub App token implementation available to
release/10.0consumers, including dotnet-monitor. The current branch still exposes the legacy Key Vault RSA-key contract, so flowing its latest Arcade build cannot satisfy dotnet-monitor PR #9847.Change
Backport #17528 and its superseding fix #17541:
appIdSecretNameandappPrivateKeySecretNamein the shared token template;release/10.0-specific supported-project guards during conflict resolution.Validation
release/10.0.git diff --checkpasses.eng/common/Get-GitHubAppToken.ps1parses successfully in PowerShell.release/11.0backport.Follow-up
After merge, use the resulting
.NET 10 EngBAR build to update dotnet-monitor, then change dotnet-monitor PR #9847 to pass the two secret names required by this contract.