Skip to content

Update partner center publishing - #194

Merged
selzoc merged 7 commits into
windows-2019from
update-partner-center-publishing
Sep 29, 2026
Merged

selzoc merged 7 commits into
windows-2019from
update-partner-center-publishing

Conversation

@selzoc

@selzoc selzoc commented Sep 29, 2026

Copy link
Copy Markdown
Member

Switch to the non-deprecated API. The old API drops the logos each time, forcing manual intervention.

selzoc and others added 6 commits September 29, 2026 15:02
Publishes Azure Marketplace image versions through the Microsoft Graph
Product Ingestion API, replacing the deprecated Cloud Partner Portal API.

ai-assisted=yes
[TNZ-155310]
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
ai-assisted=yes
[TNZ-155310]
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The Partner Center tasks publish the image, so this task only copies the
VHD to the published account and hands them its SAS-free blob URL.

ai-assisted=yes
[TNZ-155310]
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The Cloud Partner Portal API is deprecated; submit-azure-offer and
publish-azure-offer now use the Product Ingestion API tasks, keyed by
the image version recorded in azure-published-vhd-uri.

ai-assisted=yes
[TNZ-155310]
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The upload now requires exactly one VHD URI file and names the blob from
the URL path only, so a slash in the SAS query cannot change it. A failed
copy start, usually a pending copy left by an aborted run, prints how to
cancel it. The preview submit refuses an empty SAS before calling
Partner Center.

ai-assisted=yes
[TNZ-155310]
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
ai-assisted=yes
[TNZ-155310]
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Warning

Review limit reached

Next included review available in 41 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 1f7e6cbd-c365-449b-8e07-4ade6db187b4

📥 Commits

Reviewing files that changed from the base of the PR and between a20d7f2 and 66d51e1.

📒 Files selected for processing (1)
  • ci/tasks/partner-center-go-live/run

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: b1012605-b1e7-405c-8a12-2fd44ee87678

📥 Commits

Reviewing files that changed from the base of the PR and between 7efb878 and a20d7f2.

📒 Files selected for processing (12)
  • ci/common-scripts/partner-center.sh
  • ci/pipelines/stemcells-windows.yml
  • ci/tasks/azure-image-upload/run
  • ci/tasks/azure-image-upload/task.yml
  • ci/tasks/partner-center-go-live/run
  • ci/tasks/partner-center-go-live/task.yml
  • ci/tasks/partner-center-submit-preview/run
  • ci/tasks/partner-center-submit-preview/task.yml
  • ci/tasks/partner-center-wait-live/run
  • ci/tasks/partner-center-wait-live/task.yml
  • ci/tasks/partner-center-wait-preview/run
  • ci/tasks/partner-center-wait-preview/task.yml

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


Walkthrough

The pipeline now uploads Azure VHDs and submits them to Partner Center for preview. Shared helpers handle Partner Center requests, configuration jobs, release state, and polling. New tasks track preview status, promote submissions to live, and verify the requested version and VHD in the live configuration.

Priority: ➖ Normal

Merge Risk: ⚪ Minimal · up to a20d7

The change replaces the deprecated Partner Center publishing flow with staged preview, go-live and live-verification tasks. No specific merge-blocking defect was identified. Normal validation of the pipeline against the real Partner Center service is still advisable.

Security Architecture Review

Security architecture risk: 🔵 Low · up to a20d7

The staged workflow adds release-specific checks and reduces credential disclosure. No newly reachable unauthorized-publication path was established. Credential permissions, signed-image handling, and recovery guarantees still need confirmation before the migration can be considered fully assessed.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — Disclosure of a generated SAS could permit reading and listing the configured published-storage container until expiry, rather than access only to the named VHD. Publication authority is exercised through the configured Entra application; its maximum product and tenant authorization scope is not established by the client source.

Trust Boundaries and Controls

  • observed — The preview producer resolves the configured offer and SKU and checks release version and blob identity before emitting the submission ID. Go-live trusts that same-job artifact, derives its product, confirms the submission exists and has not failed, and sends it to the fixed Graph endpoint. Its independent checks do not rebind the ID to the configured offer or asset.

Resilience and Maintainability Implications

  • inferred — Separate technical-configuration and preview mutations, followed by asynchronous live promotion, make recovery dependent on provider state visibility and mutation semantics. Staleness checks, individual job serialization, non-retried POSTs, and terminal identity verification provide containment, but do not establish atomicity or safe repetition after an interrupted request.

Hardening Proposals

  • proposed — Confirm and document the application's effective product permissions, Partner Center's signed-URI confidentiality and retrieval requirements, and configure reconciliation and concurrency guarantees. Where supported, narrow SAS scope and lifetime. If promotion is reused outside this sequential job, independently validate offer, asset, and preview readiness before mutation.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the main change: updating Partner Center publishing to use the replacement API and workflow.
Description check ✅ Passed The description directly explains the API migration and the reason for the change, including the logo loss caused by the old API.
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 13 functions across 1 files. (11 skipped: …
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@ystros
ystros requested a balanced review from Copilot September 29, 2026 23:35
ystros
ystros previously approved these changes Sep 29, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Promotion may accept a successor submission while downstream polling remains pinned to the original ID.

Review effort: Balanced
Findings: 1 High severity

Open (1)
What changed in this PR

Migrates Azure offer publishing to the Partner Center Product Ingestion API while preserving existing offer assets.

Changes:

  • Adds shared Partner Center authentication, API, polling, and redaction helpers.
  • Splits preview submission, promotion, and live-status waiting into dedicated tasks.
  • Publishes copied VHD metadata through a new pipeline resource.
File Description
ci/​common-scripts/​partner-center.sh Adds shared Partner Center API helpers.
ci/​tasks/​azure-image-upload/​task.yml Updates upload task inputs and outputs.
ci/​tasks/​azure-image-upload/​run Copies the VHD and emits its published URL.
ci/​tasks/​partner-center-submit-preview/​task.yml Defines preview submission task configuration.
ci/​tasks/​partner-center-submit-preview/​run Updates the draft and submits it to preview.
ci/​tasks/​partner-center-wait-preview/​task.yml Defines preview polling task configuration.
ci/​tasks/​partner-center-wait-preview/​run Waits for preview certification and records its ID.
ci/​tasks/​partner-center-go-live/​task.yml Defines live promotion task configuration.
ci/​tasks/​partner-center-go-live/​run Promotes the certified submission.
ci/​tasks/​partner-center-wait-live/​task.yml Defines live-status polling task configuration.
ci/​tasks/​partner-center-wait-live/​run Verifies the image is live and waits for visibility.
ci/​pipelines/​stemcells-windows.yml Integrates the new publishing workflow.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread ci/tasks/partner-center-go-live/run Outdated
coderabbitai[bot]
coderabbitai Bot previously approved these changes Sep 29, 2026
go-live counts the release as promoted only when its pinned submission
is live, the same rule wait-live uses. Partner Center keeps a
submission's ID when it goes live.

ai-assisted=yes
[TNZ-155310]
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@selzoc
selzoc dismissed stale reviews from coderabbitai[bot] and ystros via 66d51e1 September 29, 2026 23:51
@selzoc
selzoc merged commit 029c205 into windows-2019 Sep 29, 2026
20 checks passed
@selzoc
selzoc deleted the update-partner-center-publishing branch September 29, 2026 23:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants