Skip to content

[release/10.0] Backport refreshable Helix Entra authentication - #17564

Merged
missymessa merged 7 commits into
dotnet:release/10.0from
missymessa:users/mjanecke/backport-17537-release-10.0
Sep 15, 2026
Merged

missymessa merged 7 commits into
dotnet:release/10.0from
missymessa:users/mjanecke/backport-17537-release-10.0

Conversation

@missymessa

Copy link
Copy Markdown
Member

Summary

Backports refreshable Helix Entra authentication to release/10.0 for AB#12269:

The backport also targets Microsoft.DotNet.ArcadeAzureIntegration for $(NetMinimum) so the release/10.0 net8.0 JobMonitor can consume the shared credential implementation without raising its runtime requirement.

Validation

  • dotnet test src\Microsoft.DotNet.Helix\Sdk.Tests\Microsoft.DotNet.Helix.Sdk.Tests\Microsoft.DotNet.Helix.Sdk.Tests.csproj --configuration Release --nologo --no-restore
  • Passed: 311, Failed: 0, Skipped: 0
  • The targeted project build includes Microsoft.DotNet.Helix.JobMonitor (net8.0).

missymessa and others added 3 commits September 14, 2026 12:54
Copilot-Session: e890b71a-c1aa-416c-a15c-be8da9fdd9b4
Copilot-Session: 0e1a942f-a44f-4e3a-8d35-af3fe8bee535
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a6ad3a92-2023-4c67-8948-f6d34de1a67c
Copilot-Session: 521e657d-a005-4f60-bcff-25a05ebcc390
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 4aa6b2e8-2313-40c0-92f6-1d578db0af15
Copilot-Session: a891597e-6dca-4706-8628-004c5837d0c9

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Critical compatibility findings show the SDK cannot compile for its net472/net481 targets because DefaultIdentityTokenCredential is unavailable there; add the required guards or framework stub.

Get a fresh assessment by requesting another Copilot review.

Pull request overview

Backports refreshable Entra authentication across Helix SDK tasks, API clients, Job Monitor, and Azure Pipelines while retaining existing authentication modes.

Changes:

  • Adds scoped, expiry-aware Entra authentication and refresh.
  • Propagates settings through SDK targets, Job Monitor, and pipeline templates.
  • Adds tests, documentation, and .NET 8 integration support.
File summaries
File Change
src/Microsoft.DotNet.Helix/Sdk/tools/Microsoft.DotNet.Helix.Sdk.props Defines authentication defaults.
src/Microsoft.DotNet.Helix/Sdk/tools/Microsoft.DotNet.Helix.Sdk.MultiQueue.targets Propagates authentication settings.
src/Microsoft.DotNet.Helix/Sdk/tools/Microsoft.DotNet.Helix.Sdk.MonoQueue.targets Propagates authentication settings.
src/Microsoft.DotNet.Helix/Sdk/tools/download-results/DownloadFromResultsContainer.targets Passes authentication to result downloads.
src/Microsoft.DotNet.Helix/Sdk/SendHelixJob.cs Updates authentication validation.
src/Microsoft.DotNet.Helix/Sdk/Readme.md Documents Entra configuration.
src/Microsoft.DotNet.Helix/Sdk/Microsoft.DotNet.Helix.Sdk.csproj Adds Azure integration reference.
src/Microsoft.DotNet.Helix/Sdk/HelixTask.cs Selects PAT, anonymous, or Entra clients.
src/Microsoft.DotNet.Helix/Sdk/GetHelixWorkItems.cs Preserves PAT file-link behavior.
src/Microsoft.DotNet.Helix/Sdk/CancelHelixJob.cs Supports authenticated cancellation.
src/Microsoft.DotNet.Helix/Sdk.Tests/Microsoft.DotNet.Helix.Sdk.Tests/QueueStatsLoggingTests.cs Tests creator validation.
src/Microsoft.DotNet.Helix/Sdk.Tests/Microsoft.DotNet.Helix.Sdk.Tests/Microsoft.DotNet.Helix.Sdk.Tests.csproj Adds client project references.
src/Microsoft.DotNet.Helix/Sdk.Tests/Microsoft.DotNet.Helix.Sdk.Tests/HelixApiAuthenticationTests.cs Tests authentication and refresh behavior.
src/Microsoft.DotNet.Helix/JobMonitor/Microsoft.DotNet.Helix.JobMonitor.csproj Adds Azure integration reference.
src/Microsoft.DotNet.Helix/JobMonitor/JobMonitorRunner.cs Selects and configures Entra authentication.
src/Microsoft.DotNet.Helix/JobMonitor/JobMonitorOptions.cs Adds CLI and environment configuration.
src/Microsoft.DotNet.Helix/Client/CSharp/HelixApiOptions.cs Adds authentication modes, scopes, and bearer policy.
src/Microsoft.DotNet.Helix/Client/CSharp/ApiFactory.cs Adds Entra client factories.
src/Microsoft.DotNet.ArcadeAzureIntegration/Microsoft.DotNet.ArcadeAzureIntegration.csproj Adds the .NET 8 target.
eng/common/core-templates/steps/send-to-helix.yml Configures pipeline Entra authentication.
eng/common/core-templates/job/job.yml Clarifies token-variable behavior.
eng/common/core-templates/job/helix-job-monitor.yml Adds monitor Entra configuration.
Documentation/AzureDevOps/SendingJobsToHelix.md Documents pipeline authentication options.
Review details
  • Files reviewed: 23/23 changed files
  • Comments generated: 2
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/Microsoft.DotNet.Helix/Sdk/HelixTask.cs Outdated
Comment thread src/Microsoft.DotNet.Helix/Sdk/Microsoft.DotNet.Helix.Sdk.csproj Outdated
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI review requested due to automatic review settings September 14, 2026 21:22

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Two unresolved critical issues affect job submission and bearer-token transport security.

Get a fresh assessment by requesting another Copilot review.

Review details
  • Files reviewed: 23/23 changed files
  • Comments generated: 2
  • Review effort level: Lite

Comment thread eng/common/core-templates/steps/send-to-helix.yml
Comment thread src/Microsoft.DotNet.Helix/Client/CSharp/HelixApiOptions.cs
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI review requested due to automatic review settings September 14, 2026 22:10

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

Custom HTTPS Helix base URI handling remains unresolved for Entra authentication in JobMonitor and HelixTask.

Review details

Suppressed comments (2)

src/Microsoft.DotNet.Helix/JobMonitor/JobMonitorRunner.cs:825

  • The standalone monitor exposes helixBaseUri, and PAT authentication accepts arbitrary base URIs, but the Entra path always selects default scope discovery here. For a custom HTTPS Helix host, HelixApiOptions throws because no default scope is known; expose an explicit Entra scope through JobMonitorOptions/the template or document and enforce the supported hosts.
        return ApiFactory.GetAuthenticatedWithEntra(
            baseUri,
            new DefaultIdentityTokenCredential());

src/Microsoft.DotNet.Helix/Sdk/HelixTask.cs:103

  • With Entra enabled, a custom HTTPS BaseUri reaches this overload, which only has default scopes for helix.dot.net and helix.int-dot.net and otherwise throws before making a request. ApiFactory exposes an explicit-scope overload for custom Helix instances, but HelixTask has no scope input, so this new auth mode breaks the existing BaseUri customization; thread the scope through the task/template or explicitly constrain the supported hosts.
        return ApiFactory.GetAuthenticatedWithEntra(
            baseUri,
            new DefaultIdentityTokenCredential());
  • Files reviewed: 25/25 changed files
  • Comments generated: 0 new
  • Review effort level: Lite

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI review requested due to automatic review settings September 14, 2026 23:20
@missymessa

Copy link
Copy Markdown
Member Author

Addressed the latest Copilot review's suppressed custom-host findings in ee37b23. Both submission tasks and JobMonitor now accept an optional explicit Entra scope (HelixEntraScope / helixEntraScope) for custom HTTPS Helix base URIs, while production and staging retain inferred scopes. The scope is propagated through all SDK tasks, result downloads, and both pipeline templates.

Validation:

  • Debug and Release Microsoft.DotNet.Helix.Sdk builds: net10.0 + net472, 0 warnings/errors
  • Release Microsoft.DotNet.Helix.JobMonitor build: net8.0, 0 warnings/errors
  • Microsoft.DotNet.Helix.Sdk.Tests: 314/314 passed, including custom-host scope coverage for both SDK tasks and JobMonitor

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The default-host download regression and public authentication-path compatibility issue remain unresolved.

Get a fresh assessment by requesting another Copilot review.

Review details

Suppressed comments (1)

src/Microsoft.DotNet.Helix/Client/CSharp/HelixApiOptions.cs:70

  • This changes the existing public HelixApiOptions(Uri, TokenCredential) path for every credential that is not HelixApiTokenCredential: it used to go through HelixApiTokenAuthenticationPolicy with empty scopes, but now every such credential is treated as Entra and gets a host-derived scope. Consumers that supplied their own TokenCredential for the legacy policy can therefore fail on custom/HTTP hosts or receive a different authorization scheme; preserve the old overload semantics and expose Entra through a distinct constructor/factory, or document this as a breaking API change.
        else
        {
            AuthenticationMode = HelixApiAuthenticationMode.EntraId;
            if (TokenScopes.Count == 0)
            {
  • Files reviewed: 25/25 changed files
  • Comments generated: 1
  • Review effort level: Lite

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 4aa6b2e8-2313-40c0-92f6-1d578db0af15
Copilot AI review requested due to automatic review settings September 14, 2026 23:40
@missymessa

Copy link
Copy Markdown
Member Author

Addressed the suppressed public-constructor compatibility finding in aa6ddf6. Existing HelixApiOptions(TokenCredential) and HelixApiOptions(Uri, TokenCredential) callers now retain the legacy token authorization policy with empty scopes, including custom/HTTP hosts. Entra factories now opt into the explicit-scopes constructor, so Bearer authentication, host-derived scopes, refresh behavior, and HTTPS validation remain on the Entra-specific paths. Regression coverage exercises both legacy constructors, custom hosts, token versus Bearer headers, and production/staging scope inference. The full Helix SDK suite passes (319 tests).

@missymessa
missymessa enabled auto-merge (squash) September 14, 2026 23:41

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

The changes span authentication, SDK tasks, JobMonitor, pipelines, framework targeting, and documentation.

Review details
  • Files reviewed: 25/25 changed files
  • Comments generated: 0 new
  • Review effort level: Lite

@missymessa
missymessa merged commit 28d2c5c into dotnet:release/10.0 Sep 15, 2026
17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants