Repository navigation
Conversation
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.Scanned FilesNone |
Codecov Report❌ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## main #13248 +/- ##
==========================================
+ Coverage 60.38% 60.44% +0.06%
==========================================
Files 774 775 +1
Lines 45682 45784 +102
==========================================
+ Hits 27583 27673 +90
- Misses 18099 18111 +12 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
make sync-resource-types and update-recipe-packs now compile recipe-packs/kubernetes/default.bicep at the pinned recipePacks ref to deploy/manifest/recipe-packs/kubernetes/default.json with the Bicep version from build/tools.yaml. The file is embedded, and pkg/defaults exposes its recipes through DefaultKubernetesRecipes. CI installs Bicep and includes the compiled pack in the drift check. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Signed-off-by: Nithya Subramanian <nithyasu@microsoft.com>
30e5320 to
5af95ef
Compare
There was a problem hiding this comment.
🟡 Changes recommended
The loader’s shallow copy and top-level-only validation mishandle valid nested recipe parameters.
2 open findings
What changed in this PR
This first stack change vendors and embeds the pinned Kubernetes recipe pack for later use by rad.
Changes:
- Compiles pinned recipe-pack Bicep into embedded JSON.
- Adds a Go loader and tests for recipe metadata.
- Extends CI drift checks and update automation.
| File | Description |
|---|---|
pkg/defaults/recipepack.go |
Adds recipe-pack parsing and access. |
pkg/defaults/recipepack_test.go |
Tests parsing and copy behavior. |
pkg/defaults/defaults.go |
Loads recipes during initialization. |
deploy/manifest/recipe-packs/kubernetes/default.json |
Vendors compiled Kubernetes recipes. |
deploy/manifest/embed.go |
Embeds the compiled pack. |
deploy/manifest/defaults.yaml |
Documents pack vendoring. |
build/scripts/test-sync-resource-types.sh |
Tests recipe-pack synchronization. |
build/scripts/sync-resource-types.sh |
Compiles pinned recipe packs. |
build/resource-types.mk |
Passes Bicep configuration to sync targets. |
.github/workflows/verify-resource-types-manifest.yaml |
Verifies recipe-pack drift. |
.github/workflows/update-resource-types.yaml |
Installs Bicep for automated updates. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
…odels DefaultKubernetesRecipePack returns the pack's RecipePackProperties as authored, so every recipe field the API defines (such as parameters and plainHttp) reaches rad without code changes. Fields the models don't know, read-only fields, a different API version, unsupported kinds and ARM expressions anywhere in a recipe fail the load instead of being dropped. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Signed-off-by: Nithya Subramanian <nithyasu@microsoft.com>
… test Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Signed-off-by: Nithya Subramanian <nithyasu@microsoft.com>
… ST1012 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Signed-off-by: Nithya Subramanian <nithyasu@microsoft.com>
Radius functional test overviewClick here to see the test run details
Test Status⌛ Building Radius and pushing container images for functional tests... |
| } | ||
| } | ||
|
|
||
| return json.Marshal(&properties) |
There was a problem hiding this comment.
[P2] Decode ARM-escaped literal strings before returning the properties
This function reads recipe-pack JSON produced by Bicep. The pinned compiler adds an extra [ to literal strings that begin with [: a Bicep-authored recipe parameter of [literal] becomes [[literal] in the compiled JSON. json.Marshal(&properties) preserves that encoding, so the loader returns a different parameter value from the one authored in Bicep. The same problem affects strings inside objects and arrays.
After rejecting ARM expressions, recursively remove exactly one leading [ from escaped literal strings. Update the valid-input test that currently expects [[literal], and add nested cases and a literal with two leading brackets to verify that decoding happens only once.
|
|
||
| .PHONY: sync-resource-types | ||
| sync-resource-types: ## Copy manifest files from the per-namespace refs pinned in defaults.yaml | ||
| sync-resource-types: ## Copy manifest files and compile the kubernetes recipe pack from the refs pinned in defaults.yaml |
There was a problem hiding this comment.
Document the new Bicep prerequisite and generated pack file (non-blocking)
make sync-resource-types now compiles the pinned Kubernetes pack's default.bicep into deploy/manifest/recipe-packs/kubernetes/default.json, so contributors running the command also need the pinned Bicep executable on PATH. Please update docs/contributing/contributing-code/contributing-code-shell-and-make/README.md to include make install-bicep, the required PATH setup, and committing regenerated default.json when changing the contrib pin. This makes the compiler prerequisite and the generated file explicit in the documented update workflow.

Summary
Stack 1/3 for the default Kubernetes recipe pack plan (#13225).
make sync-resource-types(andupdate-recipe-packs,update-resource-types-and-recipe-packs) now compilesrecipe-packs/kubernetes/default.bicepat the pinnedrecipePacksref intodeploy/manifest/recipe-packs/kubernetes/default.json. The script requires the Bicep version inbuild/tools.yamland stripsmetadata._generator. Other packs are still only verified.pkg/defaults.DefaultKubernetesRecipePack()decodes the pack's properties into the generatedRecipePackProperties(2025-08-01-preview), so every recipe field the API defines (kind,source,parameters,plainHttp,outputs) passes through without code changes. Extension imports and other template content are ignored.deploy/manifest/recipe-packs/.raddoes not use the loader yet; that is stack 2/3.Note
Rebased onto #13254, which pins the kubernetes pack to
recipe-pack/kubernetes/v0.3.0(fc1b667).make sync-resource-typesat that pin produces the committeddefault.jsonwith no diff.Reason for change
radhard-codes the default Kubernetes recipe list in Go. This vendors the pinned contrib pack soradcan build from it instead.Part of #11959
How to test
make test-sync-resource-types: passed (new tests cover a missingdefault.bicep, a wrong Bicep version, a pin move recompiling the JSON, non-vendored packs not copied, and--update-recipe-packsordering)go test ./pkg/defaults/... ./deploy/manifest/...: passedgo vet ./pkg/defaults/... ./deploy/manifest/...: passedshellcheck --rcfile .github/linters/.shellcheckrcandshfmt -i 4 -ci -don both scripts: no new findingsmake sync-resource-typesat the v0.3.0 pin: no diff (manifests anddefault.jsonunchanged)File change summary
build/scripts/sync-resource-types.shVENDORED_RECIPE_PACKS=kubernetes) with the pinned Bicep version;--update-recipe-packsnow recompiles thembuild/scripts/test-sync-resource-types.shbuild/resource-types.mkBICEP_VERSION; update comments and target helpdeploy/manifest/defaults.yamldeploy/manifest/recipe-packs/kubernetes/default.jsondeploy/manifest/embed.godefault.json; addKubernetesRecipePackPathpkg/defaults/recipepack.goDefaultKubernetesRecipePack()andRecipeSourceRepository()pkg/defaults/recipepack_test.gopkg/defaults/defaults.go.github/workflows/verify-resource-types-manifest.yamlrecipe-packs/; trigger onbuild/tools.yaml.github/workflows/update-resource-types.yaml