Skip to content

tests/images with tailor [3]: build with tailor - #844

Draft
bfjelds (bfjelds) wants to merge 5 commits into
user/bfjelds/tailor-image-configsfrom
user/bfjelds/tailor-pipeline-cutover
Draft

bfjelds (bfjelds) wants to merge 5 commits into
user/bfjelds/tailor-image-configsfrom
user/bfjelds/tailor-pipeline-cutover

Conversation

@bfjelds

@bfjelds bfjelds (bfjelds) commented Oct 10, 2026 •

Copy link
Copy Markdown
Member

Summary

  • delete tests/tailor-images/legacy_targets.py
  • delete tests/tailor-images/legacy-map.json
  • replace the legacy Python bridge with direct tailor calls in Makefile and build-image pipeline logic
  • move the explicit legacy target mapping into tests/tailor-images/targets.mk
  • replace baremetal/core-selinux base downloads with tailor bases download

Notes

  • multi-clone pipeline builds now rename *_cloneN to the historical *_N outputs
  • direct-streaming make targets still publish .cosi compatibility copies from tailor's native .raw outputs
  • signed builds still copy ca_cert.pem into the output directory

Validation

  • repo-wide git grep legacy-map.json\|legacy_targets returns no hits
  • cargo run --manifest-path tools/tailor/Cargo.toml -- --manifest tests/tailor-images/tailor.yaml validate
  • make -n all-cosi
  • make -n all-iso
  • real make builds:
    • artifacts/trident-installer.iso
    • artifacts/trident-usrverity-testimage.cosi (+ artifacts/ca_cert.pem)
    • artifacts/trident-vm-grub-verity-testimage.qcow2
    • artifacts/azurelinux-direct-streaming-testimage-amd64.cosi

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
1 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@bfjelds
bfjelds (bfjelds) force-pushed the user/bfjelds/tailor-pipeline-cutover branch from 8b09049 to 3e6a9ae Compare October 10, 2026 17:35
@bfjelds bfjelds (bfjelds) changed the title tests: cut image builds over to tailor workspace tests/images with tailor [3]: build with tailor Oct 10, 2026
@bfjelds
bfjelds (bfjelds) force-pushed the user/bfjelds/tailor-image-configs branch from ade9116 to 0b1e91a Compare October 10, 2026 18:37
@bfjelds
bfjelds (bfjelds) force-pushed the user/bfjelds/tailor-pipeline-cutover branch 2 times, most recently from 73c0682 to 0a87113 Compare October 10, 2026 22:39
bfjelds (bfjelds) and others added 3 commits October 10, 2026 23:34
Point the Makefile, image-build pipelines, documentation, and legacy target helper at tests/tailor-images so the new tailor workspace becomes the live build path.

This also renames the azl-installer pipeline staging paths to tests/tailor-images/azl-installer. That path update was not needed in the original combined branch, but it is required here because this split introduces the standalone tests/tailor-images workspace one PR earlier.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
artifacts/trident-vm-{grub,grub-verity,root-verity,usr-verity,acl-agent}-testimage.qcow2
and artifacts/trident-vm-grub-verity-azure-testimage.vhd were built by a
Makefile section invoking Image Customizer directly via `docker run`
against the pre-tailor per-scenario YAML under
tests/tailor-images/trident-vm-testimage/base/ - every one of those YAML
files was deleted by the tests-cleanup commit, since nothing else
referenced them, breaking these targets outright (confirmed from a live
pipeline failure: "No rule to make target
'tests/tailor-images/trident-vm-testimage/base/baseimg-grub-verity.yaml'").

The previous commit (tests/tailor-images) added the missing qcow2/vhd-fixed
outputs: entries to the affected scenarios, so tailor now produces these
formats natively. This commit finishes the cutover:
- extend the generic `artifacts/%.cosi artifacts/%.iso artifacts/%.vhdx:`
  pattern rule to also match `.qcow2` and `.vhd`, and delete the entire
  raw docker-run section (keeping VM_IMAGE_PATH_PREFIX,
  $(QEMU_GUEST_IMAGE)/$(CORE_ARM64_IMAGE), and the SSH-key-staging rule,
  which are still used by the tailor-based builds).
- legacy_targets.py: a legacy name's selectors can now match more than one
  tailor cell (the same scenario's .cosi and .qcow2/.vhd-fixed outputs).
  Disambiguate using the extension of the Makefile's requested output path
  (already available, since the generic pattern rule's `$*` plus its own
  extension is exactly what's being asked for) instead of requiring every
  legacy name to resolve to exactly one cell unconditionally.
- legacy-map.json: add the one legacy name with no existing entry at all,
  `trident-vm-acl-agent-testimage` (only the `-update-` variant existed).

Verified: `make -n` for all 4 previously-failing targets now resolves
correctly, and a real `make artifacts/trident-vm-acl-agent-testimage.qcow2`
build succeeds end-to-end, producing both the existing .cosi and the new
.qcow2 artifact.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@bfjelds
bfjelds (bfjelds) force-pushed the user/bfjelds/tailor-pipeline-cutover branch from 0a87113 to fec721d Compare October 11, 2026 00:06
@bfjelds
bfjelds (bfjelds) force-pushed the user/bfjelds/tailor-image-configs branch from f66dcca to ffe79c2 Compare October 11, 2026 00:06
bfjelds (bfjelds) and others added 2 commits October 11, 2026 00:22
The dev-MIC-override python heredoc body (patching tests/tailor-images/tailor.yaml
to add a local "ic-dev" toolchain entry) was written flush-left at column 0
inside a `bash: |` block literal. YAML only strips the common leading
indentation established by the block's first line; a line with less
indentation than that (here 0 vs the required 8 spaces) ends the block
scalar early and gets parsed as a new top-level mapping key, producing:

  While scanning a simple key, could not find expected ':'

This exact bug was already found and fixed once before in this same file
(see 6c8a6ec "fix(pipelines): indent inline python heredocs in
build-image-template.yml") for a since-removed heredoc; this round's
Makefile/legacy_targets.py elimination added a new heredoc with the same
mistake. Indent the heredoc body and its `PY` terminator to match the
block's indentation - YAML strips the shared indent back off before
bash/python ever see the text, so the resulting script is unchanged.

Verified: every file under .pipelines/**/*.yml (85 files) parses as valid
YAML, confirmed via `ado-pipelines_write` (action=run_pipeline,
previewRun=true), which exercises ADO's own real template-evaluation path,
not just a generic YAML parser.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…se indent, not its nesting level

My previous fix (fc6b6c3) indented the dev-MIC-override python heredoc's
body and `PY` terminator to 8 spaces, matching the `python3 - <<'PY'` line
itself - but that line sits one level deeper (inside an `if` block) than
the overall `bash: |` block's own first line (`set -euo pipefail`, at 6
spaces). YAML's block-scalar dedent strips a flat amount equal to the
*block's* base indentation from every line, not each line's own relative
indentation - so after stripping 6 spaces, the heredoc terminator still
carried 2 residual leading spaces ("  PY"), and bash's `<<'PY'` (unquoted,
non-dash) requires an exact, whitespace-sensitive match at the start of
the line. This produced, at actual pipeline runtime (not caught by a
generic YAML parse, which doesn't care about this): "warning:
here-document ... delimited by end-of-file" followed by "syntax error:
unexpected end of file" - confirmed from a real failed build (1221778,
job "Build trident-container-installer").

Fix: indent the heredoc body/terminator to the block's base level (6
spaces) instead of the `if`-block's nesting level (8 spaces), so they end
up flush-left after YAML's dedent, exactly like the original working
instance of this same pattern (6c8a6ec, which had no extra nesting to get
wrong).

Verified this time by actually replicating ADO's own dedent behavior
(strip the block's first-line indentation from every line) and running
`bash -n` on the result, not just a generic YAML parse - this is the
fix that was missing from fc6b6c3's verification. Also wrote a
one-off check script that does the same dedent+`bash -n` extraction for
every bash/script block the migration actually touched (Makefile,
legacy_targets.py already deleted, build-image-template.yml, and the
other `trident_images`/`azl_installer` templates) - all clean. Full
`.pipelines/**/*.yml` (85 files) still parses as valid YAML.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant