Skip to content

Prevent crashes when AZURE_CLIENT_ID/AZURE_TENANT_ID/INFRA_CONFIG variables are unset in linearb-deployment.yml - #163

Draft
Mathieu Gamache (PrincessMadMath) with Copilot wants to merge 5 commits into
mainfrom
copilot/update-linearb-deployment-yml
Draft

Mathieu Gamache (PrincessMadMath) with Copilot wants to merge 5 commits into
mainfrom
copilot/update-linearb-deployment-yml

Conversation

Copilot AI commented Nov 11, 2025 •

Copy link
Copy Markdown
Contributor

Applies the same defensive Azure configuration resolution logic from #155 (commit ee19f3f) to linearb-deployment.yml.

Changes

  • Created a separate get_azure_config job that runs first and computes Azure configuration
  • This job outputs client_id and tenant_id for downstream jobs to reference
  • Checks AZURE_CLIENT_ID first, falls back to INFRA_CONFIG.repo_identity_client_id, errors explicitly if neither exists
  • Checks AZURE_TENANT_ID first, falls back to INFRA_CONFIG.tenant_id, errors explicitly if neither exists
  • Separated deployment into linearb_deployment and cortex_deployment jobs that both depend on get_azure_config
  • Both deployment jobs reference the config outputs using needs.get_azure_config.outputs.client_id and needs.get_azure_config.outputs.tenant_id
  • Made Cortex deployment job conditional based on inputs.cortexEntityIdOrTag != ''
  • LinearB and Cortex deployments can run in parallel after the config job completes

Pattern Applied

get_azure_config:
  runs-on: [idp]
  permissions:
    id-token: write
  outputs:
    client_id: ${{ steps.get_azure_config.outputs.client_id }}
    tenant_id: ${{ steps.get_azure_config.outputs.tenant_id }}
  steps:
  - id: get_azure_config
    env:
      INFRA_CONFIG: ${{ vars.INFRA_CONFIG }}
      AZURE_CLIENT_ID: ${{ vars.AZURE_CLIENT_ID }}
      AZURE_TENANT_ID: ${{ vars.AZURE_TENANT_ID }}
    shell: pwsh
    run: |
      if ($env:AZURE_CLIENT_ID) {
          $ClientId = $env:AZURE_CLIENT_ID
      } elseif ($env:INFRA_CONFIG) {
          $ClientId = (ConvertFrom-Json $env:INFRA_CONFIG).repo_identity_client_id
      } else {
          Write-Error "Neither AZURE_CLIENT_ID nor INFRA_CONFIG is set. Cannot determine client id."
          exit 1
      }
      "client_id=$ClientId" >> $env:GITHUB_OUTPUT

      if ($env:AZURE_TENANT_ID) {
          $TenantId = $env:AZURE_TENANT_ID
      } elseif ($env:INFRA_CONFIG) {
          $TenantId = (ConvertFrom-Json $env:INFRA_CONFIG).tenant_id
      } else {
          Write-Error "Neither AZURE_TENANT_ID nor INFRA_CONFIG is set. Cannot determine tenant id."
          exit 1
      }
      "tenant_id=$TenantId" >> $env:GITHUB_OUTPUT

linearb_deployment:
  needs: get_azure_config
  # ... uses needs.get_azure_config.outputs.client_id and tenant_id

cortex_deployment:
  needs: get_azure_config
  if: ${{ inputs.cortexEntityIdOrTag != '' }}
  # ... uses needs.get_azure_config.outputs.client_id and tenant_id

This prevents runtime crashes from attempting to parse undefined variables, provides clear error messages when configuration is missing, and allows for parallel execution of deployment jobs while maintaining a single source of configuration truth.

Original prompt

Look at this change here ee19f3f and then apply the same logic for linearb-deployment.yml


✨ Let Copilot coding agent set things up for you — coding agent works faster and does higher quality work when set up for your repo.

Co-authored-by: PrincessMadMath <8277266+PrincessMadMath@users.noreply.github.com>
Copilot AI changed the title [WIP] Update linearb-deployment.yml with similar logic Prevent crashes when AZURE_CLIENT_ID/INFRA_CONFIG variables are unset in linearb-deployment.yml Nov 11, 2025
@PrincessMadMath

Copy link
Copy Markdown
Contributor

Copilot Ok I also want to do the same compute logic for AZURE_TENANT_ID. Do not create a new step just rethink it to better evolve.

Co-authored-by: PrincessMadMath <8277266+PrincessMadMath@users.noreply.github.com>

Copilot AI commented Nov 11, 2025

Copy link
Copy Markdown
Contributor Author

Copilot Ok I also want to do the same compute logic for AZURE_TENANT_ID. Do not create a new step just rethink it to better evolve.

Done! The step has been renamed to get_azure_config and now computes both client_id and tenant_id using the same fallback logic (checks direct variable first, then falls back to INFRA_CONFIG). Both outputs are used by the secret retrieval steps. (da59e44)

Copilot AI changed the title Prevent crashes when AZURE_CLIENT_ID/INFRA_CONFIG variables are unset in linearb-deployment.yml Prevent crashes when AZURE_CLIENT_ID/AZURE_TENANT_ID/INFRA_CONFIG variables are unset in linearb-deployment.yml Nov 11, 2025
@PrincessMadMath

Copy link
Copy Markdown
Contributor

Copilot I want a single job not duplicate steps

Co-authored-by: PrincessMadMath <8277266+PrincessMadMath@users.noreply.github.com>

Copilot AI commented Nov 11, 2025

Copy link
Copy Markdown
Contributor Author

Copilot I want a single job not duplicate steps

Consolidated! The two jobs are now merged into a single deployment job with one get_azure_config step. Cortex-related steps are conditional based on the cortexEntityIdOrTag input. This reduces duplication by 37 lines. (dd19862)

@PrincessMadMath

Copy link
Copy Markdown
Contributor

Copilot Ok no create an new jobs that precede the linearB and that both reference

Co-authored-by: PrincessMadMath <8277266+PrincessMadMath@users.noreply.github.com>

Copilot AI commented Nov 11, 2025

Copy link
Copy Markdown
Contributor Author

Copilot Ok no create an new jobs that precede the linearB and that both reference

Done! Created a separate get_azure_config job that runs first and outputs the configuration. Both linearb_deployment and cortex_deployment jobs now reference these outputs via needs.get_azure_config.outputs. The two deployment jobs can run in parallel after the config job completes. (26aa7d7)

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants