Skip to content

[docs] Note secret redaction behavior in aspire describe - #1499

Merged
Mitch Denny (mitchdenny) merged 3 commits into
release/13.6from
docs/pr-19248-31822977011-1-805faa75af9d1fe7
Sep 29, 2026
Merged

Mitch Denny (mitchdenny) merged 3 commits into
release/13.6from
docs/pr-19248-31822977011-1-805faa75af9d1fe7

Conversation

@aspire-repo-bot

Copy link
Copy Markdown
Contributor

Documents changes from microsoft/aspire#19248

@IEvangelist

Targeting release/13.6 based on the source PR milestone 13.6.

Why

microsoft/aspire#19248 fixes a bug where aspire describe --format json leaked a generated secret parameter (for example, the password created by AddPostgres) in plaintext via the owning resource's own environment variable, even though the redaction already worked correctly for dependent resources. The existing aspire describe docs did not mention secret redaction at all, so there was no place documenting the (now-fixed) guarantee that secret values are always redacted from describe/resources output.

What changed

  • src/frontend/src/content/docs/reference/cli/commands/aspire-describe.mdx: added a note (using the Aside component already imported on the page) explaining that generated secret values are redacted from aspire describe output, and that this applies to the owning resource's own environment variables as well as dependent resources.

Notes

  • Only one page was updated; no new pages were created.
  • This documents user-facing behavior (what appears in describe/resources output) rather than internal implementation details like SecretRedactionHistory or the dependency-walk mechanics, which are not part of the public docs surface.

Generated by PR Documentation Check for #19248 · auto · 66.5 AIC · ⌖ 15.8 AIC · ⊞ 19.6K · ◷

@aspire-repo-bot aspire-repo-bot Bot added the docs-from-code Copilot initiated issue from dotnet/aspire repo label Aug 14, 2026
@aspire-repo-bot

Copy link
Copy Markdown
Contributor Author

Frontend HTML artifact ready

The latest frontend build uploaded the frontend-dist artifact for PR #1499. Use the VS Code button below to open this PR with GitHub Artifacts Explorer and browse the built HTML locally.

VS Code: Open PR #1499 artifacts

This comment updates automatically when a new frontend build artifact is uploaded.

@IEvangelist
David Pine (IEvangelist) marked this pull request as ready for review August 14, 2026 18:03

@IEvangelist David Pine (IEvangelist) left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Docs-accuracy review — secret redaction note in aspire describe

Phase A source of truth: microsoft/aspire @ main — SHA bac9a7d64f1bc7b0d1327a166da87f3709729829 (contains the fix commit 5faba087 from microsoft/aspire#19248).

⚠️ Branch note: This PR targets pre/13.6, but microsoft/aspire has no pre/13.6 or release/13.6 branch (the newest release branch there is release/13.5). The 13.6 milestone hasn't branched yet, and the source PR this doc documents — microsoft/aspire#19248 (milestone 13.6) — was merged to main. I therefore used main as the closest applicable source of truth and verified every claim against it.

Phase A — claims: 4 extracted · ✅ 4 verified · ⚠️ 0 verified‑with‑nuance · ❓ 0 unverifiable · ❌ 0 contradicted.

Phase B — doc-tester (blind user): served the PR head locally (Astro dev, http://localhost:4321/reference/cli/commands/aspire-describe/) and exercised 1 route · 🔴 0 critical · 🟡 1 warning · 📝 1 knowledge gap. The new Note callout renders correctly with 0 console errors.

Verdict: 💬 COMMENT — every factual claim matches source; the only items are one optional clarity warning and one behavioral knowledge gap from the blind-user pass.


Phase A — Claim verification

The PR adds a single <Aside type="note">. All four factual claims match microsoft/aspire @ main (bac9a7d6).

✅ Verified claims (4) with evidence
# Claim Verdict Evidence (microsoft/aspire @ main bac9a7d6)
C1 Generated secret values are redacted from aspire describe / resources output. ✅ verified src/Aspire.Hosting/Backchannel/AuxiliaryBackchannelRpcTarget.cs — RedactIfSecretValue (L1215‑1216) returns null when a value matches a resolved secret; applied to every env var at L1129 (Value = RedactIfSecretValue(e.Value, secretParameterValues)). XML doc L1203‑1204: "Redacts an environment variable value … so secrets don't leak through clients (e.g. aspire describe --format json)."
C2 Redaction applies to every resource referencing the secret, including the resource that owns it, so a generated password never appears in plaintext in an env var such as POSTGRES_PASSWORD. ✅ verified This is precisely what #19248 fixed (commit 5faba087, "Redact owning resource's own secret env var in describe"). Commit message: previously the value was "emitted … in plaintext via the owning resource's own environment variable (e.g. POSTGRES_PASSWORD)." The fix mirrors ParameterProcessor's dependent‑parameter discovery (GetResourceDependenciesAsync) inside GetSecretParametersAsync (AuxiliaryBackchannelRpcTarget.cs L1267‑1355), so the redaction set now includes generated parameters referenced by any resource, including the owner. Matching is value‑based exact‑equality, so it fires regardless of which resource emits the variable.
C3 Resources like PostgreSQL, Redis, and SQL Server generate passwords. ✅ verified Aspire.Hosting.PostgreSQL/PostgresBuilderExtensions.cs:57, Aspire.Hosting.SqlServer/SqlServerBuilderExtensions.cs:44, and Aspire.Hosting.Redis/RedisBuilderExtensions.cs:76 each call CreateDefaultPasswordParameter(...), which calls CreateGeneratedParameter(builder, name, secret: true, generatedPassword) (Aspire.Hosting/ParameterResourceBuilderExtensions.cs). Redis XML doc: "If null a random password will be generated."
C4 The Postgres password environment variable is named POSTGRES_PASSWORD. ✅ verified Aspire.Hosting.PostgreSQL/PostgresBuilderExtensions.cs:24: private const string PasswordEnvVarName = "POSTGRES_PASSWORD";, assigned at L121: context.EnvironmentVariables[PasswordEnvVarName] = postgresServer.PasswordParameter;.

No contradicted or unverifiable claims → no inline claim comments.


Phase B — Doc-tester results (blind-user pass)

This phase was run without consulting any source code; the local docs site was the only window into behavior.

Route exercised: /reference/cli/commands/aspire-describe/ (PR head content served from local Astro dev on port 4321).

Summary

Category Passed Failed Warnings
Content accuracy 1 0 1
Rendering (MDX) 1 0 0
CLI / runtime behavior 0 0 0 (see knowledge gap)
Links n/a — the note adds no links 0 0

Critical issues

None.

Warnings

Warning 1 — the note cites an environment variable, but the page's sample output never shows environment variables.

  • Location: /reference/cli/commands/aspire-describe/, new Note callout.
  • Issue: The note says secrets "are redacted from the output" and points at the environment variable POSTGRES_PASSWORD, yet the only sample output on the page (the default table under Examples) shows just Name / Type / State / Health / Endpoints — no environment variables. A new reader may not realize that environment variables (and therefore POSTGRES_PASSWORD) appear in the JSON output (--format Json), not the default table, so it isn't obvious where the redaction they're being promised would actually be visible.
  • Suggestion (optional): Tie the note to JSON output, e.g. "… redacted from the output (for example, the environment variables emitted by aspire describe --format Json) …".

Passed checks

  • Page loads (HTTP 200; title "aspire describe command | Aspire").
  • The new <Aside type="note"> compiles and renders as a Starlight Note callout; text is intact, em‑dashes render, and POSTGRES_PASSWORD renders as inline code (screenshot captured).
  • Placement is logical — immediately after the existing aspire resources alias tip and before the Arguments heading.
  • 0 console errors / 0 console warnings on the page.

Knowledge gap — runtime redaction behavior was not executed

  • What I needed to know: whether aspire describe --format Json actually redacts the owning resource's POSTGRES_PASSWORD at runtime.
  • Source of my knowledge: not verified in Phase B — accepted at the documentation level only (Phase A independently confirmed it against source).
  • User impact: a user on a released GA CLI is running a build from before this fix and could still observe the leak; the documented guarantee holds only on a build that includes the change. Executing the check requires (a) a dev/PR CLI build containing the fix (the 13.6 milestone isn't released yet) and (b) Docker to run a Postgres container — neither was exercised here.
  • Recommendation: reasonable to rely on the Phase A source verification for this behavioral claim.

Recommendations

  1. Optional clarity tweak connecting "the output" / POSTGRES_PASSWORD to --format Json (Warning 1).
  2. No blocking issues — the note is accurate and renders correctly.

Automated docs-accuracy review · Phase A verified against microsoft/aspire@main bac9a7d6 · Phase B via local doc-tester on the PR head.

</Aside>

<Aside type="note">
Secret values—such as passwords generated for resources like PostgreSQL, Redis, or SQL Server—are redacted from the output. Redaction applies to every resource that references the secret, including the resource that owns it, so a generated password never appears in plaintext in an environment variable such as `POSTGRES_PASSWORD`.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is broader than the implementation. Redaction only nulls environment-variable values that exactly match a resolved secret parameter; it is not a general secret scanner, so embedded values such as connection strings are not covered. Could we scope this wording to exact known secret-parameter values?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's a lot easier when you make real inline suggestions, that can be considered and then either tweaked or applied. Leaving these sorts of general talking points takes a lot longer to think through and finalize.

Comment thread src/frontend/src/content/docs/reference/cli/commands/aspire-describe.mdx Outdated
Co-authored-by: David Pine <david.pine@microsoft.com>
@IEvangelist
David Pine (IEvangelist) changed the base branch from pre/13.6 to release/13.6 August 24, 2026 18:01

@IEvangelist David Pine (IEvangelist) left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Docs-accuracy review — secret redaction note in aspire describe (re-review of updated revision)

Phase A source of truth: microsoft/aspire @ main — SHA 1cdf7d17248ae78ee018abbc314f772ace5e624d (contains the fix commit 5faba087 from microsoft/aspire#19248).

⚠️ Branch note: This PR now targets release/13.6, but microsoft/aspire has no release/13.6 branch yet — the newest release branch there is release/13.5 (all 11 currently-open docs-from-code PRs target release/13.6, so the 13.6 line simply hasn't been branched in the product repo yet). The source PR this documents — microsoft/aspire#19248 (milestone 13.6) — merged to main, which is an allowed source of truth, so I verified every claim there and flag the branch mismatch here rather than block on it.

🔁 Since my last review (at dc233554, which used main): the PR was retargeted from pre/13.6 → release/13.6 and the note was reworded. The new text is more precise ("environment-variable values that exactly match a resolved secret parameter … redacted from every referencing resource") and adds a new caveat — "Secrets embedded within larger values, such as connection strings, are not redacted." I re-verified all claims, including the new caveat, against main.

Phase A — claims: 4 extracted · ✅ 4 verified · ⚠️ 0 verified‑with‑nuance · ❓ 0 unverifiable · ❌ 0 contradicted.

Phase B — doc-tester (blind user): exercised 1 route (/reference/cli/commands/aspire-describe/) on a running local build · 🔴 0 critical · 🟡 1 warning · 📝 1 knowledge gap.

Verdict: 💬 COMMENT — every factual claim matches source (the new connection-string caveat is essentially verbatim from the source XML doc); the only open items are one optional clarity warning and one behavioral knowledge gap carried over from the blind-user pass.


Phase A — Claim verification

The PR adds a single <Aside type="note">:

Environment-variable values that exactly match a resolved secret parameter—such as a generated PostgreSQL, Redis, or SQL Server password—are redacted from every referencing resource. Secrets embedded within larger values, such as connection strings, are not redacted.

All four factual claims match microsoft/aspire @ main (1cdf7d17). No contradicted or unverifiable claims → no inline claim comments.

✅ Verified claims (4) with evidence
# Claim Verdict Evidence (microsoft/aspire @ main 1cdf7d17)
C1 Redaction is exact-match: an env-var value is redacted only when it equals a resolved secret parameter value. ✅ verified src/Aspire.Hosting/Backchannel/AuxiliaryBackchannelRpcTarget.cs L1215‑1216: "a value is redacted only when it is exactly equal to a resolved secret parameter value." Implementation L1223‑1224: RedactIfSecretValue(...) => value is not null && secretParameterValues.Contains(value) ? null : value — a HashSet<string> exact-equality test.
C2 Generated PostgreSQL / Redis / SQL Server passwords are examples of resolved secret parameters. ✅ verified ParameterResourceBuilderExtensions.cs L432 CreateDefaultPasswordParameter → CreateGeneratedParameter(builder, name, secret: true, generatedPassword). Called by Postgres (PostgresBuilderExtensions.cs L57), Redis (RedisBuilderExtensions.cs L76, special: false), SQL Server (SqlServerBuilderExtensions.cs L44). Postgres emits it as POSTGRES_PASSWORD (PostgresBuilderExtensions.cs L24, L121).
C3 The value is redacted from every referencing resource (including the resource that owns the secret). ✅ verified GetSecretParametersAsync (L1275‑1359) builds the secret set from parameters "reachable from the application model, including parameters that are only referenced by another resource rather than registered as a top-level resource" — via a recursive dependency walk (GetDependenciesAsync), and its docstring L1280‑1283 names "the password created by AddPostgres". RedactIfSecretValue is then applied to every resource's env vars (L1136). This is exactly what #19248 (5faba087) fixed: the owning resource's own POSTGRES_PASSWORD is now redacted, not just dependents'. (Non-blocking nuance: because matching is value-based, redaction actually fires for any resource emitting that exact value — a superset of "referencing" — so the claim is true, if slightly conservative.)
C4 Secrets embedded within larger values, such as connection strings, are not redacted. ✅ verified (near-verbatim) AuxiliaryBackchannelRpcTarget.cs L1219‑1220: "A secret embedded as a substring of a larger composed value (e.g. a connection string) is not detected, because only exact-equality matches are redacted." The note's wording mirrors the source XML doc, connection-string example and all.

Phase B — Doc-tester results (blind-user pass)

This phase was run without consulting any source code; the docs site was the only window into behavior.

Route exercised: /reference/cli/commands/aspire-describe/, served from a running local aspire.dev frontend (http://localhost:51482). ⚠️ That build does not contain this PR's note (it isn't the PR branch), so I verified the page + the note's rendering-compatibility and evaluated the note's prose as a blind user, but could not render the exact new callout in-context — see the knowledge gap.

Summary

Category Passed Failed Warnings
Content accuracy 1 0 1
Rendering (MDX) 1 0 0
CLI / runtime behavior 0 0 0 (see knowledge gap)
Links n/a — the note adds no links 0 0

Critical issues

None.

Warnings

Warning 1 — the note promises env-var redaction, but no example output on the page ever shows an environment variable.

  • Location: /reference/cli/commands/aspire-describe/, new Note callout.
  • Issue: The note guarantees that "environment-variable values … are redacted." Yet the page's only sample output (Example 1) is the default table — Name / Type / State / Health / Endpoints, no env vars — and Example 5 (aspire describe --format Json) shows the command but no sample JSON output. Environment variables (and therefore POSTGRES_PASSWORD) only appear in the JSON output, which the page never renders, so a new reader can't see where the promised redaction would actually be visible. The reworded note ("environment-variable values") is more precise than the previous "the output," but the gap between the promise and what the page shows remains.
  • Suggestion (optional): Tie the note to JSON output, e.g. "… redacted from the environment variables emitted by aspire describe --format Json", and/or add a short redacted JSON snippet under Example 5.

Passed checks

  • Page loads (HTTP 200; title "aspire describe command | Aspire"); 0 console errors.
  • The page already renders an <Aside> (the Tip for the aspire resources alias) as a Starlight callout, so the PR's <Aside type="note"> — the same, already-imported component — will render as a Note callout.
  • Placement is logical: immediately after the existing aspire resources alias tip and before the Arguments heading.
  • The note introduces no links; existing internal links on the page are site-relative with trailing slashes (/reference/cli/commands/aspire-run/, …/aspire-ps/, …/aspire-wait/, …/aspire-stop/). No broken links introduced.

Knowledge gap — runtime redaction behavior was not executed

  • What I needed to know: whether aspire describe --format Json actually redacts the owning resource's POSTGRES_PASSWORD at runtime, and how the exact new note renders in-context.
  • Source of my knowledge: not verified in Phase B — the running local build predates the change, and exercising it would require a dev/PR CLI build that includes #19248 plus Docker to run a Postgres container. Neither was run here.
  • User impact: a user on a released GA CLI is on a build from before this fix and could still observe the leak; the documented guarantee holds only on a build that includes the change (13.6 hasn't shipped).
  • Recommendation: reasonable to rely on the Phase A source verification (C1–C4) for this behavioral claim.

Recommendations

  1. Optional clarity tweak connecting the note to --format Json output, ideally with a short redacted JSON sample (Warning 1).
  2. No blocking issues — the note is accurate and will render correctly.

Automated docs-accuracy review · Phase A verified against microsoft/aspire@main 1cdf7d17 (fix 5faba087 / #19248) · Phase B via local doc-tester on /reference/cli/commands/aspire-describe/. Target branch release/13.6 is not yet present in microsoft/aspire (newest release/13.5).

David Pine (IEvangelist) added a commit that referenced this pull request Sep 28, 2026
…ps (#1780)

## Summary

<!-- Describe what this pull request changes and why. -->

Reconcile the 13.6 wiki audit and **all 25 open `docs-from-code`
proposals targeting `release/13.6`** against the actual release source.
Add missing canonical guidance rather than putting all coverage in
What's new. This is a new, isolated feature PR into `release/13.6`; it
does not update the release rollup #1599, merge or close another
proposal, or push directly to a release branch.

**Draft with explicit remaining packaging/validation gates:** the six
REPL walkthroughs are source-verified, but current publicly available
13.6 packages do not contain the late `WithRepl` exports. Generated API
catalogs have deliberately not been fabricated or refreshed from 14.x.
See the open checklist below.

### Evidence baseline

- Documentation base: `717442f6666948bcf77f3d704dc2dadf7c080ec2`.
- Product source of truth:
[`microsoft/aspire@e8fd6fbb954f50ccd2e66479538392f65e13e71d`](https://github.com/microsoft/aspire/tree/e8fd6fbb954f50ccd2e66479538392f65e13e71d),
current `release/13.6` at audit time. Source was read from that Git
object, not the stale source working directory.
- [13.6 wiki](https://github.com/microsoft/aspire/wiki/13.6-Change-log)
snapshot `8e01a371d4f16a1306e48174d4cf1fdeca714348`, whose cutoff is
product PR 20511. Later backports 20541/20546/20548 are included here.
- Proposal base branches alone were **not** used as proof of release
membership. Direct ancestry and known release backports were checked.
Four fallback-targeted proposals are excluded below.
- Wiki link corrections: its REPL link #1752 actually covers Sandboxes;
the REPL proposal is #1740. Its AOT link #1714 covers PFX certificates,
not AOT.

### Complete audit-gap checklist

Checked items mean documentation coverage is implemented, not that cloud
deployment or every product runtime scenario was executed.

- [x] **1. Dotnet API graduation:** correct removal to **13.6**, not
14.0, in What's new, both Dotnet guides, and the diagnostic page;
preserve the prerelease package caveat. This applies to core
`AddDotnetProject`, `DotnetProjectResource`, and related
`WithBuildEnvironment` overloads, not all uses of the diagnostic.
Source: microsoft/aspire#20496.
- [x] **2. Sandboxes:** remove obsolete API suppressions in the article
and deployment guide while preserving Azure service preview/access and
prerelease package limitations. Source: microsoft/aspire#20483.
- [x] **3. Docked REPL documentation:** all six
PostgreSQL/MySQL/MongoDB/SQL Server/Redis/Valkey guides plus the article
now cover opt-in `WithRepl`/`withRepl`, run-only availability, actual
client privileges, credential handling, and explicit exit versus closing
a viewer. Source: microsoft/aspire#20419, backport of
microsoft/aspire#20231. Package-backed checks remain open below.
- [x] **4. Terminal CLI flag:** update current 13.6 article,
`with-terminal`, and all three terminal command references. Preserve
`terminals.v1` and experimental hosting API distinctions. Current
configuration/schema data had no flag entry to remove; historical 13.5
notes remain historical. Source: microsoft/aspire#20548.
- [x] **5. First-party Rust:** rewrite both canonical Rust guides around
`Aspire.Hosting.Rust`; document Cargo versus application arguments,
typed targets, debugging, generated Dockerfiles, workspace context, ABI
constraints, and Toolkit migration. Bacon remains explicitly
Toolkit-only. Add exact first-party package mapping. Source:
microsoft/aspire#18906 and current Rust README.
- [x] **6. Agent setup:** align command reference, skills guide,
AI-agent guide, and article on MCP opt-in, `--mcp`,
chained/non-interactive behavior, seven-skill catalog, Project v2
migration, and Copilot app detection. Also fix stale default-selection
text: all applicable bundle skills are preselected; companion tools
remain opt-in. Sources: microsoft/aspire#19893, microsoft/aspire#20405,
microsoft/aspire#19820.
- [x] **7. Deno AppHost runtime:** document Deno 2+ detection, commands,
permissions, native watch/type checking, doctor, and `DENO_CERT`,
separately from Deno guest hosting. Source: microsoft/aspire#18627,
distinct from microsoft/aspire#18628.
- [x] **8. Native AOT / Fluent UI v5:** concise article, dashboard
exploration, and standalone guidance; automatic packaged-dashboard
selection, no invented performance figures. Source:
microsoft/aspire#19565 and release packaging sources.
- [x] **9. NuGet:** document bundled in-process operations, credential
providers, non-interactive authentication, and realistic
troubleshooting. Correct the proposal's `dotnet nuget locals`
authentication advice: cache commands do not authenticate a feed.
Source: microsoft/aspire#20391.
- [x] **10. Multithreaded builds:** article and coordinated-build guide
explain `-mt`, SDK detection, distinct project/file-based SDK floors,
and fallback. Source: microsoft/aspire#20441.
- [x] **11. Radius:** add a real deployment guide with C#/TypeScript
setup, recipe-backed connections versus local endpoints, per-resource
credential behavior, unauthenticated Redis limitation, secret exposure
boundaries, and actionable runtime diagnostics 070–091. Wire navigation
and exact package mapping. Source: microsoft/aspire#19555 and release
README.
- [x] **12. Connection aliases:** replace contradictory no-encoding
guidance, retain composed logical-key-first lookup and portable-target
behavior, explain collision detection and custom-publisher metadata.
Source: microsoft/aspire#19729.
- [x] **13. Connector Namespace / Toolbox / provisioning:** add
Connector Namespace walkthrough, security/consent/revocation limits and
mapping/sidebar; add Foundry Toolbox walkthrough, connection properties,
roles, index prerequisites, approval enforcement boundaries, immutable
versions, and existing-resource behavior. Extend existing Azure
provisioning guide without a duplicate page. Sources:
microsoft/aspire#19024, microsoft/aspire#17742, microsoft/aspire#20131.
- [x] **14. Remaining high-impact items:** article covers opt-in
manifest-aware DNX and new-template CLI bundling (existing SDK guides
retained), migration skill and Copilot app detection; canonical inline
`CsiVolumeSourceV1`/`VolumeV1.Csi` example, management links, Cosmos
vNext telemetry, and AI Inference `GetModelInfoAsync`/`/info` health
checks with `DisableHealthChecks`. No Azure OpenAI health-check claim.
Sources: microsoft/aspire#19310, microsoft/aspire#19076,
microsoft/aspire#19826, microsoft/aspire#20070, microsoft/aspire#15671,
microsoft/aspire#15969.
- [x] **15. All 25 proposal dispositions:** listed below, including
newer dashboard backports and four exclusions. Existing Sandbox
inference coverage is retained rather than copied from a stale draft.
- [ ] **16. Refresh generated API/catalog/Twoslash data from an official
post-backport 13.6 build.** Existing `26473.12`/`a11eca96` data remains
untouched. The newest public `dotnet9` feed package checked,
`13.6.0-preview.1.26474.10` at
`43496a2a306c81c862c947b11b4f4e5494b6fe08`, still has no Redis
`WithRepl` in its actual package XML. Do not use 14.x, hand-edit
declarations, or attribute source changes to older binaries.
- [ ] **Validate the six REPL examples against that actual post-backport
SDK and running clients.** Their new TypeScript fences are plain
TypeScript, not annotated with unsupported Twoslash data. No existing
diagnostics are allowlisted or suppressed; no generated API exports are
fabricated. Enable Twoslash when the genuine catalog catches up.

### All 25 open proposal dispositions and provenance

Text is selectively adapted from these proposals, not merged wholesale.
#1778 and #1748 are authored by @sebastienros; the other proposals are
authored by the Aspire repo bot. The table credits the associated
product-change authors where supplied by the proposals. Existing PRs
remain open and unchanged.

| Docs PR | Release source / credited product author | Disposition |
| --- | --- | --- |
| #1778 | microsoft/aspire#19729 — @sebastienros | **Adopted:**
canonical connection-string alias correction, including logical-first
resolution and migration. |
| #1771 | microsoft/aspire#20481 — @sebastienros | **Excluded:** flat
polyglot feature keys are not in the audited release tip; no verified
backport. Preserve release key names. |
| #1770 | microsoft/aspire#20525 → microsoft/aspire#20548 — @mitchdenny
| **Corrected/adopted:** command guides plus the still-current 13.6
article, which the proposal incorrectly treats as historical. |
| #1769 | microsoft/aspire#20416 — @JamesNK | **Excluded:** brand hover
change has no verified 13.6 membership/backport. |
| #1768 | microsoft/aspire#20523 → microsoft/aspire#20546 — @JamesNK |
**Adopted:** run pin/unpin preserves selector and current selection. |
| #1766 | microsoft/aspire#20537 → microsoft/aspire#20541 — @mitchdenny
| **Adopted:** terminal dock empty state. |
| #1761 | microsoft/aspire#20490 → microsoft/aspire#20496 — @eerhardt |
**Corrected:** graduation is 13.6, package remains prerelease,
Blazor-specific exception retained. |
| #1760 | microsoft/aspire#20436 — @eerhardt | **Excluded:** CLI
net11/tools-any retarget is not in the audited release; no fallback-base
inference. |
| #1748 | microsoft/aspire#20131 — @sebastienros | **Adopted:** extend
existing provisioning guide with service-specific models/lookups and
projection limits. |
| #1744 | microsoft/aspire#20337 → microsoft/aspire#20441 — @karolz-ms |
**Adopted:** precise SDK-conditional multithreaded build coverage. |
| #1740 | microsoft/aspire#20231 → microsoft/aspire#20419 — @mitchdenny
| **Adapted:** all six guides; TypeScript-first tabs, source-verified
lifecycle/security. Actual post-backport SDK/runtime gate is open above.
|
| #1738 | microsoft/aspire#20158 → microsoft/aspire#20405 — @karolz-ms |
**Partly already covered / completed:** existing seven-skill catalog
retained; add project migration guidance and correct command
catalog/defaults. Do not misclassify the bundled skill as a companion
tool. |
| #1735 | microsoft/aspire#20334 — @karolz-ms | **Excluded:** enhanced
startup errors are not in the audited release; no verified backport. |
| #1731 | microsoft/aspire#19847 → microsoft/aspire#20391 — @eerhardt |
**Corrected/adopted:** in-process NuGet and real authenticated-restore
troubleshooting, not cache-command authentication. |
| #1719 | microsoft/aspire#20299 → microsoft/aspire#20407 — @JamesNK |
**Corrected/adopted:** cookie naming/scoping; identical names can
collide but do not guarantee cross-dashboard cookie decryptability or
shared sign-in. |
| #1664 | microsoft/aspire#20011 — @maddymontaquila | **Adopted:**
concise Azure environment icon release note. |
| #1628 | microsoft/aspire#17742 — @davidfowl | **Adapted/expanded:**
canonical Toolbox examples, consumer contract, role/index prerequisites,
approval/security and concurrency limits. |
| #1623 | microsoft/aspire#19810 — @mitchdenny | **Already covered:**
current Sandbox guide/article already describe compute inference,
explicit selection and external endpoints. Preserve that guidance while
removing obsolete suppressions. |
| #1620 | microsoft/aspire#19243 — @sebastienros | **Adapted:** AKS
credential-before-Helm cleanup and destructive-operation warning; omit
misleading ambient-context workaround. |
| #1614 | microsoft/aspire#19870 — @sebastienros | **Adopted:** typed
callback handle behavior in extension authoring and article. |
| #1574 | microsoft/aspire#19430 — @mitchdenny | **Adapted:** canonical
hostname inheritance, explicit-host precedence, catch-all default
backend. |
| #1570 | microsoft/aspire#19590 — @karolz-ms | **Adopted:** Dev Tunnel
URL regression troubleshooting. |
| #1565 | microsoft/aspire#19429 — @mitchdenny | **Corrected/adopted:**
Helm embedded parameters with real `refExpr` and `addParameter(name, {
value })`, not stringifying a handle or using an invalid actual-SDK
overload. |
| #1564 | microsoft/aspire#19026 — @karolz-ms | **Corrected/adopted:**
C#/TypeScript Dotnet gateway walkthrough. Retain both experimental
diagnostics; remove obsolete run-only restriction after
microsoft/aspire#19997 publishing support. Avoid imported ambiguous API
reference. |
| #1499 | microsoft/aspire#19248 — @IEvangelist | **Adopted:** describe
exact secret-value redaction and embedded-secret limit; release article
already covered the fix. |

### Important source-verified corrections to proposals / earlier audit
assumptions

-
[`BlazorGatewayExtensions.cs`](https://github.com/microsoft/aspire/blob/e8fd6fbb954f50ccd2e66479538392f65e13e71d/src/Aspire.Hosting.Blazor/BlazorGatewayExtensions.cs):
`AddDotnetProjectBlazorGateway` and the Dotnet `WithBlazorClientApp`
overload still carry `ASPIREDOTNETPROJECT001`; the class carries
`ASPIREBLAZOR001`. They share `WithBlazorClientAppCore`/`WithBlazorApp`
and the publish-companion path. Thus neither blanket diagnostic
retirement nor the proposal's old run-only claim is correct.
-
[`SkillDefinition.cs`](https://github.com/microsoft/aspire/blob/e8fd6fbb954f50ccd2e66479538392f65e13e71d/src/Aspire.Cli/Agents/SkillDefinition.cs)
sets bundled skills' `IsDefault=true`;
[`AgentInitCommand.cs`](https://github.com/microsoft/aspire/blob/e8fd6fbb954f50ccd2e66479538392f65e13e71d/src/Aspire.Cli/Commands/AgentInitCommand.cs)
selects the applicable catalog defaults for both flows. MCP has its own
standalone-only binding.
-
[`TypeScriptAppHostToolchainResolver.cs`](https://github.com/microsoft/aspire/blob/e8fd6fbb954f50ccd2e66479538392f65e13e71d/src/Aspire.Cli/Projects/TypeScriptAppHostToolchainResolver.cs)
is the source for Deno flags and certificate variable; guest Deno
hosting is separate.
- [`Radius
README`](https://github.com/microsoft/aspire/blob/e8fd6fbb954f50ccd2e66479538392f65e13e71d/src/Aspire.Hosting.Radius/README.md)
supplies the resource-specific credential rules and publish diagnostics,
not assumptions about local endpoints.

## Third-party links and affiliations

<!-- List third-party links and disclose material affiliations. -->

Links point to official Microsoft Learn, VS Code Marketplace debugger
extensions, Rust/Cargo/Bacon documentation, Radius documentation, and
source repositories. No sponsorship, commercial endorsement, or
affiliation claim is introduced. Maintainers should supply any personal
affiliation disclosure required by policy; automation has not inferred
one.

## Validation

<!-- List the checks you ran or explain why validation isn't needed. -->

- **97 passing focused unit checks** across API-reference
authoring/rendering, Twoslash blocks, file-tree formatting, CLI
configuration schema, SEO lengths, and resource catalog.
- **82 passing structured-data checks**, including exact integration
mapping uniqueness and page resolution.
- **11 C# samples compile**, zero warnings/errors, using genuine
`13.6.0-preview.1.26473.12` packages. Scope: Rust, Connector Namespace,
Radius, Toolbox, inline CSI, Helm, Blazor gateway, and provisioning.
`Projects.Api/Worker/Client` use compile-only `IProjectMetadata`
stand-ins; no claim of running those apps or provisioning cloud
resources.
- **10 TypeScript samples pass `tsc`** under `strict`, `NodeNext`, and
`ES2022` against three **unmodified actual SDK files**, not just the
site's declaration bundle. The fixture uses the exact `e8fd6fbb` release
`AtsCapabilityScanner` and genuine `26473.12`
TypeSystem/code-generator/integration binaries, whose informational
source is `a11eca96`. This is an isolated local generation fixture,
**not** a claim that official CLI generation or a new packaged release
was tested. An attempted restore with the older handed-off local CLI
could not discover an AppHost server; the bounded direct generator
fixture was used instead.
- The SDK scan is **not globally warning-free**: it reports a Radius
`withContainerImage` collision on `CSharpAppResource` and an App
Configuration `createRoleAssignment` overload collision. None of the
compiled examples calls those colliding methods; the warnings are
retained in evidence, not suppressed, and no generated declarations were
edited.
- Browser: Connector Namespace, Radius, both Rust pages, Foundry
hosting, and What's new return **HTTP 200**, correct headings, and no
rendered Twoslash errors. New guide/article page-local anchors and the
cross-page Blazor anchor resolve. Connector/Radius mobile layouts have
no horizontal overflow; Connector language-tab interaction works.
Standalone Astro preview emits expected `/api/live` 404s because
StaticHost is not running.
- `git diff --check` passes. No production `pnpm build`, cloud
deployment, REPL runtime session, full product suite, or blanket
validation of every pre-existing example was performed.
- Generated C#/TypeScript API data, declaration bundles, integration
catalogs, image catalogs, and contributor data are unchanged. Only the
authored package-to-guide mapping is updated.

**Before merging:** complete the two packaging/REPL checkboxes above,
inspect CI, and obtain human review. This PR intentionally does not
close or merge the source documentation proposals.

---------

Co-authored-by: David Pine <7679720+IEvangelist@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

@mitchdenny Mitch Denny (mitchdenny) left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Source of truth: microsoft/aspire release/13.6 at f4c27f2d43ddc1cacd0dd083b30d1fea1cee7a62. Three claims extracted; 3 verified, 0 verified-with-nuance, 0 unverifiable, 0 contradicted.

Phase A — Claim verification

Verified claims and evidence
  • Exact-value redaction of environment variables on resource snapshots: src/Aspire.Hosting/Backchannel/AuxiliaryBackchannelRpcTarget.cs:1143-1161,1232-1246; tests/Aspire.Hosting.Tests/Backchannel/AuxiliaryBackchannelRpcTargetTests.cs:334-375,379-425. Secret discovery covers both registered and referenced parameters (AuxiliaryBackchannelRpcTarget.cs:1323-1385).
  • Generated PostgreSQL, Redis, and SQL Server password parameters: src/Aspire.Hosting.PostgreSQL/PostgresBuilderExtensions.cs:59,121-124, src/Aspire.Hosting.Redis/RedisBuilderExtensions.cs:77,104-109, src/Aspire.Hosting.SqlServer/SqlServerBuilderExtensions.cs:46,61-64.
  • Secrets embedded in larger strings are not redacted by the environment-variable exact-equality check: AuxiliaryBackchannelRpcTarget.cs:1232-1246.

Phase B — Documentation Test Report

Focus Area: /reference/cli/commands/aspire-describe/ — new redaction note. Date: 2026-09-29. Tester: doc-tester agent. Served PR head b67404ef at http://localhost:4321/reference/cli/commands/aspire-describe/.

Category Passed Failed Warnings
Content Accuracy 1 0 0
Code Examples 0 0 0
CLI Commands 0 0 0
Links 0 0 0

Critical Issues: None.

Warnings: None.

Passed Checks: The page loads with the correct title; the complete redaction note renders as a Note aside in the Description section, and its warning about embedded values is visible. The new text adds no links or runnable examples.

Recommendations: None for the changed passage. The secret-redaction runtime behavior was not exercised from the reader path: the local CLI is 14.0.0-preview.1, not this PR’s 13.6 target, so the source-of-truth verification above is the behavioral evidence.

Knowledge gaps: None caused by the added passage.

Copilot AI balanced review requested due to automatic review settings September 29, 2026 05:13

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request. Check if the Files changed in this pull request are included in default exclusions.


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@mitchdenny
Mitch Denny (mitchdenny) merged commit 25af260 into release/13.6 Sep 29, 2026
9 checks passed
@mitchdenny
Mitch Denny (mitchdenny) deleted the docs/pr-19248-31822977011-1-805faa75af9d1fe7 branch September 29, 2026 05:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

docs-from-code Copilot initiated issue from dotnet/aspire repo

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants