Skip to content

Commit bd8a781

Browse files
gavinbarronCopilot
andcommitted
Route metadata/OpenAPI capture jobs through CFS feeds (CFSClean)
Pipeline 79 (Generation) fails CFSClean because the capture-metadata and capture-openapi jobs reach public package feeds: dotnet restore/tool-install -> api.nuget.org and npm install -> registry.npmjs.org. PR #1448 only covered the typewriter/kiota stages and wrote nuget.config to the sources dir, where a later 'checkout: self' wipes it. Add reusable create-cfs-nuget-config.yml (NuGetAuthenticate + nuget.config written to Agent.TempDirectory so checkout cannot wipe it) and create-cfs-npmrc.yml (npmAuthenticate + CFS npm registry applied to the user profile). Wire both into capture-metadata.yml (after checkouts) and the nuget config into capture-openapi's convert_openapi job, and pass --configfile to the hidi 'dotnet tool install' steps. Feed: GraphDeveloperExperiences_Public (upstreams nuget.org and npmjs.org). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: d3f8fec7-b00b-46be-ba39-7e1f3e7f7188
1 parent b1be4eb commit bd8a781

4 files changed

Lines changed: 50 additions & 2 deletions

File tree

‎.azure-pipelines/generation-templates/capture-metadata.yml‎

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -48,6 +48,11 @@ steps:
4848
- template: /.azure-pipelines/generation-templates/checkout-metadata.yml@self
4949
- template: /.azure-pipelines/generation-templates/set-user-config.yml@self
5050

51+
# Route NuGet and npm through the CFS central feed for 1ES network isolation (CFSClean).
52+
# Placed after all checkouts so the generated config files are not wiped by a checkout clean.
53+
- template: /.azure-pipelines/generation-templates/create-cfs-nuget-config.yml@self
54+
- template: /.azure-pipelines/generation-templates/create-cfs-npmrc.yml@self
55+
5156
# required for TypeSpec
5257
- task: UseNode@1
5358
inputs:
@@ -153,7 +158,7 @@ steps:
153158
parameters:
154159
version: '9.x'
155160

156-
- pwsh: dotnet tool install --global Microsoft.OpenApi.Hidi --version 1.*
161+
- pwsh: dotnet tool install --global Microsoft.OpenApi.Hidi --version 1.* --configfile "$(Agent.TempDirectory)/nuget.config"
157162
displayName: 'Install hidi tool'
158163

159164
# verify that generated metadata is parsable as an Edm model

‎.azure-pipelines/generation-templates/capture-openapi.yml‎

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -61,6 +61,9 @@ jobs:
6161
persistCredentials: true
6262

6363
- template: /.azure-pipelines/generation-templates/checkout-metadata.yml@self
64+
# Route NuGet through the CFS central feed for 1ES network isolation (CFSClean).
65+
# Placed after all checkouts so the generated config is not wiped by a checkout clean.
66+
- template: /.azure-pipelines/generation-templates/create-cfs-nuget-config.yml@self
6467
# required for the hidi to run
6568
- template: /.azure-pipelines/generation-templates/use-dotnet-sdk.yml@self
6669
parameters:
@@ -71,7 +74,7 @@ jobs:
7174
parameters:
7275
version: '9.x'
7376

74-
- pwsh: dotnet tool install --global Microsoft.OpenApi.Hidi --version 1.*
77+
- pwsh: dotnet tool install --global Microsoft.OpenApi.Hidi --version 1.* --configfile "$(Agent.TempDirectory)/nuget.config"
7578
displayName: install hidi
7679

7780
- pwsh: |
Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,20 @@
1+
# Routes npm through the CFS central feed (GraphDeveloperExperiences_Public, which upstreams
2+
# npmjs.org) instead of hitting registry.npmjs.org directly, for 1ES network isolation (CFSClean).
3+
# The authenticated .npmrc is copied to the user profile so both global (`npm install -g`) and
4+
# project (`npm ci`) commands pick up the registry + credentials without per-step configuration.
5+
steps:
6+
- pwsh: |
7+
@"
8+
registry=https://microsoftgraph.pkgs.visualstudio.com/0985d294-5762-4bc2-a565-161ef349ca3e/_packaging/GraphDeveloperExperiences_Public/npm/registry/
9+
always-auth=true
10+
"@ | Set-Content -Path "$(Agent.TempDirectory)/.npmrc" -Encoding UTF8
11+
displayName: 'Create .npmrc (CFS central feed)'
12+
13+
- task: npmAuthenticate@0
14+
displayName: 'Authenticate npm to CFS feed'
15+
inputs:
16+
workingFile: '$(Agent.TempDirectory)/.npmrc'
17+
18+
- pwsh: |
19+
Copy-Item -Path "$(Agent.TempDirectory)/.npmrc" -Destination (Join-Path $HOME '.npmrc') -Force
20+
displayName: 'Apply CFS .npmrc to user profile'
Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,20 @@
1+
# Routes dotnet/NuGet restore and tool installs through the CFS central package feed
2+
# (GraphDeveloperExperiences_Public) instead of public nuget.org, for 1ES network isolation
3+
# (CFSClean). The config is written to $(Agent.TempDirectory) so it survives any subsequent
4+
# `checkout` step (which cleans the sources directory and would wipe a config placed there).
5+
# Consumers must pass `--configfile "$(Agent.TempDirectory)/nuget.config"` to dotnet commands.
6+
steps:
7+
- task: NuGetAuthenticate@1
8+
displayName: 'Authenticate to Azure Artifacts (CFS feed)'
9+
10+
- pwsh: |
11+
@"
12+
<?xml version="1.0" encoding="utf-8"?>
13+
<configuration>
14+
<packageSources>
15+
<clear />
16+
<add key="GraphDeveloperExperiences_Public" value="https://microsoftgraph.pkgs.visualstudio.com/0985d294-5762-4bc2-a565-161ef349ca3e/_packaging/GraphDeveloperExperiences_Public/nuget/v3/index.json" />
17+
</packageSources>
18+
</configuration>
19+
"@ | Set-Content -Path "$(Agent.TempDirectory)/nuget.config" -Encoding UTF8
20+
displayName: 'Create nuget.config (CFS central feed)'

0 commit comments

Comments
 (0)