chore: migrate sample Bicep extensions to GHCR - #2678
Draft
willdavsmith wants to merge 1 commit into
Draft
willdavsmith wants to merge 1 commit into
willdavsmith wants to merge 1 commit into
Conversation
Use canonical development edge references with per-config OCI support and preserve root-only release-channel pinning. Add isolated rewrite coverage and document public-artifact and compatible-released-CLI gates. Signed-off-by: willdavsmith <willdavsmith@gmail.com>
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.Scanned FilesNone |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Migrate the public Radius and AWS Bicep extension consumers in this repository to the canonical GHCR packages:
latestto GHCR developmentedgein the root and all sample-local configurations, withexperimentalFeaturesEnabled.ociEnabled: truein every effective config. GHCRlatestmeans newest approved stable, not development.:edgereferences to its existingX.Ychannel. Stablelatest, full-version/RC/digest references, custom registries, local archives, settings, and formatting remain unchanged.Reason for change
Related to radius-project/radius#12937. Follows the design merged in radius-project/radius#12980.
This is a consumer companion targeting
edge, not the currentv0.61default branch. It covers development configs and generation of future release-channel configs; it does not rewrite existing release branches or remove the ACR compatibility contract for older released clients. The existingv0.61root still selects ACRradius:0.61, while its sample-local overrides select ACR developmentlatest.Test-tenant ACR configuration, application images, recipe registries, generic ACR examples, and historical release content are outside this change. No packages are published and no registry, cloud, credential, or repository settings are changed.
Pre-merge checklist
br:ghcr.io/radius-project/bicep-types-radius:edgeandbr:ghcr.io/radius-project/bicep-types-aws:edgerestore anonymously from an empty cache. The Radius edge publisher is tracked in radius-project/radius#13119; that PR does not establish supported release artifacts.X.Ychannel using the compatible released CLI.Keep this PR draft until these gates are satisfied. Root-only release pinning is intentionally preserved: sample-local overrides continue to use the development channel. Changing that existing selection policy is a separate follow-up.
How to test
Validation was run against
edgebase5cb53ce20ca709c7665d040197313b342c3ca1b0.PYTHONDONTWRITEBYTECODE=1 python3 -m unittest discover -s .github/scripts -p test_release_bicepconfig.py -vbash -n .github/scripts/release-samples.shshellcheck --rcfile=.github/linters/.shellcheckrc .github/scripts/release-samples.shgit diff --checkawk -v CHANNEL=0.61 -f .github/scripts/release-bicepconfig.awk bicepconfig.json:edgereference changed to:0.61; input remains unchanged.prettier --config .github/linters/.prettierrc.yml --check samples/*/bicepconfig.json .github/scripts/testdata/*.json .github/workflows/validate-bicep.yaml(Prettier 3.9.6)markdownlint-cli2 --config .github/linters/.markdownlint-cli2.yaml README.md(0.23.2)cspell lint --no-progress --no-config-search stdin://README.md < README.md(10.0.0)bicepconfigterm.The existing root
bicepconfig.jsonand README also retain their baseline Prettier formatting failures; unrelated formatting was not changed. Missing lint executables were used from an isolated temporary tool cache without changing dependency manifests or global installations.Fresh anonymous package-authorization probes were run with no production credentials:
Both failed with HTTP 403. Public restore and successful compilation are not verified. The local installed Radius still uses Bicep 0.42.1. Full
BICEP_PATH=<compatible-bicep-bin-directory> python3 .github/scripts/validate_bicep.pyand deployment-based sample checks were not run for this revision; they remain pre-merge work after the artifact/released-toolchain gates. The isolated tests never execute release, publishing, git-commit/ref-update, or deployment operations.File change summary
bicepconfig.jsonand all 12samples/*/bicepconfig.jsonoverridesedgereferences and per-config OCI opt-in, preserving other settings..github/scripts/release-samples.shX.Yrewrite; retain current verified release automation..github/scripts/release-bicepconfig.awkedge-to-channel substitutions for Radius/AWS, with an explicit missing-channel error..github/scripts/test_release_bicepconfig.py.github/scripts/testdata/release-bicepconfig.input.jsonand.github/scripts/testdata/release-bicepconfig.expected.json.github/workflows/validate-bicep.yamlREADME.md