Update partner center publishing - #194
Conversation
Publishes Azure Marketplace image versions through the Microsoft Graph Product Ingestion API, replacing the deprecated Cloud Partner Portal API. ai-assisted=yes [TNZ-155310] Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
ai-assisted=yes [TNZ-155310] Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The Partner Center tasks publish the image, so this task only copies the VHD to the published account and hands them its SAS-free blob URL. ai-assisted=yes [TNZ-155310] Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The Cloud Partner Portal API is deprecated; submit-azure-offer and publish-azure-offer now use the Product Ingestion API tasks, keyed by the image version recorded in azure-published-vhd-uri. ai-assisted=yes [TNZ-155310] Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The upload now requires exactly one VHD URI file and names the blob from the URL path only, so a slash in the SAS query cannot change it. A failed copy start, usually a pending copy left by an aborted run, prints how to cancel it. The preview submit refuses an empty SAS before calling Partner Center. ai-assisted=yes [TNZ-155310] Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
ai-assisted=yes [TNZ-155310] Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Warning Review limit reachedNext included review available in 41 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (1)
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (12)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. WalkthroughThe pipeline now uploads Azure VHDs and submits them to Partner Center for preview. Shared helpers handle Partner Center requests, configuration jobs, release state, and polling. New tasks track preview status, promote submissions to live, and verify the requested version and VHD in the live configuration. Priority: ➖ Normal Merge Risk: ⚪ Minimal · up to The change replaces the deprecated Partner Center publishing flow with staged preview, go-live and live-verification tasks. No specific merge-blocking defect was identified. Normal validation of the pipeline against the real Partner Center service is still advisable. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The staged workflow adds release-specific checks and reduces credential disclosure. No newly reachable unauthorized-publication path was established. Credential permissions, signed-image handling, and recovery guarantees still need confirmation before the migration can be considered fully assessed. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Promotion may accept a successor submission while downstream polling remains pinned to the original ID.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Migrates Azure offer publishing to the Partner Center Product Ingestion API while preserving existing offer assets.
Changes:
- Adds shared Partner Center authentication, API, polling, and redaction helpers.
- Splits preview submission, promotion, and live-status waiting into dedicated tasks.
- Publishes copied VHD metadata through a new pipeline resource.
| File | Description |
|---|---|
ci/common-scripts/partner-center.sh |
Adds shared Partner Center API helpers. |
ci/tasks/azure-image-upload/task.yml |
Updates upload task inputs and outputs. |
ci/tasks/azure-image-upload/run |
Copies the VHD and emits its published URL. |
ci/tasks/partner-center-submit-preview/task.yml |
Defines preview submission task configuration. |
ci/tasks/partner-center-submit-preview/run |
Updates the draft and submits it to preview. |
ci/tasks/partner-center-wait-preview/task.yml |
Defines preview polling task configuration. |
ci/tasks/partner-center-wait-preview/run |
Waits for preview certification and records its ID. |
ci/tasks/partner-center-go-live/task.yml |
Defines live promotion task configuration. |
ci/tasks/partner-center-go-live/run |
Promotes the certified submission. |
ci/tasks/partner-center-wait-live/task.yml |
Defines live-status polling task configuration. |
ci/tasks/partner-center-wait-live/run |
Verifies the image is live and waits for visibility. |
ci/pipelines/stemcells-windows.yml |
Integrates the new publishing workflow. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
go-live counts the release as promoted only when its pinned submission is live, the same rule wait-live uses. Partner Center keeps a submission's ID when it goes live. ai-assisted=yes [TNZ-155310] Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
66d51e1

Switch to the non-deprecated API. The old API drops the logos each time, forcing manual intervention.