Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

[Cosmos] Remove ephemeral-tenant provisioning from fixed-account live-test lanes

Abierto
#48,780 0 comentarios 1 reacción 0 asignados Ver en GitHub

Los mantenedores suelen responder en 1 día

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
5/5
Tiempo estimado
Más de una semana
Aptitud para principiantes
45/100
Tipo de issue
Refactorización
Claridad
Bastante claro
Estado de actividad
Activo
Stack tecnológico
azure, powershell, python

Línea de trabajo

Comienza con PR #48459 y la shared live-test stage, y después sigue build-test-resource-config.yml, deploy-test-resources.yml, remove-test-resources.yml y test-resources.bicep. Separa las rutas fixed-account y AAD para que los fixed jobs usen el resolver y el shared JSON secret sin ephemeral provisioning, mientras que AAD conserva la tenant-scoped role assignment. La finalización incluye scoped stale-database cleanup, ownership documentation y la validación de ejecuciones solapadas y de deployment credentials no disponibles.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

Client Cosmos

Is your feature request related to a problem? Please describe.

PR #48459 moves the Python Cosmos key-auth live tests onto fixed, team-owned accounts and proves that the selected accounts work across the live matrix. However, the shared Python live-test stage still deploys and removes a temporary Cosmos account for every matrix leg before the fixed credentials are reapplied.

As a result, the migrated key-auth tests still authenticate through the ephemeral live-test tenant during ARM deployment. A tenant rotation or broken service connection can therefore fail the job before pytest reaches the fixed account. This is the final gap between the current Python implementation and Java's no-provisioning fixed-account model.

Describe the solution you'd like

Separate the live matrix by resource-lifecycle requirements and make the fixed-account lane independent of ephemeral-tenant provisioning.

  • Split the 12 fixed key-auth jobs and the already-fixed GSI job from the 7 AAD jobs that require a tenant-scoped Cosmos data-plane role assignment.
  • Run the fixed-account jobs through a Cosmos-owned stage or job that resolves credentials from the shared versioned JSON secret but does not invoke build-test-resource-config.yml, deploy-test-resources.yml, or remove-test-resources.yml.
  • Ensure the fixed-account jobs do not require the azure-sdk-tests-cosmos service connection or any authentication against the ephemeral tenant.
  • Keep the AAD jobs on the existing provisioned-resource path so test-resources.bicep can create their tenant-specific sqlRoleAssignment.
  • Move values currently supplied only as Bicep outputs into the fixed-account matrix. In particular, set AZURE_COSMOS_ENABLE_CIRCUIT_BREAKER=True on the applicable circuit-breaker jobs.
  • Remove the transitional post-deployment credential reapplication once fixed-account jobs no longer deploy resources; the resolver pre-step should become their sole source of ACCOUNT_HOST and ACCOUNT_KEY.
  • Add best-effort cleanup for databases left by cancelled or aborted runs. Cleanup must be limited to stale PythonSDKTest-* databases owned by Python and must run across each fixed account without affecting Java or concurrent Python runs.
  • Document ownership for Java's shared account provisioning/reconciliation script and the shared JSON secret update procedure, including a smoke test after account or key rotation.
  • Validate overlapping fixed-account runs and prove they remain runnable when ephemeral-tenant deployment credentials are unavailable.

Describe alternatives you've considered

  1. Keep the current transitional deployment followed by credential override. This is already proven by PR #48459, but it does not remove the tenant dependency.
  2. Move AAD tests onto the fixed accounts and refresh their role assignments after every tenant rotation. This preserves one matrix but requires cross-subscription permissions and additional identity lifecycle work.
  3. Add a per-leg deployment condition to shared eng templates. This is generic, but changes monorepo-wide infrastructure for a Cosmos-specific requirement.
  4. Register a separate AAD pipeline while keeping the fixed-account pipeline Cosmos-owned. This is fully service-local but adds another Azure DevOps pipeline definition to maintain.

Additional context

PR #48459 already supplies the prerequisites for this work:

  • A cross-platform PowerShell resolver compatible with Java's shared JSON-secret schema.
  • Stable-account selectors for all 12 key-auth matrix jobs; GSI already uses dedicated fixed credentials.
  • Run-scoped PythonSDKTest-* database naming, bounded control-plane retries, scoped normal cleanup, and test isolation needed for concurrent use.
  • Early resolver validation through PreSteps and a Cosmos-local post-deployment hook used during the transitional rollout.
  • Successful live verification of the fixed-account query, split, multi-region, and circuit-breaker coverage.

Related tracking issue: #48236. Java reference: Azure/azure-sdk-for-java#49735.

Lenguaje dominante
Python
Estrellas
5.6k
Forks
3.4k
Merge medio
2 d 5 h
PR fusionados (30 d)
219

Preparar el entorno

Abrir en Codespaces

Inicia el contenedor de desarrollo del proyecto en tu navegador, con tu propia cuenta de GitHub.

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de Azure/azure-sdk-for-python

Todos los issues de Azure/azure-sdk-for-python

Issues similares

Más issues de Python

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.