Add custom recipe pack support and delete workflows to Repo Radius - #12367
Conversation
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.Scanned FilesNone |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #12367 +/- ##
==========================================
- Coverage 53.91% 53.90% -0.01%
==========================================
Files 765 765
Lines 50689 50689
==========================================
- Hits 27328 27326 -2
- Misses 20793 20794 +1
- Partials 2568 2569 +1 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
38ef80d to
e8a928e
Compare
Deploy any *recipe-pack*.bicep files in the app's .radius/ folder, then list all recipe packs and update the environment to reference all of them via rad env update --recipe-packs. Provider-agnostic logic lives in a new shared apply-custom-recipe-packs composite action wired into both the Azure and AWS workflows. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Signed-off-by: sk593 <shruthikumar@microsoft.com>
Register custom resource types from .radius/custom-types.yaml via rad resource-type create --from-file before deploying the recipe pack, and use the fixed .radius/custom-recipe-pack.bicep filename instead of a glob. Each file is optional and independent. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Signed-off-by: sk593 <shruthikumar@microsoft.com>
…view Add Repo Radius workflows to delete a Radius application or environment on the same ephemeral k3d control plane the deploy flow uses. Two thin dispatchers (delete-application.yml, delete-environment.yml) detect the provider and call reusable provider workflows (delete-azure.yml, delete-aws.yml), which restore persisted state, delete via the shared delete-resource composite action, and persist the updated state again. delete-resource runs `rad app delete`/`rad env delete <name> --yes --preview` and writes a rad-delete-result artifact. `--preview` is required so these commands use the Radius.Core surface instead of the legacy path; apply the same fix to the `rad env update --recipe-packs` call. Document the delete workflows in the extension README, the deploy design note, and a new radius-delete skill. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Signed-off-by: sk593 <shruthikumar@microsoft.com>
The delete provider workflows restore and persist Radius control-plane state via rad startup / rad shutdown, but they lacked the OCI-backed state-archive configuration the deploy workflows now use. As a result rad startup would fail with 'OCI archive repository is not configured; set RADIUS_STATE_REGISTRY or RADIUS_GRAPH_REGISTRY', or fall back to a different backend than deploy wrote, so the delete could not find the state it needed to plan recipe deletes. Mirror the deploy provider workflows in delete-aws.yml and delete-azure.yml: - set the job-level RADIUS_STATE_BACKEND / RADIUS_STATE_REGISTRY / RADIUS_STATE_ARCHIVE env vars from environment-scoped vars.* so the shared restore-state and teardown actions can open the archive, - add a GHCR docker login before restore-state so the private radius-state package pull/push authenticates instead of 401ing, and - raise packages: read to packages: write since rad shutdown now pushes the updated state artifact to GHCR. Update the README to note the delete workflows log in to GHCR and set the RADIUS_STATE_* variables for the OCI-backed state archive. Signed-off-by: sk593 <shruthikumar@microsoft.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
The delete-aws.yml / delete-azure.yml reusable workflows now request packages: write to push the OCI-backed state archive to GHCR. A called workflow cannot request more permissions than its caller grants, so the delete-application.yml and delete-environment.yml dispatchers failed at validation with 'is requesting packages: write, but is only allowed packages: read'. Raise both dispatchers to packages: write to match. Signed-off-by: sk593 <shruthikumar@microsoft.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
There was a problem hiding this comment.
Pull request overview
This PR extends the Repo Radius GitHub Actions workflow templates under .github/extension/ to support (1) optional custom resource type registration + custom recipe pack deployment/attachment during deploy, and (2) new delete workflows for applications/environments that reuse the same ephemeral k3d control plane + persisted state model as deploy.
Changes:
- Add
apply-custom-recipe-packscomposite action and wire it into both provider deploy workflows to optionally register.radius/custom-types.yaml, deploy.radius/custom-recipe-pack.bicep, and update the env recipe pack list. - Add delete workflow templates (
delete-application.yml/delete-environment.yml) plus provider reusable workflows (delete-azure.yml/delete-aws.yml) and a shareddelete-resourcecomposite action that emits arad-delete-resultartifact. - Update extension docs/design notes and add a
radius-deleteskill describing how to dispatch and what the workflows do.
Reviewed changes
Copilot reviewed 11 out of 11 changed files in this pull request and generated 2 comments.
Show a summary per file
| File | Description |
|---|---|
| eng/design-notes/environments/2026-06-repo-radius-deploy-workflow.md | Documents custom type/recipe-pack behavior and introduces the delete workflow design section. |
| .github/extension/skills/radius-delete/SKILL.md | Adds a new skill describing how to dispatch the delete workflows and interpret outcomes. |
| .github/extension/run-rad-commands-azure.yml | Wires in the new apply-custom-recipe-packs action after env/pack creation. |
| .github/extension/run-rad-commands-aws.yml | Wires in the new apply-custom-recipe-packs action after env/pack creation. |
| .github/extension/README.md | Documents the new composite actions and delete workflow contract/behavior. |
| .github/extension/delete-environment.yml | Adds a dispatcher workflow to delete an environment via provider detection. |
| .github/extension/delete-azure.yml | Adds reusable Azure delete workflow: restore state → delete → persist state. |
| .github/extension/delete-aws.yml | Adds reusable AWS delete workflow: restore state → delete → persist state. |
| .github/extension/delete-application.yml | Adds a dispatcher workflow to delete an application via provider detection. |
| .github/extension/actions/delete-resource/action.yml | Adds a shared composite action to run rad app/env delete --yes --preview and upload a result artifact. |
| .github/extension/actions/apply-custom-recipe-packs/action.yml | Adds a shared composite action to register custom types, deploy a custom pack, and update env recipe packs (preview). |
231409c to
0c82d6d
Compare
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Signed-off-by: Shruthi Kumar <shruthikumar@microsoft.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Signed-off-by: Shruthi Kumar <shruthikumar@microsoft.com>
9961856 to
6ba9677
Compare
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 11 out of 11 changed files in this pull request and generated no new comments.
Comments suppressed due to low confidence (2)
.github/extension/actions/apply-custom-recipe-packs/action.yml:65
- Avoid dumping the entire custom recipe-pack Bicep file into workflow logs. This file is repo-defined and could contain sensitive configuration (or simply be large/noisy); logging the path is enough for debugging.
echo "Custom recipe pack file:"
cat "$RECIPE_PACK_BICEP"
echo ""
echo "Deploying custom recipe pack from $RECIPE_PACK_BICEP..."
rad deploy "$RECIPE_PACK_BICEP"
.github/extension/actions/apply-custom-recipe-packs/action.yml:72
- When building PACK_IDS, filter out missing/null
.idvalues.RecipePackResource.IDis read-only and can be omitted/null in some responses; passing "null" through torad env update --recipe-packswill fail in a confusing way.
echo "Listing recipe packs..."
PACK_IDS=$(rad recipe-pack list -o json | jq -r '(if type == "array" then . else [.] end) | map(.id) | join(",")')
f7ce4b1 to
2212d53
Compare
Resolve README conflict from #12510 (registry creds injected into the app deploy instead of a control-plane Secret). Keep the custom-types / recipe-pack step and the OCI state-archive wording; adopt main's updated run-rad-commands step and drop the obsolete control-plane registry-cred provisioning step. Renumber the deploy stages accordingly. Signed-off-by: sk593 <shruthikumar@microsoft.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Signed-off-by: sk593 <shruthikumar@microsoft.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Signed-off-by: sk593 <shruthikumar@microsoft.com>
Radius functional test overviewClick here to see the test run details
Test Status⌛ Building Radius and pushing container images for functional tests... |
eb1226a to
f444a25
Compare
Radius functional test overviewClick here to see the test run details
Test Status |
Description
Extends the Repo Radius GitHub Actions workflow templates (
.github/extension/) in two ways:1. Custom types + recipe packs on deploy
The shared
apply-custom-recipe-packscomposite action, wired into both deploy provider workflows after the environment/recipe-pack is created:.radius/custom-types.yamlviarad resource-type create --from-file(skipped if absent)..radius/custom-recipe-pack.bicep(skipped if absent).rad recipe-pack listandrad env update <env> --recipe-packs <all pack ids> --previewso the environment references both the default provider pack and the custom pack.Both files are optional and independent.
2. Delete application / environment workflows
New workflows to delete a Radius application or environment on the same ephemeral k3d control plane the deploy flow uses:
delete-application.yml/delete-environment.yml— thin dispatchers that detect the provider (AZURE_CLIENT_ID/AWS_ROLE_ARN) and call the matching reusable provider workflow.delete-azure.yml/delete-aws.yml— reusable provider workflows that reuse the deploy provider setup (OIDC login, cluster connect, cloud OIDC token projection,rad credential register), restore persisted state, delete, then persist the updated state again. They skip the deploy-only stages (create env, deploy recipe pack, registry creds).actions/delete-resource— shared composite action runningrad app delete/rad env delete <name> --yes --preview, writing arad-delete-resultJSON artifact.Restoring state first (
rad startup) lets the delete see the environment, recipe packs, resources, and Terraform state;rad shutdown(if: always()in teardown) persists the post-delete state so the next operation plans against it.The
--previewfixrad env update,rad app delete, andrad env deletedefault to the legacy implementation and only use the Radius.Core surface when--previewis passed. All Radius.Core commands in these workflows now pass--preview— including therad env update --recipe-packscall, which previously silently no-oped.Docs
.github/extension/README.md— documents the delete workflows and thedelete-resourceaction.eng/design-notes/environments/2026-06-repo-radius-deploy-workflow.md— custom-types/recipe-pack subsection and a new delete-workflows section.radius-deleteskill;radius-deployskill updated for custom types.Type of change
This pull request adds a new feature to Radius.
Validation
yaml.safe_load); embedded bash passesbash -n.delete-resourcescript smoke-tested with a mockedrad: success, unsupported type, empty name, and command-failure paths all produce the correct exit code and artifact JSON.