Skip to content

build(wrapper): add the internal-feed release pipeline and install guide - #3753

Open
Joywambui-maina wants to merge 6 commits into
powershell-v3from
feat/wrapper-release-pipeline
Open

build(wrapper): add the internal-feed release pipeline and install guide#3753
Joywambui-maina wants to merge 6 commits into
powershell-v3from
feat/wrapper-release-pipeline

Conversation

@Joywambui-maina

Copy link
Copy Markdown
Contributor

Changes proposed in this pull request

  • Add .azure-pipelines/wrapper-release.yml: builds and packs the wrapper modules from committed sources, verifies packages were actually produced before signing, ESRP-signs, and publishes to the project-scoped Graph Developer Experiences/MSGraph_PowerShell_V3_Build feed. Mirrors sdk-release.yml - same 1ES template, security templates (pre-checks, guardian-analyzer, codesign-nuget, post-checks) and 1ES.PublishNuget@1 task.
  • Manual trigger only, and Publish defaults to false, so the first runs produce a signed drop artifact without pushing packages to the feed.
  • Version and prerelease flow through Build-WrapperModule.ps1 -ModuleVersion/-Prerelease (3.0.0-alpha<build id>); nothing edits ModuleMetadata.json, which belongs to the v2 release train.
  • Add docs/install-wrapper-modules-from-feed.md: feed registration and Install-Module -AllowPrerelease instructions for testers.

Note: a run can only succeed once the wrapper stack through #3740 has merged (the script's -ModuleVersion/-Prerelease surface and the package identity fixes land there). The pipeline is inert until then - manual trigger, no CI hooks.

Other links

Builds and packs the wrapper modules from committed sources, verifies packages
were actually produced before signing, ESRP-signs, and publishes to the
project-scoped MSGraph_PowerShell_V3_Build feed. Mirrors sdk-release.yml - same
1ES template, security templates and publish task - with no AutoRest or Node
bootstrap, manual trigger only, and Publish defaulting to false so the first
runs produce a drop artifact without pushing packages. The guide covers feed
registration and Install-Module -AllowPrerelease for testers.
@peombwa

Copy link
Copy Markdown
Member

Waiting for #3756 to be updated per my review comment and merged. Once that lands, this pipeline should be tested end-to-end from this branch to verify that packages are published to the feed successfully.

Joywambui-maina added a commit that referenced this pull request Aug 28, 2026
The guide rides #3753 to powershell-v3, where the wrapper modules live; main
only carries the pipeline definition.
Joywambui-maina added a commit that referenced this pull request Aug 28, 2026
…ide (main) (#3756)

* build(wrapper): add the internal-feed release pipeline and install guide

Builds and packs the wrapper modules from committed sources, verifies packages
were actually produced before signing, ESRP-signs, and publishes to the
project-scoped MSGraph_PowerShell_V3_Build feed. Mirrors sdk-release.yml - same
1ES template, security templates and publish task - with no AutoRest or Node
bootstrap, manual trigger only, and Publish defaulting to false so the first
runs produce a drop artifact without pushing packages. The guide covers feed
registration and Install-Module -AllowPrerelease for testers.

* docs(wrapper): keep the install guide off main

The guide rides #3753 to powershell-v3, where the wrapper modules live; main
only carries the pipeline definition.
The pipeline reused install-tools.yml wholesale, which is the AutoRest
toolchain - Node, the private npm feed, AutoRest, Rush and a full rush
rebuild - none of which the wrapper build touches, and it installs .NET 8/6
while the generator targets net10.0. The build step then failed because
Build-WrapperModule.ps1 refuses to run without the kiota CLI on PATH even
under -SkipKiota. Installs the .NET 10 SDK, feed auth, and kiota explicitly.
…solation

api.nuget.org is not reliably reachable from the 1ES pool, so the kiota tool
install failed loading the service index - and the module restore would have
failed the same way one step later. Writes a pipeline-local nuget.config that
puts the MSGraph_PowerShell_V3_Build feed (whose upstream proxies nuget.org)
first with nuget.org as fallback, used by every restore on the run.
NuGetAuthenticate supplies the credentials; the kiota step also retries.
dotnet tool install probes the service index of every configured source and
fails hard if any is unreachable, so keeping nuget.org as a fallback defeated
the routing entirely. The pipeline config now lists only the internal feed,
whose upstream proxies nuget.org, and the install ignores failed sources.
Per review: the pipeline now generates the kiota client from the committed
OpenAPI docs and the wrappers on top, then compiles - the whole process is
built and tested end to end on every run, and a run can never fail on
committed clients lagging the docs. Clients remain committed to the repo for
reviewable diffs and clean local checkouts.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants