[Cosmos] Remove ephemeral-tenant provisioning from fixed-account live-test lanes
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 5/5
- Tiempo estimado
- Más de una semana
- Aptitud para principiantes
- 45/100
Línea de trabajo
Comienza con PR #48459 y la shared live-test stage, y después sigue build-test-resource-config.yml, deploy-test-resources.yml, remove-test-resources.yml y test-resources.bicep. Separa las rutas fixed-account y AAD para que los fixed jobs usen el resolver y el shared JSON secret sin ephemeral provisioning, mientras que AAD conserva la tenant-scoped role assignment. La finalización incluye scoped stale-database cleanup, ownership documentation y la validación de ejecuciones solapadas y de deployment credentials no disponibles.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Is your feature request related to a problem? Please describe.
PR #48459 moves the Python Cosmos key-auth live tests onto fixed, team-owned accounts and proves that the selected accounts work across the live matrix. However, the shared Python live-test stage still deploys and removes a temporary Cosmos account for every matrix leg before the fixed credentials are reapplied.
As a result, the migrated key-auth tests still authenticate through the ephemeral live-test tenant during ARM deployment. A tenant rotation or broken service connection can therefore fail the job before pytest reaches the fixed account. This is the final gap between the current Python implementation and Java's no-provisioning fixed-account model.
Describe the solution you'd like
Separate the live matrix by resource-lifecycle requirements and make the fixed-account lane independent of ephemeral-tenant provisioning.
- Split the 12 fixed key-auth jobs and the already-fixed GSI job from the 7 AAD jobs that require a tenant-scoped Cosmos data-plane role assignment.
- Run the fixed-account jobs through a Cosmos-owned stage or job that resolves credentials from the shared versioned JSON secret but does not invoke
build-test-resource-config.yml,deploy-test-resources.yml, orremove-test-resources.yml. - Ensure the fixed-account jobs do not require the
azure-sdk-tests-cosmosservice connection or any authentication against the ephemeral tenant. - Keep the AAD jobs on the existing provisioned-resource path so
test-resources.bicepcan create their tenant-specificsqlRoleAssignment. - Move values currently supplied only as Bicep outputs into the fixed-account matrix. In particular, set
AZURE_COSMOS_ENABLE_CIRCUIT_BREAKER=Trueon the applicable circuit-breaker jobs. - Remove the transitional post-deployment credential reapplication once fixed-account jobs no longer deploy resources; the resolver pre-step should become their sole source of
ACCOUNT_HOSTandACCOUNT_KEY. - Add best-effort cleanup for databases left by cancelled or aborted runs. Cleanup must be limited to stale
PythonSDKTest-*databases owned by Python and must run across each fixed account without affecting Java or concurrent Python runs. - Document ownership for Java's shared account provisioning/reconciliation script and the shared JSON secret update procedure, including a smoke test after account or key rotation.
- Validate overlapping fixed-account runs and prove they remain runnable when ephemeral-tenant deployment credentials are unavailable.
Describe alternatives you've considered
- Keep the current transitional deployment followed by credential override. This is already proven by PR #48459, but it does not remove the tenant dependency.
- Move AAD tests onto the fixed accounts and refresh their role assignments after every tenant rotation. This preserves one matrix but requires cross-subscription permissions and additional identity lifecycle work.
- Add a per-leg deployment condition to shared
engtemplates. This is generic, but changes monorepo-wide infrastructure for a Cosmos-specific requirement. - Register a separate AAD pipeline while keeping the fixed-account pipeline Cosmos-owned. This is fully service-local but adds another Azure DevOps pipeline definition to maintain.
Additional context
PR #48459 already supplies the prerequisites for this work:
- A cross-platform PowerShell resolver compatible with Java's shared JSON-secret schema.
- Stable-account selectors for all 12 key-auth matrix jobs; GSI already uses dedicated fixed credentials.
- Run-scoped
PythonSDKTest-*database naming, bounded control-plane retries, scoped normal cleanup, and test isolation needed for concurrent use. - Early resolver validation through
PreStepsand a Cosmos-local post-deployment hook used during the transitional rollout. - Successful live verification of the fixed-account query, split, multi-region, and circuit-breaker coverage.
Related tracking issue: #48236. Java reference: Azure/azure-sdk-for-java#49735.
- Lenguaje dominante
- Python
- Estrellas
- 5.6k
- Forks
- 3.4k
- Merge medio
- 2 d 5 h
- PR fusionados (30 d)
- 219
Preparar el entorno
Inicia el contenedor de desarrollo del proyecto en tu navegador, con tu propia cuenta de GitHub.
- Sin Dockerfile ni archivo de Docker Compose
- Tiene una plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de Azure/azure-sdk-for-python
-
azure-monitor-opentelemetry-exporter: HTTP dependency target rendered as host:None when server.port is absentPosiblemente ocupada @rads-1996 la tomó hace 2 días. AbiertoClient customer-reported Monitor - Exporter question
Dificultad 1/5 1-3 horas Aptitud para principiantes 92/100
Azure/azure-sdk-for-python#49343 · 1 comentario · 1 reacción · 1 asignado ·
Los mantenedores suelen responder en 1 día
-
azure-ai-evaluation: a content-harm score of 0 (no harm) is parsed as NaN in _parse_content_harm_response (numeric branch uses 0 < x instead of 0 <= x)Posiblemente ocupada @pujitha24 la tomó hace 11 días. AbiertoEvaluation Service Attention
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
Azure/azure-sdk-for-python#49190 · 1 comentario · 1 reacción ·
Los mantenedores suelen responder en 1 día
-
Update CODEOWNERSAbierto
Dificultad 1/5 Menos de una hora Aptitud para principiantes 90/100
Azure/azure-sdk-for-python#49183 · 1 reacción ·
Los mantenedores suelen responder en 1 día
-
azure-ai-evaluation: PromptyEvaluatorBase falls back to the first digit anywhere in the judge's reply, and the threshold turns a stray digit into a wrong pass/fail (15 evaluators)Posiblemente ocupada @wasim-builds la tomó hace 5 días. AbiertoEvaluation Service Attention
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
Azure/azure-sdk-for-python#49153 · 1 comentario · 1 reacción ·
Los mantenedores suelen responder en 1 día
-
azure-search-documents ContentUnderstandingSkill is missing model_name and model_deploymentPosiblemente ocupada @wasim-builds la tomó hace 5 días. AbiertoSearch Service Attention
Dificultad 2/5 1-3 horas Aptitud para principiantes 74/100
Azure/azure-sdk-for-python#48555 · 1 comentario · 1 reacción ·
Los mantenedores suelen responder en 1 día
Todos los issues de Azure/azure-sdk-for-python
Issues similares
-
request-theme
Dificultad 2/5 Menos de una hora Aptitud para principiantes 70/100
LizardByte/ThemerrDB#8877 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
area/install-update comp/gateway P0 sweeper:risk-compatibility type/bug
Dificultad 2/5 Menos de una hora Aptitud para principiantes 72/100
NousResearch/hermes-agent#135997 · 3 comentarios ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
deepset-ai/haystack#13199 ·
Los mantenedores suelen responder en 1 día
-
[BUG] JSONLoader rejects valid UTF-8 BOM filesPosiblemente ocupada @zouyonghe la tomó hoy. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
anthropics/knowledge-work-plugins#1298 ·
Los mantenedores suelen responder en 1 día