Skip to content

[release/6.0] Backport refreshable Helix Entra authentication - #17565

Merged
missymessa merged 4 commits into
dotnet:release/6.0from
missymessa:users/mjanecke/backport-17537-release-6.0
Sep 15, 2026
Merged

missymessa merged 4 commits into
dotnet:release/6.0from
missymessa:users/mjanecke/backport-17537-release-6.0

Conversation

@missymessa

@missymessa missymessa commented Sep 14, 2026 •

Copy link
Copy Markdown
Member

Summary

Validation

DOTNET_ROLL_FORWARD=Major Build.cmd -projects src\Microsoft.DotNet.Helix\Sdk.Tests\Microsoft.DotNet.Helix.Sdk.Tests\Microsoft.DotNet.Helix.Sdk.Tests.csproj -test

Result: 62 tests passed, 0 failed, 0 skipped, including focused coverage that verifies repository Helix consumers treat Entra mode as authenticated. Roll-forward is required locally because this branch targets netcoreapp3.1 while the repository bootstrap provides the .NET 6 runtime.

Intentionally omitted

The main-branch standalone JobMonitor project and eng/common/core-templates changes from #17537 are not included because those surfaces do not exist on release/6.0. Their files were not introduced solely for this backport.

missymessa and others added 3 commits September 14, 2026 12:53
Copilot-Session: e890b71a-c1aa-416c-a15c-be8da9fdd9b4
Copilot-Session: 0e1a942f-a44f-4e3a-8d35-af3fe8bee535
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a6ad3a92-2023-4c67-8948-f6d34de1a67c
Copilot-Session: 521e657d-a005-4f60-bcff-25a05ebcc390
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 4aa6b2e8-2313-40c0-92f6-1d578db0af15
Copilot-Session: a891597e-6dca-4706-8628-004c5837d0c9

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Critical authentication-mode handling remains unresolved in repository Helix project consumers.

Get a fresh assessment by requesting another Copilot review.

Pull request overview

Backports refreshable Entra authentication for Helix clients, SDK tasks, and Azure Pipelines while preserving PAT and anonymous modes.

Changes:

  • Adds scoped TokenCredential authentication with refresh support.
  • Propagates authentication settings through SDK tasks and pipeline templates.
  • Updates dependencies, tests, and documentation.
File summaries
File Reviewed change
src/Microsoft.DotNet.Helix/Sdk/tools/Microsoft.DotNet.Helix.Sdk.props Defines Entra authentication settings.
src/Microsoft.DotNet.Helix/Sdk/tools/Microsoft.DotNet.Helix.Sdk.MultiQueue.targets Propagates authentication to multi-queue tasks.
src/Microsoft.DotNet.Helix/Sdk/tools/Microsoft.DotNet.Helix.Sdk.MonoQueue.targets Propagates authentication to job submission.
src/Microsoft.DotNet.Helix/Sdk/SendHelixJob.cs Handles creator validation by authentication mode.
src/Microsoft.DotNet.Helix/Sdk/Readme.md Documents SDK authentication options.
src/Microsoft.DotNet.Helix/Sdk/Microsoft.DotNet.Helix.Sdk.csproj Adds Azure Identity and source-build support.
src/Microsoft.DotNet.Helix/Sdk/HelixTask.cs Selects PAT, anonymous, or refreshable Entra clients.
src/Microsoft.DotNet.Helix/Sdk/GetHelixWorkItems.cs Handles result links by authentication mode.
src/Microsoft.DotNet.Helix/Sdk/CancelHelixJob.cs Supports Entra-authenticated cancellation.
src/Microsoft.DotNet.Helix/Sdk.Tests/Microsoft.DotNet.Helix.Sdk.Tests/Microsoft.DotNet.Helix.Sdk.Tests.csproj Updates test references and dependencies.
src/Microsoft.DotNet.Helix/Sdk.Tests/Microsoft.DotNet.Helix.Sdk.Tests/HelixApiAuthenticationTests.cs Tests authentication selection, refresh, links, and cancellation.
src/Microsoft.DotNet.Helix/Client/CSharp/Microsoft.DotNet.Helix.Client.csproj Aligns Azure client dependencies.
src/Microsoft.DotNet.Helix/Client/CSharp/HelixApiOptions.cs Configures authentication modes, scopes, and bearer policies.
src/Microsoft.DotNet.Helix/Client/CSharp/ApiFactory.cs Adds Entra-authenticated client factories.
eng/common/templates/steps/send-to-helix.yml Configures Entra service connections for standard pipelines.
eng/common/templates-official/steps/send-to-helix.yml Configures Entra service connections for official pipelines.
Documentation/AzureDevOps/SendingJobsToHelix.md Documents Entra and legacy authentication setup.
Review details
  • Files reviewed: 17/17 changed files
  • Comments generated: 2
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread eng/common/templates-official/steps/send-to-helix.yml
Comment thread eng/common/templates/steps/send-to-helix.yml
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI review requested due to automatic review settings September 14, 2026 21:21

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

One critical packaging issue and one moderate compatibility issue remain unresolved.

Get a fresh assessment by requesting another Copilot review.

Review details

Suppressed comments (1)

src/Microsoft.DotNet.Helix/Client/CSharp/HelixApiOptions.cs:67

  • This else changes the behavior of the existing public HelixApiOptions(TokenCredential) / (Uri, TokenCredential) constructors for every custom TokenCredential that is not HelixApiTokenCredential: before this change InitializeOptions attached HelixApiTokenAuthenticationPolicy (the legacy token header and empty scopes), whereas it now attaches a Bearer policy and requests a Helix Entra scope. That is a behavioral breaking change for release/6.0 consumers using a custom credential; keep the legacy constructor on the PAT policy and add an explicit Entra constructor/marker for the new factory path.
            else
            {
                AuthenticationMode = HelixApiAuthenticationMode.EntraId;
                if (TokenScopes.Count == 0)
                {
  • Files reviewed: 20/20 changed files
  • Comments generated: 1
  • Review effort level: Lite

<PackageReference Include="Newtonsoft.Json" Version="$(NewtonsoftJsonVersion)" />
<PackageReference Include="NuGet.Versioning" Version="$(NuGetVersion)" />
<PackageReference Include="System.Net.Http" Version="4.3.4" />
<PackageReference Include="Azure.Identity" Version="1.13.2" Condition="'$(DotNetBuildSourceOnly)' != 'true'" />
@missymessa
missymessa merged commit e67729e into dotnet:release/6.0 Sep 15, 2026
17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants