Fix Bicep deployment lookup across projects - #9490
Fix Bicep deployment lookup across projects#9490Victor Vazquez (vhvb1989) wants to merge 5 commits into
Conversation
|
Azure Pipelines: Successfully started running 1 pipeline(s). 21 pipeline(s) were filtered out due to trigger conditions. There may be pipelines that require an authorized user to comment /azp run to run. |
Tag standard ARM deployments with project identity and prefer project-specific deployment history while retaining a legacy fallback for existing environments. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8f8fec20-564b-4f35-8720-6c8f88bc9f08
Avoid gosec taint-analysis blowups from debug logging and update the provision-state playback recording with the project tag emitted by the first upgraded deployment. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8f8fec20-564b-4f35-8720-6c8f88bc9f08
Align all recorded standard deployment snapshots with the project identity tag emitted by upgraded provisions so cache checks replay the new ARM state. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8f8fec20-564b-4f35-8720-6c8f88bc9f08
c8073ac to
80a2822
Compare
There was a problem hiding this comment.
Pull request overview
Adds project-scoped Bicep deployment identity to prevent cross-project deployment selection.
Changes:
- Tags and filters standard deployments by project, environment, and layer.
- Preserves legacy migration and deployment-stack behavior.
- Retains identity tags when voiding deployment state.
Reviewed changes
Copilot reviewed 11 out of 12 changed files in this pull request and generated 1 comment.
Show a summary per file
| File | Description |
|---|---|
cli/azd/pkg/azure/tags.go |
Defines the project tag key. |
cli/azd/pkg/infra/deployment_manager.go |
Adds project-aware deployment matching. |
cli/azd/pkg/infra/deployment_manager_test.go |
Tests project and legacy selection. |
cli/azd/pkg/infra/provisioning/bicep/bicep_provider.go |
Wires project identity into Bicep operations. |
cli/azd/pkg/infra/provisioning/bicep/bicep_provider_test.go |
Tests legacy state migration. |
cli/azd/pkg/infra/provisioning/bicep/deployment_stacks.go |
Exempts deployment stacks from new identity behavior. |
cli/azd/pkg/infra/provisioning/bicep/project_name.go |
Resolves project identity. |
cli/azd/pkg/infra/provisioning/bicep/project_name_test.go |
Tests identity resolution. |
cli/azd/pkg/azapi/standard_deployments.go |
Preserves tags while voiding state. |
cli/azd/pkg/azapi/standard_deployments_test.go |
Tests preserved tags. |
cli/azd/test/functional/testdata/recordings/Test_CLI_ProvisionState.yaml |
Updates provision recordings. |
cli/azd/test/functional/testdata/recordings/Test_CLI_ProvisionStateWithDown.yaml |
Updates down-state recordings. |
💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Cover the intentional ownership behavior for standard deployments and deployment stacks. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8f8fec20-564b-4f35-8720-6c8f88bc9f08
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 12 out of 13 changed files in this pull request and generated 1 comment.
Suppressed comments (1)
cli/azd/test/functional/testdata/recordings/Test_CLI_ProvisionStateWithDown.yaml:866
- This cassette adds
azd-project-nameonly to the list response, while the same deployment returned by the later GET (line 2088) and the void PUT/response (lines 2134 and 2161) remain untagged. Playback therefore feedsvoidDeploymentTagslegacy metadata and never exercises the end-to-end project/layer tag preservation this PR adds. Re-record or update all corresponding interactions so the fetched deployment and voided deployment carry both identity tags. azd-code-reviewer
body: '{"nextLink":"https://management.azure.com/subscriptions/5ca082f3-38f2-4bb0-b0a4-c401184ae3a8/providers/Microsoft.Resources/deployments/?api-version=2021-04-01\u0026%24skiptoken=1c%2fBbsIwDAbgZ2nORUqAw9RbRzypjLgksTX1iKaOFVAqbUVtivruW4d4iJ1s%2bf8P%2fm7ivQ1dE66HrmkDtec6fIvsJiD3xH45r6Eeuv3hq2vmxmsdRSZU8pRYgmhktRDpX8O1%2fSNTapkg47PRx%2bhOZiyhigjbjYGit%2bQ06nwwdJSWebT0%2beEUljsv%2b1LzGrWVpTbSkBmROJqTUSYqIolbywMxvHg%2fttFpWCFVKxyL3wkLMaUiZ08u3xX5%2fLzIwvVyScUbeAJ25R4elzvtX8lmxAZw1rG%2fO6bpBw%3d%3d","value":[{"id":"/subscriptions/5ca082f3-38f2-4bb0-b0a4-c401184ae3a8/providers/Microsoft.Resources/deployments/azdtest-d7f3516-1775755989","location":"eastus2","name":"azdtest-d7f3516-1775755989","properties":{"correlationId":"cb0b7914b98a4a7b9ef35b04586ed120","dependencies":[{"dependsOn":[{"id":"/subscriptions/5ca082f3-38f2-4bb0-b0a4-c401184ae3a8/resourceGroups/rg-azdtest-d7f3516","resourceName":"rg-azdtest-d7f3516","resourceType":"Microsoft.Resources/resourceGroups"}],"id":"/subscriptions/5ca082f3-38f2-4bb0-b0a4-c401184ae3a8/resourceGroups/rg-azdtest-d7f3516/providers/Microsoft.Resources/deployments/resources","resourceName":"resources","resourceType":"Microsoft.Resources/deployments"}],"duration":"PT26.5307597S","mode":"Incremental","outputResources":[{"id":"/subscriptions/5ca082f3-38f2-4bb0-b0a4-c401184ae3a8/resourceGroups/rg-azdtest-d7f3516"},{"id":"/subscriptions/5ca082f3-38f2-4bb0-b0a4-c401184ae3a8/resourceGroups/rg-azdtest-d7f3516/providers/Microsoft.Storage/storageAccounts/sthgngsljiw7i2k"}],"outputs":{"arraY_INT":{"type":"Array","value":[1,2,3]},"arraY_PARAM":{"type":"Array","value":[]},"arraY_STRING":{"type":"Array","value":["elem1","elem2","elem3"]},"array":{"type":"Array","value":[true,"abc",1234]},"azurE_STORAGE_ACCOUNT_ID":{"type":"String","value":"/subscriptions/5ca082f3-38f2-4bb0-b0a4-c401184ae3a8/resourceGroups/rg-azdtest-d7f3516/providers/Microsoft.Storage/storageAccounts/sthgngsljiw7i2k"},"azurE_STORAGE_ACCOUNT_NAME":{"type":"String","value":"sthgngsljiw7i2k"},"bool":{"type":"Bool","value":true},"int":{"type":"Int","value":1234},"nullableParamOutput":{"type":"String"},"objecT_PARAM":{"type":"Object","value":{}},"object":{"type":"Object","value":{"array":[true,"abc",1234],"foo":"bar","inner":{"foo":"bar"}}},"string":{"type":"String","value":"abc"}},"parameters":{"arrayValue":{"type":"Array","value":[]},"boolTagValue":{"type":"Bool","value":false},"deleteAfterTime":{"type":"String","value":"2026-04-09T18:33:28Z"},"environmentName":{"type":"String","value":"azdtest-d7f3516"},"intTagValue":{"type":"Int","value":678},"location":{"type":"String","value":"eastus2"},"nullableParam":{"type":"String"},"objectValue":{"type":"Object","value":{}},"secureObject":{"type":"SecureObject"},"secureValue":{"type":"SecureString"}},"providers":[{"namespace":"Microsoft.Resources","resourceTypes":[{"locations":["eastus2"],"resourceType":"resourceGroups"},{"locations":[null],"resourceType":"deployments"}]}],"provisioningState":"Succeeded","templateHash":"4488259817381607990","timestamp":"2026-04-09T17:33:55.2995246Z"},"tags":{"azd-env-name":"azdtest-d7f3516","azd-layer-name":"","azd-project-name":"storage","azd-provision-param-hash":"d965096b5a2205f3c41c9af8184c507340547db22c4a12560b723511d771a960"},"type":"Microsoft.Resources/deployments"}]}'
Preserve short project names and deterministically hash names that exceed ARM tag value limits. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8f8fec20-564b-4f35-8720-6c8f88bc9f08
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 12 out of 13 changed files in this pull request and generated no new comments.
Suppressed comments (1)
cli/azd/pkg/infra/provisioning/bicep/project_name.go:56
- ARM enforces the 256-character tag limit in UTF-16 code units, but converting to
[]runecounts supplementary characters such as emoji as one. A project name containing 129–256 emoji therefore bypasses shortening even though ARM will reject the deployment tag. Count UTF-16 units while truncating on rune boundaries, and add a non-BMP boundary case. azd-code-reviewer
projectNameRunes := []rune(projectName)
if len(projectNameRunes) <= maxProjectTagValueLength {
Azure Dev CLI Install InstructionsInstall scriptsMacOS/Linux
bash: pwsh: WindowsPowerShell install MSI install Standalone Binary
MSI
Documentationlearn.microsoft.com documentationtitle: Azure Developer CLI reference
|
Summary
azd-project-nameidentity resolved fromazure.yaml.nameor the project directoryFixes #8701
Migration behavior
Existing deployments without
azd-project-namecontinue to use the previous newest-deployment fallback. The first provision with this version cannot reuse a legacy deployment's cached state, so it writes a project-tagged deployment and future lookups become unambiguous. Each colliding project/environment must be provisioned once to complete migration.Deployment stacks intentionally retain their existing identity behavior because changing stack names would create a second owner for resources managed by an existing stack.
Validation
go test ./pkg/infra/... ./pkg/azapi -count=1go build ./...Full
mage preflightwas not completed because golangci-lint 2.11.4 remains CPU-bound indefinitely when multiple package roots run together; the same linters pass when isolated by package/analyzer.