Skip to content

chore: migrate sample Bicep extensions to GHCR - #2678

Draft
willdavsmith wants to merge 1 commit into
edgefrom
willdavsmith-ghcr-migration-samples
Draft

willdavsmith wants to merge 1 commit into
edgefrom
willdavsmith-ghcr-migration-samples

Conversation

@willdavsmith

Copy link
Copy Markdown
Contributor

Summary

Migrate the public Radius and AWS Bicep extension consumers in this repository to the canonical GHCR packages:

  • Map ACR development latest to GHCR development edge in the root and all sample-local configurations, with experimentalFeaturesEnabled.ociEnabled: true in every effective config. GHCR latest means newest approved stable, not development.
  • Preserve root-only release-channel pinning: the release script rewrites exact canonical :edge references to its existing X.Y channel. Stable latest, full-version/RC/digest references, custom registries, local archives, settings, and formatting remain unchanged.
  • Isolate only the two release substitutions in a small AWK filter and run eight safe regression tests in the existing Bicep validation workflow. Retain the current GitHub App verified-commit/ref-update release path unchanged.
  • Document development/stable semantics, full-version and digest reference formats, and compatibility requirements.

Reason for change

Related to radius-project/radius#12937. Follows the design merged in radius-project/radius#12980.

This is a consumer companion targeting edge, not the current v0.61 default branch. It covers development configs and generation of future release-channel configs; it does not rewrite existing release branches or remove the ACR compatibility contract for older released clients. The existing v0.61 root still selects ACR radius:0.61, while its sample-local overrides select ACR development latest.

Test-tenant ACR configuration, application images, recipe registries, generic ACR examples, and historical release content are outside this change. No packages are published and no registry, cloud, credential, or repository settings are changed.

Pre-merge checklist

  • OCI-capable toolchain upgrade merged: radius-project/radius#13075 upgrades Bicep to v0.46.1. A merged toolchain change alone is not a compatible released CLI.
  • A released Radius CLI ships the compatible Bicep toolchain (at least v0.45.6) and passes the GHCR consumer/publish/restore validation applicable to the selected release.
  • Both br:ghcr.io/radius-project/bicep-types-radius:edge and br:ghcr.io/radius-project/bicep-types-aws:edge restore anonymously from an empty cache. The Radius edge publisher is tracked in radius-project/radius#13119; that PR does not establish supported release artifacts.
  • Both packages contain the supported full-version and release-channel artifacts corresponding to the selected Radius release. Release verification/approval and stable alias promotion are complete; development publishing alone is insufficient.
  • Re-run all Bicep compilation and the relevant development/released-client sample checks against those public artifacts. Verify a generated root release config resolves its selected X.Y channel using the compatible released CLI.

Keep this PR draft until these gates are satisfied. Root-only release pinning is intentionally preserved: sample-local overrides continue to use the development channel. Changing that existing selection policy is a separate follow-up.

How to test

Validation was run against edge base 5cb53ce20ca709c7665d040197313b342c3ca1b0.

Command/check Result
PYTHONDONTWRITEBYTECODE=1 python3 -m unittest discover -s .github/scripts -p test_release_bicepconfig.py -v Passed: 8 tests. Both canonical development references, exact pretty/compact output, preservation of stable/latest/RC/digest/custom/local references and near matches, idempotence, alternate channels, and explicit missing-input/channel failures.
bash -n .github/scripts/release-samples.sh Passed. Syntax only; the release script was not executed.
shellcheck --rcfile=.github/linters/.shellcheckrc .github/scripts/release-samples.sh Passed.
git diff --check Passed before commit.
awk -v CHANNEL=0.61 -f .github/scripts/release-bicepconfig.awk bicepconfig.json Passed. Output is byte-for-byte the root config with only its canonical :edge reference changed to :0.61; input remains unchanged.
Read-only JSON/reference and release-script equivalence checks Passed. All 13 effective configs enable OCI; 13 Radius and 2 AWS development references migrate correctly; other settings are preserved. Current release setup, channel calculation, root-only input, GitHub-verified commit creation, and ref updates are unchanged. No active old public extension host remains on this branch.
prettier --config .github/linters/.prettierrc.yml --check samples/*/bicepconfig.json .github/scripts/testdata/*.json .github/workflows/validate-bicep.yaml (Prettier 3.9.6) Passed.
markdownlint-cli2 --config .github/linters/.markdownlint-cli2.yaml README.md (0.23.2) Failed on the same 18 pre-existing bare-URL/table diagnostics as the base. The added compatibility section passes Markdown and formatting checks.
cspell lint --no-progress --no-config-search stdin://README.md < README.md (10.0.0) Failed on the same 18 unique existing technical terms as the base. No new unknown spelling terms; the added text repeats the existing bicepconfig term.

The existing root bicepconfig.json and README also retain their baseline Prettier formatting failures; unrelated formatting was not changed. Missing lint executables were used from an isolated temporary tool cache without changing dependency manifests or global installations.

Fresh anonymous package-authorization probes were run with no production credentials:

curl -q --fail --silent --show-error --connect-timeout 10 --max-time 30 --output /dev/null --write-out 'Radius anonymous GHCR authorization: HTTP %{http_code}\n' 'https://ghcr.io/token?service=ghcr.io&scope=repository%3Aradius-project%2Fbicep-types-radius%3Apull'
curl -q --fail --silent --show-error --connect-timeout 10 --max-time 30 --output /dev/null --write-out 'AWS anonymous GHCR authorization: HTTP %{http_code}\n' 'https://ghcr.io/token?service=ghcr.io&scope=repository%3Aradius-project%2Fbicep-types-aws%3Apull'

Both failed with HTTP 403. Public restore and successful compilation are not verified. The local installed Radius still uses Bicep 0.42.1. Full BICEP_PATH=<compatible-bicep-bin-directory> python3 .github/scripts/validate_bicep.py and deployment-based sample checks were not run for this revision; they remain pre-merge work after the artifact/released-toolchain gates. The isolated tests never execute release, publishing, git-commit/ref-update, or deployment operations.

File change summary

File Summary of change
bicepconfig.json and all 12 samples/*/bicepconfig.json overrides Canonical GHCR development edge references and per-config OCI opt-in, preserving other settings.
.github/scripts/release-samples.sh Use the isolated filter for the existing root-only X.Y rewrite; retain current verified release automation.
.github/scripts/release-bicepconfig.awk Exact canonical edge-to-channel substitutions for Radius/AWS, with an explicit missing-channel error.
.github/scripts/test_release_bicepconfig.py Eight safe deterministic rewrite/preservation/failure tests.
.github/scripts/testdata/release-bicepconfig.input.json and .github/scripts/testdata/release-bicepconfig.expected.json Development, stable, full-version, custom/local and unrelated-setting fixtures.
.github/workflows/validate-bicep.yaml Run the isolated rewrite tests before compilation.
README.md Explain tag semantics, unchanged release selection, stable/digest reference formats, and compatibility gates.

Use canonical development edge references with per-config OCI support and preserve root-only release-channel pinning. Add isolated rewrite coverage and document public-artifact and compatible-released-CLI gates.

Signed-off-by: willdavsmith <willdavsmith@gmail.com>
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Scanned Files

None

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant