Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 5 additions & 5 deletions .devcontainer/Dockerfile
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
FROM mcr.microsoft.com/devcontainers/dotnet:dev-10.0-noble
FROM mcr.microsoft.com/devcontainers/base:3-ubuntu24.04

# Fix Yarn GPG key issue - remove the problematic Yarn repository
# that has an expired/rotated signing key causing apt-get update to fail
# See: https://github.com/devcontainers/images/issues/1752
RUN rm -f /etc/apt/sources.list.d/yarn.list 2>/dev/null || true
# The nightly CLI needs ICU even when the standalone .NET SDK feature is omitted.
RUN apt-get update \
&& apt-get install -y --no-install-recommends libicu74 \
&& rm -rf /var/lib/apt/lists/*
43 changes: 20 additions & 23 deletions .devcontainer/devcontainer.json
Original file line number Diff line number Diff line change
@@ -1,8 +1,5 @@
// For format details, see https://aka.ms/devcontainer.json. For config options, see the
// README at: https://github.com/devcontainers/templates/tree/main/src/dotnet
{
"name": "Aspire (Nightly)",
// Or use a Dockerfile or Docker Compose file. More info: https://containers.dev/guide/dockerfile
"build": {
"dockerfile": "Dockerfile"
},
Expand All @@ -11,47 +8,47 @@
"ghcr.io/devcontainers/features/docker-in-docker:2": {},
"ghcr.io/devcontainers/features/powershell:1": {},
"ghcr.io/azure/azure-dev/azd:0": {},
"ghcr.io/devcontainers/features/node:1": {},
"ghcr.io/devcontainers/features/python:1": {},
"ghcr.io/devcontainers/features/node:1": {
"version": "lts"
},
"ghcr.io/devcontainers/features/python:1": {
"version": "os-provided"
},
"ghcr.io/devcontainers-extra/features/uv:1": {},
"ghcr.io/devcontainers/features/dotnet:2": {
"version": "10.0"
},
"ghcr.io/devcontainers/features/kubectl-helm-minikube:1": {
"version": "latest",
"helm": "latest",
"minikube": "latest"
}
},

"hostRequirements": {
"cpus": 8,
"memory": "32gb",
"storage": "64gb"
},

// Use 'forwardPorts' to make a list of ports inside the container available locally.
// "forwardPorts": [5000, 5001],
// "portsAttributes": {
// "5001": {
// "protocol": "https"
// }
// }

// Use 'postCreateCommand' to run commands after the container is created.
// "postCreateCommand": "dotnet restore",
"remoteEnv": {
"PATH": "/home/vscode/.aspire/bin:/home/vscode/.dotnet/tools:${containerEnv:PATH}",
"SSL_CERT_DIR": "/usr/lib/ssl/certs:/home/vscode/.aspnet/dev-certs/trust"
},
"onCreateCommand": "bash .devcontainer/oncreate.sh",
"postStartCommand": "dotnet dev-certs https --trust",
"postStartCommand": "aspire certs trust --non-interactive",
"customizations": {
"vscode": {
"extensions": [
"microsoft-aspire.aspire-vscode",
"dbaeumer.vscode-eslint",
"ms-python.python",
"ms-python.vscode-pylance",
"ms-dotnettools.csdevkit",
"ms-azuretools.vscode-bicep",
"ms-azuretools.azure-dev",
"GitHub.copilot-chat",
"GitHub.copilot",
"ms-kubernetes-tools.vscode-kubernetes-tools",
"microsoft-aspire.aspire-vscode"
"ms-kubernetes-tools.vscode-kubernetes-tools"
]
}
}

// Uncomment to connect as root instead. More info: https://aka.ms/dev-containers-non-root.
// "remoteUser": "root"
}
8 changes: 6 additions & 2 deletions .devcontainer/oncreate.sh
Original file line number Diff line number Diff line change
Expand Up @@ -28,7 +28,11 @@ for attempt in $(seq 1 "$MAX_ATTEMPTS"); do
sleep "$RETRY_DELAY"
done

echo "Clearing NuGet cache to reduce prebuild template size..."
dotnet nuget locals all --clear
if command -v dotnet >/dev/null 2>&1; then
echo "Clearing NuGet cache to reduce prebuild template size..."
dotnet nuget locals all --clear
else
echo "Standalone .NET SDK not installed; skipping NuGet cache cleanup."
fi

echo "onCreateCommand completed successfully."
32 changes: 32 additions & 0 deletions .github/scripts/prepare-config.mjs
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
import assert from 'node:assert/strict';
import { mkdirSync, readFileSync, writeFileSync } from 'node:fs';
import { basename, dirname, resolve } from 'node:path';
import { parseArgs } from 'node:util';

const { values } = parseArgs({
options: {
output: { type: 'string' },
'without-dotnet': { type: 'boolean', default: false },
},
});
assert.ok(values.output, '--output is required.');

const source = resolve('.devcontainer/devcontainer.json');
const configuration = JSON.parse(readFileSync(source, 'utf8'));
if (values['without-dotnet']) {
const features = Object.keys(configuration.features)
.filter(feature => feature.startsWith('ghcr.io/devcontainers/features/dotnet:'));
assert.equal(features.length, 1, 'Expected one standalone .NET SDK feature to omit.');
delete configuration.features[features[0]];
}

// Keep the nightly Dockerfile and its build context valid outside .devcontainer.
configuration.build.dockerfile = resolve(dirname(source), configuration.build.dockerfile);
configuration.build.context = resolve(dirname(source), configuration.build.context ?? '.');

const output = resolve(values.output);
assert.notEqual(output, source, 'Use a separate output path for the test configuration.');
assert.ok(['devcontainer.json', '.devcontainer.json'].includes(basename(output)),
'The test configuration must be named devcontainer.json or .devcontainer.json.');
mkdirSync(dirname(output), { recursive: true });
writeFileSync(output, `${JSON.stringify(configuration, null, 2)}\n`);
59 changes: 59 additions & 0 deletions .github/scripts/prepare-config.test.mjs
Original file line number Diff line number Diff line change
@@ -0,0 +1,59 @@
import assert from 'node:assert/strict';
import { execFileSync, spawnSync } from 'node:child_process';
import { existsSync, mkdtempSync, readFileSync, rmSync } from 'node:fs';
import { tmpdir } from 'node:os';
import { join, resolve } from 'node:path';
import { test } from 'node:test';

const script = resolve('.github/scripts/prepare-config.mjs');
const source = resolve('.devcontainer/devcontainer.json');

for (const withoutDotnet of [false, true]) {
test(`relocates the ${withoutDotnet ? 'SDK-free' : 'standard'} configuration`, t => {
const directory = mkdtempSync(join(tmpdir(), 'aspire-nightly-config-'));
t.after(() => rmSync(directory, { recursive: true }));
const original = readFileSync(source, 'utf8');
const output = join(directory, 'nested', 'devcontainer.json');
execFileSync(process.execPath, [
script, '--output', output, ...(withoutDotnet ? ['--without-dotnet'] : []),
]);

const expected = JSON.parse(original);
expected.build.dockerfile = resolve('.devcontainer/Dockerfile');
expected.build.context = resolve('.devcontainer');
if (withoutDotnet) {
delete expected.features['ghcr.io/devcontainers/features/dotnet:2'];
}
const actual = JSON.parse(readFileSync(output, 'utf8'));
assert.deepEqual(actual, expected);
assert.ok(actual.remoteEnv.PATH.split(':').includes('/home/vscode/.dotnet/tools'),
'Global .NET tools must remain on the remote PATH.');
assert.ok(existsSync(actual.build.dockerfile));
assert.ok(existsSync(actual.build.context));
assert.equal(readFileSync(source, 'utf8'), original);
});
}

test('rejects overwriting the source configuration', () => {
const original = readFileSync(source, 'utf8');
const result = spawnSync(process.execPath, [script, '--output', source], { encoding: 'utf8' });
assert.notEqual(result.status, 0);
assert.match(result.stderr, /Use a separate output path/);
assert.equal(readFileSync(source, 'utf8'), original);
});

test('requires a supported output filename', t => {
const directory = mkdtempSync(join(tmpdir(), 'aspire-nightly-config-'));
t.after(() => rmSync(directory, { recursive: true }));
const output = join(directory, 'invalid.json');
const result = spawnSync(process.execPath, [script, '--output', output], { encoding: 'utf8' });
assert.notEqual(result.status, 0);
assert.match(result.stderr, /must be named devcontainer.json or .devcontainer.json/);
assert.equal(existsSync(output), false);
});

test('requires an output path', () => {
const result = spawnSync(process.execPath, [script], { encoding: 'utf8' });
assert.notEqual(result.status, 0);
assert.match(result.stderr, /--output is required/);
});
194 changes: 194 additions & 0 deletions .github/scripts/smoke-test.mjs
Original file line number Diff line number Diff line change
@@ -0,0 +1,194 @@
import assert from 'node:assert/strict';
import { execFileSync, spawnSync } from 'node:child_process';
import { accessSync, constants, copyFileSync, mkdirSync, mkdtempSync, readdirSync, rmSync, writeFileSync } from 'node:fs';
import { homedir } from 'node:os';
import { join } from 'node:path';

process.env.ASPIRE_CLI_TELEMETRY_OPTOUT = '1';
process.env.DOTNET_CLI_TELEMETRY_OPTOUT = '1';

const scenarios = {
python: { template: 'aspire-py-starter', api: 'app', frontend: 'frontend', cache: true },
csharp: { template: 'aspire-starter', api: 'apiservice', frontend: 'webfrontend', cache: true },
'typescript-no-dotnet': { template: 'aspire-ts-starter', api: 'app', frontend: 'frontend', cache: false },
};
const scenarioName = process.argv[2] ?? 'python';
assert.ok(Object.hasOwn(scenarios, scenarioName), `Unknown scenario: ${scenarioName}`);
const scenario = scenarios[scenarioName];
const withoutDotnet = scenarioName === 'typescript-no-dotnet';

function execute(command, args, { cwd = process.cwd(), capture = false, input } = {}) {
console.log(`> ${command} ${args.join(' ')}`);
return execFileSync(command, args, {
cwd,
encoding: 'utf8',
input,
stdio: [input === undefined ? 'ignore' : 'pipe', capture ? 'pipe' : 'inherit', 'inherit'],
});
}

function assertNoDotnet() {
const result = spawnSync('dotnet', ['--version'], { encoding: 'utf8' });
assert.equal(result.error?.code, 'ENOENT', 'The TypeScript scenario must have no standalone dotnet on PATH.');
console.log('No standalone dotnet found on PATH.');
}

assert.equal(process.platform, 'linux', 'Run this script inside the devcontainer.');
assert.notEqual(process.getuid(), 0, 'The remote user must not be root.');
accessSync('.devcontainer/devcontainer.json', constants.R_OK);
accessSync('.', constants.W_OK);

// Check the lifecycle hook before Aspire starts and can perform its own certificate setup.
const trustDirectory = join(homedir(), '.aspnet', 'dev-certs', 'trust');
const certificates = readdirSync(trustDirectory).filter(name => name.endsWith('.pem'));
assert.ok(certificates.length > 0, 'The startup hook must create a development certificate.');
for (const certificate of certificates) {
execute('openssl', ['verify', join(trustDirectory, certificate)]);
}

for (const command of ['node', 'npm', 'python3', 'uv', 'pwsh', 'aspire', 'az']) {
execute(command, ['--version']);
}
execute('azd', ['version']);
execute('kubectl', ['version', '--client']);
execute('helm', ['version', '--short']);
execute('minikube', ['version', '--short']);
if (withoutDotnet) {
assertNoDotnet();
} else {
execute('dotnet', ['--version']);
}

execute('docker', ['info', '--format', 'Docker server: {{.ServerVersion}}']);
execute('docker', ['run', '--rm', 'hello-world']);

const testDirectory = mkdtempSync(join(homedir(), '.aspire-devcontainer-test-'));
const appDirectory = join(testDirectory, 'app');
const dotnetDirectory = join(testDirectory, 'dotnet');
// Exercise this repository's feeds without generating sample apps in the workspace.
copyFileSync('nuget.config', join(testDirectory, 'nuget.config'));
let startAttempted = false;

try {
if (scenarioName === 'python') {
execute('dotnet', ['new', 'console', '--output', dotnetDirectory, '--no-restore']);
const consoleOutput = execute('dotnet', ['run', '--project', dotnetDirectory], { capture: true });
assert.ok(consoleOutput.includes('Hello, World!'), '.NET must restore, compile, and run a project.');
}

execute('aspire', [
'new', scenario.template,
'--name', 'DevcontainerSmoke',
'--output', appDirectory,
...(scenario.cache ? ['--use-redis-cache', 'true'] : []),
'--suppress-agent-init',
'--non-interactive',
], { cwd: testDirectory });

startAttempted = true;
execute('aspire', ['start', '--isolated', '--non-interactive'], { cwd: appDirectory });
for (const name of [...(scenario.cache ? ['cache'] : []), scenario.api, scenario.frontend]) {
execute('aspire', ['wait', name, '--timeout', '180', '--non-interactive'], { cwd: appDirectory });
}

const description = execute('aspire', ['describe', '--format', 'Json', '--non-interactive'], {
cwd: appDirectory,
capture: true,
});
// The CLI can print a discovery message before its JSON output.
const jsonStart = description.indexOf('{');
assert.ok(jsonStart >= 0, 'Aspire must return a resource description.');
const { resources } = JSON.parse(description.slice(jsonStart));
const resource = name => {
const result = resources.find(item => item.displayName === name);
assert.ok(result, `Missing resource: ${name}`);
assert.equal(result.healthStatus, 'Healthy', `${name} must be healthy.`);
return result;
};

const api = resource(scenario.api);
const frontend = resource(scenario.frontend);
const endpoint = item => item.urls.find(url => url.url.startsWith('https:'))?.url
?? item.urls.find(url => url.url.startsWith('http:'))?.url;
const apiUrl = endpoint(api);
const frontendUrl = endpoint(frontend);
assert.ok(apiUrl, 'The API must expose an endpoint.');
assert.ok(frontendUrl, 'The frontend must expose an endpoint.');
if (!withoutDotnet) {
assert.equal(new URL(apiUrl).protocol, 'https:', 'The API smoke test must exercise HTTPS.');
}
if (scenario.cache) {
assert.equal(resource('cache').resourceType, 'Container');
}

const get = url => execute('curl', [
'--fail', '--silent', '--show-error', '--location', '--max-time', '30', url,
], { capture: true });

assert.equal(get(new URL('/health', apiUrl).href), 'Healthy');
const forecastPath = scenarioName === 'csharp' ? '/weatherforecast' : '/api/weatherforecast';
const direct = JSON.parse(get(new URL(forecastPath, apiUrl).href));
assert.equal(direct.length, 5, 'The API must return five forecasts.');
for (const forecast of direct) {
assert.equal(typeof forecast.temperatureC, 'number');
assert.equal(typeof forecast.summary, 'string');
}

if (scenarioName === 'csharp') {
assert.equal(api.resourceType, 'Project');
assert.equal(frontend.resourceType, 'Project');
assert.equal(get(new URL('/health', frontendUrl).href), 'Healthy');
const weatherPage = get(new URL('/weather', frontendUrl).href);
assert.ok(weatherPage.includes('<h1>Weather</h1>'), 'Blazor must render the weather page.');
assert.equal([...weatherPage.matchAll(/<td>/g)].length, 20, 'Blazor must render all five API forecasts.');
} else {
assert.ok(get(frontendUrl).includes('id="root"'), 'The frontend must serve the React app.');
const proxied = JSON.parse(get(new URL(forecastPath, frontendUrl).href));
assert.equal(proxied.length, 5, 'The frontend must proxy requests to the API.');
}

if (scenarioName === 'python') {
// Seed a non-expiring value so this checks cache hits without depending on the sample's five-second TTL.
const cached = direct.map(forecast => ({ ...forecast, summary: 'CI cache sentinel' }));
const result = execute('docker', [
'exec', '-i', resource('cache').properties['container.id'],
'sh', '-c',
'REDISCLI_AUTH="$REDIS_PASSWORD" redis-cli --tls --cacert /usr/lib/ssl/aspire/cert.pem --raw -x SET weatherforecast',
], { capture: true, input: JSON.stringify(cached) });
assert.equal(result.trim(), 'OK', 'The test must seed Redis successfully.');
assert.deepEqual(JSON.parse(get(new URL(forecastPath, apiUrl).href)), cached, 'The API must read Redis.');
assert.deepEqual(JSON.parse(get(new URL(forecastPath, frontendUrl).href)), cached, 'The frontend must return cached API data.');
}

const dashboardStatus = execute('curl', [
'--fail', '--silent', '--show-error', '--location', '--max-time', '30',
'--output', '/dev/null', '--write-out', '%{http_code}',
new URL(api.dashboardUrl).origin,
], { capture: true });
assert.equal(dashboardStatus, '200', 'The dashboard must be reachable over trusted HTTPS.');
if (withoutDotnet) {
assertNoDotnet();
}
} catch (error) {
console.error(error);
if (startAttempted) {
const logs = spawnSync('aspire', [
'logs', '--tail', '200', '--include-hidden', '--format', 'Json', '--non-interactive',
], { cwd: appDirectory, encoding: 'utf8', timeout: 30_000 });
const logDirectory = join(homedir(), '.aspire', 'logs');
mkdirSync(logDirectory, { recursive: true });
writeFileSync(join(logDirectory, `smoke-${scenarioName}-resources.log`),
[logs.stdout, logs.stderr, logs.error?.stack, `Log capture exit status: ${logs.status}`].filter(Boolean).join('\n'));
if (logs.error || logs.status !== 0) {
console.error('Resource log capture failed:', logs.error ?? logs.stderr);
}
}
throw error;
} finally {
if (startAttempted) {
execute('aspire', ['stop', '--non-interactive'], { cwd: appDirectory });
}
}

rmSync(testDirectory, { recursive: true });
console.log(`Devcontainer ${scenarioName} checks passed.`);
Loading